firefoxsetup.exe

Internet

Dova Network (New Media Holdings Ltd.)

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application firefoxsetup.exe, “Internet Setup ” by Dova Network (New Media Holdings) has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:

Product:
Internet

Description:
Internet Setup

MD5:
7b2ac49b6634b1e48b24f9ce5299912b

SHA-1:
fbf2a16d768ce70234205ebd3a3eee8ef02b328b

SHA-256:
83f0880c1fb57843eedd5510c3341638c32a5bc58ef4f98b7e5f6508d91e0fc5

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 7:50:30 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
Adware/InstallCo.zkt.1
7.11.200.12

avast!
Malware-gen
2014.9-151229

AVG
Generic
2016.0.2881

Comodo Security
Application.Win32.InstallCore.GH
20639

Dr.Web
Trojan.InstallCore.33
9.0.1.0363

ESET NOD32
Win32/InstallCore.TU potentially unwanted application
9.7.0.302.0

G Data
Win32.Application.InstallCore.CZ
15.12.24

IKARUS anti.virus
AdWare.InstallCore
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.1814574

NANO AntiVirus
Riskware.Win32.InstallCore.dkmnkn
0.30.0.64448

Reason Heuristics
PUP.NewMedia.Installer.New Media Holdings.Installer (M)
15.12.29.7

Sophos
PUA 'Install Core Click run software'
59

VIPRE Antivirus
InstallCore
36470

File size:
830.2 KB (850,152 bytes)

Product version:
2.3

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\firefoxsetup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/29/2014 1:13:24 PM

Valid to:
10/30/2015 1:13:24 PM

Subject:
CN=Dova Network (New Media Holdings Ltd.), O=Dova Network (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121EA6FC07B9DEE393ABBAEF1AA874D6483

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:HQNh7DvcEHYt9K/vBA4upAi/dCtC+G8v:HO1HYtWA4eAigtC+G8v

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8745

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file firefoxsetup.exe has been seen being distributed by the following URL.

Remove firefoxsetup.exe - Powered by Reason Core Security