bubblehit.exe

Perion Network Ltd.

The application bubblehit.exe, “BubbleHit Setup ” by Perion Network has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from cdn.download.sweetpacks.com. While running, it connects to the Internet address ude.databssint.com on port 80 using the HTTP protocol.
Publisher:
BubbleHit   (signed by Perion Network Ltd.)

Product:
BubbleHit

Description:
BubbleHit Setup

MD5:
e556ab5ff2e7dbf269ca20df2ddf76a6

SHA-1:
09986dc5b5e3e8a2c9f9cec9d85205e1cc5af6c0

SHA-256:
f5356f03f883f3b71d4bc601759b5e48f4c51a84c61067b936b85630d86acb26

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 10:51:54 PM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
not-a-virus:WebToolbar.Win32.Perinet
15.0.0.543

Reason Heuristics
PUP.Installer.Perion
15.1.30.0

File size:
740.2 KB (758,008 bytes)

Product version:
2.0

Copyright:
Copyright © (BubbleHit_g90_consider_askperhost)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bubblehit.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/23/2012 7:00:00 PM

Valid to:
4/23/2015 6:59:59 PM

Subject:
CN=Perion Network Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Perion Network Ltd., L=Tel Aviv, S=Tel Aviv, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
45F87694FE8D1984719796AEC8031DF4

File PE Metadata
Compilation timestamp:
2/4/2013 12:24:57 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:iSxG0ezX/d4BL8+iDso2cp/A+XHLARWP7sGIeQ3PAk0bdJI0iTdVvBrzVxNQa/:JxGhzA872oYqHcMqIkqdHiJXWa/

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9233

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file bubblehit.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ude.databssint.com  (107.22.223.150:80)

TCP (HTTP):
Connects to storage.stgbssint.com  (172.229.236.170:80)

Remove bubblehit.exe - Powered by Reason Core Security