× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 6b4260b2260abf4e259509e1b1763f405cc6539012afe4fdb766f29172233d5f
File name: FirefoxPortable32-54.0.zip
Detection ratio: 1 / 57
Analysis date: 2017-06-14 07:32:55 UTC ( 1 week, 6 days ago ) View latest
Antivirus Result Update
TheHacker Trojan/Refroso.drxr 20170612
Ad-Aware 20170614
AegisLab 20170614
AhnLab-V3 20170614
Alibaba 20170614
ALYac 20170614
Antiy-AVL 20170613
Arcabit 20170614
Avast 20170613
AVG 20170613
Avira (no cloud) 20170614
AVware 20170613
Baidu 20170613
BitDefender 20170613
CAT-QuickHeal 20170613
ClamAV 20170613
CMC 20170613
Comodo 20170613
CrowdStrike Falcon (ML) 20170420
Cyren 20170613
DrWeb 20170614
Emsisoft 20170613
Endgame 20170612
ESET-NOD32 20170613
F-Prot 20170613
F-Secure 20170613
Fortinet 20170613
GData 20170613
Ikarus 20170613
Invincea 20170607
Jiangmin 20170613
K7AntiVirus 20170613
K7GW 20170613
Kaspersky 20170613
Kingsoft 20170614
Malwarebytes 20170613
McAfee 20170613
McAfee-GW-Edition 20170613
Microsoft 20170613
eScan 20170614
NANO-Antivirus 20170614
nProtect 20170613
Palo Alto Networks (Known Signatures) 20170614
Panda 20170613
Qihoo-360 20170614
Rising 20170612
SentinelOne (Static ML) 20170516
Sophos 20170613
SUPERAntiSpyware 20170614
Symantec 20170613
Symantec Mobile Insight 20170613
Tencent 20170614
TrendMicro 20170614
TrendMicro-HouseCall 20170614
Trustlook 20170614
VBA32 20170613
VIPRE 20170614
ViRobot 20170614
Webroot 20170614
WhiteArmor 20170613
Yandex 20170613
Zillya 20170613
ZoneAlarm by Check Point 20170614
Zoner 20170614
The file being studied is a compressed stream! More specifically, it is a Google Chrome Extension file.
Interesting properties
The studied file contains at least one Portable Executable.
The ZIP magic number has been left instead of substituting it with Cr24, this is perfectly legit.
Contained files
Compression metadata
Contained files
180
Uncompressed size
94136390
Highest datetime
2017-06-14 09:20:16
Lowest datetime
2005-05-13 00:54:00
Contained files by extension
dll
61
nsh
24
exe
12
ini
11
png
10
xpi
6
txt
5
chk
3
ico
2
xml
2
js
2
ja
2
bin
1
nsi
1
1/
1
aff
1
jpg
1
tlb
1
dic
1
ttf
1
Contained files by type
Portable Executable
73
unknown
70
directory
25
PNG
10
XML
1
JPG
1
ExifTool file metadata
MIMEType
application/zip

ZipRequiredVersion
20

ZipCRC
0x00000000

FileType
ZIP

ZipCompression
None

ZipUncompressedSize
0

ZipCompressedSize
0

FileTypeExtension
zip

ZipFileName
FirefoxPortable32/

ZipBitFlag
0x0002

ZipModifyDate
2017:06:14 09:19:26

File identification
MD5 98111dfa018961831ab61c2b0460ae92
SHA1 60e50e6ceac5a965bc0f5e823e8aa511c715b05b
SHA256 6b4260b2260abf4e259509e1b1763f405cc6539012afe4fdb766f29172233d5f
ssdeep
1572864:GH4CKJAePH1uHOiwAWFT7B5y/uDyOYAzCUn:GHVy4HOikTd5y/uOOxB

File size 53.5 MB ( 56141764 bytes )
File type Google Chrome Extension
Magic literal
Zip archive data, at least v2.0 to extract

TrID Speckie Dictionary Installation (71.4%)
ZIP compressed archive (28.5%)
Tags
nsis zipped contains-pe crx

VirusTotal metadata
First submission 2017-06-14 07:32:55 UTC ( 1 week, 6 days ago )
Last submission 2017-06-18 20:22:37 UTC ( 1 week, 1 day ago )
File names FirefoxPortable32-54.0.zip
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!