installer_firefox_english.exe

The application installer_firefox_english.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from firefox.descargar.es.
MD5:
aada9d82b3f9722a81cf6324bd566451

SHA-1:
99ea6870fa7ce53e40285c62358f3856723ee25e

SHA-256:
4295465358ce94207f4596cab4051c197ec30c8a188da14ccacabb2451a66d6b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 5:35:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Bundler (M)
16.6.16.22

File size:
409.3 KB (419,095 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\installer_firefox_english.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
12288:Am+cZVA+ScLQ+iUGy/++VBjdC30VwCbf/xjtzuF:d9k+/L3XG+VpdCkyCD/xpK

Entry point:
78, 9C, EC, 9D, 07, 5C, 13, CB, DA, F0, 13, A4, 17, 4D, 00, 11, 10, 31, 04, 54, 90, 1A, 6A, 40, 50, 20, 09, 84, 12, 7A, 07, 95, 90, 04, 08, 84, 04, 92, 40, 00, 1B, 2A, 68, 28, 52, 2C, 60, C3, 02, 58, 01, A5, 57, 15, 45, 90, 2A, 76, 51, 41, 11, 14, B0, 23, A2, A2, A2, F8, 6D, 20, 78, D4, A3, F7, 7C, F7, 9E, FB, 7B, EF, 5B, F6, AF, CB, CC, 6E, 9E, 99, 79, A6, 3D, 33, B3, 99, DD, 40, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20...
 
[+]

Entropy:
7.9960  (probably packed)

The file installer_firefox_english.exe has been seen being distributed by the following URL.

Remove installer_firefox_english.exe - Powered by Reason Core Security