microsoft-word-2013.exe

Cabum

Destiny Dream S.A.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application microsoft-word-2013.exe, “Cabum Setup ” by Destiny Dream S.A has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.towerbundleapplications.com and multiple other hosts.
Publisher:
Destiny Dream S.A.  (signed and verified)

Product:
Cabum

Description:
Cabum Setup

Version:
4.0.2.2

MD5:
06bdac439d3f0917ff4b0cd3fd3364a1

SHA-1:
a4ca086acfde9783ea0c1fb5c07cff19b0a8f750

SHA-256:
f2afb4f9ea844f300afa1ca2fe04a41be1480759100406842ed2021d37841d1d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/24/2024 12:51:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.DestinyD.Installer (M)
16.5.5.14

File size:
1002.2 KB (1,026,216 bytes)

Product version:
1.2.1

Copyright:
Wizard

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\microsoft-word-2013.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 2:55:11 PM

Valid to:
10/2/2016 3:36:18 PM

Subject:
CN=Destiny Dream S.A., O=Destiny Dream S.A., L=Clarens, S=Vaud, C=CH

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11217A75EB912AE2167326222C18D9E2357F

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Cgvb1DA3WAmtJtxuO2uc2JiDCcFHNzwguP/KrepII2J4m:C8bd9jth2uc2M+cza/KSpI9Om

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9286

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file microsoft-word-2013.exe has been seen being distributed by the following 50 URLs.

http://www.towerbundleapplications.com/c?x=7I8Dc0g2FjZ/d6LzZEnLq/qAcaar4Xh2Fq9viZ7 Skk=&c=ck00Vx4kcQXFq qdXWm6/5f280ooyFOeYx8bXl0Mgjfl/4e4 fQuAmMnCkIEIxJLfMMriK16GxM4lV1pgOOl1EK3AyZJ9ajOLyZOHfkJOBtTSHedEkzAzAnehY9cC/7T7dnKP5LdvGnbSNxVgysjablSJnYrlsKLS4FLwjMIvPByahzuD0Kl3/cjefF7x9su&e=0&downloadAs=microsoft-word-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.bestbinariesvaults.com/c?x=UcOmdvL8X3n71bjL/SKSeC9Uddyp8HxZUYNV7Vgr1SA=&c=xe6TwC6wLp5LXzlraiOc8B0DllBDj0DW408qp4udwriM2rGnmV5Suw3VSU0zXEkNZUxuuCl9GkU8RIdQrcsDTNHwwEEByUueikjHjJomXwE1SsVv1oz2nN4p7xCC8wBJh/1alji7w1xTRrIYe0HRJJv5jZquQMA8NQUhX5MOU56f/5KYtquspbVAsvI0nrEM&e=0&downloadAs=microsoft-word-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.bestbinariesvaults.com/WVl6OTRQV0ZHY0RZNVpUSlNTR2RsVm5oNmNscHZXRGhQYlV4eFUwMUtabHBMZUc1VFVuSXhSMVJEV21wUGQwVWxNMFFtWXoxMFdubEhlVUV5U213eVRGZGxOblZVV0V0V2FIYzNVWEZDZERsV1FUZDFNVXhyZFhZMVR6UldiV1pYTmtKR2FVTnZSR2x0U2xKNmN6RlpjbEJRVWtZbE1rSkdORXcwYWpoV1NqRmhXV3BLVm1GV1VrdzBWU1V5UmxKRlZXWmxORkpPVEdocEpUSkdWRlZSUlhsUGJuSm5VRE0zTUU0d1FtaExabVIxWTJ0blRHMXJKVEpHWVdocWJVOWpiR3hNVjBzd05XcHNSbkowV0daMVEzcGlkeVV6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxdGFXTnliM052Wm5RdGQyOXlaQzB5TURFekxtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbTltWm1salpTNXRhV055YjNOdlpuUXVZMjl0SlRKR1pXNHRNREF4SlRKR2QyOXlaQ1V5Umc9PQ==

http://www.softwaredeliverytag.com/WVl6OTRQVEZaTkdRbE1rWmFUR1JUVjFnbE1rWkRTSGh1YjFORVRGZFJNbGtsTWtZMVRYcHpNMVJVVWtkS1RIaDZZbGxOTkdjbE0wUW1ZejFwUzJaa1Uwa3hUMXAxVW10dE5uVjVOSEZ6T0haTlZrSmtPREpGVjNNMmR6aFhOVFppWm1wRGFrRXdWalZxYUdNd1NrOUhiekpSVW1kVkpUSkNiekZ6YjFreVkwNVZibmQ1TTJGbldUVnRNMmhDUlc1TWVIRlJjVzlHYWpGMU5GRXlXa1l6VmtoRmR6WTNhbVVsTWtabFNsZExjVzlaVDBkNFUxcEtVa1V6YmxFelYydFZaVXBvTVVoQlYycEpWV2cyZEhCb1lreGthR3BCSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBXMXBZM0p2YzI5bWRDMTNiM0prTFRJd01UTXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHYjJabWFXTmxMbTFwWTNKdmMyOW1kQzVqYjIwbE1rWmxiaTB3TURFbE1rWjNiM0prSlRKRw==

http://www.bestbinariesvaults.com/c?x=WlCktBMsddXh2dyL7MscMc48efxa6dRdUGqNSKRDt/8=&c=jzXDdGJyIFttdf D5V60xYQeBPZh GLbf6033CQj6wFeFGSpSF2l4luCmXmWEwXDvUjjRTiypk kWSUXRvFNTMo2G/PwwC66GXPWs1LMlchXns8SiXgDQ9Y8hnLagEMZnqmP7bg1oBv7hjc02hbhvWChBo5clBGRduBsa4WDVyAK849/sAov4Lu808ry7DO9&e=0&downloadAs=microsoft-word-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.bitscontentfun.com/WVl6OTRQVzFJUW1OMGRuZFhWamhsTXlVeVFrSm5Ta04yUm5CbWRGUjFNVkpOVEV4RGVUZHhUak54Y0VZeWNuRlNheVV6UkNaalBYTnZXblVsTWtKQ1NqVkdTWEpQVm05dGNUbFliV2Q0VlNVeVFuTlVhSHBZTjBKMlkyUnJXRTUwVkVWeVEwZ3dSWFpqYTA5YVVUbHNhVU5FVG5KVFVFZExOU1V5Um5kaGVXSnBOVVY0VEVSNlpFd3hiREpqV0ZWU1JtSnRiVVJWVm1NMFEwUktNbFVsTWtKNlUydHpKVEpHYW5sMFVsWkVPV0kwZURGWWJWWkliemRIVG5aTFkxTjRNblpHVTNadE1FcFFVbmxuWlZOcVFYbFdTamhSVW1jbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTliV2xqY205emIyWjBMWGR2Y21RdE1qQXhNeTVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtadlptWnBZMlV1YldsamNtOXpiMlowTG1OdmJTVXlSbVZ1TFRBd01TVXlSbmR2Y21RbE1rWT0=

http://www.softwarefuncenter.com/c?x=sROb9Niug1fLW65GbOqp1KD0adPDRzkHjLSEinL7EIs=&c=QFbgswWG1ANvhUnnxVhQMt/9vhBhxNie5ymTgOis1CWmyZBLHwdTO5fO4WTmgc1LVdf2aS4VZPSaYrRoCmf9C9ctT8H/UTvK3TGplKfUVcRyKvtu79dOv6QwZzvYrSi5y7qAezre/AvN0TkOFmPF7Gk2opuKYJzMHpRC c5UxA=&e=0&downloadAs=microsoft-word-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.bestbinariesvaults.com/c?x=U4pkfg2 yWoO90TrZ8KsW5I5dWTwavYcOr8j6A HGqI=&c=ytMr3a8EzI9c0qGDiMikmoYJH fNmCBZB25FeO3HAqG/dlXV8XmhNtQo2n0kobew9na3NhwwSBqUmQXo5bTnf/BoKnlpOv3KZSeAdNKVXUPVWvxxh59sjrWA0pS5THj1iNVWnzSm4X 00DckALzKyVjyhceUSmqaap6 gYa2n2dnfWrqJndhaIvay70maW0j&e=0&downloadAs=microsoft-word-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.softwaredeliverytag.com/c?x=wKH8LbvdC7CXeKTnpgyVgz684JQTaC8fiqjsDp2AbTM=&c=uXVPMPMe3SI/ 1lr5WUNrVpMGJwojAkRrX4Zo/6VejRiughFTMyfjjb0BPbCoPDd9IaW7SyxR9sNP21Nujz QK8rIngWQLw6p3kSY2jNMaiRaJFp5NLlvRGuApLLjwONyXHP/cofVcgkYBtKxZGRwQ==&e=0&downloadAs=microsoft-word-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.towerbundleapplications.com/WVl6OTRQVFV4U0VRNVJYVTJNWGdsTWtaUFdEVlBNMk5yUkRONlRVZ3piM3BpSlRKR2Jua3lORFZUTmxFNGQxbGpKVEpHT1dzbE0wUW1ZejBsTWtadmVraElTWFpXTVVoNlIwZEhXRzlaTW1Sa2RHRnpSWEExT0c5WlVHTnBORGt5WkZWQk5GVlBSa0ZWTVVnNVZsbHljMGxCYmpWRFFWUkxVemhVZFdKWmJIRkpUbmxUVjNRbE1rSkJlbUl4YVU5VWRHaFRlVlZsZEhOTVV6ZzFXVzV2Y0V0ck9FUm1OMDVrVlhsd04yMTJkR2t5WjNKYVMyVmhTRWgxZFVZNWEzQTBUbTEwVmxwaFQzQjZKVEpHYkRrMlkwSmlNRWR0VTBFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTliV2xqY205emIyWjBMWGR2Y21RdE1qQXhNeTVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtadlptWnBZMlV1YldsamNtOXpiMlowTG1OdmJTVXlSbVZ1TFRBd01TVXlSbmR2Y21RbE1rWT0=

http://www.newsendbinaries.com/WVl6OTRQV1paWlU4MEpUSkdPR0pEWkVwMFMyNWtKVEpHV0NVeVJuZFNhVTlyWm5sVWRVZFRPVXBXTTNSWVJ5VXlSakJ0TnpaM2J5VXpSQ1pqUFZNbE1rWkNlblZxVmpGb1ZEVmFKVEpHVTBabVRXTlhlbk5IWW5Ga1QzUTBSM2RZWWlVeVJrczNiWE5qVEcwbE1rWjVjMHBhWjAxVFkwcEdRbk5SZG5jNFowbHlTVEppVVVnNVJuWXpNRGxIYm5RME4xZHFNMGhsT0VKQllYSk5jMUY0TVVvMU5tNXlVMnN4TTB4WlNUQjRhblJqT1dZbE1rWnlVRTkzWlRaMlRqUjFabTFXYjFOVGEycDVPRXA0YzNnekpUSkdjRWMzUkNVeVJtSWxNa0pwZWxWblZGRWxNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05YldsamNtOXpiMlowTFhkdmNtUXRNakF4TXk1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWnZabVpwWTJVdWJXbGpjbTl6YjJaMExtTnZiU1V5Um1WdUxUQXdNU1V5Um5kdmNtUWxNa1k9

http://www.newsendbinaries.com/c?x=rSmzXUpcjD1JJvtN4rnQuK0HuSbaOz405mfUZRdxOpE=&c=4tsfNnM8G5F yfwg pRyrgCHWOqR5EkRCv2OvXKjN67RjpSvdxfRKVVXUfdaHWf7YsxK2fWPykTyRnxcNi6oKpvS5CaS5Ru2DVWfVCg rREzMTtTI3bnqUCHvCR/HtCV/ pHGWULj0u8kqvcQVyFpVqE R0gRSQWVzOgzLxcwss=&e=0&downloadAs=microsoft-word-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

Latest 30 of 70 download URLs

Remove microsoft-word-2013.exe - Powered by Reason Core Security