malwarebytes anti-malware.exe

Contumar Empresarial s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application malwarebytes anti-malware.exe by Contumar Empresarial s.l has been detected as adware by 27 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from get.nailbestfiles.com.
Publisher:
Contumar Empresarial s.l.  (signed and verified)

MD5:
bd4a90f48b120598ba067d1915a06a9b

SHA-1:
93a3a2d5e1df1bf2c153d5cd1948817932b36144

SHA-256:
65eee493005e58a31047914cb96117d23949754e3df821cf2d589245af3b729a

Scanner detections:
27 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/5/2024 4:32:58 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.190520
5742487

Agnitum Outpost
PUA.Downloader
7.1.1

AhnLab V3 Security
PUP/Win32.BundleInstaller
2015.06.19

Avira AntiVirus
PUA/Firseria.fddtf
8.3.1.6

Arcabit
Trojan.Adware.Graftor.D2E838
1.0.0.425

AVG
Generic
2016.0.3074

Bitdefender
Gen:Variant.Adware.Graftor.190520
1.0.20.845

Clam AntiVirus
Win.Adware.Graftor-947
0.98/20580

Dr.Web
Adware.Downware.11521
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.190520
10.0.0.5366

ESET NOD32
Win32/TrojanDropper.Addrop.J trojan
7.0.302.0

Fortinet FortiGate
Riskware/Generic.AC.551205
6/18/2015

F-Prot
W32/S-b96a44a4
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor
5.14.151

G Data
Gen:Variant.Adware.Graftor.190520
15.6.25

IKARUS anti.virus
AdWare.Downware
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.205.16293

Kaspersky
not-a-virus:RiskTool.Win32.ADInstaller
15.0.0.543

Malwarebytes
PUP.Optional.Solimba
v2015.06.18.08

MicroWorld eScan
Gen:Variant.Adware.Graftor.190520
16.0.0.507

NANO AntiVirus
Riskware.Win32.Downware.dsnqhl
0.30.24.2086

Norman
Gen:Variant.Adware.Graftor.190520
02.06.2015 14:23:46

Panda Antivirus
Trj/Genetic.gen
15.06.18.08

Reason Heuristics
PUP.ContumarEmpresarial
15.6.16.21

Sophos
PUA 'Solimba Installer'
5.15

VIPRE Antivirus
Threat.4150696
41244

Zillya! Antivirus
Dropper.Addrop.Win32.276
2.0.0.2235

File size:
655.1 KB (670,816 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\malwarebytes anti-malware.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/2/2015 8:00:38 AM

Valid to:
9/24/2016 9:00:25 AM

Subject:
CN=Contumar Empresarial s.l., O=Contumar Empresarial s.l., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112119FE6AFB4FA7129F4F594CD3E07D5B21

File PE Metadata
Compilation timestamp:
5/28/2015 6:37:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:C1heIHTECcwLbmMkSxB2Filn+rKibmeeJC5LOFKGE3KoHKWfw0d7x1+ZR9Xj:4eIfz3ajKZeeJrmKoHu+l0H9Xj

Entry address:
0x10FEC

Entry point:
E8, 7E, 96, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, F0, CB, 42, 00, E8, BE, 57, 00, 00, E8, 2C, 1D, 00, 00, 0F, B7, F0, 6A, 02, E8, 11, 96, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, BD, 4D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.4721

Code size:
139 KB (142,336 bytes)

The file malwarebytes anti-malware.exe has been seen being distributed by the following URL.

Remove malwarebytes anti-malware.exe - Powered by Reason Core Security