bundle_solimba_spacesoundpro.exe

The application bundle_solimba_spacesoundpro.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from csdi-dlstatic.tennoio.com.
MD5:
0d2a3430aa89c0a366c1515b73ae0c6b

SHA-1:
db5857fafc84193463c7e2b0a0599a53ba3486d4

SHA-256:
ad9a9c08eefe04cbb9275a0d5b44624c336213492515a44452b52f8b4264cc13

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 9:54:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Bundler (M)
16.8.28.21

File size:
5 KB (5,120 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\bundle_solimba_spacesoundpro.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
96:d9M+BiuAKhrlFMTLmqpW7hPMqU90FmP/unwnZDHH7HH6jnnInnnEq6jxOSJbK6to:dfB3QTLmqpUPMNnuQZDnb0onE5QSJ+6G

Entry point:
A1, 3D, AC, 3D, CE, 3D, D9, 3D, 07, 3E, 51, 3F, 00, E0, 00, 00, 88, 00, 00, 00, 2C, 32, C1, 32, E0, 32, F7, 32, 06, 33, 77, 33, 91, 37, B2, 37, BD, 37, C3, 37, D5, 37, DF, 37, E8, 37, 30, 38, 35, 38, 3F, 38, 82, 38, E3, 38, 0F, 39, 43, 39, 57, 39, 87, 39, FF, 39, 18, 3A, 63, 3A, 87, 3A, 7C, 3B, 9C, 3B, ED, 3B, 05, 3C, 0A, 3C, 78, 3D, 89, 3D, A9, 3E, AF, 3E, B3, 3E, B8, 3E, BE, 3E, C2, 3E, C8, 3E, CC, 3E, D2, 3E, D6, 3E, DB, 3E, E1, 3E, E5, 3E, EB, 3E, EF, 3E, F5, 3E, F9, 3E, FF, 3E, 03, 3F, 12, 3F, 2F, 3F...
 
[+]

The file bundle_solimba_spacesoundpro.exe has been seen being distributed by the following URL.

Remove bundle_solimba_spacesoundpro.exe - Powered by Reason Core Security