adobe flash player.exe

Apps manager

Bechiro S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application adobe flash player.exe by Bechiro S.L has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. While running, it connects to the Internet address cdn.solimba.com on port 80 using the HTTP protocol.
Publisher:
Bechiro. Installer · sl  (signed by Bechiro S.L.)

Product:
Apps manager

Description:
Installer

Version:
3.1.22

MD5:
0315b79f7a35a00399a359448b7bfcc1

SHA-1:
e26e0155280a1ad1413cedd73684bd9acced10e1

SHA-256:
270af806a116a0266a23822ea7bab722b724b5cb12bd27570c61c7ff3b87c5b2

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 2:19:13 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Solimba
7.1.1

Avira AntiVirus
APPL/Firseria.Gen2
7.11.181.44

avast!
Win32:Solimba-O [PUP]
141025-0

AVG
Adware BundleApp_r.AV
2014.0.4040

Comodo Security
Application.Win32.Firseria.AFGH
19896

Dr.Web
Trojan.DownLoader11.24441
9.0.1.05190

ESET NOD32
MSIL/Solimba.AF potentially unwanted application
7.0.302.0

F-Prot
W32/A-a6ab64a8
v6.4.7.1.166

G Data
Win32.Application.FirseriaInstaller
14.10.24

IKARUS anti.virus
AdWare.BundleApp
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.185.13805

Kaspersky
not-a-virus:AdWare.Win32.Fiseria
15.0.0.494

Malwarebytes
PUP.Optional.Fiseria
v2014.10.25.08

NANO AntiVirus
Riskware.Win32.Fiseria.ddnzzd
0.28.2.62841

nProtect
Trojan-Clicker/W32.Fiseria.571072
14.10.24.01

Reason Heuristics
PUP.Installer.BechiroSL.W
14.10.25.7

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
34232

File size:
557.7 KB (571,072 bytes)

Product version:
3.1.21

Copyright:
copyright © 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/25/2014 2:00:00 AM

Valid to:
7/25/2016 1:59:59 AM

Subject:
CN=Bechiro S.L., O=Bechiro S.L., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0DE376129471B42CE6BCA90326047A34

File PE Metadata
Compilation timestamp:
7/30/2014 9:59:38 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:SIzzVozccgTGyJEa4GGO0th+GFGR+wy9N2aeU53Mi8jl5o7RL:FzYgTZJEa4GG9h+KBH9w5UL

Entry address:
0xD7ED

Entry point:
E8, 2C, 79, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 78, 6E, 42, 00, E8, 3D, 12, 00, 00, E8, A9, 67, 00, 00, 0F, B7, F0, 6A, 02, E8, BF, 78, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, A2, 73, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
113 KB (115,712 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/37406148/launch

Remove adobe flash player.exe - Powered by Reason Core Security