ashampoo-burning-studio-12487-dp.exe

Bab

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application ashampoo-burning-studio-12487-dp.exe, “Bab Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Bab

Description:
Bab Setup

Version:
1.6.2.1

MD5:
b6cb2d3cc3aa867a701a1ee38dac2dc2

SHA-1:
663e61261a0259be47d1ff553d297f60e53a0830

SHA-256:
4e611f8c448256c804e8d2012d68483247cfd7be5b59fd32f2a3cadc8165c643

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/15/2024 9:55:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.5.4.18

File size:
951.2 KB (974,072 bytes)

Product version:
1.5.2

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:7vp7y5I5PpEla6JVWwIar2hfWz21GkqfQT7L7/bpoQOGZ/u:jx8culbVzIaKhc2gkqfQTz99Z/u

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file ashampoo-burning-studio-12487-dp.exe has been seen being distributed by the following 23 URLs.

http://www.townbitsquick.com/WVl6OTRQVVJLYVdJMGVteGpVbXcwVlVGb1NVaDFUMnRIVFUxRGIxUnpTVE5GYkZKRVMxbHlhazFCU2paVGJITWxNMFFtWXoxT0pUSkdOeVV5UW1weWVFMWlXVTBsTWtKVU9YRjNka3RwUVhVeVVIZEVSMUpXYVVKelZ5VXlSbmR1ZW1kdFJISTRKVEpHTmxKclNHMXdhSFJMWjJGSmMzQjZORXBHZUVFNVdIRTFTR2hRU0hWT1JXeDRVRkl3Umxrd1lsbHRNa1p5VGpoeEpUSkdSM2hVVkdaU2RFMUVWMmhzWkRGVlJXNVFORVZOZDBFbE1rSk9SamRPU1VzbE1rSk5Wak51UzFnMmJIUktiMk5NVVVNMk56aEJXV01sTWtaTlRtaGljR2NsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3Y3lVellTVXlaaVV5Wm1Oa2JqRXVZWE5vWVcxd2IyOHVibVYwSlRKbWNIVmliR2xqSlRKbWVHVnVKVEptTkRZeE1DVXlabUZ6YUdGdGNHOXZYMkoxY201cGJtZGZjM1IxWkdsdlh6SXdNVFpmTWpJd016a3VaWGhsSm1SdmQyNXNiMkZrUVhNOVFYTm9ZVzF3YjI4dFFuVnlibWx1WnkxVGRIVmthVzh0TVRJME9EY3RaSEF1WlhobA==

http://www.tourcontentdownloads.com/WVl6OTRQVXBzYmtGa2FFaFhTRTlMWkdKWVFVWm1OMGN5UW1wclExaElSalZCZVZCb2RqWmtOVnBLVlZRM1NrMGxNMFFtWXoxdlREbHFkMEZqVVZNM2RqRlhkREpzWlNVeVJrWldKVEpHVFVrNFdtaGpaRVpGY1hKa1pXRlFSVmhWVlVscVJuTnVNbWQ0VGtSNVUzTjNWRmxRUjJaQ2FHMU5Namw1UVhwRWR6QlhhMFUzVmpKVVFtWXlPQ1V5UWxwTU5XcGxTbEYzVTBGblpuUmhWR05DVlVkWlVVeFRKVEpHT1cweU5UQnRaR1Z6YkdWRFZIVkhla3RCWVdreUpUSkdjVzlwUjNBNWRucHJXSFZPUzNsM09EVmpWbEZCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0yRWxNbVlsTW1aalpHNHhMbUZ6YUdGdGNHOXZMbTVsZENVeVpuQjFZbXhwWXlVeVpuaGxiaVV5WmpRMk1UQWxNbVpoYzJoaGJYQnZiMTlpZFhKdWFXNW5YM04wZFdScGIxOHlNREUyWHpJeU1ETTVMbVY0WlNaa2IzZHViRzloWkVGelBVRnphR0Z0Y0c5dkxVSjFjbTVwYm1jdFUzUjFaR2x2TFRFeU5EZzNMV1J3TG1WNFpRPT0=

http://www.tourcontentdownloads.com/WVl6OTRQWE5IVjFSS2FWSm5NalZ1ZFVwVlRERkRkVEpwYVdweGF5VXlRalJZVDFKVFIzTnpiMkZxVjJWRmRsZHRheVV6UkNaalBXUlpKVEpDYWtOaGQwZzRNVVJ2VjNOTWFXcHRiVm9sTWtaWllUSjBZM2xDU2tSNmMzQktTVVkxU1dReE0wc2xNa0o1WVd0TEpUSkdUWHBFYlVvNFprZHpSamxoVFdoeVQycFpZblJWVm14eVJVSkZWa3R4TWpWWVVETjBNVWR2TXpOb05EQm9hMWhDV25wQ1prUmxXR3hsZEZoVlMwVlVZWEJQUjFFNU4xSnRSVGxZV2tScVowUkZkV3c0WkVZd1UyMUhaSFJFU0Vjek1GcHBXRlYzSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0yRWxNbVlsTW1aalpHNHhMbUZ6YUdGdGNHOXZMbTVsZENVeVpuQjFZbXhwWXlVeVpuaGxiaVV5WmpRMk1UQWxNbVpoYzJoaGJYQnZiMTlpZFhKdWFXNW5YM04wZFdScGIxOHlNREUyWHpJeU1ETTVMbVY0WlNaa2IzZHViRzloWkVGelBVRnphR0Z0Y0c5dkxVSjFjbTVwYm1jdFUzUjFaR2x2TFRFeU5EZzNMV1J3TG1WNFpRPT0=

http://www.nowapplicationsranch.com/c?x=T8Lbkhp3Mu5PrFxyuU 4hmukBW/DcPQNrQ49Co9lbq8=&c=CoL4q6BtHMEALc2A7xrQyvpV N32M5YT/wChTmdIBIg42KNvB 4/1nGPeuzCApjuO6u2GIcI2H/R4 CWwS/ uAmdAlT1P1 2 1IokkfZmUUCFcNsDTFCzML6MHf500/M0a6c9EcmnLKkvTAhm62 T sUnNw1meZxHlzjp 5/b2E=&e=0&fallback_url=https://cdn1.ashampoo.net/public/xen/.../ashampoo_burning_studio_2016_22039.exe&downloadAs=Ashampoo-Burning-Studio-12487-dp.exe

http://www.bundlebesthost.com/WVl6OTRQVUU0UmxneWFFRTJNa0ZUV0haQ2JYWjNkMVk1UmlVeVJtdDZUbGM1ZG1sVlVXeDBXa0pUWkRobFlUaDBOQ1V6UkNaalBVWTNSM2d6ZUVSWVlUbG9URlk0Um13M1ZWUmpUU1V5UWpWUVNXZDJabTA0V2tSNFZEQmlNV1IxYVc5MWRUUnhhakJEZEVoMlF6VklVR3hRVTBoNlVEaDVKVEpHT0VoMVJFdDZhamRtUkdkc1ltaHhUR3hJSlRKQ1YzZHpUSGhpTUdSSlRVTTVVazFzUVdnd05YcFljV2c1ZVZCelZHMUVOREZ6ZERKV1VHNW1VSGQxUzFKemMycDJZamRDSlRKQ2ExTllhR1ptU0dOcVQwOXZPSFJSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0yRWxNbVlsTW1aalpHNHhMbUZ6YUdGdGNHOXZMbTVsZENVeVpuQjFZbXhwWXlVeVpuaGxiaVV5WmpRMk1UQWxNbVpoYzJoaGJYQnZiMTlpZFhKdWFXNW5YM04wZFdScGIxOHlNREUyWHpJeU1ETTVMbVY0WlNaa2IzZHViRzloWkVGelBVRnphR0Z0Y0c5dkxVSjFjbTVwYm1jdFUzUjFaR2x2TFRFeU5EZzNMV1J3TG1WNFpRPT0=

http://www.vaultsgrabstock.com/WVl6OTRQVEYyVVRkelJscFpRMWRVY0d4VlUzUnFVRTFIUjBOUGNWWTRiM0p1WmxKMmNFWjZRU1V5Um1sT1VsSkxTU1V6UkNaalBXZFVNekVsTWtaVE5UaHBRU1V5UW01MmRsVlZaMlIwTTNWaVV6UjVjaVV5UWt0a1dtbzFiaVV5UW5oM2FrUnNXRTVyVUVOMk5teEJSWE4wVFU4bE1rWktNSHBEYVNVeVJtTWxNa0pXV0ROSlEyVkZRa1J6UjJOa2VWZHBZbWxUVEc5S1RrRllSbEJKTldkSlRHbExlSE53TkRSSVZqWkpiR29sTWtaV1VERTViakJ0YlRkclIzWTJkVk4yWlVSQk1UbDFSakZVVTNsVFFuaFFWemgzVmt4T2RXRXpkWGNsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3Y3lVellTVXlaaVV5Wm1Oa2JqRXVZWE5vWVcxd2IyOHVibVYwSlRKbWNIVmliR2xqSlRKbWVHVnVKVEptTkRZeE1DVXlabUZ6YUdGdGNHOXZYMkoxY201cGJtZGZjM1IxWkdsdlh6SXdNVFpmTWpJd016a3VaWGhsSm1SdmQyNXNiMkZrUVhNOVFYTm9ZVzF3YjI4dFFuVnlibWx1WnkxVGRIVmthVzh0TVRJME9EY3RaSEF1WlhobA==

http://www.tournowsend.com/WVl6OTRQVVJqUTJSNWVrc3dkbEJVYTI5RWFWVXhhRFIwV0VaTGFVSmhkR1I2UlRkWFpEQnZRVWh1UzJKSWRHc2xNMFFtWXoxcFpUSXlORmRCYXpOaWNuSkVTR1JoSlRKR1ZVMVZVMDFFYTFsSlNHMXZNbEo1UlVFMGVEVnJSVUp2VUVzMGVtazNOVUZoVjI0MFVVVnNVR1IwT1NVeVFtaG9XbkpFYlVoaU4xUklXakJQTlRZbE1rWjVTV1J1ZVV4YVdXSTRWemwwVlVSRllXdEtZVzlOUkc1TU1qSkVUalU1UVVsdFZFZG9XbEJoYVZNM1IxVjVkMlp5TW5wU01IVnpVazlpZGs0NE4wOTVNemx2V2pSVVVHY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndjeVV6WVNVeVppVXlabU5rYmpFdVlYTm9ZVzF3YjI4dWJtVjBKVEptY0hWaWJHbGpKVEptZUdWdUpUSm1ORFl4TUNVeVptRnphR0Z0Y0c5dlgySjFjbTVwYm1kZmMzUjFaR2x2WHpJd01UWmZNakl3TXprdVpYaGxKbVJ2ZDI1c2IyRmtRWE05UVhOb1lXMXdiMjh0UW5WeWJtbHVaeTFUZEhWa2FXOHRNVEkwT0RjdFpIQXVaWGhs

http://www.sendnowtown.com/WVl6OTRQVk15T1RGaWQxSnRSakJ2UWs1bVlUTm9TM1ZMWkdSdFYxVTFiRW8xWlVSRGFEUkhNV296UVhNMVYwVWxNMFFtWXoxTVZIZE9jbHBaZUU5dU1WSkZiMGxRVGtWR1V6TnZkRXhaY0V4NlVHNWlTbWRQUkd4SWRtRkVPV1JNWldGdmRrazFiaVV5UmtwSVEyWTVWMVZNYjNaWmFIcHpiMk5WYkdGT2JFRkpSRVpuVWs1MVZFRkpUSFJXVkRobFkxTXlXWEp3WWtoSVFVbzNjRGR1WjJ4emFYTlBVRUZJZDBkckpUSkNUV1pIZW1oeFkycERUM1JsZW1GV2VUVnpXVEJqTlVGQlkyOU1la0VsTWtJNGRrRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndjeVV6WVNVeVppVXlabU5rYmpFdVlYTm9ZVzF3YjI4dWJtVjBKVEptY0hWaWJHbGpKVEptZUdWdUpUSm1ORFl4TUNVeVptRnphR0Z0Y0c5dlgySjFjbTVwYm1kZmMzUjFaR2x2WHpJd01UWmZNakl3TXprdVpYaGxKbVJ2ZDI1c2IyRmtRWE05UVhOb1lXMXdiMjh0UW5WeWJtbHVaeTFUZEhWa2FXOHRNVEkwT0RjdFpIQXVaWGhs

http://www.dlchuckledl.com/WVl6OTRQVFJaVUc4bE1rWktWVUpWVjNjd1pFVlhTRkEzYlcxNVNYSlRVVUpTTVZsRlpVZHdaVmd4SlRKQ2FHdElaa1JuSlRORUptTTlaMHgwYlVwYWJ6RmFUblpRWWtwa04zUktSa1J2VVdRMkpUSkdkRXhDYzJwMU4zZGtOalpTSlRKQ1JXTjZlR05tYW10c1IyUjNUV1ZLYVhsaVoycFVPR1ZKWmxoU2EwTlFSREZKYlV4bE1EZDRTM0ZoVURCeVZHUTNWM1Z1UldwSldrVkNjMGhWYmtzNE5EQnZhVWhISlRKQ1ZFMTRhV2xPV1RSbmQzRmhSbU5aUVVSeE1tUkxkMjR3VUdSelpVeFVSekZTU0RjeWJrNUhSekZuSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0yRWxNbVlsTW1aalpHNHhMbUZ6YUdGdGNHOXZMbTVsZENVeVpuQjFZbXhwWXlVeVpuaGxiaVV5WmpRMk1UQWxNbVpoYzJoaGJYQnZiMTlpZFhKdWFXNW5YM04wZFdScGIxOHlNREUyWHpJeU1ETTVMbVY0WlNaa2IzZHViRzloWkVGelBVRnphR0Z0Y0c5dkxVSjFjbTVwYm1jdFUzUjFaR2x2TFRFeU5EZzNMV1J3TG1WNFpRPT0=

Remove ashampoo-burning-studio-12487-dp.exe - Powered by Reason Core Security