windows-movie-maker-11546-dp.exe

Kisi

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application windows-movie-maker-11546-dp.exe, “Kisi Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Sacip   (signed by Mode Beta (Fried Cookie Ltd))

Product:
Kisi

Description:
Kisi Setup

Version:
3.2.2.4

MD5:
16c9f219f6ca0ea56bac8fbde6729c1c

SHA-1:
ef76714f73406c3bec426a0666cfb23a10e51314

SHA-256:
5d5a61bd9665bba13e706bb20b892673bb29c235a518dc07195ccdf254ca351a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/28/2024 7:59:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.4.21.21

File size:
952.6 KB (975,504 bytes)

Product version:
4.4.2

Copyright:
File Lite

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\windows-movie-maker-11546-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:cjJz9OiMv1hlYlmHZRY5L5H/9x7NJXH6:clZMb/5RYRV9h36

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file windows-movie-maker-11546-dp.exe has been seen being distributed by the following 45 URLs.

http://www.gifttownsign.com/WVl6OTRQVWQyUTJrbE1rWTRiREp5ZDJ0U0pUSkdjbEZHWkhBbE1rSlpkVlo0Tm1WeE5WaEdSa0pCVFRsQldTVXlRbFJCUTJKNVRTVXpSQ1pqUFVobFVYVkxialJCUkVZNE9YWk5RMHQ0UkcxaVVDVXlRbmhoZVdOaFFraHdlRXB4WmxSdFVpVXlSbk5VUXpFeVRXRlljMU55TVZNeFlsUlFTakZQVVhGM01GZEpPRXAzYVRkUUpUSkdOV3RWVlVzbE1rSkRKVEpHU2poblRtdElaR2tsTWtKVFYwMXVRbEYwUXpSUFpWVnpabFJhYTJaU2RWTkNZVkk1Ym1rMVIzcFFjbko1YWtGRVNERXdXakpHZFdab0pUSkNWSEZZUjA5TGRHMVZlU1V5UWtkNVZGRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1iWFZzZEdsdFpXUnBZU1V5WmsxTk1qWmZVRXdvWkc5aWNtVndjbTluY21GdGVTNXdiQ2t1YlhOcEptUnZkMjVzYjJGa1FYTTlWMmx1Wkc5M2N5MU5iM1pwWlMxTllXdGxjaTB4TVRVME5pMWtjQzVsZUdVPQ==

http://www.capitalsoftwaredownload.com/WVl6OTRQV0V5YzJGNVkxQkxWSHBtY0VaNk5tUlljVlF5UzNOc1pVeHNNVFI1WkVkTVJVdDVUV3RFU2xkRFdVMGxNMFFtWXoxemJURkhZbnBvVjNCT1ZHZGlRM0pWYkRkS2VsWjFVMlJETnpSeFFrTlFjMnhMT1hwYVZtRk9WRnBZTkZreGNqQjRibUZNSlRKQ1dFZFBUMUZ6VVdwSFVWbzJSbmhYUm1Gb01HTTNlVzl2U2tKdWFYUmliM3AxZVhWRllWQnlRM0o2UTBaRlEzRkhZek5EWVhRelZsTkVkMHB2ZFdsV2FVaDFSalpLVTJsbWNXcEtTRmxwYUhGTlFXdEhjRnBGU1VKMFRDVXlSazlCUzI1bkpUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpZU1V5WmlVeVpuTjBiM0poWjJVdVpHOWljbVZ3Y205bmNtRnRlUzV3YkNVeVptMTFiSFJwYldWa2FXRWxNbVpOVFRJMlgxQk1LR1J2WW5KbGNISnZaM0poYlhrdWNHd3BMbTF6YVNaa2IzZHViRzloWkVGelBWZHBibVJ2ZDNNdFRXOTJhV1V0VFdGclpYSXRNVEUxTkRZdFpIQXVaWGhs

http://www.capitaltoursoftware.com/WVl6OTRQVmxrYm1kSmMwVjZTbkl4U1VOc04wWnJTVnBGWldjMGVEZFFheVV5Um5reVluTk5aVUZFYWs5blMzSkVaeVV6UkNaalBXNVpkRkJuTjNWa1NtaFBZVk54Vm1ObmMzRkpjVTB3YjFwV1JEY2xNa0pwT0ZaU1kwOHhOM1J5VlRreVJYUWxNa1pzTkROTlZVZHBRU1V5Um5ad1owRkRXRkpTTmxSblkyZHZOSEJrY25oWU1VTm5NV295VTAxaFRHVTJZazFJZEhCaGIwNWlhMlprUW5KSloyTnRja3B2YXpka2NEQnJKVEpHY1dWR2FGTlNWRXhLTmlVeVJrOVJOWGx5ZUhKVEpUSkdPVk5EWWpaUlVtNXplVUprY0V4elVTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWnRkV3gwYVcxbFpHbGhKVEptVFUweU5sOVFUQ2hrYjJKeVpYQnliMmR5WVcxNUxuQnNLUzV0YzJrbVpHOTNibXh2WVdSQmN6MVhhVzVrYjNkekxVMXZkbWxsTFUxaGEyVnlMVEV4TlRRMkxXUndMbVY0WlE9PQ==

http://www.capitalsoftwaredownload.com/WVl6OTRQWEUzYnpoMmFrWnZjMloxWVVKS1ExVlNWQ1V5UWpCbmFtUk9jR0l4Y0VkU1ZHOUhUMVF5Y1c5elUwWkdNQ1V6UkNaalBXeDVWMlo0WnpGeGEwdGxVMEVsTWtKWGNVTmtha2RRVWtaRGQySWxNa0poVkdseVVHb2xNa0l5YkdGUFVHSkNNSEl6WVdaemNGbEtXbGhKUm5Rd1QySnRkMGRKY1ZOc09YVk9aazk1UlVGWloxaE5aR1ZYY1RCSFdUbElVakJwUmpkdFduTnhhRVZGU1cxcU5YZHlaR3QwUlhaaEpUSkNka3RCUW0wMWFHSktObk5KVGpCU2VtUkRZa1pNYlc4MVMyOTVKVEpDVG5rM1NsWklNRkFsTWtZd1VTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWnRkV3gwYVcxbFpHbGhKVEptVFUweU5sOVFUQ2hrYjJKeVpYQnliMmR5WVcxNUxuQnNLUzV0YzJrbVpHOTNibXh2WVdSQmN6MVhhVzVrYjNkekxVMXZkbWxsTFUxaGEyVnlMVEV4TlRRMkxXUndMbVY0WlE9PQ==

http://www.farmtowntowers.com/WVl6OTRQWE5SU2xoV1dtZHNWbWxYVjNkQmVFRlNNMjVtTVhnMWFGQnNjbmRET0hocVFVRkxSRVJrV1RSRFpqQWxNMFFtWXoxaFVVZGxkWG80WjJvNVlXZ3hTekZoYkdGR1JXRmlUMlF6T1U0bE1rWmlWRWQyYW5CeVlUWkdkVVZ4VUdSWGJYRldPVmQyUlhkMWEyUnNVek54VEdSb1MyRnZjMWxrYUV0V1ZHeFViV3R5YldsMmRIQklPRlYyV1RRM04wcHROakkxVUdacFRUTlhkVzFvVVdjNVYyMUVSRlp3TkRGblVtWkxOV00yYzNsM1Z6ZEJWM3BsV1ZWbFRucFRkWEpDWkVKMVUxZHZRVTFLUVNVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aemRHOXlZV2RsTG1SdlluSmxjSEp2WjNKaGJYa3VjR3dsTW1adGRXeDBhVzFsWkdsaEpUSm1UVTB5Tmw5UVRDaGtiMkp5WlhCeWIyZHlZVzE1TG5Cc0tTNXRjMmttWkc5M2JteHZZV1JCY3oxWGFXNWtiM2R6TFUxdmRtbGxMVTFoYTJWeUxURXhOVFEyTFdSd0xtVjRaUT09

http://www.sharerepositoryhosting.com/WVl6OTRQVGd5ZDFVelJYSTNWWEF5VDJSRGNEVklOR1UzVldWU1RFWTRaRmhLU1VKdmQxQnZkbXBDZWxOTVdXTWxNMFFtWXoxQmFtOTRORU5MZVZkbVVUZEhjMUZwUjNacE5GaHZlVUZrT0ZKRk4xaDBUM3BNWVNVeVFuTTVRbWgxZWtwQ2VWRWxNa1pMWVZGc1JGQXdTVXBNYTNwRU1rVkRKVEpDYlVOdFJrNUhjbE53ZDNGblVsZHhTRVp0ZG1oVWRuTmtRV2xPUVd0NUpUSkNWek5ZV0UxSmNFczRUbHAzV0hSVk1DVXlRazlpUjNveE5saE9KVEpHTjI5c04yUlNaRTVJTUdoeU5tNU1TbXQwVFU1M2EwNGxNa0o0VUZOTFFTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWnRkV3gwYVcxbFpHbGhKVEptVFUweU5sOVFUQ2hrYjJKeVpYQnliMmR5WVcxNUxuQnNLUzV0YzJrbVpHOTNibXh2WVdSQmN6MVhhVzVrYjNkekxVMXZkbWxsTFUxaGEyVnlMVEV4TlRRMkxXUndMbVY0WlE9PQ==

http://www.sharerepositoryhosting.com/WVl6OTRQVlJFZDBkNmR6ZFRXRlZwVFVJMVJscFFlSEJIWkVWWFFYcFBOMmxWYTFCWVdEZFNibXhOTlUxWFNUUWxNMFFtWXoxMFVtNU5KVEpHV2xVeGVIcHBibXR4VTBWMFl6QTJhbE5pTTNKMFRYbFNWR3A0U205dmJ6ZEpiMEZ6ZWlVeVJtWmtUVmhoT0RSVlFsQTVSbWxLT1VGeE1raERWR1F3VkV0MFIxTnliRlZJTTJaWldrcGxNVE42YzJ0bFlqZFBjemhtTkNVeVJtMUhKVEpHVEUxWlJXeFdkazF5UzBOT1JUbENSVlY0ZVUxbmRHeDVjblZKWW5seE9XcHhSM1Z2WVRaWmVqUmtRbFlsTWtKalpWVm9RV1JSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm0xMWJIUnBiV1ZrYVdFbE1tWk5UVEkyWDFCTUtHUnZZbkpsY0hKdlozSmhiWGt1Y0d3cExtMXphU1prYjNkdWJHOWhaRUZ6UFZkcGJtUnZkM010VFc5MmFXVXRUV0ZyWlhJdE1URTFORFl0WkhBdVpYaGw=

Latest 30 of 45 download URLs

Remove windows-movie-maker-11546-dp.exe - Powered by Reason Core Security