installer_microsoft_powerpoint_sciagnij.exe

Debegarune

AGORA S.A.

The application installer_microsoft_powerpoint_sciagnij.exe, “Debegarune Setup ” by AGORA S.A has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.packagenewsend.com and multiple other hosts.
Publisher:
Beseg   (signed by AGORA S.A.)

Product:
Debegarune

Description:
Debegarune Setup

MD5:
e450e04d1754537aa6d2d3d0c5d1a956

SHA-1:
1c0da21fed918162425ba959a426964f9b0fdd2d

SHA-256:
f420cba647d20d8e15952fe855539a17fedea771e0b343db2b92cb55c08ac077

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
9/29/2024 8:38:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AGORASA.Installer (M)
16.4.13.18

File size:
923.3 KB (945,416 bytes)

Product version:
1.0.3

Copyright:
Fast

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\installer_microsoft_powerpoint_sciagnij.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
9/9/2015 2:00:00 AM

Valid to:
9/9/2016 1:59:59 AM

Subject:
CN=AGORA S.A., O=AGORA S.A., L=WARSZAWA, S=MAZOWIECKIE, C=PL

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
615B57E3504C929E3B64ED936D1CE68B

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:VwcSeGbEsZPjsFsNgE0NqxzJVd74pgZnO0G0I0STS89EirLZfk:VPwPwiNOAzJ0GZnOAbSu8WirLNk

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file installer_microsoft_powerpoint_sciagnij.exe has been seen being distributed by the following 50 URLs.

http://www.packagenewsend.com/c?x=HLRDtPhsjE4jEOCLKQzR3a29hZ2/rfLBmhpToXHUq0s=&c=Jf0r3o4VTNnDmN9pKeFSqV3gE8Pc6aYf/pHquHnjRvzfPueiAHrYMCSvEiSvB/k7EtFXAyQjM5t0NM/JjNw6bxly8UciF9WwdstOY7xzb54YJcx2HcCapzPcdQdPeGXbmxmD6/45E0QABXGLo/NaGg==&e=0&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_PowerPoint_sciagnij.exe

http://www.packagenewsend.com/c?x=oGPoK94vjLcYNOedcTswB54lCNh8eh4ROvEpOcLOCbQ=&c=H1TSpe9hZ 1ulCPHGOLOUbtKya65XUIUPcfaPpetdwb9JGcRxVtYmV9DgUuSq0XEg1TVFN36wxm2MRCRvIx95PbiVO0IpZaVhGknNF6YxEyVms5azJNvVxr/OtnGjeEnBKaPsdckbKXaTPjVT0pZvA==&e=0&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_PowerPoint_sciagnij.exe

http://www.tourcentralbundle.com/c?x=eNG9l U1ZjyKLsLGy D33sSwIjHNlMwYIHf0axAZoE0=&c=wG81p6EfbvVgq5KTV7pnBra7E5JYd6Qqdh0azR2iIZa3Wu5OoVmWCO8JNMEKbMcgdYSnUYZ0Nf/83zUcAyEHALJbdkAxPOGcxw5qsxARe5O3sgZf2PorfndzYIrfaLtB&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_PowerPoint_sciagnij.exe

http://www.packagenewsend.com/c?x=TyBCt2VsowJ7PPepxkMQuPAEdUzw93jTyBTPi4aMSA8=&c=uFt Lxxy2 wdS7KN/RW9F1O4cSe1ckl6My1QH4ln7nT8V6VRQtQdNo4A48UeDY8fNBJFeoSRPEIyOiAZBoS1DANa6QBgXCoecOev TpMMTWV3wtWBQa2IofJdx6zlPd7HG2oltGsWff70q7mlapdmQ==&e=0&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_PowerPoint_sciagnij.exe

http://www.vaultsharestock.com/c?x=UnhzR0ufenhtEcvC4fnzHpTlpSbC3GFEJVL Km8jdTY=&c=89Kjp3Oxh2h1IhgtIj9rszoV5NvD PvCEHeqZPvWuOkjmQf3NIdgJPM/EvtjGI65fVbaQAo Yn1KHoLcASloqrgvkyTa/cyECXGkbDxw3kLoaST8qpt6C0MNAWRhA/cV&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_PowerPoint_sciagnij.exe

http://www.vaultsharestock.com/c?x=sf2u1QtAsZvOHMKcJmUGGpufYZ1xGu9S/61q72MVtOk=&c=tUWUsgkr7hREc2rQwZZvZk9AGDVIiRzJk/Km7ez6FeEDZ6ZAxoUkQaYekq0kBhmAqhbrVT87RJgOmeVOVeOr/8loIU6qaM9F9K5mjqf6n4Fr8FPq33wpmq7c2KXpKB02&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_PowerPoint_sciagnij.exe

http://www.applicationsbulkbundle.com/c?x=YU3iN3yXzR9PacxJCj/x46TVjFseh/IvcGjbOPCnyew=&c=B9uM1EDBFoArrviyzlobYle3qk4nSCt1HCdhSZ0YTY tMczbzSzoWjBgIcTk8WW39Ie0O0owo8I99gGn9mSiJWrijMb 5suC5tHv13Ok46 vc/CFjxHtLsjLVRkY4p7D&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_PowerPoint_sciagnij.exe

http://www.tagapplicationrepository.com/c?x=T7DXGBCPLU2jGef5jreMvsycjLk4 swPwE/AtgFeTWI=&c=4q2TdBYlrLA7UtopfcBbgPuhK5hGttRzp5GyQUnWL6rijj6oSYSaC9Tsn7BIv8qDSxZe jSpWBaywxacCY3Lc03lTBmmHMjXQrYsx/ks64eCYoxOkJ763JON4yjDfaUb&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_PowerPoint_sciagnij.exe

Latest 30 of 53 download URLs

Remove installer_microsoft_powerpoint_sciagnij.exe - Powered by Reason Core Security