61046.bubble_dock.bbd023.no.exe

Bubble Dock

NOSIBAY

The application 61046.bubble_dock.bbd023.no.exe, “Bubble Dock installer” by NOSIBAY has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cdn.bubbledock.it and multiple other hosts.
Publisher:
NOSIBAY  (signed and verified)

Product:
Bubble Dock

Description:
Bubble Dock installer

Version:
3.0.643.0.61046

MD5:
96b39ca576a64ceaebe2ac4d71555ac7

SHA-1:
ba77935ac9a5aef0426d45f6f94b3e7cd3b75836

SHA-256:
7c9910b096115ee86a310e79c37d9da30747499fdd458543496d3a18a8085572

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
11/22/2024 8:35:51 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.BubbleDock
2014.07.07

AVG
Generic
2015.0.3420

ESET NOD32
Win32/BubbleDock
8.10056

Malwarebytes
PUP.Optional.BubbleDock.A
v2014.07.07.12

Reason Heuristics
PUP.Installer.NOSIBAY.Y
14.7.7.12

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
BubbleDock
31048

File size:
6.5 MB (6,860,744 bytes)

Copyright:
© Nosibay

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\61046.bubble_dock.bbd023.no.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/21/2013 2:00:00 AM

Valid to:
11/21/2014 12:59:59 AM

Subject:
CN=NOSIBAY, OU=Nosibay Secure Developement, O=NOSIBAY, L=PEROLS, S=Hérault, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4F1CA396B891ED381AFEECC074DB8714

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:+LYgw6QCGhSYXFm96f/G/XwfRDHIZnEet6EzAv:cXNQCenXUBXKTIlKdv

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 61046.bubble_dock.bbd023.no.exe has been seen being distributed by the following 3 URLs.

Remove 61046.bubble_dock.bbd023.no.exe - Powered by Reason Core Security