bfinstallde.exe

Musiclab, LLC

The application bfinstallde.exe, “BearFlix Installer” by Musiclab has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Wise Installer installer. The file has been seen being downloaded from bearflix.en.softonic.com and multiple other hosts.
Publisher:
Musiclab, LLC.  (signed by Musiclab, LLC)

Description:
BearFlix Installer

Version:
6.1.5.1ES

MD5:
1f435fec56b5136996acc24dfe60d38a

SHA-1:
d71f616a01f91c3ec513e1b397146f3e9bcfdb3e

SHA-256:
c84196e2d001398e90da2e33aaa5c8c00a23becb600b6db83f72e8dec9c6679a

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 1:04:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Installer.L
14.11.18.15

Vba32 AntiVirus
Signed-AdWare.Win32.Mostofate.j
3.12.26.3

File size:
3.2 MB (3,396,936 bytes)

Copyright:
Copyright (C) 2006 Musiclab, LLC.

File type:
Executable application (Win32 EXE)

Installer:
Wise Installer

Language:
English (United States)

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/3/2006 8:00:00 PM

Valid to:
5/4/2007 7:59:59 PM

Subject:
CN="Musiclab, LLC", OU=Secure Application Development, O="Musiclab, LLC", L=New York, S=New York, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
0F1C545C6576957E6812260D1416A979

File PE Metadata
Compilation timestamp:
4/8/1999 4:24:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:LeEbviz6EEIjCBc0vGQrtpLgzFhT3PBeiMrNx1:LeEbviOEEIjCBxGQr7wrBk1

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, 78, 05, 00, 00, 53, 56, BE, 04, 01, 00, 00, 57, 8D, 85, 94, FD, FF, FF, 56, 33, DB, 50, 53, FF, 15, 34, 20, 40, 00, 8D, 85, 94, FD, FF, FF, 56, 50, 8D, 85, 94, FD, FF, FF, 50, FF, 15, 30, 20, 40, 00, 8B, 3D, 2C, 20, 40, 00, 53, 53, 6A, 03, 53, 6A, 01, 8D, 85, 94, FD, FF, FF, 68, 00, 00, 00, 80, 50, FF, D7, 83, F8, FF, 89, 45, FC, 0F, 84, 7B, 01, 00, 00, 8D, 85, 90, FC, FF, FF, 50, 56, FF, 15, 28, 20, 40, 00, 8D, 85, 98, FE, FF, FF, 50, 53, 8D, 85, 90, FC, FF, FF, 68, 10, 30, 40, 00, 50...
 
[+]

Entropy:
7.9987

Packer / compiler:
Wise Installer Stub

Code size:
512 Bytes (512 bytes)

The file bfinstallde.exe has been seen being distributed by the following 33 URLs.

https://bearflix.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAOSshH/AKyha564786MBd5K cBEVp8j1uAFiQPpFfEqN9xwjKBzws8bKao57VBlWhZ42O6zrh2utN8UlMdHjslqG8Jh/QFdkDTl4EOCSjibIeMqq4bHlGmLfbfHWFD6TXpXyX5LYeEC71EBpT390VBG36aSLNt2rilHGP g6fGZujm2nYUw2JZoHmR3nDNYE2dVg5wOseAsyU99Ui7260BbcBPWu3vtoz4Lp4a5uOgmrisykwROySkzbP6ZZz51nlV/jtU6cOx9THviXN7BZNKXIIVxtONfMRCC92chJGCLdoHGwx1NtjDfEwITcm/YRA2p97fRk734WuS8iUXFgwRIwVuCrze tzSIcPLfM0etP/gqwTThNCobXQ GYJFzRrj33HkBu8ALYQzj4hzKr00aBEM0exvDSbWzwU0VXpH1QqBXpl7OScDY6tXbCChlO969hQuQXS3CVhCs2eFhzKD3ntqOheoLyY5EZlmLR66RQdlL/.../WhKyGyzFprg7

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1455451581&Signature=XTzvDFrg7g2dvSLMK9iFYAZ4T5FilRNu8S-DklGu92ryBd5fpUur6CHx1NkgnrZ2Q0jKo-m0c~bQO1O7MYh265MzPnChjkzh6JquRmh~85RZWILEVjUJvLdYUm5vQUl~O9el~EspIdJ-SLCormxLvV6KhF4mR7HbplEc1CgtoAo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1460244928&Signature=hTCilkUTvLQMWP7b2YMdhB1y612pInsb~YPJf2CWuWcFHDd1JJsPOYyJk1TDKZTCNSWyIV-xqyT6ZkSxwmeKzglIZEKvUPP5fpPv0spXazCvPrDdzTGPr6SpiBcGpIaIi7p6aiEv-cdgXdXFRLA11n4dcmTgtOrO9zOeD90phtk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1448431656&Signature=RN~gkRdHMmgf-mZEKUR1KXfEhl0hs-6QnAfSiXyuolrEXNVH7~pQxgCdA2JF~RV~dhx9ZpSeOWMZYrbGKbSvQ6IFDH99oCOGbhLqzonJzdTd-sANWvqgg5jOLLC~fqKtTCZbSFOO59MKI2U7cps-aY2PYHOmXfINnL65lW-hkC8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1481769813&Signature=AmrYYbOCMj7AQxckgDSn-8t2IDmS-aeDV8DpNHHc-KHOopG55JelCTvmgiko8kOND-j7Lc9F7SaqzKPqrLB3mC~2RiWqq7O-wwzD8PNJrx2ART1w-RiyslVSdYAdFEk5LeehT9MCgCyJ0-t~arWDBl3tkyMVy7KjNSFFznfGKtg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

https://bearflix.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAOSshH/AKyha564786MBd5K cBEVp8j1uAFiQPpFfEqN9xwjKBzws8bKao57VBlWhZ42O6zrh2utN8UlMdHjslqG8Jh/QFdkDTl4EOCSjibIeMqq4bHlGmLfbfHWFD6TXpXyX5LYeEC71EBpT390VBG36aSLNt2rilHGP g6fGZujm2nYUw2JZoHmR3nDNYE2dVg5wOseAsyU99Ui7260BbcBPWu3vtoz4Lp4a5uOgmrisykwROySkzbP6ZZz51nlUluWKS3xJF/NYG Tp1z1CmF6HYKjzyAVs5nflObhLn2lzFXB9mpzKYPLn4Y4lX8et7EYBDskSTjRFFBWmIjSwKQD0i7Vz5N3vwURPK1HqOSMwet4qsMa1rckm1kU/Z8J/k8BikK 2VqwtTQwAq1aEUrI/Qp0DgF PVkuo1qNtQ3xGwS9kSKnmJNKEucEjODP94pByPtBls/.../WhKyGyzFprg7

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1482651229&Signature=Q~pTXeKJ4fGXRrhdXMA1pTT5BG-ieNo5GX8X3neTXhS32if7zkSPslDcc5uQIc2Y3wyGz4hU8dLwc9cVnrYzLouhdNVW4e4U5qV45sg5d5xHSASP6r3QgxpWIApal~jDxzZmz6I~7HCMTGTFdzONNEBuVBZfkjr9yCGquxdrzcM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1478502787&Signature=YczwXiitEbuVMpnrasm-czp3a8T5TDhmPRjOOmRxsyz4dkTmkmeitRJUHghzV7aOQHMjWj~gVdQLS4n4~K5LOHmjI6c3vjcLEH~OvXPSOs~toGX8pCIIYyd9utBdweLZRpq0HUGfzNn-RfaSU1XQvwVb2Ehpbz0jB5H0SO0ES2w_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1448350930&Signature=VVCxk3ZnP82fdE79i2jFT9P9ceK1q3BpGk4BydOgZ98CZXMcP0rqY5n1m3DilWe8757HdGmaCoSwZp4yG6SxFxj2Jo0yuANrhKrdHBxi10jyAUTIkuz9D3Z1tye4Hd00E6cdLsJIkQTLWH7KkKQAJ5C9lwN8NgagnXstPFaYTAw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1476876829&Signature=Esd40cjPullwTWf9fEuStd6t4vqA6CVjgbbW2LVDQnpx9hs9gaLs59tQEFcxGGr2vSO9aWE0CkH7B8BNifEbSPiKxGzBvsyNT2tIO8oeVjLfCrP3G-saeYsqskTSnFD5xVquZrK5qxC4n01cdzBxdqa8W5SpO5~JATrxMKFSeGc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1479991525&Signature=WwrE7bxKmHVrr9VsdLMsVcSwtlNfk2ZERNn5doekVPalOhm6sUE3yTXYbm7e2mGcXbh4RP8ARuNcDYliIW8eO5tJWnUGvHECus91F2pbNtHnXV20CJ175b56Ch29mfmmgSD4xteL0uKjbXSvVvqQBRzaQu1qe9rnG-Nbco7Ol2M_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://global-shared-files-lw.softonic.com/d71/f61/.../BFINSTALLDE.exe

https://bearflix.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAOSshH/AKyha564786MBd5K cBEVp8j1uAFiQPpFfEqN9xwjKBzws8bKao57VBlWhZ42O6zrh2utN8UlMdHjslqG8Jh/QFdkDTl4EOCSjibIeMqq4bHlGmLfbfHWFD6TXpXyX5LYeEC71EBpT390VBG36aSLNt2rilHGP g6fGZujm2nYUw2JZoHmR3nDNYE2dVg5wOseAsyU99Ui7260BbcBPWu3vtoz4Lp4a5uOgmrisykwROySkzbP6ZZz51nlVZzEGkSdKBiucLO10cG Z75cocp oKVRZPhwy0sJoDwdJBHHPBS1ZAZPRLSbZnHx0XEj8tbdQB eh2ClKhQLR4S7PnTtp5aHauUsynq3uwx39qae/htuRwIpQNrB40eJ9LWOxj4AkeHtSF 6R0LS1RQoo 9hFD1ng5TAtwicTMcZEwLVMcKPKY/ZZngbOcQEgbUZEWk948wsE8zfEJERdWjUjK e/.../WhKyGyzFprg7

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1476829043&Signature=buFVN4M~EALfS4shBjvGEyHzyZU7eeP31b59alr-ss0r1L2Si~fmivSv9BuHHkxGZ4GbvmBLz4wwbHpr6TSsSHRjlRjz879paXGqz8RWoEYHqPOo2LUGKphVF9TEeix6xTOpwA78GTDyVhGHj0MMw0i4mEZ8lH3PNjM5pQhCHhg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://bearflix.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAOSshH/AKyha564786MBd5K cBEVp8j1uAFiQPpFfEqN9xwjKBzws8bKao57VBlWhZ42O6zrh2utN8UlMdHjslqG8Jh/.../WhKyGyzFprg7

http://bearflix.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAOSshH/AKyha564786MBd5K cBEVp8j1uAFiQPpFfEqN9xwjKBzws8bKao57VBlWhZ42O6zrh2utN8UlMdHjslqG8Jh/QFdkDTl4EOCSjibIeMqq4bHlGmLfbfHWFD6TXpXyX5LYeEC71EBpT390VBG36aSLNt2rilHGP g6fGZujm2nYUw2JZoHmR3nDNYE2dVg5wOseAsyU99Ui7260BbcBPWu3vtoz4Lp4a5uOgmrisykwROySkzbP6ZZz51nlUecn1V4OFWFarv5SjNCoUU7LW79n2ugCLYBKnrHM11W/in2qxxm4SR3jsiUEY2AcyaqVkBdC4DquD5d 73wkbZKVRFJwYFOuHNATXoRSruGblcFVUFfdwFrHgmOHqUhpnwqU7x3 Kgcv BVnX0YJQJK7UnvdDTVKtv7EygFxJRLQd iKzD2PqhMKZZ3eKrrKpfEA91HInbDPtrNJ4zBDSKnMfSC icxDJ8VrAmN/Z0rN9u /cbf/.../WhKyGyzFprg7

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1476948564&Signature=AykeH0E7PClsuPFCZ6qcCkbzOQRfDSJ8~AAq~5934cliTi~ZdLu~Vf4qwEsxUlDU4JUeHA9HSz-AS1uz6EzIxG4-FCYXscPL~msmsOd2o6~ac0sAmg2uGkuHfub2pAoc4XW7LkmJD6L332lLMqOBcsjxMy4z4oE~tL37khDmQFU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1475542572&Signature=IW4W6Bc5qVval9pm7RhqfAK7Nxx7F7Ol2BP1Y1QwUhbemBzCQK5aup7l9ycQkQjtWEm5AoHSSz698UUFb-oxWLbVMi0LoFESoBgkTVrAjpbXuV4DnWDfPYUAkVZSoC9ZlB5jPhf1rViP-VJ-rKHI~Cigzgo1ZHLa4tZjgzFObzw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

http://bearflix.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAOSshH/AKyha564786MBd5K cBEVp8j1uAFiQPpFfEqN9xwjKBzws8bKao57VBlWhZ42O6zrh2utN8UlMdHjslqG8Jh/QFdkDTl4EOCSjibIeMqq4bHlGmLfbfHWFD6TXpXyX5LYeEC71EBpT390VBG36aSLNt2rilHGP g6fGZujm2nYUw2JZoHmR3nDNYE2dVg5wOseAsyU99Ui7260BbcBPWu3vtoz4Lp4a5uOgmrisykwROySkzbP6ZZz51nlXJiuZbDC2XY3NdAJPLOTpkFNsHQBCQ8rYzYx/MrfQJRum8AykJJQFX9gy9vhI4aihOv2m8JDHmKbjF4VZkUeRzTTogXwMP3Sg8xtJu0O10By1mqwhe1f/2zUaEv58mA dAB5MngypgNv4mW IXe6QolfNIhh5AT6Og45Dx2EZrxXZEZPDeU7dzl spUxtp/.../WhKyGyzFprg7

http://bearflix.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAOSshH/AKyha564786MBd5K cBEVp8j1uAFiQPpFfEqN9xwjKBzws8bKao57VBlWhZ42O6zrh2utN8UlMdHjslqG8Jh/QFdkDTl4EOCSjibIeMqq4bHlGmLfbfHWFD6TXpXyX5LYeEC71EBpT390VBG36aSLNt2rilHGP g6fGZujm2nYUw2JZoHmR3nDNYE2dVg5wOseAsyU99Ui7260BbcBPWu3vtoz4Lp4a5uOgmrisykwROySkzbP6ZZz51nlVoBMg7Y0uPSX9p6BoqFQsbBExWBbzHg4qDcNR6fV v3ftdvV7InvoaCOiQUjfE3At1pwvEm2lix8vXmJvkME0l9LM7j8RgcX9gAJ2flv0nppXxWFlQG9w/rpZP6sadj4033fhlpS/aUjH69HphLC0N66ibRtEud AtibmbnocFgI2A2kG6gZsIJ0MWHSSbhhEuTSTT8 Gr/LW/nTCulxbrMhO9vSpt7zr/.../WhKyGyzFprg7

http://gsf-cf.softonic.com/d71/f61/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55042&instance=softonic_en&type=PROGRAM&Expires=1446586422&Signature=GjyV~acg5ZN-rPro4eNvrQspnPLUzMRPVKS7KMy5UHf2b1suEV3mttR3U04kcUda8YEwloWuGtTYA8orUXt3MyfOBdq~dAw1sg4Xl~d6sYLimOTtnU7SsKae5RxpqoynT~KzOwbqREiu1SSfUWxgOiPaWX-U~blOa~hqAIrdv88_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BFINSTALLDE.exe

Latest 30 of 33 download URLs

Remove bfinstallde.exe - Powered by Reason Core Security