firefox setup 47.0_win64.exe

7-Zip

Mozilla Corporation

This is a self-extracting archive and installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
Igor Pavlov  (signed by Mozilla Corporation)

Product:
7-Zip

Description:
7z Setup SFX

Version:
4.42

MD5:
96d5614ab88648c00028c2b237a7d1a1

SHA-1:
abec8eff1414c405e2a83e5e04d447f38dde4e7c

SHA-256:
a1767d76db44572b6addca598e44438ff1ce252502448c360640bd0a8eafad8b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/1/2024 5:23:40 PM UTC  (today)

File size:
45.3 MB (47,466,776 bytes)

Product version:
4.42

Copyright:
Copyright (c) 1999-2006 Igor Pavlov

Original file name:
7zS.sfx.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mozilla firefox 47.0 final\firefox setup 47.0_win64.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/9/2015 5:00:00 AM

Valid to:
7/13/2018 5:00:00 PM

Subject:
CN=Mozilla Corporation, O=Mozilla Corporation, L=Mountain View, S=California, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
09E65AD807B8497B0749D41568D626D0

File PE Metadata
Compilation timestamp:
4/17/2014 10:29:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:uUciimhy5SlkHIw58iJzeNLt4V/AZRCUEUlMjnhMzziUaqMaeKiwE8UivnAAUFaB:umhy5HIwmQzkB42ZRC86jnw/a1DsdABU

Entry address:
0x21E30

Entry point:
60, BE, 00, 80, 41, 00, 8D, BE, 00, 90, FE, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
8.0000

Packer / compiler:
UPX 2.90LZMA

Code size:
40 KB (40,960 bytes)

The file firefox setup 47.0_win64.exe has been seen being distributed by the following 16 URLs.

http://dw.uptodown.com/dwn/bexze28xDZDpLB3jMIpwq2FoZrBTEF5Qf10hx59NfInpzs99Q0h9rxlNZQkkLEM6-zqzrp5-J9WmI9ej0mAXxRYJLRjA-uRCaddmf85Rb4H3FS2E01bmoa1TL24M7D-z/ALcjWnco9lHu72xh2Rb4K_fxML10qWS--JIzxtv9ROtoqwXL1maucxki6ZSUVdSx2P_f3xorrUbdzNb9ytIyBVj85Ero6rBCFk6JuHZ7HdkMbbXR5ZHauck6wJ4ABm60/ad_p0m1Zo9l1l32XgKytVeIN1yz7bS1PTETQvK13q2YoQKqAkuUB8iPFFaIncK0nQEjgZtqCrFQq3vQGY9R_Q-Ad1vR3C5ZU8GH_ZIiAMhaJOB-Av0a-haQeeoXp4Cbc/.../

http://dw11.uptodown.com/dwn/jyR53i2AOem70hAzdc-z3R_zJGMIcovWED_uIn6LF8QeXTlpo3BLRxmYhW6xykfYdeED26fYK1-S4Ed3FTFXsrrdJ5HAFTebFdGzQyHzaq5w4rWoJTkK5AHrvI0HEyDE/3DqvDwFtP2FeKCz40SapXXKAoWiZdgs7ORR43IS7EIUFgBhNtoKER-ArX_gKI-tqJiwBP_gnWMEtbJq87K3OJw_NNjY5cMmqtiMnMyu4-Xoq1YMVcWArmAXVNU-Y2nBP/GyvCW3F09WkUZM2CpPI1z7BQGV-I-lk74DDKX5kFtQ749Imr10OB8xYNiq8jM1R9Y-rGEl9yUlQA05QTgsQxmEJ-v0yD1lQ2xdWr-SJl2oFhnfOaffr7eIJMLWwlvwqB/.../mozilla-firefox-47-0-64-bit.exe

http://dw.uptodown.com/dwn/PfIwllf02UPS3UPaj3TFd1N1qTKq64pVnRWzbO3uEvQhQJj3DuTKqBShbe5i2VhThjSr5SxDnIj5mDhAJ6tovErUeYri3eykdfbJmmf8JC0mJ_ZBnZ6iswoO44W93CER/JpK7dNqDq129LGWoiiVwQihmM3DPNXbsKXPKImpCUMx1tnf4DX6XBLWdxRpF_rEru21xVcWjveTQNJ9nS2T4O53BbAv4UFJJQH0lazPG7s-BeRHM0xzbV8PIPYvXsIFC/K-23164CdLxhXYggUwwI647u6_7CjUX5EFSDp9fk-wft1I2_a5Q72MtxvsPjE0K4UwqS2ZgzNe8WAfHDknfx4kLd3tBUW7LAenwb6YGX5Al9IzvAOW7ntxKHXjpAIWGI/.../

http://dw.uptodown.com/dwn/SIxNtqQPpCoxLQN4X-bPp83mBBlHCO5jx1r8NBy2fQIcFBjSYyQ8Anx0oUVEaIIJeZdvlu6Msc9JJXv5MnFzfxVKToVF1ZnF_rMAND3Hhm9PpVEx2F3aiwhBF7xRhkEo/ztWjtAn1Ltg8ftrtrroseJZKH4xPAnfbwoM_ozLspuzzKYZC8OoamkJc-sSVmZNSzNKaOyHdMreSKUfgVJcqzXOZMurcjeP_rnMUMxuDOrP0rms_Xlm3fBsLHNjCrGh4/tp-kBnmsL5VW8PqpKHwjtSz34rErsNuIs1ZVXx-45A_Lkz7hIgSRIoqq-T07mRXHlAo0EqLsrzPtXTAWacY3sgSghvg_nCqQkVDRqrVMs8T5puol0YJOlLgHpt_oy-uD/.../

https://download.mozilla.org/?product=firefox-47.0-SSL&os=win64&lang=ru

http://dw.uptodown.com/dwn/CxBmI2Y1hkFmYlBhztAApVHN9QwbiFtBS9oDl-069uSgKpMrvXcDF9j7mmroemHz8TvH6rHU1RGh7JFIiARsCwnDMn2ZHpw3s6BuncvSZ6eB8hbdgWo04cMQyKMy9Ue9/CXvacsXlcMNcvmqcPjCAtA9GL1bpbWZECb6QMaIu5NQ6Oz-YZu4pLi-CeAcUX13i3HXBDnXizKyx3Ag1gEPaTXCgn73Ho0ZTJCIQQ5sIfBrJjxaXZiWQdHRCCyBhoUNZ/FY6TEKrd_zXM6oKj_piniUIM6WkA2i5RF57CWSA_hSF8uisScuOZWfKg2AhBI11aIuIq4t1JwJglKqc4iT-mf5IpdCHgqmJHCm0A8tiuK-HpjIFaeaJvEbZTjrZfSeSe/.../

https://dw.uptodown.com/dwn/ept2Q6Nh0OolyOPvMeiZwmOBzaj8s_Y3GR9XNJBsWKUmJ90mO60o01BKvtZ99JkI0p1agg2k_HYDigel9fBn8Ifq-dwNWgrwofvMN9BQf0K922reuKwHAuOeLYFaNFQZ/oBqdKfnnxCrEdMKWW2Hb5pCqm09vplxgMzw1xzGXDr6r05gQNQoAUkOYzGU0gf292TEdRMwYDE1rADEhiDQGHwbU1yWSt9j9Cl0hmDprsNiSqOEUgUikdEV4XZYnk89s/bK12lIstJlh1_C7scVqhfiTo8qp5-xa3Rsgm-eY_FPwe12oFaJy7N1xfx1Ebvv-7RJBWTo7ol1ffmxu4Wv7FhxLPzW7yXfkP9Qn5p10ZfHwnybLqn_9H2oot1j_XWygB/.../

http://dw.uptodown.com/dwn/FI9n5cYc3UftBH7mKU_21cswqZpRvB0J1LcFpAfUgwYm8R9rjhpdgjsByE9tb38YSImm1PEa04ss_YH9nWWhOq4iJ5BWiz1KhG8kp1HwEAmyaiMbhCnh99RPLWBD5kwk/-XJkzYkL56px9lR56Xm6DzllWEq_abir9G8621PPZzgjAUu6cCOmKaaKLZKVkNqeWNZ6CQRz0Db73y2fu-3nmq3i4UXpfHWkaInoCRyd95q36qLDtlo3c71tmwIyPWYQ/fss6LSvpuQCaiHmR646756ETLGyzNLevxu3kioKfyXFuKLRtznhPqCxd5PaU0ZdZoRp4OWVrN73Wmx90h-C9GwYbHRjH86L0GQbyyNEiFitRicH-Z31bi1l3-uJSwfER/.../

http://dw.uptodown.com/dwn/O-98BJpbdlknYZ5KAe_rQBZ3-dBaJif1x_jXcKP7aeo2-8_Paewy96E7g9FJXKSBttWvuSU9i0b_UraWU8i277C-vSB6eMDvQhZKenuj0uGaqOSpu2dbP56wdAlJlfEt/o0vtDzajKNi4lz91ea3xdsI7gSwr2isdF2dieN11o8RNRwoXR6IuSWX0TJ24HJGw52HHr6iCbpZ_5MPrzvVXZlvCfleP954jLtsZmvA4UfzKRkIRDQe6_SBNta-deyIc/mBRI6ZI9vYuUmgYAHLXuXFrcDeo9W4sQs-iNQRxKk3TA9kqff4a_Nh947O6PN197dTxevlnNCT-OYaxuzmLnRB_bnvdo_3T3d3V5dsgv-g2LxnUUiwAh3oyrm26zUS4b/.../

http://dw.uptodown.com/dwn/RcG2qmdlOGTvr_M1E8ktwPJVQP4pQeL7fbHNCaj9tggTHygjIHMkt9Yyw3UVoK2J5rgJ5nLWuDyAaNoFMKOrKJ82GfduzmLvGC2QtntWDFKw72IbU6KyZat2rPmO-8Vn/SwsnZQydla0DyVvvPTHTDYHS8Sk8ONYJ98-ighuwzdL9klmtP2hSvoOHFjOlBgEjbZ_VN7CEhvvQifjBHmK06XXImfD5stI-hcFbqa3ZhkvT4haYqLuBn1udhkBB_snI/crGsnN9NjFt5LeJnYXbKL87vbXJw9g8I7BfEv2hglnSM392_wV6sEDr6lpC3gTPRS5S1V9QgbZ8oewHR1Ix2CUN8IE8jNbXeX0wdvmwTc1MNWAXKCYXINBcyOS0II4rr/.../