docx recovery 3.2.exe

Firseria

The setup program uses the Firseria/Solimba AppInstaller (DownloadMR) which is a monetization download manager that bundles additional adware offers, typically by wrapping legitimate applications. The application docx recovery 3.2.exe by Firseria has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. The file has been seen being downloaded from www.softpicks.br.com.
Publisher:
setupprocess   (signed by Firseria)

Description:
Setup Manager

Version:
3.0.30.6

MD5:
03b7f2ca289e0fdf4ad5eeddce529e3d

SHA-1:
634b65e0158b946f62c0a8804121105b65c8f5c7

SHA-256:
c06baf019db89f8c46d4eb90dff26166ed72943d16fd10deb2d8223f8820944b

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 1:33:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.Firseria.N
14.8.7.17

File size:
270.7 KB (277,224 bytes)

Product version:
3.0.30

Copyright:
Copyright©2014

Original file name:
installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\docx recovery 3.2.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/11/2013 1:34:44 PM

Valid to:
11/12/2014 1:34:44 PM

Subject:
E=support@solimba.com, CN=Firseria, O=Firseria, L=Badalona, S=Barcelona, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112130C3B28D7C9C29B8B07321EF3F8A1462

File PE Metadata
Compilation timestamp:
2/10/2014 9:34:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:OSVFVe91EZ1ypY+186MWWxBRXp5IPRdjtHt0KjHAc+go:OSV3e91fY+6XWOjXpUtHt0Jgo

Entry address:
0x81117

Entry point:
60, E8, 00, 00, 00, 00, 58, 05, 9F, 02, 00, 00, 8B, 30, 03, F0, 2B, C0, 8B, FE, 66, AD, C1, E0, 0C, 8B, C8, 50, AD, 2B, C8, 03, F1, 8B, C8, 57, 51, 49, 8A, 44, 39, 06, 88, 04, 31, 75, F6, 8B, D6, 8B, CF, E8, 5C, 00, 00, 00, 5E, 5A, 2B, C0, 89, 04, 32, B4, 10, 2B, D0, 2B, C9, 3B, CA, 73, 26, 8B, D9, AC, 41, 24, FE, 3C, E8, 75, F2, 43, 83, C1, 04, AD, 0B, C0, 78, 06, 3B, C2, 73, E5, EB, 06, 03, C3, 78, DF, 03, C2, 2B, C3, 89, 46, FC, EB, D6, E8, 00, 00, 00, 00, 5F, 81, C7, 8C, FF, FF, FF, B0, E9, AA, B8, 9B...
 
[+]

Code size:
98.5 KB (100,864 bytes)

The file docx recovery 3.2.exe has been seen being distributed by the following URL.

Remove docx recovery 3.2.exe - Powered by Reason Core Security