isobuster.exe

IsoBuster

Solimba Aplicaciones S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application isobuster.exe by Solimba Aplicaciones S.L has been detected as adware by 27 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from d9yt0xeucd09m.cloudfront.net.
Publisher:
Solimba Aplicaciones S.L.  (signed and verified)

Product:
IsoBuster

Version:
2.1.159.0

MD5:
5e4d26ad2ab2f84f447237df511fcb0c

SHA-1:
d27cf3cde7102fc3697004c4dc907e1b9e3f5dc3

SHA-256:
ad9deeb9bfa9110018a14d53a41be358c24901af40b0d4cae23429a185ff5e3a

Scanner detections:
27 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 4:17:09 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Solimba.1
827

AhnLab V3 Security
Win-PUP/Solimba
2014.10.31

Avira AntiVirus
APPL/Solimba.Gen5
7.11.182.126

avast!
PUP-gen [PUP]
141025-0

Bitdefender
Gen:Variant.Adware.Solimba.1
1.0.20.1520

Clam AntiVirus
Win.Adware.Solimba-10
0.98/21411

Comodo Security
UnclassifiedMalware
19948

Dr.Web
Adware.Downware.83
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Solimba
14.10.27

ESET NOD32
MSIL/Solimba potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/MSIL_Solimba
10/31/2014

F-Prot
W32/Solimba.A.gen
4.6.5.141

F-Secure
Gen:Variant.Adware.Solimba.1
11.2014-31-10_6

G Data
Gen:Variant.Adware.Solimba
14.10.24

K7 AntiVirus
Unwanted-Program
13.185.13853

Kaspersky
not-a-virus:AdWare.MSIL.Solimba
14.0.0.3020

Malwarebytes
Trojan.Repacked
v2014.10.31.12

MicroWorld eScan
Gen:Variant.Adware.Solimba.1
15.0.0.912

NANO AntiVirus
Riskware.Win32.Downware.cthmqi
0.28.6.62995

Quick Heal
AdWare.MSIL.r3 (Not a Virus)
10.14.14.00

Reason Heuristics
PUP.SolimbaAplicacionesSL.J
14.10.27.12

Rising Antivirus
PE:Trojan.Win32.Generic.152043FB!354436091
23.00.65.141029

Sophos
Solimba Installer
4.98

Trend Micro House Call
TROJ_GE.59D169E9
7.2.304

Trend Micro
TROJ_GE.59D169E9
10.465.31

Vba32 AntiVirus
Signed-AdWare.MSIL.SolimbaAplicacionesSL
3.12.26.3

VIPRE Antivirus
Threat.4782980
34232

File size:
108.1 KB (110,720 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\isobuster.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/16/2011 2:00:00 AM

Valid to:
5/16/2013 1:59:59 AM

Subject:
CN=Solimba Aplicaciones S.L., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Solimba Aplicaciones S.L., L=Badalona, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
450EE582E26020D5F7632F2BECC6C5BD

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:HQIURTXJ8eqgKJ+BCxCQnwOL0AEBVbXBe9:HsugK4C4zBV1e9

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.3024

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file isobuster.exe has been seen being distributed by the following URL.

Remove isobuster.exe - Powered by Reason Core Security