firefox - chip-downloader.exe

OCSClient

CHIP Digital GmbH

The application firefox - chip-downloader.exe by CHIP Digital GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. The installer is marketed through download protals and search ads as the free Mozilla Firefox web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
CHIP Digital GmbH  (signed and verified)

Product:
OCSClient

Version:
1.00

MD5:
96cebf37aa948e2730588c3ca0988c5a

SHA-1:
858a75089d43746664edd51f26621f29dc9eeafa

SHA-256:
2b6109c5ac45fca655671f9576231db4b942ada94ab95fe60f71ade3f1ed6772

Scanner detections:
1 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/27/2024 4:58:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ChipDigital.Bundler (M)
17.2.25.21

File size:
600.4 KB (614,784 bytes)

Product version:
1.00

Original file name:
ocsclient.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
English (United States)

Common path:
C:\users\{user}\downloads\firefox - chip-downloader.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/26/2013 1:00:00 AM

Valid to:
11/27/2014 12:59:59 AM

Subject:
CN=CHIP Digital GmbH, O=CHIP Digital GmbH, STREET=St.-Martin-Str. 66, L=Munich, S=Bavaria, PostalCode=81541, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
360BEAFE1EBBCC59FBA31179BE3192C0

File PE Metadata
Compilation timestamp:
11/27/2013 1:28:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1620

Entry point:
68, 08, F6, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, EF, 4E, 90, D9, AA, 0A, CD, 43, 91, 50, 46, 79, E4, 37, D4, 82, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4F, 43, 53, 43, 6C, 69, 65, 6E, 74, 00, 6E, 64, 72, 65, 5C, 44, 00, 00, 00, 00, FF, CC, 31, 00, 03, 23, 5A, 55, 3A, 3C, E0, 07, 47, B3, 35, 82, 3C, 05, 78, AE, A7, 47, FF, BF, 0B, 62, DE, 67, 44, A8, 40, C9, 76, C0, F9, 23, 95, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
96 KB (98,304 bytes)

Remove firefox - chip-downloader.exe - Powered by Reason Core Security