glary utilities.exe

SETUPPROCESS

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application glary utilities.exe by SETUPPROCESS has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from jp.download366.info. While running, it connects to the Internet address cdn.solimba.com on port 80 using the HTTP protocol.
Publisher:
_Rapiddown_  (signed by SETUPPROCESS)

Description:
Setup Manager

Version:
1.0.0.33

MD5:
a293219579100510e38f933b27b605fc

SHA-1:
09135f270616adf6c500e912ddf6fb41df6aa919

SHA-256:
a25e615d854d568c68cc9586373a176d94d333fff79fac5fe674a6248ac43078

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 1:08:38 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Downloader
7.1.1

Avira AntiVirus
TR/Dropper.Gen
7.11.141.30

Comodo Security
Application.Win32.Bechiro.BDC
18039

Dr.Web
Trojan.DownLoader11.3516
9.0.1.093

ESET NOD32
Win32/FirseriaInstaller (variant)
8.9631

Fortinet FortiGate
Adware/Firseria
4/3/2014

G Data
Win32.Application.Morstar
14.4.24

IKARUS anti.virus
not-a-virus:Downloader.Win32.Morstar
t3scan.2.2.29

Kaspersky
not-a-virus:Downloader.Win32.Morstar
14.0.0.4072

NANO AntiVirus
Trojan.Win32.Morstar.creklv
0.28.0.58873

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.SETUPPROCESS.P
14.3.12.10

Rising Antivirus
PE:PUF.FirseriaInstaller@CV!1.9C54
23.00.65.14401

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Downware.Morstar
3.12.26.0

VIPRE Antivirus
DownloadMR
27982

File size:
193.4 KB (198,000 bytes)

Product version:
3.0.28

Copyright:
Copyright-©-2014

Original file name:
**intaller.exe**

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
11/27/2013 9:00:00 AM

Valid to:
12/1/2014 9:00:00 PM

Subject:
CN=SETUPPROCESS, O=SETUPPROCESS, L=Badalona, S=Barcelona, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A8ABFC7C80D0C2F0A3A89CF6139A91D

File PE Metadata
Compilation timestamp:
1/15/2014 6:14:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:A1rrNsSg7Y+utQyn33r0ywXNvyvm70w+/:erNpg8fjnHr0ywXNvyOg9/

Entry address:
0x63780

Entry point:
60, BE, 00, A0, 43, 00, 8D, BE, 00, 70, FC, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8141

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
168 KB (172,032 bytes)

The file glary utilities.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/8917041/launch

Remove glary utilities.exe - Powered by Reason Core Security