59574.bubble dock addonsui.exe

Bubble Dock

NOSIBAY

The application 59574.bubble dock addonsui.exe, “Bubble Dock installer” by NOSIBAY has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cdn.bubbledock.it and multiple other hosts.
Publisher:
NOSIBAY  (signed and verified)

Product:
Bubble Dock

Description:
Bubble Dock installer

Version:
3.0.634.0.59574

MD5:
cc550c5fd405a5563ab8170cd9ebbc22

SHA-1:
ecc4bc25f8a4cd4c5fb8b333d65c122d05d3c9e2

SHA-256:
ea69d07d3f87511a80e82b1a3555a4d3c83844f5fc1b58c27dd6ea2940f398cb

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
12/23/2024 1:23:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.NOSIBAY.DD
14.2.16.5

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

VIPRE Antivirus
BubbleDock
22588

File size:
542.7 KB (555,728 bytes)

Copyright:
© Nosibay

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\59574.bubble%20dock%20addonsui.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/16/2012 1:00:00 AM

Valid to:
10/17/2013 12:59:59 AM

Subject:
CN=NOSIBAY, OU=Nosibay Secure Developement, O=NOSIBAY, L=PEROLS, S=Hérault, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
15D415FC07F39945D54BD293F72D8A5F

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:xe34rB3ri0RfDR9/0dZWLMb0Xudr3E3zL6YHey2ZYc6Hknq73ZX8wjveEtt2NB6A:TTBj/02kdr3EjuYz2TqNyEWfXs5mTj

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file 59574.bubble dock addonsui.exe has been seen being distributed by the following 3 URLs.

Remove 59574.bubble dock addonsui.exe - Powered by Reason Core Security