mario forever.exe

Mario Forever

Apps Installer S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application mario forever.exe, “Mario Forever AppInstaller” by Apps Installer S.L has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Apps Installer S.L.  (signed and verified)

Product:
Mario Forever

Description:
Mario Forever AppInstaller

Version:
3.0.14.3

MD5:
1f9ac9b75ac67d64e5ac83c9356cb0b0

SHA-1:
5d6a414d793b48116915fffe1bf7f1e1846055cb

SHA-256:
2169a6bd132b3afd7c95c71a775e28999e56e9c58f50540fa38db601f932c538

Scanner detections:
19 / 68

Status:
Adware

Explanation:
This is a wrapped installation of legitimate software (without persmission of the developer) and bundles adware such as toolbars and extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 6:22:32 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Solimba
7.1.1

Avira AntiVirus
APPL/Solimba.Gen
7.11.182.78

avast!
Solimba-C [PUP]
141025-0

Comodo Security
Application.Win32.Solimba.GW
19944

Dr.Web
Adware.Downware.1125
9.0.1.05190

ESET NOD32
MSIL/Solimba potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Solimba
10/30/2014

K7 AntiVirus
Unwanted-Program
13.185.13853

Kaspersky
not-a-virus:AdWare.Win32.Fiseria
15.0.0.494

Malwarebytes
PUP.Optional.Solimba
v2014.10.30.11

McAfee
Artemis!6952E7F408E9
5600.6962

NANO AntiVirus
Trojan.Win32.Solimba.daevvb
0.28.6.62995

Quick Heal
Downloader.Solimba.r3 (Not a Virus)
10.14.14.00

Reason Heuristics
PUP.Installer.AppsInstallerSL.N
14.10.27.15

Rising Antivirus
PE:PUF.FirseriaInstaller@CV!1.5C42
23.00.65.141028

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Signed-Downware.Morstar.AppsInstallerSL
3.12.26.3

VIPRE Antivirus
Threat.4782980
34232

Zillya! Antivirus
Downloader.Solimba.Win32.4275
2.0.0.1972

File size:
238.6 KB (244,368 bytes)

Copyright:
AppInstaller 2013 (131881408)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\mario forever.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/19/2013 1:00:00 AM

Valid to:
2/20/2015 12:59:59 AM

Subject:
CN=Apps Installer S.L., O=Apps Installer S.L., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
323F44D66AEF890F43C32CFD743A4AD0

File PE Metadata
Compilation timestamp:
2/19/2012 4:01:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
6144:UsaocyLCxK/8Z+o4pJznk9d4k83FWbLUYY:UtobOKyPCCajFWb0

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/37712340/launch

Remove mario forever.exe - Powered by Reason Core Security