setup.exe

FLVMPlayer

Bechiro S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application setup.exe, “FLVMPlayer AppInstaller” by Bechiro S.L has been detected as adware by 26 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Bechiro S.L.  (signed and verified)

Product:
FLVMPlayer

Description:
FLVMPlayer AppInstaller

Version:
3.0.17.6

MD5:
83f3163cbc380760a339666cac83cc4e

SHA-1:
62067f2b625248137d311433f89d13440d18a336

SHA-256:
acd0bebcc6717db9a188cc03933cc9a9b3345240ef55302482934b42d29d6df8

Scanner detections:
26 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 11:47:58 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Solimba
7.1.1

AhnLab V3 Security
PUP/Win32.Solimba
15.01.28

Avira AntiVirus
APPL/Solimba.Gen
7.11.138.58

AVG
Adware Skodna.Generic.AMG
2014.0.4253

Baidu Antivirus
Adware.MSIL.Solimba
4.0.3.15128

Clam AntiVirus
Win.Adware.Solimba-30
0.98/21411

Comodo Security
Application.Win32.Solimba.L
17967

Dr.Web
Adware.Downware.1302
9.0.1.05190

ESET NOD32
MSIL/Solimba potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Solimba
1/28/2015

G Data
MSIL.Application.Solimba
15.1.25

IKARUS anti.virus
PUA.Bechiro
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.176.11510

Kaspersky
not-a-virus:Downloader.Win32.Solimba
15.0.0.543

Malwarebytes
PUP.Optional.Solimba
v2015.01.28.01

McAfee
Artemis!7CF3BCE5ECF2
5600.6871

NANO AntiVirus
Trojan.Win32.Generic.cskuge
0.28.0.58491

nProtect
Adware/W32.Agent.277440
14.04.21.01

Panda Antivirus
Adware/Firseria
15.01.28.01

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.Solimba
15.1.28.13

Rising Antivirus
PE:PUF.FirseriaInstaller@CV!1.5C42
23.00.65.15126

Sophos
PUA 'Solimba Installer'
5.10

SUPERAntiSpyware
Adware.Solimba/Variant
10088

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.24.3

VIPRE Antivirus
DownloadMR
27596

File size:
281.9 KB (288,704 bytes)

Copyright:
AppInstaller 2013 (132122320)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/13/2012 2:00:00 AM

Valid to:
6/14/2014 1:59:59 AM

Subject:
CN=Bechiro S.L., OU=Devel, O=Bechiro S.L., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
738DCAC697C06E1B89D106073773010D

File PE Metadata
Compilation timestamp:
1/5/2012 7:21:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
6144:2saocyLCp7YY+GZJfKb0pqraSIHh2Pkyvkv76/RO:2tobKYDwfg8G/kckTmO

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/50728398/launch

Remove setup.exe - Powered by Reason Core Security