installer_microsoft_word_sciagnij.exe

Debegarune

AGORA S.A.

The application installer_microsoft_word_sciagnij.exe, “Debegarune Setup ” by AGORA S.A has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.stockfuncontent.com and multiple other hosts.
Publisher:
Beseg   (signed by AGORA S.A.)

Product:
Debegarune

Description:
Debegarune Setup

MD5:
7f54be3d0f87fefd9605d99517343080

SHA-1:
8228d0c3a152b66d27100e06775185a2ccb6d5a0

SHA-256:
506369defb4afc27d798dba2b424ce9e09e5df04fd524ee86da810590bfe2a57

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
9/29/2024 4:20:51 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.InstallCore.1411
9.0.1.05190

Microsoft Security Essentials
Threat.Undefined
1.217.1229.0

Reason Heuristics
PUP.InstallCore.AGORASA.Installer (M)
16.4.14.17

File size:
923.3 KB (945,416 bytes)

Product version:
1.0.3

Copyright:
Fast

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\installer_microsoft_word_sciagnij.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
9/9/2015 2:00:00 AM

Valid to:
9/9/2016 1:59:59 AM

Subject:
CN=AGORA S.A., O=AGORA S.A., L=WARSZAWA, S=MAZOWIECKIE, C=PL

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
615B57E3504C929E3B64ED936D1CE68B

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:hwcSeGbEsZPjsFsNgE0NqxzJVd74pgZnO0G0I0STS89EirLZfk:hPwPwiNOAzJ0GZnOAbSu8WirLNk

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file installer_microsoft_word_sciagnij.exe has been seen being distributed by the following 50 URLs.

http://www.stockfuncontent.com/c?x=NTQZEGv8wcLwlx VUKG77ryp/TEhMyXjay5EhJK8tVk=&c=mU5PtStDsf sx2bvFMx5VqsvUQqRNO19XJhxkWkTlUm9PraCr4O 7uXdxNtm8r9pdY9 Tb4q m2cMVyigpbKXAGowU DACT9y9CcTbXB wTxn4DUGbVSuBjX95iww5ij&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_Word_sciagnij.exe

http://www.vaultsharestock.com/c?x=elp23NyKR5QsSy1NlvS1TfXnbpMeG3Zwub388iEmSSM=&c=xx h1uozlQRTp961cu 0O0tDjWk/TYVhCvr6USJjdWmD61gLXu Zb9Rge0SsKS5Ae4eF1HHl7bbBRWudmzlWEXW6jqFI93hSHcGcVfLoeus7bOVxuI 6knCKQwMfh2vS&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_Word_sciagnij.exe

http://www.appstoursbulk.com/c?x=Tioz7HuVQAUwgHU464cpttFjD8KeMae1F8Y6r9Cw82U=&c=Wes9hqRP31mA5W5 vvpxIFv6ZqEn6JgaroxRtqI1 SV9 /c0P48cL5qyXLuRViLPmL9H0v4iyV5ThzNInjL85nUFiD7Pjxze3uYm0nfii5OCyc/LwscM4TlImLcjxn4&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_Word_sciagnij.exe

http://www.shareclearbundles.com/c?x=ogRoZCgoHtMUzzq8HgSP4pmM57iTdSYsZxxmb6u/bHs=&c=LhHJTY5JATcHn9sMBeA19Bcr/2UUaghrfRvqOrrHrbevHRWZvNs11qq40HTaPkQWDF9alZy3WoKBLpQuRpoPmoZjKMvjo371/O/Qwxws21dKN5b7Rea8Z3c48kEF5Zea&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_Word_sciagnij.exe

http://www.bundlesvaultstown.com/c?x=31EdETj4m0Hvecri9IC9vnrddemdkXTj73f4ASwhZQI=&c=SF9dZRhj426s8CxeDL2jqlsfMzhHl3LcQFW8khSq C8Uf5Iq5NVdYXYKh7fpVm14gG1rYX1V2Ko0hlGrldor2vhqfKJCdkJT2d1sOynvUsZDKFcXDIaVhVW9pJmVukAIIXtnzpkjukjns8j2y OtQg==&e=0&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_Word_sciagnij.exe

http://www.hosttowersapp.com/c?x=Ipb3V3 TlRyTp9tN 6G9nNxrbJ0FTpswGBSMrUk/5a0=&c=dg1zXMl4sJ1vvPRomLn59 4H8aDGTys01fTZnGDI9 impgT1nUMKOIIKH4RddZItHVvLl1h75er0Q1DDx B8/mT2J/T8mYIybioHt8bTbQwoKXzxDPvFmPlx18Dpo0bv&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_Word_sciagnij.exe

http://www.stocktowerspackage.com/c?x=3Zb2wJsYWq1pWxYlo3CScy/2amq27kdcnD1TRznkUl8=&c=DvtGLhKwxZZ3iUxAQ3vtlkX1g5kwDxTWoy3HKiRn1HCd9ePKaybdqYC2bdPL0HFyP3XANHS28OH5npf4wmtAuyUFKeF1RA2BtsZx4NRPsYrUFfw8Ea5eaqeKHz82pIz/5d015CJlB94dA e XjjkHw==&e=0&fallback_url=https://products.office.com/.../try&downloadAs=installer_Microsoft_Word_sciagnij.exe

Latest 30 of 71 download URLs

Remove installer_microsoft_word_sciagnij.exe - Powered by Reason Core Security