hotspot-shield-5.3.2.exe

Cagolig

Destiny Dream S.A.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application hotspot-shield-5.3.2.exe, “Cagolig Setup ” by Destiny Dream S.A has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.applicationbesttowers.com and multiple other hosts.
Publisher:
Huful   (signed by Destiny Dream S.A.)

Product:
Cagolig

Description:
Cagolig Setup

Version:
3.6.3.0

MD5:
63beceb8cec2dbe6235122e953e663a8

SHA-1:
541243d130033a2185e9531eaeee905d77319a09

SHA-256:
d3f4bd965eb1276f8ab58246ff1fbdb487e3e0c9e1569565237e3550769fffb6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/27/2024 4:24:01 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.DestinyD.Installer (M)
16.4.25.19

File size:
989.7 KB (1,013,448 bytes)

Product version:
2.0

Copyright:
program

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\hotspot-shield-5.3.2.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 4:55:11 PM

Valid to:
10/2/2016 5:36:18 PM

Subject:
CN=Destiny Dream S.A., O=Destiny Dream S.A., L=Clarens, S=Vaud, C=CH

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11217A75EB912AE2167326222C18D9E2357F

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:qo9v/Sb8ISdMPNf/kLkfz8HF2+7jDBVCyP39KvlDVJx:q6SkaPNXkQfziF2sjL8l/x

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9262

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file hotspot-shield-5.3.2.exe has been seen being distributed by the following 50 URLs.

http://www.applicationbesttowers.com/WVl6OTRQWGxrVjJKdWFERm9Xa2RtYVVObVZXWXpOR2RpV2tKNFVtaHZaV01sTWtKcVVVZ3hSMWhxVlZsTGMxcGpZeVV6UkNaalBVSlRhME5yTXpOVWRVbEdhblJrWTB3M01FRmFja0ZRYmpWSlFWaGFTWE5xVG1SbFVHaE9lR05hYWxkNWRXbEViMmw0UVRsdVFURTNWMmd5VG5salNESkNSMUFsTWtKeWFrNXZVRXBaTW5KUGVGSldTV1ZhVUdSek1uZHFkVWxHYlZvemVqSk9iMjQ1VUVOUWVtSkZOeVV5UWlVeVFqZFBabWwzTjNad2IyTWxNa0k0ZDNKSmRFVnJjWEZhVUhWNWFGUjJjM0ZaYWxobGJsQjNhWFpCSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBXaHZkSE53YjNRdGMyaHBaV3hrTFRVdU15NHlMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0wRWxNa1lsTWtadGVXUmhkR2t1WTI5dEpUSkdKVEpHWkc5M2JteHZZV1FsTWtab2MzTXRkMmx1TWlVeVJraFRVeTA0TURFdVpYaGw=

http://www.gifttowndelivery.com/c?x=OSVtrfTDyw/InJF4D9LnfblMgZjPbcOQNS8dbSjjD A=&c=OW1TZNHdFP9PVzl5qifo7Adk5O9r5hRQ4H/wc1wauNih84YPuX6hshTWetTb/IuNQ7TENYgqQDkCK ZbdcTYbowkpsrJmjcZNs6AZPCCUSXgfSBkI2EZ3l7kbhl4mxogNni/JzUEFUcGP5Ryjm6eyQ==&e=0&downloadAs=hotspot-shield-5.3.2.exe&fallback_url=https://mydati.com//download/.../HSS-801.exe

http://www.softwarebundlebulk.com/WVl6OTRQVGd3Wm5SVFZqaENWbWxVZW1vNGNWaHBlVzFKYTJWalZFNWtkbVJJUm1zMWFFcG1aWEI0ZWxOS01sVWxNMFFtWXoxelUzZ3hNbmw2ZUc5WlVVRndVVEJVV0hkcWJFdFplV05MU3pOUlltVk1aM2RuYjNOeFFta2xNa1pvYVU0NVZUVm1aM3BrTVhkRWR6RmxlRk0zTmxaT1ZVRkNlVFUwYm01ek1rVlViMUp2YzNkb0pUSkdPSEJOZFdwamIwZFZPR0ZYZURoS01tNGxNa0pTU1hWbVJFdzJVMjlIWWt4RVNFOUJZM294ZERNM2JqbGhhMnRwY21kUGNtMXhjVVZqYjFKbFptMXRaV1ExWmxWaFltY2xNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05YUc5MGMzQnZkQzF6YUdsbGJHUXROUzR6TGpJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndjeVV6UVNVeVJpVXlSbTE1WkdGMGFTNWpiMjBsTWtZbE1rWmtiM2R1Ykc5aFpDVXlSbWh6Y3kxM2FXNHlKVEpHU0ZOVExUZ3dNUzVsZUdVPQ==

http://www.centergiftcontent.com/c?x=SYHWyq5aenn1kx3zCZUdpB1IEcCXIKg6aiRkO5BGBzE=&c=oz/3e/QfkZ kGkqeWnSZvCuGC5epWrRdzX0qZssK asCenvbMNurhtXVxV9rV7pVd9wj0nhqszBnaR7vxZmcoIaPA0Y31ZrvMQ5KYVL9cnO60viTSxEO9ZXxV10SxCoaSzalSGAHo2dq2nmMYe2z8Q==&e=0&downloadAs=hotspot-shield-5.3.2.exe&fallback_url=https://mydati.com//download/.../HSS-801.exe

http://www.contentsoftwarepackage.com/c?x=z6gvxd3IiRTrnxCetywDGGD36mEFj5NmWq06dPsmAOk=&c=gjd1CHWRszykA881XmempMeR/5JoiwiFSeh1BqRC50peW4b4qwxW0kEL8nenLKnaO9VuLceYQpDgRjL 7oxuMtoBolrPVBsI5E968MLvZA4w4k7T3tJKRxxtG 6izfQ9I0XtuFA97cpLdUnI8d2gbQ==&e=0&downloadAs=hotspot-shield-5.3.2.exe&fallback_url=https://mydati.com//download/.../HSS-801.exe

http://www.contentsoftwarepackage.com/WVl6OTRQVnBCUzFKR1NDVXlSalJFVGpsWFRFZG1Oa05IVURsS1dXbHNjelpoYzNCSFZDVXlRbGs0UTFNelNETXpPVkZCSlRORUptTTljek15TUU1SlRuaFlRbUZpY2pJeFRERnlTREEzVEZsSVZsRk9UVFJ6WmlVeVJsWndhMEpEVjBWRVRESlJWSEF5VjFkd1RWZGFXSFpaT0daa2FUTkhhME56TkhnbE1rWnpNMUVsTWtaMVYwTnFSSEJ4YlRGbGRrVTBWVWhIVGt3eE0yRmhUSGR3V1c5WlJXMVhla0ZPTm0xbWJWbFVTV2xaZGpGSlRqbHRKVEpDU0ZwRGFYUlpaWEJvV21WYVkzTk1OekZWUlVJMWVIVkxOMGhpZGtFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlhRzkwYzNCdmRDMXphR2xsYkdRdE5TNHpMakl1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd2N5VXpRU1V5UmlVeVJtMTVaR0YwYVM1amIyMGxNa1lsTWtaa2IzZHViRzloWkNVeVJtaHpjeTEzYVc0eUpUSkdTRk5UTFRnd01TNWxlR1U9

http://www.applicationbesttowers.com/WVl6OTRQV3MzUVcwbE1rSnBZMDlaZGtoRlkxQnlReVV5UW01d1NXVnBlRzVFVnpVMlZWcGxUMHcwU0ZCRFRFZHRUV1JqSlRORUptTTlVakZFTkcxU0pUSkNSRkpLYVZONldsQllURW8zYmtSSFVWZG5NSG8yV1ZOQk5FNHlVbmxwYlU0MVVpVXlSbmhhYkV0TVdGZzViaVV5Um5sSVdsUjZhbTkwVjB0SVNGTndUMEkyTWpGWWRtOWFhR2xYUXpobFVFOUdabk5uV2tWMGEwbElkRUZHUmxaYU5HdHBWVWhMVDJoNk9Ib3hhRUZXZW5sQmJta3lkWEJrZFVkalJucGxhMGhuVTNGcmVERllSVEpsVFdScFNXaFVWMjluSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBXaHZkSE53YjNRdGMyaHBaV3hrTFRVdU15NHlMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0wRWxNa1lsTWtadGVXUmhkR2t1WTI5dEpUSkdKVEpHWkc5M2JteHZZV1FsTWtab2MzTXRkMmx1TWlVeVJraFRVeTA0TURFdVpYaGw=

http://www.contentsoftwarepackage.com/WVl6OTRQV0ZvU1VScFpVSlVjbmhoWW1ZNFdWSWxNa0lsTWtKaFpGSXhVVFpzT0daS1JFRm1lVTVNVEZSR1YybDRUMnB6SlRORUptTTlUWGgzUTNGWlpTVXlSbE5uYzJ0YVFVUkxOQ1V5UWpKQ2EySnhOVUZUTjBST1RWaHRUM1JISlRKR2F5VXlRblYwY0dablZYYzVaMEZGU1VSWFpuUk5RaVV5UmxGRlZYRjFhVVEwV1ZKWWRFOTRValVsTWtKbFNDVXlRblZUYlU0M2VIZFRWbGx2V2pFNFJuSlFaVVk0V2pjeGEyRklhMnRpYkVWaGVrZEZPVFJzWVc1bVdGcGtWVGh6WTBnNWNYQmxiRXRDTWtwM05FNXFkWFpIZFZSTGRHTlJPSGNsTTBRbE0wUW1aVDB3Sm1SdmQyNXNiMkZrUVhNOWFHOTBjM0J2ZEMxemFHbGxiR1F0TlM0ekxqSXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3Y3lVelFTVXlSaVV5Um0xNVpHRjBhUzVqYjIwbE1rWWxNa1prYjNkdWJHOWhaQ1V5Um1oemN5MTNhVzR5SlRKR1NGTlRMVGd3TVM1bGVHVT0=

http://www.nowfactorymeta.com/c?x=kryXFBVGOIv7AOpK10yEt04WhifeBgBtHWtKLo HkmU=&c=blf2Rxa6lPYkKNo5PJgCSLLFU9SvQHGBsyPMa5462bULCpdAujI8JkW7dj5kwXSf0WMIj71unn3oNY6VfUKC/hrBo5ku6DLTkPkITEE6M sqNoBEnjLWwft7L55ADyzOI3xbZa9aYvR2rWda ojscQ==&e=0&downloadAs=hotspot-shield-5.3.2.exe&fallback_url=https://mydati.com//download/.../HSS-801.exe

http://www.deliveryvaultsdelivery.com/c?x=fQuYqGuMgSUBDugCokNpcWezPq3SxtlRgcxgd0Zwjcw=&c=uhFNUgs6ZHJSAxSCLQkjxPM3AcuHYgxr8lfv1KU5nql2oheGf9Hox4KOSvueqE3p5ZI1w ON9OdCgtMvaBCrtelIVPQtET11TNXjb8zLrQD47FuDK4aG0G O XzgcyqinQjutg6lw0B9u1W9AwZiUA==&e=0&downloadAs=hotspot-shield-5.3.2.exe&fallback_url=https://mydati.com//download/.../HSS-801.exe

http://www.tagsendheart.com/c?x=B2CooIeaCxyoeFNwrS8wfMLUta4 0aE40spY8atkBQM=&c=E8DUuOCtBCnrEaAVWVQgNZomMjwY1W5cQ5q ZJhE8uoKeYqom 247nRijHwy /TMu4C5SubGdgyPgHau8oWG4R82r5USN6ujHtyUeYyf5Z1d5hE4IxbY9uZqJCVjpb/4x36d0aSHSiRaINDZGinVOA==&e=0&downloadAs=hotspot-shield-5.3.2.exe&fallback_url=https://mydati.com//download/.../HSS-801.exe

http://www.deliveryvaultsdelivery.com/WVl6OTRQV05zZW5GVWFIRkxkRGRQVUVzM1MxbHVZVkFsTWtaUmJYZG9UbXA0VUZkdFpuUlFjRTVTVWpadFJFRXdZeVV6UkNaalBWVk5XVGgwTnpONGNFSmFlR3BOUjNGc2RtWkphbVZCSlRKQ0pUSkNSM0pNU0NVeVFrWkZjRmhIYms4bE1rWTNaVkpqZFVaWFdHbFpjM3BxVldkcVJFUktWV3hpZFZJd09USlFhamxuZVc1SmNIVm9KVEpDUVV0VFEzVXpVWFJOUjNwRWVFVldaVzlVYTFNek9EVllkRXBQYkdsRllWRWxNa1pJZDB0Mk1rUlNORnBuU1VwWFJYazNSall3VUVoTk1XZzBNREVsTWtKdVRESkRaMG95WkhkR1QzUlJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFdodmRITndiM1F0YzJocFpXeGtMVFV1TXk0eUxtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjSE1sTTBFbE1rWWxNa1p0ZVdSaGRHa3VZMjl0SlRKR0pUSkdaRzkzYm14dllXUWxNa1pvYzNNdGQybHVNaVV5UmtoVFV5MDRNREV1WlhobA==

http://www.centergiftcontent.com/WVl6OTRQVFI1UzBobVluaEdURFpUZEZvNVQzRWxNa0pZY2lVeVJrUWxNa1pRUTFSVmRHbzRTV1ZQUVhkaU56bHVlbGg2UVZrbE0wUW1ZejFVYjNSSlVrWnZhMDlLUlRsM1prNHdNVEZxWmxGVmNsZFVUR1U1T0VoeVVtTk5OVUUwVUdScFdGUlNTVVkwY0RKSk1FaFRkVzUyU2tSMWQwa2xNa1l6SlRKQ1Z6UkVkWEpzUVdWbU5GWlRlblpDYUVSYWMwUTNaMVZ5UVUxTmQyNHdhalZNTTFKMVdIbHBabGxQVW10RlNXc2xNa0poU2s5b1kzcHNielptWW01Wk5FMU9SV2RWYm5Sc2NrSTJKVEpDUnlVeVFscG1RMlJaYUVaaldrZEJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFdodmRITndiM1F0YzJocFpXeGtMVFV1TXk0eUxtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjSE1sTTBFbE1rWWxNa1p0ZVdSaGRHa3VZMjl0SlRKR0pUSkdaRzkzYm14dllXUWxNa1pvYzNNdGQybHVNaVV5UmtoVFV5MDRNREV1WlhobA==

http://www.headconceptsuniverse.com/WVl6OTRQVUpxVmtRbE1rSmxZM0JhWjBoMmNUbHNZV0ZrWm1SWE0wbE9ka05pWVVaRVJHZE1ia3hUUVNVeVFuVnBjVE52SlRORUptTTlKVEpHV0VJeVVYZG1KVEpDTkdseGIwWXlRbWMwZVZwV1VFTkhSbGhRT1dsMmMzTldka2hNUkRNNU5XdzVNVUZHTVhwV1NYTjBiVmxxWms5VU9VTXhZWEYzYTFscU5uZ3hiREpQT0dKcVZGcHJRakJJTm1JbE1rSkxWbWxUYWtrM2FtOVJXbU0zVldzM1dYQjRWR3hGZWpsVmJIbzBWblptZEdOaFlXa3piMVZHZVhsRVNXZDBNU1V5Ums1TGRFOGxNa1pLYmtneFYwMUJTMmQxYkZsRFFTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFvYjNSemNHOTBMWE5vYVdWc1pDMDFMak11TWk1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQnpKVE5CSlRKR0pUSkdiWGxrWVhScExtTnZiU1V5UmlVeVJtUnZkMjVzYjJGa0pUSkdhSE56TFhkcGJqSWxNa1pJVTFNdE9EQXhMbVY0WlE9PQ==

Latest 30 of 135 download URLs

Remove hotspot-shield-5.3.2.exe - Powered by Reason Core Security