mozilla-firefox.exe

App Program

UpdateStar GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application mozilla-firefox.exe, “App Program Setup ” by UpdateStar GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
UpdateStar GmbH  (signed and verified)

Product:
App Program

Description:
App Program Setup

Version:
3.5.4.8

MD5:
a036c4be590b3ff3059e5d910126572a

SHA-1:
cd7928fdba6a0cb5f96ada536fbd569d392af2a5

SHA-256:
59c969af97e495940fb63f761aa8500c984af7bdeedb53b1ee75c7277a7b6711

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/22/2024 1:20:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.UpdateStar.Installer (M)
16.2.13.1

File size:
975.5 KB (998,880 bytes)

Product version:
5.6

Copyright:
Installer app

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mozilla-firefox.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/25/2016 11:35:00 AM

Valid to:
3/23/2017 3:24:09 PM

Subject:
CN=UpdateStar GmbH, O=UpdateStar GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C7585A2F5B2218EC6B36D472BA6496D8

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:OHPneYrR5Qu7kOATHl9O6f+HL1ZeXvjG1AS0q:Ov79597klTHPXf+r1ZeXieq

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file mozilla-firefox.exe has been seen being distributed by the following 2 URLs.

Remove mozilla-firefox.exe - Powered by Reason Core Security