whatsapp.exe

Thawte manager

Eilio Developments s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application whatsapp.exe by Eilio Developments s.l has been detected as adware by 37 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from dl.fasterdownfiles.com.
Publisher:
Thawte.Installer_S.L.  (signed by Eilio Developments s.l.)

Product:
Thawte manager

Description:
Installer

Version:
3.1.22.18.4

MD5:
99d42ed40c90b33fb11e1f8f68b6da07

SHA-1:
624f7404a95333b2b9657a9092cd89b058936389

SHA-256:
cd1438c8a78efa6a97d9de957e1dfa79443fe2a5da0e4439b6e86a284b70ef2b

Scanner detections:
37 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/9/2024 8:57:19 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Kazy.132995
738

Agnitum Outpost
PUA.Solimba
7.1.1

AhnLab V3 Security
PUP/Win32.Solimba
2014.09.25

Avira AntiVirus
APPL/Firseria.Gen8
7.11.173.226

avast!
Win32:GenMalicious-AEY [PUP]
2014.9-150127

AVG
Generic
2016.0.3216

Baidu Antivirus
Adware.MSIL.Solimba
4.0.3.15127

Bitdefender
Gen:Variant.Application.Bundler.Kazy.132995
1.0.20.135

Bkav FE
W32.HfsAdware
1.3.0.6267

Clam AntiVirus
Win.Trojan.Morstar-21
0.98/19418

Comodo Security
Application.Win32.Solimba.LSW
19607

Dr.Web
Trojan.DownLoader11.24441
9.0.1.027

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Kazy.132995
8.15.01.27.06

ESET NOD32
MSIL/Solimba.AH (variant)
9.10449

Fortinet FortiGate
Riskware/Morstar
1/27/2015

F-Prot
W32/A-a79dd9a7
v6.4.7.1.166

F-Secure
Gen:Variant.Application.Bundler
11.2015-27-01_3

G Data
Gen:Variant.Application.Bundler.Kazy.132995
15.1.24

IKARUS anti.virus
not-a-virus:Downloader.Morstar
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.183.13463

Kaspersky
not-a-virus:Downloader.Win32.Morstar
14.0.0.2576

Malwarebytes
PUP.Optional.Solimba
v2015.01.27.06

McAfee
Artemis!99D42ED40C90
5600.6872

MicroWorld eScan
Gen:Variant.Application.Bundler.Kazy.132995
16.0.0.81

NANO AntiVirus
Trojan.Win32.Morstar.dfgpsr
0.28.2.62286

Norman
Gen:Variant.Strictor.67357
11.20150127

nProtect
Trojan.Generic.11823520
14.09.28.01

Panda Antivirus
Trj/CI.A
15.01.27.06

Qihoo 360 Security
Win32/Virus.Downloader.d21
1.0.0.1015

Quick Heal
Adware.Firseria.A5
1.15.14.00

Reason Heuristics
PUP.Installer.EilioDevelopments
15.1.27.18

Sophos
Solimba Installer
4.98

SUPERAntiSpyware
PUP.Solimba/Variant
10089

Trend Micro House Call
TROJ_GEN.F0C2H00IM14
7.2.27

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
33352

Zillya! Antivirus
Downloader.Morstar.Win32.84
2.0.0.1929

File size:
517.7 KB (530,136 bytes)

Product version:
3.1.22

Copyright:
copyright © 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\whatsapp.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/25/2014 2:00:00 AM

Valid to:
7/25/2016 1:59:59 AM

Subject:
CN=Eilio Developments s.l., O=Eilio Developments s.l., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
62A9979715091C35A10D5CC1298205DA

File PE Metadata
Compilation timestamp:
9/18/2014 10:11:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:rmvQlk6OnF+T6zgSZQKxKFKAdK3QFvEqZ0YHw4GiYJBDhrCVi/:rmvQC5+TlSZQkENdK3QyqZ0YHNGlZsi/

Entry address:
0xDFEC

Entry point:
E8, AE, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, 70, 42, 00, E8, FE, 15, 00, 00, E8, 7F, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 41, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0A, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
114 KB (116,736 bytes)

The file whatsapp.exe has been seen being distributed by the following URL.

Remove whatsapp.exe - Powered by Reason Core Security