mozilla firefox setup.exe

WeDownload, Ltd

The application mozilla firefox setup.exe by WeDownload has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the Midia Downloader installer. The installer is marketed through download protals and search ads as the free Mozilla Firefox web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
WeDownload, Ltd  (signed and verified)

MD5:
a8018ef3aa45435082447d2674570723

SHA-1:
6c35cc17b3a49ac35cb9fd23764c9704e536962a

SHA-256:
38e8aab3ac0e8da35e6fe363509617f3d2e40583c6970f7601cfb38b6f187fd4

Scanner detections:
15 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 10:38:20 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Soft32Downloader
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.164.242

avast!
Downloader-TOV [PUP]
2014.9-140731

AVG
Wedownload
2015.0.3396

ESET NOD32
MSIL/Soft32Downloader.C potentially unwanted application
8.7.0.302.0

G Data
Win32.Application.Soft32Downloader
14.7.24

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.3476

McAfee
Artemis!A0093B3D2DD7
5600.7052

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.Installer.WeDownload.V
14.8.7.20

Rising Antivirus
PE:Trojan.Win32.Generic.16D3C834!382978100
23.00.65.14729

Trend Micro House Call
TROJ_GE.4F8820EF
7.2.212

Vba32 AntiVirus
Signed-AdWare.WeDownload
3.12.26.3

VIPRE Antivirus
Threat.4783370
29800

File size:
617.1 KB (631,920 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\mozilla firefox setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/6/2013 12:00:00 AM

Valid to:
2/11/2016 12:00:00 PM

Subject:
CN="WeDownload, Ltd", O="WeDownload, Ltd", L=Nicosia, C=CY

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0320C5B8F7CE6E92D3665598826A4480

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:LwMDD4ypKTzNTR9WxwzCoPk9lveZKuM5rfJlLvrmMgnTRF3/qET6BQcFmV:LtgEuzN7dze3vyruVljfYRZv6Tm

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9239

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove mozilla firefox setup.exe - Powered by Reason Core Security