downloader_for_firefox setup 31.0.exe

Totalpc

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application downloader_for_firefox setup 31.0.exe by Totalpc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Totalpc  (signed and verified)

MD5:
5e937d8a6c8a32f3b45d701b4b36165d

SHA-1:
95b2e636a678809e6877a03e00606f3dc89e716e

SHA-256:
bdd2f4f18c21f82a2dc1616a20dae23c29c07b5e3ea8c628c6cce54ed2d89d3f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 7:08:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Totalpc.Installer (M)
16.1.18.17

File size:
759.1 KB (777,320 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\downloader_for_firefox setup 31.0.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/22/2013 2:00:00 AM

Valid to:
7/23/2014 1:59:59 AM

Subject:
CN=Totalpc, O=Totalpc, STREET=29 Coopers Mill Avenue, STREET=Dundonald, L=Belfast, S=Antrim, PostalCode=BT161WR, C=GB

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C41049E590A85A4E45F8DF4839AFAE52

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:v8vpBvxyi5gZqnglkJkkIlLM+DyHf/fax1u9K5MPeWPB4RkIbwZlNNJ7rgP:v8vzvxtgZ/mAfOHyx1u9K2PeWJB4wZla

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file downloader_for_firefox setup 31.0.exe has been seen being distributed by the following 2 URLs.

http://www.filefacts.com/.../5605?sfadownload=1&psid=68232208

Remove downloader_for_firefox setup 31.0.exe - Powered by Reason Core Security