firefox setup 47.0.ar.x64.e_m_a.exe

7-Zip

Mozilla Corporation

This is a setup and installation application. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
Igor Pavlov  (signed by Mozilla Corporation)

Product:
7-Zip

Description:
7z Setup SFX

Version:
4.42

MD5:
f817a7e6157736f9d44433a66f4467fd

SHA-1:
e205d67351fed7053a3a9f65a439ec26dd1b9ea1

SHA-256:
dc4605fe3b0bea0aeabf41e1cddff14fba37520294aaf61e11f6e6979e475048

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 2:15:55 PM UTC  (today)

File size:
45 MB (47,138,544 bytes)

Product version:
4.42

Copyright:
Copyright (c) 1999-2006 Igor Pavlov

Original file name:
7zS.sfx.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\firefox setup 47.0.ar.x64.e_m_a.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/9/2015 3:00:00 AM

Valid to:
7/13/2018 3:00:00 PM

Subject:
CN=Mozilla Corporation, O=Mozilla Corporation, L=Mountain View, S=California, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
09E65AD807B8497B0749D41568D626D0

File PE Metadata
Compilation timestamp:
4/17/2014 8:29:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:CEeRB7v5RKDagH69NPpWvsg9+zEgjMdzSLMTwD+vdbw7+bFcDAADS1c:BaB7KDhANPpWkg9dc/kd07UF3ADS1c

Entry address:
0x21E30

Entry point:
60, BE, 00, 80, 41, 00, 8D, BE, 00, 90, FE, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
8.0000

Packer / compiler:
UPX 2.90LZMA

Code size:
40 KB (40,960 bytes)

The file firefox setup 47.0.ar.x64.e_m_a.exe has been seen being distributed by the following 31 URLs.

https://dw.uptodown.com/dwn/UBMs-YjJb60weMeSxz1bYTQOZaH6A-1CzTpE37Po-hj_oDZMHNk1F-IunUoN4iIXyfxwRQoAqRpzxLAng0whWHj7CNM8Zvp5bHW5KC2fPycg8E0o7qrqBEUEywO23mon/2lkeMxHefbKcqW3it6p3zY0I0X1c8S9eXTDp1Yzf1_DEqRO8s-O56p_ywzPK7eYUE80sNew_Si8o1D7Bwk73MZypR-kgA3ftcCEuDl1Va_MKcJA_nDjWKMQSSsPJF0Hg/SdgvhMRNpXUCB4QPahqxKVArQzSgPuIuj9Zhxm_-xXDBiJxfwcFzwmEwH_szvr-Nknaasc5XxMpPz1y_KD9BP86r-hg8ZYDp_QAlYxTt6mcc4sOSawskpa2ZCX7oDNLr/.../

http://dll-mutaz.net/index.php?id=14

http://dw.uptodown.com/dwn/eub3AS2WrI1R0zX2HRuew5Oc67Y2vnItXmZ0X660GOxrVSeflFHde84oLTxG0fcCRnuwVgyLWVuPHvdsPvr1EMKTLFvtW_onwyBPtL_srJjGQymmfVqxgqcO4dqWnObo/m8Th4aTowICfLRoxFrKTRUl7EgZif8FcV8_9qpphxPc4gYTDj5OyHLw0JeOfb6pV7VPEnX1-f8hq0NO5XrBO67u0h1ke_1k_nyKiCzBf4gOkkBoyAShbCcBPtAPbtuYf/6vT263wqVOWNv9ELabDtqf4c6TCD8ArextuSE6XgfzPz9koWOUtUUBoXYpfsd_awQao6kZPYMzmQ09gIVRjW7bFNczwf5vuiMRy8rEVvyT9Ose8vNhV1Wpv4Ba_tKS88/.../

http://dw.uptodown.com/dwn/djmvYxvCyxSWtEbD3wRmJQfkWYMSByAE2ArpUOktNzes5hv2qIHPL81ABJoUpZFZUEFsvjf9dlyOAMykJVRWj--q4KJhJqMz29k9NUyt5sewWI8CW0XGgY0hnuqGhK8W/CfD4YwiwZ-x0DFSbQAAwmSoXjP4W2B2aGcKOKBPAzckU6aDJh47oNU79C7T0Pao4d5j5P30cjF7HbCZ4mnrH8B3183JTYEKlJVSSw8iytOXw3XDvdpmr5fagKXy-xEkR/oiBJibDcBto4UiPv9imvXgC04ChhS2p7Ic797prVio5YAD0O5QFG4hszc2Jrqet24OrvfGx5Os3nEGMjfAaEBKLXaaDovE_X-z-Ln6QxLLekCdP1HkB0dFvD8tFnI82R/.../

http://dw.uptodown.com/dwn/bvcglMtaZgYSU7S38Ybtcs9vKec0r4D3NI-fPfNYUmdpp_XriG4COvreWyA7EMZHNiQg5gBfnRJbFatOAnSzqiIwm1yw8Z4CxxARLdK8XRarRG85dFVkibyQ5ZYI9aNb/R6UEBqa6uF79SFbGoZfmPtqNwhCsEQbArdoWb1R2E7wrbdRFYTocUkX58Yxar-zn3lOk2-w6VpTYfVlGtsIPpW1xae7Xagvyj5TzLuVDlgPunlY5LIs8zxhztpDa11FL/lj7wKH6BDFcqj1KHKQVkOFqU2v_-iX2sxLLFLl0zCkS4GM-2GhIjY_tXNRur2ijTVQ3OaAkv6dVV__9NHw5b_tTpyeXTlLIUJL_qdeBcXtUjuBFTw3o5sAd_qI53nif4/.../

http://dw.uptodown.com/dwn/ypFuX4ekG6C6e2jL4-wj4Wxy9XtJVb_aOVHz_TL9SxuHmtw1QLO7HNY6LqD3O57qgR7OB1yJQDEtOZ29SnZcz1P80wSRWLnHAudDpu03JhIFCuA73uberQpy-S_llHDa/PMBEs6OAPSSI3yux2pRbuIFfNdmIXaKMaDOhpBSVskpw59yUneJzWvsEdNbpQCu3pcK1_rkYkWDHSEKZtr4s5_txHdEjRdGehfQyBeOB8X4XNEBujhvmPlFthzBa7hzI/lMfyFPwLAWBXepPTPFO8m_FcSxsdc_m2d3Eyz4cG_wGPzd2ACnsWM92l5HPWT9qonTfgG08NzxSJGnnwckWqHq9-j5H0098khPeR7GpPQc_fVWyibaK8RqLHQ582LII2/.../

https://download.mozilla.org/?product=firefox-47.0-SSL&os=win&lang=ar

https://dw.uptodown.com/dwn/10qM8G7JT_-wahaygOzBGKv4wRmHzFVx-ZivNAsRASqdJVMffzy1TX2vVV6smQGsLquNb_c58lJ-imyG7Eff1B59Np3fece_omq4DTudbDrGOdgrLeCKvH-sEQh9vzL5/bi7iK_8b-gFv6t_dvLocAMhyg5yIpuUR7m51LOdGguIl5J3YaaPhfpEjdphepGzBsI5lpvlsfMJqE5SF8IB8CSvpqikZhOeJnGnza6BoWAXSrvCC3XV-iXChU8T69-w9/VW6IBewHEt2BIO1P-Ou4j3NCH_MCK7vOKLGnFn6FM4YgP3Av55di1nVGfyps1ZtQRcib6rJXYBfNjqxUqDBuZAm3Ds2PI-z0Px9Ci0JVckaGytDsHsD4724Dzw5YKuFV/.../

https://download-installer.cdn.mozilla.net/pub/firefox/releases/47.0/win64/.../Firefox Setup 47.0.exe

https://dw.uptodown.com/dwn/gyZHXtzzNP2_kT21FGJlIQALlbSlq9clNIJaJxhKLoRlDdyhs5Q_lbBqVOFfpDn1LTbbfVMw27ybQs2fJ-iNfZSDoo01PT5YE14BS3huH5tTnBY2RJBDdnkAt-DiOgCj/RJkgZlPUoroLFXgo0Ozq6k-_8jWvoTUYVICYEbDDHC4sMs9QgmoXZl76eaSj0fGqhSX6zBV6SmdIVxSg16p-ezNIKW0y07_8o2p6IM9Ar4_-LWxWD-3TARvF6sa4kVMN/Dq2-nLtADqJISCzK_mlfjxkT0H2fE-7Kof1yooavaL2p8CmBSBN37Ht46Wllst0q-CNBJO6df05N3d1Y0Vg5oo06gBke98hj0orfLgG2EpBPe9s3mvD9clTXdc5eFFxx/.../

http://dw.uptodown.com/dwn/S9YgZKp5lwNO5Rbzcg-nKNPArRCrVUV66Zu_VjmfKW4fVcbJcgMfkF1BBw1keMKgW8wYJD2YB0RVN6LtmL8qehGCbpemcCFKKcSqvWqFU9BNXq4T2XevQHnifZVlLkEt/wLqAF-hMKERSCHzUufFy0X4k1WciFvKj_qfNFOVxn_qbE-4ettSPAvwfF81u_iW60sEiyoN8sIWLR14dPSB9mn8rSgCMZtnXzuxad82xPo0B0ejqlz_6KpgLiOG2fmAL/z9-qtNONomQSEipT-tuiUhCAx324ebcQjpvXgadwcR4Ulmvx_X-QaECOdig-N1a7OT93Fg_pcJtC5q6J3W1_e29nmV6_RkosPZ_7hxjAmQDvqSA2H6DkSu7R4TPKhfny/.../

https://dw.uptodown.com/dwn/BT9J4M9VRIL8S4miOSVSEl-7KfSPcZUBW968J7sf9lLhs5N67rLck8D1TsD0V0UO-arPIUpQVEfOIbuAYVKDgQAkAgjQo7w7kegtYLx6IZlM6AV5ESruGtkIHTMNUdDm/XqQgaB67nUNkT6DFGp5RUwQeDCHP3kPjrC5_nNVnMXEjHDs56i3z1MQo-L425uVW0qYX1pJ8B7e8pO0rOn6sKH11-lMmeHfJh8b6mIASCV34WN-UjHNbVEmHHo7RKnQa/Dk9R7_KYZs3r5B7N1hSoZCSz8SfdPlTqMy_1c6F-mPosmBBnLeXe5qAi87yzXSGBR4DMbB4Roxvkbub_UZS1i4aYEGI5gG7eMOvg-PsHEWoXJti6iL7zsKiosGppCy4K/.../

https://dw.uptodown.com/dwn/o3eBoAd0l7HwH6eprUby23fM4dftkNGs0qjRdpVUg-_s8NHWL3B3kVvdIjPMR5doDBtriYgM4QvjkftE-QpjL8pG0IZ7TrJhwKtGx-S64NZ1nKzwg0a-fLshE019mNA5/9SWEGWNc8k-b0Ei1TE8H7X3t-17FxaohGwj0Io5Geikm5_c1pp-hzGJAkQR5lqaTba-XK6uMm6Mbz8B6iYoEUrMOuwnGDPuTBkOvkyS5Rpn4GI4DyJoyfloBXxI3rLs7/cByJkYeoCSCZ_RA0YtrTNrgSJS0YVFXwDuVEVBYy5yVLnnqCF_2tIpXPfND8mV7DA3n-7eGyzR5K94WBsM9dupNXHMKCa2KO7D-j1MX1UVv2OUlYtO2GV9gX4tcsNb1-/.../

Latest 30 of 31 download URLs