google chrome.exe

FIRSERIA, S.L.

The setup program uses the Firseria/Solimba AppInstaller (DownloadMR) which is a monetization download manager that bundles additional adware offers, typically by wrapping legitimate applications. The application google chrome.exe by FIRSERIA, S.L has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. With this installer, users are expecting to download Google's Chrome web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Frsera·sl  (signed by FIRSERIA, S.L.)

Description:
Dwnld·Mnger

Version:
1.0.0.20

MD5:
17f875ce69f4f9078ee5f7ff981c807b

SHA-1:
6388684ddb26c13124c7357395a6f065066e8492

SHA-256:
e62c988eb86c9046079f3bd0e471127e92b1f055072abba69e0bff0133fd5096

Scanner detections:
25 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 2:09:38 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.77453
1011

Agnitum Outpost
Trojan.Strictor
7.1.1

AhnLab V3 Security
PUP/Win32.Firseria
2014.01.12

Avira AntiVirus
Adware/Strictor.48157
7.11.124.210

avast!
Win32:Firseria-A [PUP]
2014.9-140430

AVG
AdInstaller.Firseria
2015.0.3489

Baidu Antivirus
Adware.Win32.FirseriaInstaller
4.0.3.14430

Bitdefender
Gen:Variant.Zusy.77453
1.0.20.600

Comodo Security
Application.Win32.Solimba.J
17595

Dr.Web
Trojan.DownLoader10.51613
9.0.1.0120

Emsisoft Anti-Malware
Gen:Variant.Zusy.77453
8.14.04.30.11

ESET NOD32
Win32/FirseriaInstaller (variant)
8.9279

Fortinet FortiGate
Adware/Firseria
4/30/2014

G Data
Gen:Variant.Zusy.77453
14.4.22

IKARUS anti.virus
Trojan-Dropper
t3scan.2.2.29

Kaspersky
not-a-virus:Downloader.Win32.Morstar
14.0.0.3938

Malwarebytes
PUP.Optional.Firseria
v2014.04.30.11

McAfee
Artemis!17F875CE69F4
5600.7145

MicroWorld eScan
Gen:Variant.Zusy.77453
15.0.0.360

NANO AntiVirus
Trojan.Win32.Morstar.cqhuua
0.28.0.57029

Reason Heuristics
PUP.FIRSERIASL.N
14.8.7.17

Rising Antivirus
PE:PUF.FirseriaInstaller@CV!1.9C54
23.00.65.14428

Sophos
Solimba Installer
4.96

Vba32 AntiVirus
Downloader.Morstar
3.12.24.3

VIPRE Antivirus
DownloadMR
25342

File size:
161.3 KB (165,176 bytes)

Product version:
3.0.23

Copyright:
Copyright © 2013

Original file name:
·install·exe·

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\google chrome.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/24/2013 2:00:00 AM

Valid to:
7/25/2014 1:59:59 AM

Subject:
CN="FIRSERIA, S.L.", OU=IT, O="FIRSERIA, S.L.", L=Badalona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73C4780FAC0CD497B0778732FB8AF673

File PE Metadata
Compilation timestamp:
11/12/2013 1:07:22 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:fjSkrwevwwuvy6/Dq13YvXZZtLt8gQb6i+w5woutWj/n:mOBvwwFz1ohriYoSK

Entry address:
0x73080

Entry point:
60, BE, 00, 20, 45, 00, 8D, BE, 00, F0, FA, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 1D, 13, 07, 00, 57, 83, C3, 04, 53, 68, 72, 10, 02, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 00, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.8685  (probably packed)

Code size:
136 KB (139,264 bytes)

The file google chrome.exe has been seen being distributed by the following URL.

Remove google chrome.exe - Powered by Reason Core Security