garageband.exe

Imbernes Premium, s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application garageband.exe by Imbernes Premium, s.l has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from smugfile.com.
Publisher:
Imbernes Premium, s.l.  (signed and verified)

MD5:
2e6bd50ff3fcaf88fa129f853353c7d7

SHA-1:
47b8a67a0c61dcfed4e508a7e85de62b17b461fd

SHA-256:
4425979331330b2ea5ce1097db50412559ac24299c2236839e509549442e48f0

Scanner detections:
18 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
1/14/2025 2:25:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1001574
6212523

Avira AntiVirus
APPL/Firseria.Gen
7.11.197.26

avast!
Win32:Trojan-gen
141214-1

AVG
Adware BundleApp_r.AJ
2014.0.4235

Bitdefender
Application.Generic.1001574
1.0.20.1775

Emsisoft Anti-Malware
Application.Generic.1001574
9.0.0.4668

ESET NOD32
MSIL/Solimba.AK.gen potentially unwanted application
7.0.302.0

F-Secure
Riskware.Application.Generic.1001574
5.13.68

G Data
Application.Generic.1001574
14.12.24

IKARUS anti.virus
not-a-virus:Downloader.Morstar
t3scan.1.8.5.0

MicroWorld eScan
Application.Generic.1001574
15.0.0.1065

NANO AntiVirus
Trojan.Win32.Morstar.dkmwot
0.28.6.64267

Norman
Application.Generic.1001574
04.12.2014 14:30:06

Panda Antivirus
Trj/Genetic.gen
14.12.21.02

Reason Heuristics
PUP.Solimba
15.2.14.11

Sophos
PUA 'Solimba Installer'
5.09

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Threat.4150696
35418

File size:
613 KB (627,744 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\garageband.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/5/2014 7:00:00 PM

Valid to:
11/5/2017 6:59:59 PM

Subject:
CN="Imbernes Premium, s.l.", O="Imbernes Premium, s.l.", STREET="CALLE DIPUTACIO, 279 - P. 1", L=Barcelona, S=Barcelona, PostalCode=08007, C=ES

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A6EF0CC37BACB2FA7E515717F8E11C59

File PE Metadata
Compilation timestamp:
12/18/2014 10:58:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:EDBZggVvTaffzUt9zCktr9Hl4T9eYyKNEgIajvTviq3:EDBZtvT5zCWlcdy8v

Entry address:
0xD44C

Entry point:
E8, AF, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 40, 60, 42, 00, E8, FE, 15, 00, 00, E8, 80, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 42, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0B, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.5103

Code size:
111 KB (113,664 bytes)

The file garageband.exe has been seen being distributed by the following URL.

Remove garageband.exe - Powered by Reason Core Security