firefoxsetup.exe

Web

Dova Network (New Media Holdings Ltd.)

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application firefoxsetup.exe, “Web Setup ” by Dova Network (New Media Holdings) has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Application Internet   (signed by Dova Network (New Media Holdings Ltd.))

Product:
Web

Description:
Web Setup

Version:
2.2.4.1

MD5:
af4e455dfd9254d0bb84b19bb35ef7cc

SHA-1:
49e33b506707415ac9b0275826c0737cd8cde557

SHA-256:
553b0c1776aa81997a7e2f0af05e6fa918b2bd83879be2908f5d42309da79c95

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/18/2024 11:19:09 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/InstallCo.zkt
8.3.1.6

AVG
Generic
2017.0.2869

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.InstallCore.33
9.0.1.010

ESET NOD32
Win32/InstallCore.XD potentially unwanted application
10.7.0.302.0

G Data
Win32.Application.InstallCore.CZ
16.1.25

K7 AntiVirus
Unwanted-Program
13.205.16224

Malwarebytes
v2016.01.10.01

NANO AntiVirus
Riskware.Win32.InstallCore.drfvvg
0.30.24.2086

Reason Heuristics
PUP.NewMedia.Installer.New Media Holdings.Installer (M)
16.1.10.1

Sophos
PUA 'Install Core Click run software'
5.15

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

VIPRE Antivirus
Threat.4786018
40830

File size:
809.7 KB (829,088 bytes)

Product version:
3.7.3

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\firefoxsetup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/29/2014 6:13:24 PM

Valid to:
10/30/2015 6:13:24 PM

Subject:
CN=Dova Network (New Media Holdings Ltd.), O=Dova Network (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121EA6FC07B9DEE393ABBAEF1AA874D6483

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:r3rG+liWP3In6OK1cltQf0+J3nE2GFOp4KVXyCv81qFtRn1IYXTdkswM:r3rbgG3xelT+VEwp4KdyCvBn1VXTpw

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file firefoxsetup.exe has been seen being distributed by the following URL.

Remove firefoxsetup.exe - Powered by Reason Core Security