firefox_download_2647189920.exe

Sahile

ConnectorSpeedy (New Media Holdings Ltd.)

The application firefox_download_2647189920.exe, “Sahile Setup ” by ConnectorSpeedy (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The installer is marketed through download protals and search ads as the free Mozilla Firefox web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Toker   (signed by ConnectorSpeedy (New Media Holdings Ltd.))

Product:
Sahile

Description:
Sahile Setup

MD5:
0430b39b26bdbe940e9b33582f9b3d5a

SHA-1:
1fd8e18941b1a898282308a1a3a7febf26cb54c2

SHA-256:
0d8ffb5d137c59c4a988536d80346f2dee1d7aec78eafeffc81fca69653238bc

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/23/2024 11:32:32 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH (M)
17.3.15.0

File size:
948.3 KB (971,032 bytes)

Product version:
2.8.3

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\firefox_download_2647189920.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/15/2016 1:51:17 PM

Valid to:
7/11/2017 10:51:47 AM

Subject:
CN=ConnectorSpeedy (New Media Holdings Ltd.), O=ConnectorSpeedy (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121814B859A983623A89FCFF9F06C7D2C51

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file firefox_download_2647189920.exe has been seen being distributed by the following URL.

http://www.download-files-now.com/c?x=rghEJcmpSElXof3fd0wxL/XFtv7n1oNHyPcXJOwpKdQ=&e=0&c=NpfK6LO20CB37 Q43D3Lk04MMLHho8Zl ULmwIwvqP62 HpmeELvcCu0KxLMyaFGpdeNHsFBxe7/XxANZ 5e96wvZ1E/GCp7AbuqP8B/RQOsz5TLy5JLriw8nCJRpZtdPSC3hrxb6ht0uM/6xSUHwoocfyxukcyPWZA3aBXOhc=&downloadAs=firefox_download.exe&fallback_url=https://.../?product=firefox-latest&os=win&lang=es-ES

Remove firefox_download_2647189920.exe - Powered by Reason Core Security