google chrome.exe

Apps-manager

Bechiro S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application google chrome.exe by Bechiro S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Bechiro-Installer · sl  (signed by Bechiro S.L.)

Product:
Apps-manager

Description:
Installer

Version:
3.1.22.3

MD5:
89dcdab57e07eb1854c4428c9b21b5f1

SHA-1:
7a7d0ce18a740ce9a266de7fce9b6a95468a5bb2

SHA-256:
9d3afa95868889fa145f8e9649f41e283786cc89bb4b11d0fe1f1c73dc5bce71

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/4/2024 10:13:14 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solimba.Bechiro.Bundler (M)
16.3.29.2

File size:
633.7 KB (648,896 bytes)

Product version:
3.1.21

Copyright:
copyright © 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\google chrome.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/25/2014 2:00:00 AM

Valid to:
7/25/2016 1:59:59 AM

Subject:
CN=Bechiro S.L., O=Bechiro S.L., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0DE376129471B42CE6BCA90326047A34

File PE Metadata
Compilation timestamp:
7/31/2014 10:52:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:q0xzdQ3OOTIxj9E8uYK5tQRUprGmvMBM00GqI1GSPekwLazO4r0/jM:q0ZzOT+9MYstBlbwv1DPekbhI/

Entry address:
0xE03C

Entry point:
E8, CC, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 38, 6E, 42, 00, E8, FE, 15, 00, 00, E8, 9D, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 5F, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 28, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
114 KB (116,736 bytes)

The file google chrome.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/336576831/launch

Remove google chrome.exe - Powered by Reason Core Security