realplayer.exe

BIBADO INVESTMENTS

The application realplayer.exe by BIBADO INVESTMENTS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Bibado Downloader installer. With this installer, users are expecting to download RealPlayer but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
BIBADO INVESTMENTS  (signed and verified)

MD5:
d37e220ba4ae87c45dec3ca323a1e8c2

SHA-1:
60d6676dc4696225dfcc108093ccd63b098b81e6

SHA-256:
f3b1b0e84c6bbbfb7c3a0bab4e258c1b7d6d21a6481c93884cfe6c6d79fb3cc5

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 12:48:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bibado.BIBADOINVESTMENTS.Bundler (M)
16.2.14.5

File size:
167.1 KB (171,096 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Bibado Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\realplayer.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/26/2012 1:00:00 AM

Valid to:
1/26/2014 12:59:59 AM

Subject:
CN=BIBADO INVESTMENTS, OU=QA DEPARTMENT, O=BIBADO INVESTMENTS, L=VILLAVICIOSA DE ODON, S=MADRID, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
04F067CB9EFD3EEBEDABCC3882579B37

File PE Metadata
Compilation timestamp:
2/24/2012 8:20:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:k5BuYAVrgUCPnd45zDZGnjR1n0a3M1PQNIXyBWy23RPms6CJ4s9ThFEYs:k50gUCVEDs1nrOyBX231mePFds

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.5846

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

Remove realplayer.exe - Powered by Reason Core Security