firefoxupdate.exe

Firefox

Chao Wei

The application firefoxupdate.exe by Chao Wei has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update Service(FirefoxU)”. While running, it connects to the Internet address euve246913.serverprofi24.com on port 80 using the HTTP protocol.
Publisher:
Chao Wei  (signed and verified)

Product:
Firefox

Version:
50.0.5.325

MD5:
bdc962d92b3b0898445c99f63892e2d4

SHA-1:
e4f53f0aa3f3dbd54a3bb67f5b3fa533f9146b06

SHA-256:
55525118587642f6f26993a81af0740bebadd29bf04cc47ad5470b99b1879771

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/11/2025 2:48:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Elex.Chao (M)
16.12.2.9

File size:
102.2 KB (104,624 bytes)

Product version:
50.0.5.325

Copyright:
Copyright (C) 2016 Firefox Authors

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\firefox\bin\firefoxupdate.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
12/2/2016 7:00:00 AM

Valid to:
8/19/2017 6:59:59 AM

Subject:
CN=Chao Wei, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
426B9B1A32F1FA79A1D4E4E61168E69A

File PE Metadata
Compilation timestamp:
12/2/2016 2:27:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
1536:zh3LILz5cLkvwfZ2/bXevDpdJredMxrsvJH3lZBJeEQnTszsWO1tcdQfYlA09b:V7QrbMpb5tmJH1ZOEqwi8QfYlA09b

Entry address:
0x60B1

Entry point:
E8, 75, 04, 00, 00, E9, 8E, FE, FF, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 58, 00, 00, 00, C7, 06, B4, 21, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, BC, 21, 41, 00, C7, 01, B4, 21, 41, 00, C3, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 25, 00, 00, 00, C7, 06, D0, 21, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, D8, 21, 41, 00, C7, 01, D0, 21, 41, 00, C3, 55, 8B, EC, 56, 8B, F1, 8D, 46, 04, C7, 06, 94, 21, 41, 00, 83...
 
[+]

Entropy:
6.3632

Code size:
66 KB (67,584 bytes)

Service
Display name:
Update Service(FirefoxU)

Service name:
FirefoxU

Description:
Keeps your Firefox software up to date. If this service is disabled or stopped, your Firefox software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and f

Type:
Win32OwnProcess

Depends on:
RpcSs


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to euve246913.serverprofi24.com  (62.75.142.165:80)

Remove firefoxupdate.exe - Powered by Reason Core Security