edius-pro-7.exe

Mala

Bibado Investments S.L.

The application edius-pro-7.exe, “Mala Setup ” by Bibado Investments S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Bibado Downloader installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.vaultsfarmhosting.com.
Publisher:
Bibado Investments S.L.  (signed and verified)

Product:
Mala

Description:
Mala Setup

Version:
1.6.2.4

MD5:
09046cdb2debdeb839946f3e0f4e1bec

SHA-1:
ee630e37cfcff6300446abb8b3bfd01fd53d6198

SHA-256:
9f16a52e7c0bd3d23a82d098ac9bdd0bb1bd190cee53fd1037dc400ab0bf661c

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/27/2024 3:00:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.3.6.0

File size:
1.2 MB (1,253,064 bytes)

Product version:
4.6

Copyright:
Stub fast

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Bibado Downloader (using Inno Setup)

Common path:
C:\users\{user}\downloads\edius-pro-7.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 8:45:47 AM

Valid to:
10/10/2016 8:59:18 AM

Subject:
CN=Bibado Investments S.L., O=Bibado Investments S.L., L=Alcorcon, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C7CDCA8256DFB1BF27E11C9CC97F08E3

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file edius-pro-7.exe has been seen being distributed by the following URL.

http://www.vaultsfarmhosting.com/dntT_pI7RJkZ4RdybmWzlEQN3Odt6SigyMgixWdGfHzj_8cLleCSLOQcDy5HHadCCG2ihkN9qxmPpX5YWrQLOJK0a_EfbO56bqa5VU0AxiDuIHbsP27DskFYgVqjZhq5m0ad02ty153iZQsYfPrxTSMEKM6uPAVjk5W5Oyl24kv3zpQ_trf_EnC_tIRgI38EC9K3haF3-G_0CAGS ttEfD2wQuT_BoXoU8eIjagiRKHDIAfu3M8QcSOIcbMAlXrDtGhM_LgJ1Ttch74otWbtFbxyMyq1QJW96hWLBiejhAdOJ93Fg1494aWNhxtf9wHa4u6T5Bvr7R8_fCbrFA2LHG_vGkrqSOxDiWiXxbGorXoEWurlmSXXPMpVkA5uN027MCs6qBCUhsrPoZEKFJe_BICXe1Ntogky9VhWF61ssTxwSZyOhZqFTqzbYvqlQzEs0nQPCw83DrhE2Dk xeof5u8jaPJPv6cjD51UGB R3xZLlBbKIC6MUJA6U71yLvfN7 sUvbGSKHHcAgsa8jV7P8SE8rlfr48XcX05XctiduLLMP3SvZZQVxZLZgl090Vsc6rrZ4 gEqS1JC17z2eNT4g db3QAcoNl0nsxNfS7yiZONLNeoRSbDCWnj4TBry4DxX2L4K7JqnKL3MKsHn0VZJQJSNylAqshec4zClvTAx7z71bWNC7lezRTJ5WqQiwEOfDk7ODyd Jv8ykrAFis85ETNRVzG7uwWzSS05TwlUxHo3xNgq2C hGaJIZTg86dwnfUvI0 uCE1RL_cbfoAXE8_7p XWFjTU4HlbXuxeWR7tbYNVApkAl3R0ABr8Q94vEsPe0 Q614zc0sZi O9vfsqtdzwdVtHmQQM1LtGok65SS0oinMq DYJzpco4woHaunISSD 56eKV6Jow4zc3C4WbEag5u_QBb50s3VnBaKZqKLpgKNGrz2IqYl6Ds2aJYJSiL

Remove edius-pro-7.exe - Powered by Reason Core Security