nero_burning_rom_2015_multilenguaje_espanol_portable_la_mejor_herramienta_de_grabacion_del_mundo_dow

Somoto Israel Ltd.

This is the Somoto BetterInstaller, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The file nero_burning_rom_2015_multilenguaje_espanol_portable_la_mejor_herramienta_de_grabacion_del_mundo_dow by Somoto Israel has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Somoto BetterInstaller installer.
Publisher:
Somoto Israel Ltd.  (signed and verified)

Version:
1.0.0.1

MD5:
2a927663804b302596d3a66bd77f66ae

SHA-1:
8520df047ab0840739a69eaefa963b6e0f998c4d

SHA-256:
7cc8b6a6c5cdc9895b8e802893a7ccba27dcba72a420580d063690e8f6f967b4

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/6/2024 4:58:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Somoto (M)
16.11.1.3

File size:
403.3 KB (413,008 bytes)

Bundler/Installer:
Somoto BetterInstaller

Common path:
C:\users\{user}\downloads\nero_burning_rom_2015_multilenguaje_espanol_portable_la_mejor_herramienta_de_grabacion_del_mundo_downloader-nffzue0qi.exe

Digital Signature
Authority:
Somoto Israel Ltd.

Valid from:
1/28/2015 3:45:34 PM

Valid to:
1/28/2016 4:05:34 PM

Subject:
CN=Somoto Israel Ltd., OU="", O=Somoto Israel Ltd., L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=Somoto Israel Ltd., OU="", O=Somoto Israel Ltd., L=Tel Aviv, S=Israel, C=IL

Serial number:
66193B5EACC01CB140D8D920D06C3660

File PE Metadata
Compilation timestamp:
12/17/2010 10:14:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
12288:4A0i50GjsCRUAsTsrDPIcno1+y0Zq6chU:4AfyGwCOiZpy0Zq6chU

Entry address:
0x39AC

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 97, 46, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 42, 43, 00, 00, 6A, 00, E8, AB, 46, 00, 00, 6A, 08, A3, 88, 4C, 42, 00, E8, B1, 28, 00, 00, 6A, 00, 68, 60, 01, 00, 00, A3, 38, 4D, 42, 00, 8D, 85, 90, FE, FF, FF, 50, 6A, 00, 68, A4, A2, 40, 00, E8, F0, 45, 00, 00, 83, EC, 0C, 68, A5, A2, 40, 00, 68, 68, 4D, 42, 00, E8, EF, 2A, 00, 00, 83, C4, 18, E8, FE, 42, 00, 00, 52, 52, 50, 68, 00, D0, 42, 00, E8, DA, 2A, 00, 00, 57, 6A, 00, E8, 39, 42, 00, 00, 83...
 
[+]

Code size:
28.5 KB (29,184 bytes)