cinema 4d.exe

XLIX-II praecox

Condestil Developments s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application cinema 4d.exe, “potissimus digressio despecto relinquo” by Condestil Developments s.l has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
fuga  (signed by Condestil Developments s.l.)

Product:
XLIX-II praecox

Description:
potissimus digressio despecto relinquo

Version:
27.24.32.56

MD5:
8b116d0085c518ffccb0cf0a76e1f6d2

SHA-1:
ee5b1dd868cdf9434da74ee43f110d54873cd379

SHA-256:
2587f5edc4e88c208aef2e4cb2a6ca6ff3b613c46790c3dc3c744c8646d567d3

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/28/2024 11:00:46 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Firseria.Gen8
7.11.181.56

AVG
Adware BundleApp_r.AV
2014.0.4040

Comodo Security
Application.Win32.Solimba.LSW
19908

Dr.Web
Adware.Downware.8808
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Kazy.132995
14.10.26

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/Morstars
10/26/2014

F-Prot
W32/A-a1e0d357
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.185.13805

Malwarebytes
PUP.Optional.Solimba
v2014.10.26.09

MicroWorld eScan
Gen:Variant.Application.Bundler.Kazy.132995
15.0.0.897

Reason Heuristics
PUP.CondestilDevelopmentssl.J
14.10.26.8

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Threat.4782980
34232

File size:
538.2 KB (551,136 bytes)

Product version:
74.92.26.61

Copyright:
ingero nauta

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\cinema 4d.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/25/2014 2:00:00 AM

Valid to:
7/25/2016 1:59:59 AM

Subject:
CN=Condestil Developments s.l., O=Condestil Developments s.l., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
43F850AA43DAD92FF6603BEB72F415DD

File PE Metadata
Compilation timestamp:
10/24/2014 10:57:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:QJB1vxtlnzqT4y4R2wbEyxyHLUIo4AIOYQCAJ8h7cHkMcW2TqpVV:QJlHqTNMrbhxyyEMcWSqzV

Entry address:
0xDE2C

Entry point:
E8, A3, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 58, 70, 42, 00, E8, FE, 15, 00, 00, E8, 74, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 36, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, FF, 64, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
113.5 KB (116,224 bytes)

The file cinema 4d.exe has been seen being distributed by the following URL.

Remove cinema 4d.exe - Powered by Reason Core Security