7-data android recover.exe

XL-I viscus cilicium abscido

Condestil Developments, s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application 7-data android recover.exe, “noceo pecco flumen” by Condestil Developments, s.l has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
dolosus minimus renuo  (signed by Condestil Developments, s.l.)

Product:
XL-I viscus cilicium abscido

Description:
noceo pecco flumen

Version:
29.46.16.5

MD5:
15c802fee1d6a98828f487b75813b4c7

SHA-1:
d2f3790038a62f23be21738c417fa8d5e27d77b5

SHA-256:
9356a2bf6aec62a0a6b432f0b882945757813f743277f6fad245b3c6de3485ac

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/5/2024 2:53:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solimba (M)
17.2.15.23

File size:
538.8 KB (551,696 bytes)

Product version:
34.81.1.74

Copyright:
ubi fortunate nocens purgo

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\7-data%20android%20recover.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/25/2014 1:00:00 AM

Valid to:
7/25/2017 12:59:59 AM

Subject:
CN="Condestil Developments, s.l.", O="Condestil Developments, s.l.", L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1D3748575F923798E7549D60FC6C4D50

File PE Metadata
Compilation timestamp:
10/13/2014 11:22:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0xDE9C

Entry point:
E8, A5, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 28, 6E, 42, 00, E8, FE, 15, 00, 00, E8, 76, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 38, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 01, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Packer / compiler:
PEQuake V0.06

Code size:
113.5 KB (116,224 bytes)

Remove 7-data android recover.exe - Powered by Reason Core Security