realdownloader.exe

Apps-manager

Eilio Developments s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application realdownloader.exe by Eilio Developments s.l has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Eilio.-.Installer · sl  (signed by Eilio Developments s.l.)

Product:
Apps-manager

Description:
Installer

Version:
3.1.24.0

MD5:
95f73dd1ecb8b6d88d11206b3e60e167

SHA-1:
447e286e54d1c33a8359b6099b08c75760905a0e

SHA-256:
064e42fd1e6b0f719d33dc88b7dd69343c27db19f3563c1440222f7b361177fa

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/27/2024 5:54:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solimba.EilioDev.Installer (M)
16.6.6.6

File size:
517.7 KB (530,136 bytes)

Product version:
3.1.22

Copyright:
copyright © 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\realdownloader.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/24/2014 9:00:00 PM

Valid to:
7/24/2016 8:59:59 PM

Subject:
CN=Eilio Developments s.l., O=Eilio Developments s.l., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
62A9979715091C35A10D5CC1298205DA

File PE Metadata
Compilation timestamp:
9/17/2014 7:27:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:/93qjAky4FYTaYvCY8sySmQQBYrZUW/u8Rpi1R93C90ba8RikK:/93QhYTVvB8TSmQQBYrZUW/zi1R9xBRc

Entry address:
0xDEBC

Entry point:
E8, AC, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B8, 71, 42, 00, E8, FE, 15, 00, 00, E8, 7D, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 3F, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 08, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
113.5 KB (116,224 bytes)

The file realdownloader.exe has been seen being distributed by the following URL.

Remove realdownloader.exe - Powered by Reason Core Security