mozilla-firefox-todownload.exe

The executable mozilla-firefox-todownload.exe has been detected as malware by 1 anti-virus scanner. The file has been seen being downloaded from mozilla-firefox.todownload.com.
MD5:
ee20ffce7f03f24c00127b8efe856699

SHA-1:
2509c8b957a04b45307f8d80bd1e30be3c441e40

SHA-256:
1577354ab5f53e5d665d7f51b222c5d4cce2195f7c1c9f9d7bacd7528f92677a

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/24/2024 4:19:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.6.27.6

File size:
1 MB (1,096,976 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\mozilla-firefox-todownload.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:31nZePuTJyGoDz1xMUzoz9m76jx4GRU87wmww58IgXm4:zePODUZWkGdL372w5/Q

Entry address:
0xCB930

Entry point:
55, 8B, EC, 83, C4, F0, B8, 70, FB, 40, 00, E8, FD, D4, FF, FF, 57, 55, 83, C4, F4, 89, 4C, 24, 04, 89, 14, 24, 8B, D0, 8B, EA, 81, E5, 00, F0, FF, FF, 03, 14, 24, 81, C2, FF, 0F, 00, 00, 81, E2, 00, F0, FF, FF, 89, 54, 24, 08, 8B, 44, 24, 04, 89, 28, 8B, 44, 24, 08, 2B, C5, 8B, 54, 24, 04, 89, 42, 04, 8B, 35, E4, 35, 47, 00, EB, 3C, 8B, 5E, 08, 8B, 7E, 0C, 03, FB, 3B, EB, 76, 02, 8B, DD, 3B, 7C, 24, 08, 76, 04, 8B, 7C, 24, 08, 3B, FB, 76, 1E, 6A, 04, 68, 00, 10, 00, 00, 2B, FB, 57, 53, E8, 26, FC, FF, FF...
 
[+]

Entropy:
6.9541

Developed / compiled with:
Microsoft Visual C++

Code size:
829.5 KB (849,408 bytes)

The file mozilla-firefox-todownload.exe has been seen being distributed by the following URL.

Remove mozilla-firefox-todownload.exe - Powered by Reason Core Security