photofiltre.exe

XLIX-II praecox

Condestil Developments s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application photofiltre.exe, “potissimus digressio despecto relinquo” by Condestil Developments s.l has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
fuga  (signed by Condestil Developments s.l.)

Product:
XLIX-II praecox

Description:
potissimus digressio despecto relinquo

Version:
27.24.32.56

MD5:
6d8eb6ce92f112c54df8f1b0a98e2d15

SHA-1:
0df61ff1cd784155c38a3ab2c4e6ef7f158d2f9e

SHA-256:
bd485e09a1cd34c852b70fcb5df86adfa8df43e4ff0eb3a86ecd14d6d603eadd

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 8:53:23 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Solimba
7.1.1

Avira AntiVirus
APPL/Firseria.Gen8
7.11.181.56

avast!
Win32:Adware-gen [Adw]
2014.9-150106

AVG
Adware BundleApp_r
2016.0.3237

Clam AntiVirus
Win.Adware.Agent-27634
0.98/19576

Comodo Security
Application.Win32.Solimba.LSW
19900

Dr.Web
Adware.Downware.8808
9.0.1.06

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Kazy.132995
8.15.01.06.01

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/Morstars
1/6/2015

F-Prot
W32/A-a1e0d357
v6.4.7.1.166

G Data
Win32.Application.Morstar
15.1.24

K7 AntiVirus
Unwanted-Program
13.185.13805

Malwarebytes
PUP.Optional.Solimba
v2015.01.06.01

McAfee
Artemis!9D37236DB865
5600.6893

MicroWorld eScan
Gen:Variant.Application.Bundler.Kazy.132995
16.0.0.18

NANO AntiVirus
Trojan.Win32.Morstar.dhdhyl
0.28.6.62995

Panda Antivirus
Trj/Genetic.gen
15.01.06.01

Quick Heal
Adware.Firseria.A5
1.15.14.00

Reason Heuristics
PUP.CondestilDevelopmentssl.L
15.1.6.13

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
DownloadMR
34232

File size:
538.2 KB (551,136 bytes)

Product version:
74.92.26.61

Copyright:
ingero nauta

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\photofiltre.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/25/2014 2:00:00 AM

Valid to:
7/25/2016 1:59:59 AM

Subject:
CN=Condestil Developments s.l., O=Condestil Developments s.l., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
43F850AA43DAD92FF6603BEB72F415DD

File PE Metadata
Compilation timestamp:
10/24/2014 10:57:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:QJB1vxtlnzqT4y4R2wbEyxyHLUIo4AIOYQCAJ8h7cHkMcW2TqpVV:QJlHqTNMrbhxyyEMcWSqzV

Entry address:
0xDE2C

Entry point:
E8, A3, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 58, 70, 42, 00, E8, FE, 15, 00, 00, E8, 74, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 36, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, FF, 64, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
113.5 KB (116,224 bytes)

The file photofiltre.exe has been seen being distributed by the following URL.

Remove photofiltre.exe - Powered by Reason Core Security