xbmc.exe

Apps-manager

FIRSERIA, S.L.

The setup program uses the Firseria/Solimba AppInstaller (DownloadMR) which is a monetization download manager that bundles additional adware offers, typically by wrapping legitimate applications. The application xbmc.exe by FIRSERIA, S.L has been detected as adware by 31 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Firseria.-.Installer · sl  (signed by FIRSERIA, S.L.)

Product:
Apps-manager

Description:
Installer

Version:
3.1.22.4

MD5:
2e1e97fb98f34d87cadb0a921aeeddb9

SHA-1:
37fcce456b7dbf93257997d806681b1bc098bf77

SHA-256:
8677349e2981d224b7297c3c64e4b192e1fc7f94dadc7782c6e840e434c339c7

Scanner detections:
31 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 7:35:11 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Firseria.M
799

Agnitum Outpost
PUA.Solimba
7.1.1

AhnLab V3 Security
PUP/Win32.Firseria
2014.08.07

Avira AntiVirus
APPL/Firseria.Gen8
7.11.166.78

avast!
Win32:Solimba-Q [PUP]
141119-1

AVG
Adware BundleApp_r.AJ
2014.0.4189

Baidu Antivirus
Adware.MSIL.Solimba
4.0.3.141128

Bitdefender
Application.Bundler.Firseria.M
1.0.20.1660

Comodo Security
Application.Win32.Firseria.MAP
19134

Dr.Web
Trojan.DownLoader11.24441
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Firseria.M
9.0.0.4570

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
7.0.302.0

F-Prot
W32/A-eac696bb
v6.4.7.1.166

F-Secure
Application.Bundler.Firseria
11.2014-28-11_6

G Data
Application.Bundler.Firseria
14.11.24

IKARUS anti.virus
PUA.MSIL.Solimba
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.12998

Kaspersky
not-a-virus:Downloader.Win32.Morstar
15.0.0.543

Malwarebytes
PUP.Optional.Firseria
v2014.11.28.06

McAfee
Trojan.Artemis!B6B7F772589C
5600.6933

MicroWorld eScan
Application.Bundler.Firseria.M
15.0.0.996

NANO AntiVirus
Trojan.Win32.DownLoader11.ddphbo
0.28.2.61349

nProtect
Trojan.Generic.11632684
14.09.02.01

Panda Antivirus
Adware/Firseria
14.11.28.06

Qihoo 360 Security
Win32/Trojan.Adware.37e
1.0.0.1015

Reason Heuristics
PUP.Installer.FIRSERIASL.E
14.11.28.6

Sophos
Solimba Installer
4.98

Trend Micro House Call
Suspicious_GEN.F47V0806
7.2.332

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
DownloadMR
32078

Zillya! Antivirus
Backdoor.PePatch.Win32.39330
2.0.0.1897

File size:
572.2 KB (585,920 bytes)

Product version:
3.1.21

Copyright:
copyright © 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\xbmc.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/25/2014 2:00:00 AM

Valid to:
7/24/2016 1:59:59 AM

Subject:
CN="FIRSERIA, S.L.", O="FIRSERIA, S.L.", L=Badalona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7658ACC15B33D93ABD5A967181DEF901

File PE Metadata
Compilation timestamp:
8/1/2014 5:25:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:VlhYhEh8T2831CdsXdYH+7r0hh9cK4cFxk5yhQuG:Vlh38TdIeUh9cwFxSb

Entry address:
0xDFDC

Entry point:
E8, AC, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, 6E, 42, 00, E8, FE, 15, 00, 00, E8, 7D, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 3F, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 08, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
114 KB (116,736 bytes)

The file xbmc.exe has been seen being distributed by the following URL.

Remove xbmc.exe - Powered by Reason Core Security