microsoft office 2010.exe

POPELER SYSTEM, S.L.

The setup program uses the Firseria/Solimba AppInstaller (DownloadMR) which is a monetization download manager that bundles additional adware offers, typically by wrapping legitimate applications. The application microsoft office 2010.exe by POPELER SYSTEM, S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Installation helper  (signed by POPELER SYSTEM, S.L.)

Product:
Installation helper

Version:
3.1.13.35

MD5:
6b4f23cd9e3d0144f81ac127e4d9c212

SHA-1:
e7e918107848b7f1e49bdd1ac72f0babc2e9a880

SHA-256:
c46edc41dcf3ad63a57fdfc6d90633f7e62d36cdfd9bdff42221bece2d4369da

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 8:53:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solimba.POPELERSYSTEM (M)
16.2.12.4

File size:
410.3 KB (420,160 bytes)

Product version:
3.1.19

Copyright:
© 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\microsoft office 2010.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/29/2013 2:00:00 AM

Valid to:
8/30/2014 1:59:59 AM

Subject:
CN="POPELER SYSTEM, S.L.", OU=IT, O="POPELER SYSTEM, S.L.", L=Badalona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
58806C1A153885D4BFE2E3370340491F

File PE Metadata
Compilation timestamp:
7/11/2014 4:34:47 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:6dL3yB9jUP+WDw6QEukVyzhjFSY+pBN6YVxW34ojyf9VDdRi1d9:CL2WP+gQ7ys3SBN6YV5oyHdRi1d9

Entry address:
0x830A4

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 5A, 0B, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 2B, C0, AC, 8B, C8, 80, E1, F0, 24, 0F, C1, E1, 0C, 8A, E8, AC, 0B, C8, 51, 02, CD, BD, 00, FD, FF, FF, D3, E5, 59, 58, 8B, DC, 8D, A4, 6C, 90, F1, FF, FF, 51, 2B, C9, 51, 51, 8B, CC, 51, 66, 8B, 17, C1, E2, 0C, 52, 57, 83, C1, 04, 51, 50, 83, C1, 04, 56, 51, E8, 5E, 00, 00, 00, 8B, E3, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
121 KB (123,904 bytes)

The file microsoft office 2010.exe has been seen being distributed by the following URL.

Remove microsoft office 2010.exe - Powered by Reason Core Security