rockmelt-windows-downloader.exe

Malavida Network International, S.L.

The application rockmelt-windows-downloader.exe by Malavida Network International, S.L has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from dl1332d9e.mvmfd.net and multiple other hosts.
Publisher:
Malavida Network International, S.L.  (signed and verified)

MD5:
a951a40994b4e2f431a156a068de43f6

SHA-1:
0a83141325c9a200a75bd163f5924c5315c5a467

SHA-256:
130b8222b32cdaeea8e68fe4cc2b0555bfd944e4d7e441904edbc3d08c420f2b

Scanner detections:
10 / 68

Status:
Adware

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
5/3/2024 11:09:44 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Toolbar.Babylon
2015.0.3604

Dr.Web
Adware.Downware.1448
9.0.1.04

ESET NOD32
Win32/Malavida
8.9308

K7 AntiVirus
Unwanted-Program
13.175.10881

McAfee
Artemis!A951A40994B4
5600.7260

Reason Heuristics
PUP.MalavidaNetworkInternationalSL.BB
14.8.7.21

Rising Antivirus
NS:Malware.Install!1.9F21
23.00.65.14102

Sophos
Malavida
4.96

Trend Micro House Call
TROJ_GEN.F47V1220
7.2.4

VIPRE Antivirus
Malavida
25570

File size:
332.5 KB (340,448 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\rockmelt-windows-downloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/27/2013 12:00:00 AM

Valid to:
3/27/2014 11:59:59 PM

Subject:
CN="Malavida Network International, S.L.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Malavida Network International, S.L.", L=Valencia, S=Valencia, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0DC341780137340F059956E88184360E

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:UQqyPszjtmMyHYZowAjO3UeKv4WpNqAXJ2WptMHLRHkaYnZ3NR:1PgpnRYjTlN9XNOR0Z9R

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8807

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file rockmelt-windows-downloader.exe has been seen being distributed by the following 21 URLs.

http://dl1332d9e.mvmfd.net/en/.../photoshop-windows-downloader.exe

http://dl133504b.mvmfd.net/en/.../e-sword-windows-downloader.exe

http://dl133505e.mvmfd.net/en/.../oxford-dictionary-of-english-windows-downloader.exe

Remove rockmelt-windows-downloader.exe - Powered by Reason Core Security