microsoft-office-2007-pl-service-pack-1-12126-dp.exe

Bab

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application microsoft-office-2007-pl-service-pack-1-12126-dp.exe, “Bab Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Bab

Description:
Bab Setup

Version:
1.6.2.1

MD5:
59fc5984eada53b84770a07caff17af8

SHA-1:
c2cce54c3080c3ae314f895ad41eed0c28ee0081

SHA-256:
09687dd6260f8e64afdfc759bcf0eb288ccea2fd124b6312570d188687e455b3

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 2:37:56 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.5.4.13

File size:
951.2 KB (974,072 bytes)

Product version:
1.5.2

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Wvp7y5I5PpEla6JVWwIar2hfWz21GkqfQT7L7/bpoQOGZ/u:Wx8culbVzIaKhc2gkqfQTz99Z/u

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file microsoft-office-2007-pl-service-pack-1-12126-dp.exe has been seen being distributed by the following 39 URLs.

http://www.nowapplicationsranch.com/WVl6OTRQV1ZhYTNaaU1sZ3hUQ1V5UWtWSGFIazNkbE0wZW5OR1dIVm5aVlZJWlZvd2VWZGthREZOVlVjbE1rSmpjWE5ySlRORUptTTlhVTVCYmpaMWRrWklUWFZWUVdGRE9XcGpXbWd4Tm10bFVtdEVlV2hrYzNNekpUSkNjRUpKUVZWVFpIbzVUMWxIVkUweVZFWXdZV1F6WldST2NteFNWa1JUY1hGVlYyNHhibUV4T1ZZNUpUSkNNamhaYW5WT05GUm1la3MzZVd0NGJsSlJVbGRtUldaWWNrcFdORWhWVm1Fek0weHhSMlJUZDNKVWNsQjZhME5hU21SaVZIZ2xNa1pSTkZWSVJESkZRa3Q0UVhCNFJVUlVURzlSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1SdmQyNXNiMkZrTG0xcFkzSnZjMjltZEM1amIyMGxNbVprYjNkdWJHOWhaQ1V5Wm1ZbE1tWXdKVEptT1NVeVptWXdPVGM1WldRNExUTmxNek10TkRZek5pMDRaall5TFdZNU9XUXdNR014TVRBeE15VXlabTltWm1salpUSXdNRGR6Y0RFdGEySTVNelk1T0RJdFpuVnNiR1pwYkdVdGNHd3RjR3d1WlhobEptUnZkMjVzYjJGa1FYTTlUV2xqY205emIyWjBMVTltWm1salpTMHlNREEzTFZCTUxWTmxjblpwWTJVdFVHRmpheTB4TFRFeU1USTJMV1J3TG1WNFpRPT0=

http://www.sendtodaychuckle.com/WVl6OTRQVlprVERjMlNtdFhXRWhVUmtoQmRFWmtkRFZrYzJkdmJrTXpZekpqYldoRE5IRnlSbGM0YkNVeVJtMTJZeVV6UkNaalBXNGxNa0owUVZkd1dUZHRRVFpHVENVeVFraDBXVmR1T0dKWlNDVXlRbTVRWkdnbE1rWjFaWEJEVFVGRFJIRTFWR2hXUzFBeFFYaE1VVEZxYWprbE1rWklhbU5DWW1Ob1ZXUjNaWGR5VkVSMFoxRlFjMVJWY1dVMVpGTjZSRGRIU1dOcmVqbEtlWE4xZHlVeVFqQlJhVWRRSlRKQ1VGSkhRMkZDVEhSV1QzWldUR2xKYjI5TE1YVkJaekJUYjNCNVpFVmhkMkl5ZVhwT1EyTnhlWEJ4YTA1dlVEVlJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabVJ2ZDI1c2IyRmtMbTFwWTNKdmMyOW1kQzVqYjIwbE1tWmtiM2R1Ykc5aFpDVXlabVlsTW1Zd0pUSm1PU1V5Wm1Zd09UYzVaV1E0TFRObE16TXRORFl6TmkwNFpqWXlMV1k1T1dRd01HTXhNVEF4TXlVeVptOW1abWxqWlRJd01EZHpjREV0YTJJNU16WTVPREl0Wm5Wc2JHWnBiR1V0Y0d3dGNHd3VaWGhsSm1SdmQyNXNiMkZrUVhNOVRXbGpjbTl6YjJaMExVOW1abWxqWlMweU1EQTNMVkJNTFZObGNuWnBZMlV0VUdGamF5MHhMVEV5TVRJMkxXUndMbVY0WlE9PQ==

http://www.packagesoftwaretowers.com/WVl6OTRQVFpNSlRKQ1MyNHdja1F3U1dOeWVrZHVhWHBvYVRkWUpUSkNOM0F4TlVKT2JVZzFNVU52U1c1S2NHbG1TakJqSlRORUptTTlaVk0yV0hCVFRVYzFOWGxuZEd0aVRqZFljMGxJVTFadFFUTjZjMUJsZW5vbE1rWkxNMndsTWtJbE1rWlBKVEpDV1djbE1rSnJPR1l6WVhKRGIySnNSVmRaUlVoTFp5VXlRaVV5Umt0MVEwWkhibWhyYlZCakpUSkNValYzWnpWVVR6UjRkbTFGUkZWSmRuZ3pVamh2T1RRbE1rSjBUMVJTVEZJeFR6Y3hiV3BGZFVKSWFrYzFkbVZyZDNrNVRUVndjV3BNTVU1NWNtVnRXVkptV0dKRldVODVaVVJsVDAxUkpUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpZU1V5WmlVeVptUnZkMjVzYjJGa0xtMXBZM0p2YzI5bWRDNWpiMjBsTW1aa2IzZHViRzloWkNVeVptWWxNbVl3SlRKbU9TVXlabVl3T1RjNVpXUTRMVE5sTXpNdE5EWXpOaTA0WmpZeUxXWTVPV1F3TUdNeE1UQXhNeVV5Wm05bVptbGpaVEl3TURkemNERXRhMkk1TXpZNU9ESXRablZzYkdacGJHVXRjR3d0Y0d3dVpYaGxKbVJ2ZDI1c2IyRmtRWE05VFdsamNtOXpiMlowTFU5bVptbGpaUzB5TURBM0xWQk1MVk5sY25acFkyVXRVR0ZqYXkweExURXlNVEkyTFdSd0xtVjRaUT09

http://www.chucklebestapp.com/WVl6OTRQVzl5TjJSd1NYZzBWRU5qWjB0WFJWZG5OMGgxU1NVeVJuRndVSGR5T0U0emVXcGtiM3B3ZFRod1R6SkRTU1V6UkNaalBVWnFKVEpHU1dnMWEwbHBZbVpKZEc1b1RsVldkMVF6YW1ScFdGQjZPR2MxWVRoemIxbE1XbkJYTlVoT2FFSnJlVmRCVUZvMllXZG5Vek5zTTAxNmRqTnlVSEZCU1VnM1ZXTndUWGdsTWtaSVpUVm5SMHBsYkhOcWIybFFjRU5XUW13bE1rSjZUMjFQTjBoWE5VZHpXV2x1WW14VE1EZEtTbEJMYlZGMGRrTXlhbGt3TlhKTFkyRnphSGxXZDNCUWJITkRNV1pGWjBSdldGUlZVU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVprYjNkdWJHOWhaQzV0YVdOeWIzTnZablF1WTI5dEpUSm1aRzkzYm14dllXUWxNbVptSlRKbU1DVXlaamtsTW1abU1EazNPV1ZrT0MwelpUTXpMVFEyTXpZdE9HWTJNaTFtT1Rsa01EQmpNVEV3TVRNbE1tWnZabVpwWTJVeU1EQTNjM0F4TFd0aU9UTTJPVGd5TFdaMWJHeG1hV3hsTFhCc0xYQnNMbVY0WlNaa2IzZHViRzloWkVGelBVMXBZM0p2YzI5bWRDMVBabVpwWTJVdE1qQXdOeTFRVEMxVFpYSjJhV05sTFZCaFkyc3RNUzB4TWpFeU5pMWtjQzVsZUdVPQ==

http://www.chucklebestapp.com/c?x=gNpMCPa4Ob6q7IQJtDl7P5vxLT/ rr5z9zDZVrnvjsY=&c=bM5 3u5S6b9f49d5KO31zOpqncVmzs3c44S/vkXj1DWt7D4uvniyguEgJNf QME 0MouvkFOa11dolVXe6JTvhmxA4yQpijOlOXTFpwEKtf9p7NdoHwNASBLhvGed6GRF5 TRe6nnWQ Vhww8atq5A==&e=0&fallback_url=http://download.microsoft.com/download/f/0/9/.../office2007sp1-kb936982-fullfile-pl-pl.exe&downloadAs=Microsoft-Office-2007-PL-Service-Pack-1-12126-dp.exe

http://www.sendnowtown.com/WVl6OTRQVlF4U21NNFZ6RnNOMkp1WjFJM1ZVcG9ZV0Y0ZVVGck1GTk5OSEZ4YldZNFNERjBRVFJSUjFobUpUSkNkeVV6UkNaalBUTmhWR2xWY21VME5XaFVRMDFzVlZvelRIQkNZVVo1U0dwM2RDVXlSakEzWWpSNVlWQkpTMlpqYkZSeFpYbFZRbk5DYUZwVE55VXlRamc0UnpSb2FrMWFiekFsTWtaNk5YWjVaMDlhV0U0eFZsUTFSbnBuUjBSd05YRkRKVEpHSlRKR1pHVjROMkZwVVRFeGFWSkRabWN6TUdGUVdUVXdOVmhYUWtkQ1NVc3lWbkZrUW1aWlNISjJUVGxWZG1aNmJERmFSbTVVY1RsYWFVbHFVMVIxUkZFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbVpHOTNibXh2WVdRdWJXbGpjbTl6YjJaMExtTnZiU1V5Wm1SdmQyNXNiMkZrSlRKbVppVXlaakFsTW1ZNUpUSm1aakE1TnpsbFpEZ3RNMlV6TXkwME5qTTJMVGhtTmpJdFpqazVaREF3WXpFeE1ERXpKVEptYjJabWFXTmxNakF3TjNOd01TMXJZamt6TmprNE1pMW1kV3hzWm1sc1pTMXdiQzF3YkM1bGVHVW1aRzkzYm14dllXUkJjejFOYVdOeWIzTnZablF0VDJabWFXTmxMVEl3TURjdFVFd3RVMlZ5ZG1salpTMVFZV05yTFRFdE1USXhNall0WkhBdVpYaGw=

http://www.sendnowtown.com/WVl6OTRQVzFYTms5WWFqZE1UV1JGU1dwTk9YTnVjV3hXZVRSd05VRWxNa1pFYmtadFZsQkVlWEpVWkc5cllYTWxNa1pySlRORUptTTlhREp6WWs1bU9IcENjRWRDYkdVMVkzRjZZekJRZVZObU5EbENaWFJoYUhwc1l6WklhRk1sTWtKUGVTVXlRbEowYm04NVZYTmpka0ZUU0RsdlpWcGxiR1VsTWtaRlpuQnVUR2d3WlVOR2RWZEhRVTVxTlZKMlNIZDVKVEpDUW5KQ1NrOTZTMnR2VTNST0pUSkNKVEpDYW10NllpVXlSa1ZXYm14Q2FFTm5iM2RpYmtOS09EWjBVVE0zUWpkVE1VZ3lZWEVsTWtaYVVXWkZSVGsxV2tONVZUQnFTMkZZUVNVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aa2IzZHViRzloWkM1dGFXTnliM052Wm5RdVkyOXRKVEptWkc5M2JteHZZV1FsTW1abUpUSm1NQ1V5WmprbE1tWm1NRGszT1dWa09DMHpaVE16TFRRMk16WXRPR1kyTWkxbU9UbGtNREJqTVRFd01UTWxNbVp2Wm1acFkyVXlNREEzYzNBeExXdGlPVE0yT1RneUxXWjFiR3htYVd4bExYQnNMWEJzTG1WNFpTWmtiM2R1Ykc5aFpFRnpQVTFwWTNKdmMyOW1kQzFQWm1acFkyVXRNakF3TnkxUVRDMVRaWEoyYVdObExWQmhZMnN0TVMweE1qRXlOaTFrY0M1bGVHVT0=

http://www.headheartvault.com/WVl6OTRQVGw2U21vMVVXczNhMkZaVW0wM2QydGhlRXhNWW05cE9UQk1lRnBJVTIxek4xZ2xNa0pvT1dka1NIRTBOQ1V6UkNaalBUaHpXRkIzY1dabFdpVXlRbGRRVEVseFoxWnZiMU5JVEU5TGRVbGFibTFTUjNGc2N6Wk5TREJrUnpWWlNWaEllVWxVWlZoTFNsVXhZM2tsTWtaNFdXaG1SRTkxYVhkMWRqQTRkRU5xT1ZaS2JrSk9hazVhZG1KV2FuaENUSFZpT1RCelYzSkRKVEpHVFdWNlNuSjNNMjk2TkZZeVRWcEhVRlpvYW00bE1rWnNNamRtVTB4MFF6ZFJOM2hwTldocmNFOWxTMDVWYkdONmNsQTBRM1ZSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1SdmQyNXNiMkZrTG0xcFkzSnZjMjltZEM1amIyMGxNbVprYjNkdWJHOWhaQ1V5Wm1ZbE1tWXdKVEptT1NVeVptWXdPVGM1WldRNExUTmxNek10TkRZek5pMDRaall5TFdZNU9XUXdNR014TVRBeE15VXlabTltWm1salpUSXdNRGR6Y0RFdGEySTVNelk1T0RJdFpuVnNiR1pwYkdVdGNHd3RjR3d1WlhobEptUnZkMjVzYjJGa1FYTTlUV2xqY205emIyWjBMVTltWm1salpTMHlNREEzTFZCTUxWTmxjblpwWTJVdFVHRmpheTB4TFRFeU1USTJMV1J3TG1WNFpRPT0=

Latest 30 of 39 download URLs