mozilla_firefox.exe

Webcellence Ltd.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application mozilla_firefox.exe by Webcellence has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Webcellence Ltd.  (signed and verified)

MD5:
40e3ea2803e7ea9bdcfd89a85daa3e70

SHA-1:
f459e204ddffec6b6a970e975a91a720a7b94904

SHA-256:
c66ee6c702b0d73e4a5e41e31eaaafebff310530c5013d3cb139fe79af9a2e0c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 2:37:27 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Webcellence (M)
16.2.15.2

File size:
763.7 KB (782,064 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bahan lg\mozilla_firefox.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/10/2014 7:00:00 AM

Valid to:
6/10/2015 6:59:59 AM

Subject:
CN=Webcellence Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Webcellence Ltd., L=Moshav Ora, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
083059C7641A95E130A5846DC91CCC06

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:L+FaTL5jL+b/STSLyI+FZ8P3n/YOS5mLJroVaafInwg1J9/15LsweyKTqwE9eDZx:L+FW5jcqvT83/YOS5mN+aOg7115QwEqe

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

Remove mozilla_firefox.exe - Powered by Reason Core Security