firefox.exe

Quick Downloader

The Adlogica setup manager, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application firefox.exe by Quick Downloader has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Adlogica Quick Downloader installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from us.download-file.downloadinfo.co.
Publisher:
Quick Downloader  (signed and verified)

MD5:
1dce6efa9843b8fa58902c9db53e318d

SHA-1:
537ebb57fe2b9276c44a78e5726520ecc6a7ef50

SHA-256:
f48c24614705d1d43ad29f4d541f72f69b022a35d4d43d0587743bb392362b94

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 11:06:55 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

AVG
Downloader
2015.0.3342

Dr.Web
Trojan.Packed.28678
9.0.1.0266

ESET NOD32
Win32/OutBrowse.AU
8.10495

herdProtect (fuzzy)
2014.12.5.19

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.183.13550

Malwarebytes
PUP.Optional.OutBrowse
v2014.09.23.05

McAfee
Adware-OutBrowse.a
5600.6925

Reason Heuristics
PUP.QuickDownloader.H
14.9.23.15

VIPRE Antivirus
Threat.4786018
33120

File size:
558.5 KB (571,856 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adlogica Quick Downloader (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\firefox.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/11/2014 7:00:00 PM

Valid to:
8/11/2017 6:59:59 PM

Subject:
CN=Quick Downloader, O=Quick Downloader, STREET="96 Jessie St, 4th Floor", L=San Francisco, S=CA, PostalCode=94105, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0087CE63C7728E982ECA2980DCA8DDE091

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:1qOCJz/1Srh0hmE3WyEfO8HyGpsqUrn39WeBYt4dhqPzue99Mn:1qTJJSOB3WyEfOkyGFatWe2KgPKe9A

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9764

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file firefox.exe has been seen being distributed by the following URL.

Remove firefox.exe - Powered by Reason Core Security