aqua-bubble.exe

The application aqua-bubble.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from installerlaunch-mtfg1.com.
MD5:
9816a89f8a11c69b6ff2ea5594591563

SHA-1:
a6287b93ba5d046979052f89fe6b23c733bd0c6c

SHA-256:
2d466d8134b8322201e2d4b1097b8d941eb2ed5c5c505f9c5275e4988ea93bde

Scanner detections:
18 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 6:53:39 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Adware
7.1.1

AhnLab V3 Security
PUP/Win32.InstallCore
2015.07.15

Avira AntiVirus
PUA/InstallCore.Gen
8.3.1.6

Clam AntiVirus
W32.Adware.InstallCore
0.98/20698

Dr.Web
Adware.InstallCore.40
9.0.1.05190

ESET NOD32
Win32/InstallCore.Q potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.C.gen
4.6.5.141

K7 AntiVirus
Riskware
13.206.16567

Malwarebytes
PUP.Optional.FearlessArcade.A
v2015.07.15.10

NANO AntiVirus
Trojan.Win32.InstallCore.bclgws
0.30.24.2487

Rising Antivirus
PE:Malware.InstallCore!6.DCE
23.00.65.15713

Sophos
PUA 'Install Core Installer'
5.15

SUPERAntiSpyware
Adware.InstallCore
9751

Trend Micro House Call
TSPY_INSTALLCORE_BK0802C9.TOMC
7.2.196

Trend Micro
TSPY_INSTALLCORE_BK0802C9.TOMC
10.465.15

Vba32 AntiVirus
Adware.InstallCore.gen
3.12.26.4

VIPRE Antivirus
Threat.4150696
41608

Zillya! Antivirus
Trojan.Genome.Win32.201656
2.0.0.2291

File size:
1 MB (1,070,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\aqua-bubble.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:zPqxmfxN1ixtiZy6MntoNXfRya9YST1oUrp3v:zqxUH4iZN80PsbST1D

Entry address:
0xC1A73

Entry point:
55, 8B, EC, 83, C4, F0, B8, 63, D8, 49, 00, E8, 85, E7, FF, FF, 6C, 79, F0, 98, FD, C3, 73, 83, FE, B7, 61, A5, 3F, B5, 05, 1B, 6F, 83, 89, 29, 89, 04, 1B, E5, 20, 68, 28, DD, 74, 60, EF, E4, 8F, 40, 8D, 9C, BF, 24, 20, 5E, 2B, 71, D3, 90, 5C, 5C, D2, 9B, 00, 3D, 74, FB, 37, DF, 2F, 34, 2D, 21, 1E, 8B, DD, 75, 20, E9, 33, 43, E5, 37, EF, 0E, 6D, 11, 0A, F5, C5, B8, 61, 07, 1D, 90, 0B, 45, 67, 8D, 89, 8A, 2B, 6A, AC, 96, 41, 8B, 05, EC, 8E, D8, 09, 56, 08, 02, 6A, 2B, 8E, F5, 39, BA, 68, 71, C7, 71, 6A, FD...
 
[+]

Entropy:
6.7124

Developed / compiled with:
Microsoft Visual C++

Code size:
786.5 KB (805,376 bytes)

The file aqua-bubble.exe has been seen being distributed by the following URL.

Remove aqua-bubble.exe - Powered by Reason Core Security