microsoft-office-visio-professional-2013.exe

Bebokekek

Destiny Dream S.A.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application microsoft-office-visio-professional-2013.exe, “Bebokekek Setup ” by Destiny Dream S.A has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.bundletagtower.com and multiple other hosts.
Publisher:
Destiny Dream S.A.  (signed and verified)

Product:
Bebokekek

Description:
Bebokekek Setup

MD5:
950171b9df71c00423096d0a83cd6ecb

SHA-1:
8cc2845d501ebb42f2838b1f1e82df618ee801e6

SHA-256:
bbe1705e7f64c672ea6e33f14f400d1fa8c0ab98bc898d98c303e333aacb85f0

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/21/2024 4:41:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.DestinyD.Installer (M)
16.5.9.22

File size:
993.2 KB (1,017,016 bytes)

Product version:
4.4

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/9/2015 11:58:51 AM

Valid to:
10/2/2016 10:36:18 AM

Subject:
CN=Destiny Dream S.A., O=Destiny Dream S.A., L=Clarens, S=Vaud, C=CH

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112188521AED0C8EC20707151AF45D10C88E

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:tJTWlt94fR7jZcnhoPhjSX548zMzXWqCL24zHx0T1+6f6:tZICZcY0uwMzXLCL2u

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file microsoft-office-visio-professional-2013.exe has been seen being distributed by the following 50 URLs.

http://www.bundletagtower.com/c?x=oLQZKqoYIwDkhIot4nkJoeJPuxsxqQGaOE567bKD3OQ=&c=S5YndNNNbI/5NJ6wbQyd MKlGhh7RgxpyURm0YdB70xFnK qib2lZQkQlyA4ifO3l0ilHHJK7kH6JCs037FaG0q0hLXkQ7Iqj/oVddDwltFNSXSpQXbisc/xWrKkTBjcvp9d9dTbsJCSiKOVzktw3tx40kUQmXPYwnWD28VYl8=&e=0&downloadAs=microsoft-office-visio-professional-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.metaconecptnew.com/c?x=z7YiMSr4rGq8KiDp8xQWVsHMb VI/LJ11szid5YCrLU=&c=SHKDG/DTMeO0DFByZ5ivq/41pgAuEdmT1Du5D6diTfFOmvdwHmaQhX1tehLuN xmEzFfUVG4Lcnlz7FcgcCV3aWpZywm1AQuG7S6 XyUGh/lPL3mfKrVNDOSuKuC/AG2AGXa KQDSz9p5bHyxRbT9KUsHXcmnKPGjVVuJsnUSvQ=&e=0&downloadAs=microsoft-office-visio-professional-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.clearsharetoday.com/WVl6OTRQWE5EYTBwS1VXNU5XRzgwTUhkSlEwWnpaWFZJYlhKNE1FSkxKVEpHUmxGTVQxSlRkVzRsTWtadlJFOVZkMEV3SlRORUptTTljbFJqWVZSVVVGQTBNRWROVTNwS1YwMUZkRlIxY1ZsM01taFBZemhuY0daQ1UzVTRaM2h4TmxaR05EVlhWREJxSlRKR1FYVk5NR3BPTVd0a2JXUXpObGRuZFNVeVFsaFVKVEpHU1cxMGExVk5kM0J5VG5RelJXZzBhbXhZUzJaU05IbDVVVTVXVlhGallWRk5OMDlCZEV4VE9HOW5VVXB5V0RSNFpuTkdaV3hCUjI5M1ZrSXlVRkZOSlRKR1MwRlpjM05WVDNkbmRFSnlNR1ZGT1djbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTliV2xqY205emIyWjBMVzltWm1salpTMTJhWE5wYnkxd2NtOW1aWE56YVc5dVlXd3RNakF4TXk1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWnZabVpwWTJVdWJXbGpjbTl6YjJaMExtTnZiU1V5Um1WdUxUQXdNU1V5Um5acGMybHZKVEpH

http://www.cleannewsafe.com/WVl6OTRQVWQxVEcxQ2NuRnRKVEpDWTJ0dmMzcHBibFlsTWtaTU5VMVhXR1k1TW1WVE1XVlZORE1sTWtKdE0wdEJNR3RyWkRnbE0wUW1ZejFFVW5OVmRscFpiMlk0ZG5rbE1rSkNiems0SlRKQ05WUmFkWGdsTWtaemVFcHVlV3R1VHpKSGJISlhPR1JCTm5oUlkzQlliRVZCVVhsTGNtZG9NMDkzWjBKVVREWjVaVVZETmlVeVFrOVJiakJ6ZDNCcFNYRjBPRWxTTWxOdFowaGtSMVZLUlhGVE1HRlFlRGx1TjFCNmJuZFhiVzgwY2xacWFUaDBaMlo2WkV4VmR6Sk1UVmx6VG5aUVN6SWxNa0pwYWxSSFdIbFBRbTVXV0VOQ1RXeFJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFcxcFkzSnZjMjltZEMxdlptWnBZMlV0ZG1semFXOHRjSEp2Wm1WemMybHZibUZzTFRJd01UTXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHYjJabWFXTmxMbTFwWTNKdmMyOW1kQzVqYjIwbE1rWmxiaTB3TURFbE1rWjJhWE5wYnlVeVJnPT0=

http://www.universequicksigns.com/WVl6OTRQVEExYUZWWWRWZHdaRzAyU0ZjemJESm5PR0VsTWtKNVN6azRVRE5FTm1GNFQyeGhaMFE0ZGxwRUpUSkdTRFJ2SlRORUptTTlVWHBqWkUwM2RGQlZUSHB5TTJaTlVtaEtaak41UWxCaVIzbFZhSGRFZWsxd2NIRXhNbVJLUTFWR1J6RnpTMVZ1VVVaWU9ERmplR28wZVhWdlUyMHlKVEpHV0VKek1ITlhTVGxZV1daaVZrVnVZVkI2UXpaSVRVVmtRbVEwUWpabU1HOWFkV2x3ZGswM2FGcFFOekl5V1dWMVRUVTJkbTVrU1ZkWVNIUmpVRzlKUjBwR1VuTnlNMUJUV1dwdllrNVljMnRvYzJoWGVtY2xNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05YldsamNtOXpiMlowTFc5bVptbGpaUzEyYVhOcGJ5MXdjbTltWlhOemFXOXVZV3d0TWpBeE15NWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1p2Wm1acFkyVXViV2xqY205emIyWjBMbU52YlNVeVJtVnVMVEF3TVNVeVJuWnBjMmx2SlRKRw==

http://www.townranchbundle.com/c?x=Hxv2SbkLMQxbCaqRjJE8CE/oBBnV3I21tCgXEFq6qWo=&c=jLURqL153G1os7iKL4FZzxy1/tD9HFrTIw9p76y56k5fICRrdKOrAIHWpEQDJbx Hzo1LR4uur4PkQbJf4u8F2i4FTt4xy jze8IRzeTvEWv0VoPX6Yj/HfPYjt7e9PpaVIFbnPpVFwXVsi0fsDakw==&e=0&downloadAs=microsoft-office-visio-professional-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.cleanvaultsworld.com/c?x=YjTJ0vQ2mYT7HjZvyacfUmVWUIa SGRq166H6PrWA/o=&c=dnu MLc RB5QtQSHic4AjKnvACbhf0x0qbKoNR3UIG7rjvHhHj0fp0XDvEnU7I13fXtev8xM8SmSAwwZEn0zJNuMqyheo5RI7KuotihdWFwuMcu rKmuO5cT hvgtR2gP6Ax82ITV5saPZYmLa1cig==&e=0&downloadAs=microsoft-office-visio-professional-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.worldbitsnew.com/c?x=V4LwVBgXRBgtS0ket7uC4kCbkMtRjiZGr0pkvYpEJ3w=&c=BmF6itZ2TqmPa4zPJa3vXCmPqG55bRIfiIsde5dEyckNuWgFIbAcHT9vBOHWnFHEb4WXS3ygnAClpJ1AHkMBAIz3zBZvJ1Z0iFIfVa9m9YBlOXnhi7A8XzN5jmKiwIS00dk 6lcnaiSgDiXrKx6H6ad/zL7RMFZC76Em0v3u1KU=&e=0&downloadAs=microsoft-office-visio-professional-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.todaycleanbundle.com/c?x=qenbS2TU331ERdCJuFrnIX18vybmZi7xl dTHrvE Qo=&c=nhHYq0i JXucvCbZUdi5QPVOMj5aogCpqlcFwt4IP5kM zKT59/ 2tmx vVB1fwjTUn6Paqwh3Zn/kli6w6MozUG9O8fPsuHxqWRJy2Y6CUA4T7/aRWBFKJ1g1l8 /5kCkn1eVEuDhny3DhBtZtmJGPRBGRPNHl0W03umW41cJqW5y82FVogjkVw26peDjZy&e=0&downloadAs=microsoft-office-visio-professional-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.repositoryconceptstag.com/c?x=XgjoC6eSXQSzBVRT6I7ek8ElSN4HLxgBF3JH 39jRkI=&c=7jzukWBIGBPJ6eZVsXC4Wjp tZq0fxEttkCjzupI2dRBTvTNL ilB NYT8xtCLWLyr9EeKDb3fnDif0DratJayN7crhNpD7R/0tx0/oAiV cqNXKMYNsvpzckDX9P/Bx3VIYL0ZeBdrtz/ZgtnEWIA==&e=0&downloadAs=microsoft-office-visio-professional-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

http://www.cleanvaultsworld.com/WVl6OTRQVVV4Tkd4blRrdG1Ta3RTY1dGcFdFMU9UVkJzWjNGb1FXRmpXRVZGVW10VE55VXlRazFuVTNKTUpUSkNPRXR2SlRORUptTTlRMnBTU0VOUWFsWTVkRmhHWnpKMlJEa3hiVWMyTXpBeWQyNXBUbkpDVURKME1ubFFRWE14UlhGdVdGRjNKVEpHYkVkMmVIVTNOREJsY214bFFrWmFKVEpDTUcxNmEydGxjQ1V5UmlVeVJrNTNKVEpHTldwM2FUZDBVU1V5UW5SbVEzY2xNa1lsTWtaTFVHTTRkMmt6SlRKQ01rMDFlVk5RVG5GMk9EbEZUbVpCTlVObWNYSnBORU0wV2pWdmVFNWlhQ1V5UW1wYWNub3lObGxvY0RNbE1rWlZVSEZqYkVOTGFVTnJVU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxdGFXTnliM052Wm5RdGIyWm1hV05sTFhacGMybHZMWEJ5YjJabGMzTnBiMjVoYkMweU1ERXpMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um05bVptbGpaUzV0YVdOeWIzTnZablF1WTI5dEpUSkdaVzR0TURBeEpUSkdkbWx6YVc4bE1rWT0=

Latest 30 of 81 download URLs

Remove microsoft-office-visio-professional-2013.exe - Powered by Reason Core Security