mozilla firefox setup.exe

WeDownload, Ltd

The application mozilla firefox setup.exe by WeDownload has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the Midia Downloader installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
WeDownload, Ltd  (signed and verified)

MD5:
180df0feb080328f03fdd64f1028ba11

SHA-1:
6c654d8e3b96384c0fe53e3f577d695ad37586eb

SHA-256:
356bc214e468b5a2d24ccfa7b70a3ad653b00fe934ebba7081cc4f3874543171

Scanner detections:
16 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 2:45:38 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Soft32Downloader
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.164.150

avast!
Downloader-TOV [PUP]
140929-0

AVG
Wedownload
2015.0.3334

Clam AntiVirus
Win.Trojan.Agent-754117
0.98/19466

ESET NOD32
MSIL/Soft32Downloader.A potentially unwanted application
7.0.302.0

G Data
Win32.Application.Soft32Downloader
14.10.24

K7 AntiVirus
Unwanted-Program
13.183.13286

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.10.02.08

NANO AntiVirus
Trojan.Win32.KillFiles.ddsvpt
0.28.2.61519

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.Installer.WeDownload.V
14.10.2.8

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10324

Trend Micro House Call
TROJ_GE.0ADD1E3E
7.2.275

Vba32 AntiVirus
Signed-AdWare.WeDownload
3.12.26.3

VIPRE Antivirus
Soft32Downloader
27502

File size:
593 KB (607,192 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\mozilla firefox setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/5/2013 7:00:00 PM

Valid to:
2/11/2016 7:00:00 AM

Subject:
CN="WeDownload, Ltd", O="WeDownload, Ltd", L=Nicosia, C=CY

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0320C5B8F7CE6E92D3665598826A4480

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:rwMDD4yOtJVrfyDL3xcqXIHBC3OLQjPHyEOOym:rtgyOjVbyHJXkuOL2SEGm

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove mozilla firefox setup.exe - Powered by Reason Core Security