adobe reader.exe

popeller.installr

Condestil Developments s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application adobe reader.exe by Condestil Developments s.l has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Popeller, sl  (signed by Condestil Developments s.l.)

Product:
popeller.installr

Description:
popeller Manager

Version:
3.1.19.1

MD5:
f7adb009099280514322123dfac0ee5b

SHA-1:
f97b96ac32c6b3bc8c1cc9265b655ebd1e270a8a

SHA-256:
e47b44d7cf0626bfb4d7f97183b0448733aec32d50971beb28b9a046c6d172ec

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/19/2024 4:06:10 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solimba.Condesti (M)
16.4.25.15

File size:
504.2 KB (516,296 bytes)

Product version:
3.1.20

Copyright:
copyright© 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\adobe reader.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/24/2014 9:00:00 PM

Valid to:
7/24/2016 8:59:59 PM

Subject:
CN=Condestil Developments s.l., O=Condestil Developments s.l., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
43F850AA43DAD92FF6603BEB72F415DD

File PE Metadata
Compilation timestamp:
7/26/2014 7:14:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:FOlSdJHzslHc1Ga7s9Be6EYN7R/ZcikmmZtaK9S8NSRUU1uz5Dz7OCN44jq8Ww:FCS3zslHc4YudoPZ8K1SqFXq4u8Ww

Entry address:
0xDFE8

Entry point:
E8, 5E, 6D, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 55, 08, 56, 57, 85, D2, 74, 07, 8B, 7D, 0C, 85, FF, 75, 13, E8, 5F, 2C, 00, 00, 6A, 16, 5E, 89, 30, E8, 03, 2C, 00, 00, 8B, C6, EB, 33, 8B, 45, 10, 85, C0, 75, 04, 88, 02, EB, E2, 8B, F2, 2B, F0, 8A, 08, 88, 0C, 06, 40, 84, C9, 74, 03, 4F, 75, F3, 85, FF, 75, 11, C6, 02, 00, E8, 29, 2C, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, C6, 33, C0, 5F, 5E, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00...
 
[+]

Code size:
116.5 KB (119,296 bytes)

The file adobe reader.exe has been seen being distributed by the following URL.

Remove adobe reader.exe - Powered by Reason Core Security