mobipocket-reader-windows-downloader.exe

Malavida Network International, S.L.

The application mobipocket-reader-windows-downloader.exe by Malavida Network International, S.L has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from dl1332b33.mvmfd.net and multiple other hosts.
Publisher:
Malavida Network International, S.L.  (signed and verified)

MD5:
87f505ab7f2bcadb83c3a099d5035ed3

SHA-1:
11da48a2ef0ecd2735ff44ba9a11df79d8588c20

SHA-256:
c3bcf66e1ca1c86db946fe79b83b23e302dc0896fb510a648fa825f9648d43f2

Scanner detections:
8 / 68

Status:
Adware

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
12/26/2024 12:33:07 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Toolbar.Babylon
2015.0.3598

Dr.Web
Adware.Downware.1448
9.0.1.010

ESET NOD32
Win32/Malavida
8.8944

McAfee
Artemis!87F505AB7F2B
5600.7254

Reason Heuristics
PUP.MalavidaNetworkInternationalSL.e
14.8.7.21

Sophos
Malavida
4.93

Trend Micro House Call
TROJ_GEN.F47V0506
7.2.10

VIPRE Antivirus
Malavida
22590

File size:
158.1 KB (161,880 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\mobipocket-reader-windows-downloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/26/2013 6:00:00 PM

Valid to:
3/27/2014 5:59:59 PM

Subject:
CN="Malavida Network International, S.L.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Malavida Network International, S.L.", L=Valencia, S=Valencia, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0DC341780137340F059956E88184360E

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:1Lk395hYXJsN2UwHjy4mMirHYZfLUwA7JEDe9WDXndYOH:1QqvXHjtmMyHYZowAQe0d3

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.6319

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file mobipocket-reader-windows-downloader.exe has been seen being distributed by the following 20 URLs.

http://dl1332b33.mvmfd.net/en/.../ulead-videostudio-windows-downloader.exe

Remove mobipocket-reader-windows-downloader.exe - Powered by Reason Core Security