59983.bubble_dock.bbd023.no.exe

Bubble Dock

NOSIBAY

The application 59983.bubble_dock.bbd023.no.exe, “Bubble Dock installer” by NOSIBAY has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cdn.bubbledock.co.uk and multiple other hosts.
Publisher:
NOSIBAY  (signed and verified)

Product:
Bubble Dock

Description:
Bubble Dock installer

Version:
3.0.641.0.59983

MD5:
3ee7e0dac59418dfe78f0721b28e2417

SHA-1:
06a952901b9ac4a4c6589d7791e5e7b733e29962

SHA-256:
9fd1dae7646930564fb9cab70197bc088e85e67236fc61a871218230411203a3

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 1:34:22 AM UTC  (today)

Scan engine
Detection
Engine version

Malwarebytes
PUP.Optional.BubbleDock.A
v2014.01.19.09

Reason Heuristics
PUP.Installer.NOSIBAY.Y
14.2.22.3

Rising Antivirus
NS:Malware.Install!1.9F62
23.00.65.14117

Trend Micro House Call
TROJ_GEN.F47V0117
7.2.19

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

VIPRE Antivirus
BubbleDock
25530

File size:
6.8 MB (7,124,640 bytes)

Copyright:
© Nosibay

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\59983.bubble_dock.bbd023.no.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/21/2013 2:00:00 AM

Valid to:
11/21/2014 12:59:59 AM

Subject:
CN=NOSIBAY, OU=Nosibay Secure Developement, O=NOSIBAY, L=PEROLS, S=Hérault, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4F1CA396B891ED381AFEECC074DB8714

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:voVvwixh5fOZemWM/MorAM+CL4V2QDLS6TpQh:gVvxQMtMUo8M0AQDu6TpQh

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 59983.bubble_dock.bbd023.no.exe has been seen being distributed by the following 3 URLs.

http://cdn.bubbledock.co.uk/cl/.../59983.Bubble_Dock.BBD023.no.exe

Remove 59983.bubble_dock.bbd023.no.exe - Powered by Reason Core Security