java.exe

Internal Setup

Condestil Developments s.l.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application java.exe, “Configuration Process” by Condestil Developments s.l has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
The Apps Path  (signed by Condestil Developments s.l.)

Product:
Internal Setup

Description:
Configuration Process

Version:
3,1,18,3

MD5:
05ff3968aae36493c1d8dbc0a59fd999

SHA-1:
1b0d8c897b7f8d6a2ecba067e0133cf2811d7efd

SHA-256:
f070acba1d171eeacc6a0dc918af0ff46ffa7a6538d4b3ee12fe4b9a82fd82a6

Scanner detections:
30 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/27/2024 9:04:35 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Firseria.T
365

Agnitum Outpost
PUA.Firseria
7.1.1

AhnLab V3 Security
PUP/Win32.Firseria
2014.12.11

Avira AntiVirus
APPL/FirseriaM.A.2
7.11.194.62

avast!
Win32:Malware-gen
2014.9-160204

AVG
Adware BundleApp
2017.0.2843

Bitdefender
Application.Bundler.Firseria.T
1.0.20.175

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Agent-755856
0.98/20565

Comodo Security
Application.Win32.Solimba.KUY
18995

Dr.Web
Trojan.MulDrop5.34679
9.0.1.035

Emsisoft Anti-Malware
Application.Bundler.Firseria.T
8.16.02.04.12

ESET NOD32
Win32/FirseriaInstaller.M potentially unwanted application
10.7.0.302.0

F-Prot
W32/A-7a47ae63
v6.4.7.1.166

F-Secure
Riskware.Application.Bundler.Firseria
11.2016-04-02_5

G Data
Application.Bundler.Firseria
16.2.24

IKARUS anti.virus
not-a-virus:AdWare.Fiseria
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.186.14295

Malwarebytes
PUP.Optional.Solimba
v2016.02.04.12

MicroWorld eScan
Application.Bundler.Firseria.T
17.0.0.105

Norman
Application.Bundler.Firseria.T
11.20160204

Panda Antivirus
Trj/Genetic.gen
16.02.04.12

Qihoo 360 Security
Malware.QVM18.Gen
1.0.0.1015

Quick Heal
PUA.Condestild.Gen
2.16.14.00

Reason Heuristics
PUP.Solimba.CondestilDevelopments.Installer (M)
16.2.4.12

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.16202

Sophos
PUA 'Solimba Installer'
5.15

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Threat.4150696
35418

Zillya! Antivirus
Backdoor.PePatch.Win32.39331
2.0.0.2003

File size:
414.7 KB (424,648 bytes)

Product version:
3.1.20

Copyright:
Reserved © 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\java.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/24/2014 9:00:00 PM

Valid to:
7/24/2016 8:59:59 PM

Subject:
CN=Condestil Developments s.l., O=Condestil Developments s.l., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
43F850AA43DAD92FF6603BEB72F415DD

File PE Metadata
Compilation timestamp:
7/26/2014 6:06:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:H4W8/VUlVGRwfpQb5kP3NZVn9Mb2yOVhatb3uaNz5g7vT2XbSrZbdu6YgTmavAcg:YW8RR6PYiyYa53um5g7vT2+xfmavzg

Entry address:
0x840A4

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 5A, 0B, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 2B, C0, AC, 8B, C8, 80, E1, F0, 24, 0F, C1, E1, 0C, 8A, E8, AC, 0B, C8, 51, 02, CD, BD, 00, FD, FF, FF, D3, E5, 59, 58, 8B, DC, 8D, A4, 6C, 90, F1, FF, FF, 51, 2B, C9, 51, 51, 8B, CC, 51, 66, 8B, 17, C1, E2, 0C, 52, 57, 83, C1, 04, 51, 50, 83, C1, 04, 56, 51, E8, 5E, 00, 00, 00, 8B, E3, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
121 KB (123,904 bytes)

The file java.exe has been seen being distributed by the following URL.

Remove java.exe - Powered by Reason Core Security