viber.exe

volens eloquentia XLII-II

trepide

The application viber.exe, “fulgeo mansuetus cometes” has been detected as a potentially unwanted program by 7 anti-malware scanners. This is a setup program which is used to install the application. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from sunkfile.com.
Publisher:
trepide

Product:
volens eloquentia XLII-II

Description:
fulgeo mansuetus cometes

Version:
0.91.17.25

MD5:
443d8b93eb7520440fca0c1d6a47c1bb

SHA-1:
eac9f6bb689f76be459dc1cfdd5581617df0eec2

SHA-256:
bba7809aa30502dd4abae1961539d802653e228e53dd75aff2c2c3c1323db336

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Uses the Solimba installer to bundle adware offers.

Analysis date:
11/28/2024 4:14:26 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
MSIL:Solimba-Z [PUP]
160414-2

AVG
Adware BundleApp_r.AV
2015.0.4591

Emsisoft Anti-Malware
Application.Bundler.Morstar.L
16.07.11

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
8.0.319.0

Microsoft Security Essentials
Threat.Undefined
1.225.793.0

Norman
Application.Bundler.Morstar.L
19.05.2016 01:04:49

VIPRE Antivirus
Threat.4150696
50532

File size:
523.2 KB (535,807 bytes)

Product version:
24.15.34.38

Copyright:
Copyright specto

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\viber.exe

File PE Metadata
Compilation timestamp:
10/14/2014 8:27:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:xTySyXMWfPTuNnB2WfFZ9dQ+rHhl4ZDdlxipv1snRotIS:xTySy9PTUnhfU2Hhl4DdlIcRotIS

Entry address:
0xDEDC

Entry point:
E8, AE, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, D8, 6F, 42, 00, E8, FE, 15, 00, 00, E8, 7F, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 41, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0A, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.7024  (probably packed)

Code size:
113.5 KB (116,224 bytes)

The file viber.exe has been seen being distributed by the following URL.

Remove viber.exe - Powered by Reason Core Security