onaylanmayan 854349.crdownload

XLIX-II praecox

Condestil Developments s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The file onaylanmayan 854349.crdownload, “potissimus digressio despecto relinquo” by Condestil Developments s.l has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
fuga  (signed by Condestil Developments s.l.)

Product:
XLIX-II praecox

Description:
potissimus digressio despecto relinquo

Version:
27.24.32.56

MD5:
6e65fe6f3e0a0105e97f2c7174322f70

SHA-1:
2c79e1300e9eb788a4c21a0d473d12e0c5b19074

SHA-256:
20aca86cdb0d553f16ce24b02e294aa44273d815389a57458df09b8ccf487814

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/10/2024 7:11:58 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Solimba
7.1.1

Avira AntiVirus
APPL/Firseria.Gen8
7.11.181.56

avast!
Win32:Adware-gen [Adw]
2014.9-141123

AVG
Adware BundleApp_r.AV
2014.0.4189

Clam AntiVirus
Win.Adware.Agent-27634
0.98/19576

Comodo Security
Application.Win32.Solimba.LSW
19900

Dr.Web
Adware.Downware.8808
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Kazy.132995
8.14.11.23.09

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/Morstars
11/23/2014

F-Prot
W32/A-a1e0d357
v6.4.7.1.166

G Data
Win32.Application.Morstar
14.11.24

K7 AntiVirus
Unwanted-Program
13.185.13805

Malwarebytes
PUP.Optional.Solimba
v2014.11.23.09

McAfee
Artemis!9D37236DB865
5600.6937

MicroWorld eScan
Gen:Variant.Application.Bundler.Kazy.132995
15.0.0.981

NANO AntiVirus
Trojan.Win32.Morstar.dhdhyl
0.28.6.62995

Quick Heal
Adware.Firseria.A5
11.14.14.00

Reason Heuristics
PUP.CondestilDevelopmentssl.DD
14.11.23.21

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
DownloadMR
34232

File size:
538.2 KB (551,136 bytes)

Product version:
74.92.26.61

Copyright:
ingero nauta

Bundler/Installer:
Solimba DownloadMR

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\downloads\onaylanmayan 854349.crdownload

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/25/2014 3:00:00 AM

Valid to:
7/25/2016 2:59:59 AM

Subject:
CN=Condestil Developments s.l., O=Condestil Developments s.l., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
43F850AA43DAD92FF6603BEB72F415DD

File PE Metadata
Compilation timestamp:
10/24/2014 11:57:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:QJB1vxtlnzqT4y4R2wbEyxyHLUIo4AIOYQCAJ8h7cHkMcW2TqpVV:QJlHqTNMrbhxyyEMcWSqzV

Entry address:
0xDE2C

Entry point:
E8, A3, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 58, 70, 42, 00, E8, FE, 15, 00, 00, E8, 74, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 36, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, FF, 64, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
113.5 KB (116,224 bytes)

Remove onaylanmayan 854349.crdownload - Powered by Reason Core Security