windows-8-windows-downloader.exe

Malavida Network International, S.L.

The application windows-8-windows-downloader.exe by Malavida Network International, S.L has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from dl13350be.mvmfd.net and multiple other hosts.
Publisher:
Malavida Network International, S.L.  (signed and verified)

MD5:
c4ae6949a585d9a4abe2e50f3fbe09e6

SHA-1:
b2d32e79b2c9fe4d2a9f0655fdb78fd3b0d0d4dc

SHA-256:
4f9430c6010a6170865d38a13a1e48267a9d06224a0e3802b9c135d0247510f3

Scanner detections:
8 / 68

Status:
Adware

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
1/15/2025 4:52:46 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Toolbar.Babylon
2015.0.3531

Dr.Web
Adware.Downware.1448
9.0.1.078

ESET NOD32
Win32/Malavida
8.9464

McAfee
Artemis!C4AE6949A585
5600.7187

Reason Heuristics
PUP.MalavidaNetworkInternationalSL.CC
14.8.7.21

Sophos
Malavida
4.97

Trend Micro House Call
TROJ_GEN.F47V0219
7.2.78

VIPRE Antivirus
Malavida
26806

File size:
389.3 KB (398,648 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\windows-8-windows-downloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/27/2013 5:30:00 AM

Valid to:
3/28/2014 5:29:59 AM

Subject:
CN="Malavida Network International, S.L.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Malavida Network International, S.L.", L=Valencia, S=Valencia, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0DC341780137340F059956E88184360E

File PE Metadata
Compilation timestamp:
12/6/2009 4:20:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:HQqZAb82WjtmMyHYZowAjO3UeKv4WpNqAXJ2WptMHLRHkaYnZ3iva8JjXZDYU:zyIpnRYjTlN9XNOR0ZAa4DYU

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9063

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file windows-8-windows-downloader.exe has been seen being distributed by the following 2 URLs.

Remove windows-8-windows-downloader.exe - Powered by Reason Core Security