setup.exe

Bechiro S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application setup.exe by Bechiro S.L has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from sebcotrk.com. While running, it connects to the Internet address cdn.solimba.com on port 80 using the HTTP protocol.
Publisher:
r-installer  (signed by Bechiro S.L.)

Description:
app download

Version:
3.1.11.2

MD5:
c73af3cb1b63e8e2b0e1f4d0dbd3615b

SHA-1:
4c755e3ad857d6244c265e88f25181e3ebdf86c9

SHA-256:
907276b1510f35249f963b72ef7354e9b6f1b305411624fc14de2acf8251d6d2

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 9:17:27 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Firseria.B
986

Agnitum Outpost
PUA.Firseria
7.1.1

Avira AntiVirus
APPL/Firseria.A.33
7.11.151.40

AVG
BundleApp
2015.0.3464

Bitdefender
Application.Bundler.Firseria.B
1.0.20.720

Comodo Security
Application.Win32.FirseriaInstaller.RRA
18314

Dr.Web
Adware.Downware.3938
9.0.1.0144

ESET NOD32
Win32/FirseriaInstaller.H potentially unwanted application
8.7.0.302.0

F-Secure
Application.Bundler.Firseria
11.2014-24-05_7

G Data
Application.Bundler.Firseria
14.5.24

K7 AntiVirus
Trojan
13.178.12171

Malwarebytes
PUP.Optional.AppsInstaller
v2014.05.24.10

MicroWorld eScan
Application.Bundler.Firseria.B
15.0.0.432

Reason Heuristics
PUP.Installer.BechiroSL.F
14.8.8.2

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Downware.Morstar
3.12.26.0

VIPRE Antivirus
Threat.4150696
29418

File size:
495.9 KB (507,752 bytes)

Product version:
3.1.13

Copyright:
copyright © MMXIV

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/13/2012 2:00:00 AM

Valid to:
6/14/2014 1:59:59 AM

Subject:
CN=Bechiro S.L., OU=Devel, O=Bechiro S.L., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
738DCAC697C06E1B89D106073773010D

File PE Metadata
Compilation timestamp:
5/15/2014 11:59:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:32xvIowx9CSZi+vdXhcVhkdtW0zmIMf5h2gPoFjdz52Wb3/mh7Q/u1PE0e/qHPB6:32hHYEqrvdKX+q5IVL0G2uJCtJM

Entry address:
0xEA0A

Entry point:
E8, BC, 79, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 80, E4, 41, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 2C, E1, 41, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 60, 54, 42, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 64...
 
[+]

Code size:
116 KB (118,784 bytes)

The file setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/16544349/launch

Remove setup.exe - Powered by Reason Core Security