63100.bubble_dock.bbd023.no.exe

Bubble Dock

NOSIBAY

The application 63100.bubble_dock.bbd023.no.exe, “Bubble Dock Installer” by NOSIBAY has been detected as a potentially unwanted program by 16 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from 192.168.1.1 and multiple other hosts. While running, it connects to the Internet address server-54-230-37-203.jfk1.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
NOSIBAY  (signed and verified)

Product:
Bubble Dock

Description:
Bubble Dock Installer

Version:
3.0.705.0.63100

MD5:
6cfc89e105878e4d0a6e1532dcbb0b46

SHA-1:
1f0f9a64110c3dcf1fd3203c35b8de9c8d366ac7

SHA-256:
e0656056cffd5fcc45e69fcc1c2e9f133cbff05ad170007c47283070ba2fc9b0

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
11/22/2024 9:06:15 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AVG
Generic
2016.0.3106

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Downware.10519, Adware.Downware.9155
9.0.1.05190

ESET NOD32
Win32/BubbleDock.A potentially unwanted application
7.0.302.0

Fortinet FortiGate
W32/Bubble_Dock.A
5/18/2015

IKARUS anti.virus
PUA.BubbleDock
t3scan.1.8.9.0

K7 AntiVirus
Riskware
13.204.15934

Malwarebytes
PUP.Optional.Nosibay.A
v2015.05.18.05

McAfee
Trojan.Artemis!484039B92DF4
17.6.569.0

Panda Antivirus
PUP/Nosibay
15.05.18.05

Reason Heuristics
PUP.Installer.NOSIBAY
15.5.18.5

Sophos
PUA 'Bubble Dock' (of type Adware)
5.14

Trend Micro House Call
Suspicious_GEN.F47V0514
7.2.138

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Threat.4791953
39486

File size:
6.6 MB (6,916,112 bytes)

Copyright:
© Nosibay

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\63100.bubble_dock.bbd023.no.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/25/2014 2:00:00 AM

Valid to:
12/26/2015 12:59:59 AM

Subject:
CN=NOSIBAY, OU=Secure Application Development, O=NOSIBAY, L=PEROLS, S=Hérault, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
52E368957AD1C7202A103C7CFD7BD6C2

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:of/jXNOmyT7vCpN2cQ6Qw88JD8KuOoUGJ/GiS:iTEbTZcQdwtad1/GiS

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 63100.bubble_dock.bbd023.no.exe has been seen being distributed by the following 7 URLs.

http://192.168.1.1:8181/http://cdn.bubbledock.us/setup/us/.../63100.Bubble_Dock.BBD023.no.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to server-54-230-37-203.jfk1.r.cloudfront.net  (54.230.37.203:80)

Remove 63100.bubble_dock.bbd023.no.exe - Powered by Reason Core Security