mozilla thunderbird setup.exe

WeDownload, Ltd

The application mozilla thunderbird setup.exe by WeDownload has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the Midia Downloader installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. With this installer, users are expecting to download Mozilla Thunderbird but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware. The file has been seen being downloaded from mozilla-thunderbird.xtremedownload.com.
Publisher:
WeDownload, Ltd  (signed and verified)

MD5:
6c12f4a952f72faebb59339cfe2dbfa7

SHA-1:
2a03d2416f1f5c7ba59b3357e447b030c949da81

SHA-256:
fef12fbe4a7ac332e4ffd86126848d509944aa55fd575b0d686cd5d119bc6aa0

Scanner detections:
23 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 1:45:54 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.Generic.783181
834

Agnitum Outpost
PUA.Soft32Downloader
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.176.244

avast!
Downloader-TOV [PUP]
141023-1

AVG
Wedownload
2015.0.3312

Bitdefender
Dropped:Application.Generic.783181
1.0.20.1485

Clam AntiVirus
Win.Trojan.Agent-754117
0.98/21411

ESET NOD32
MSIL/Soft32Downloader.C potentially unwanted application
7.0.302.0

F-Secure
Dropped:Application.Generic.783181
11.2014-24-10_6

G Data
Dropped:Application.Generic.783181
14.10.24

K7 AntiVirus
Unwanted-Program
13.183.13597

Kaspersky
not-a-virus:Downloader.Win32.Agent
15.0.0.494

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.10.24.06

MicroWorld eScan
Dropped:Application.Generic.783181
15.0.0.891

nProtect
Dropped:Application.Generic.783181
14.09.28.01

Panda Antivirus
Trj/CI.A
14.10.24.06

Qihoo 360 Security
Win32/Trojan.Adware.37e
1.0.0.1015

Reason Heuristics
PUP.Installer.WeDownload.Z
14.10.24.6

Rising Antivirus
PE:Trojan.Win32.Generic.17459ADD!390437597
23.00.65.141022

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10280

Vba32 AntiVirus
Signed-AdWare.WeDownload
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
33708

Zillya! Antivirus
Downloader.Agent.Win32.217726
2.0.0.1945

File size:
892.1 KB (913,464 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\mozilla thunderbird setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/6/2013 10:00:00 AM

Valid to:
2/11/2016 10:00:00 PM

Subject:
CN="WeDownload, Ltd", O="WeDownload, Ltd", L=Nicosia, C=CY

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0320C5B8F7CE6E92D3665598826A4480

File PE Metadata
Compilation timestamp:
12/6/2009 8:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:Ctg1fCvTT9e8x/nP2Pk6DiUvOHRfrI9z4EY1K55BhrTVm:CtefCvM8ZWziUvKfUd0g5BT

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9607

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file mozilla thunderbird setup.exe has been seen being distributed by the following URL.

Remove mozilla thunderbird setup.exe - Powered by Reason Core Security