nimbusnote.exe

Nimbus Note

Nimbus Web Inc

The application nimbusnote.exe, “Nimbus Note Setup ” by Nimbus Web Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from nimbus.everhelper.me.
Publisher:
Nimbus Web Inc   (signed by Nimbus Web Inc)

Product:
Nimbus Note

Description:
Nimbus Note Setup

MD5:
c66dce47121def2820b8e56a7ee4076c

SHA-1:
5a46883d9048825282370161d6e4233351acdd00

SHA-256:
647eb7b83049a8b332b3f32e407873e0db4eab9d5dd1356c439511b009455093

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/27/2024 10:48:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.2.7.2

File size:
4.4 MB (4,588,616 bytes)

Product version:
2.0.9

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/19/2015 3:00:00 AM

Valid to:
10/19/2017 2:59:59 AM

Subject:
CN=Nimbus Web Inc, O=Nimbus Web Inc, STREET=4167 hinsdale rd, L=South Euclid, S=Ohio, PostalCode=44121, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4BD0156E63D8B7DA4D4E74E3E2E4ADB0

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file nimbusnote.exe has been seen being distributed by the following URL.

https://nimbus.everhelper.me/download.php

Remove nimbusnote.exe - Powered by Reason Core Security