Gridinsoft Logo
File Icon

Firefox115.exe Trojan Heuristic Analysis

Technical Analysis

File Name firefox115.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.211.174
Database Version 2025-03-20 12:00:37 UTC

Trojan.Heur!.00040033

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
561,216
File Size (bytes)
2025-03-20
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
7b0faafd39564bdbcc56486c26212a69
SHA1
90cedf587fad03fb9c1eab03dbbccb2d6540ae82
SHA256
28c1986fe484cb684af8cbd70cfb1b0a7ed6acbbbfd5e626a2f02360c0f14ea9
SHA512
a1ea277b91bcd719b1f02a2eefdf08d9dc47b5b001ce241f2e975cb93beca351bda61ee2b2630e357a4dfa607a486a8759dc2e0a4bdea40bfad72ef22b037be4
ImpHash
31816bb37b906266874b4fc9befa2749

PE Analysis

Basic Information

Icon
Hash: b678d6ebdeceda7dbb12f611f1a7c746
Fuzzy: 93e99ba708fa2b02ac39525de811d7c3
dHash: 60e6969a96cce070
Image Base 0x140000000
Entry Point 0x14002d990
Compilation Time 2025-01-27 14:21:05
Checksum 0x00095a36 (Actual: 0x00095a36)
OS Version 6.1
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path firefox.pdb
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 17 libraries
Exports 97 functions
Resources 28 Resources
Sections 11 Sections

Version Information

Comments
LegalCopyright ©Firefox and Mozilla Developers; available under the MPL 2 license.
CompanyName Mozilla Corporation
FileDescription Firefox
FileVersion 115.20.0
ProductVersion 115.20.0
InternalName Firefox
LegalTrademarks Firefox is a Trademark of The Mozilla Foundation.
OriginalFilename firefox.exe
ProductName Firefox
BuildID 20250127124940
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 339,841 bytes 339,968 bytes 6.28 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 64A675F335A1F03EB289CFEB31E20148
.rdata 0x00054000 58,692 bytes 58,880 bytes 5.22 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 51D768280D632A018BC6FE7324E824DF
.data 0x00063000 11,160 bytes 1,024 bytes 3.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8AA1613BEA0D07B893F86926EDC31E70
.pdata 0x00066000 11,016 bytes 11,264 bytes 5.45 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ AC0FE440CF938A37019B32FB2B2213E3
.00cfg 0x00069000 40 bytes 512 bytes 0.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E607BB2A3CDE64136730A29724D6D747
.freestd 0x0006a000 16 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BF619EAC0CDF3F68D496EA9344137E8B
.retplne 0x0006b000 36 bytes 512 bytes 0.56 (Normal) 0x00000000 60E7349E46063B144CF642326DA037FD
.tls 0x0006c000 25 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1F354D76203061BFDD5A53DAE48D5435
.voltbl 0x0006d000 27 bytes 512 bytes 0.49 (Normal) 0x00000000 4860A7B6EED6D24835AEC4DAC866F1C3
.rsrc 0x0006e000 132,640 bytes 133,120 bytes 6.46 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3E2FD011F7366B73E47D32E4E6E8FB0F
.reloc 0x0008f000 1,164 bytes 1,536 bytes 4.69 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ CAE24CB43E82C925A255ABFE11843A81

Resource Analysis

Total Resources: 28 (131,148 bytes)
Resource Type Count Total Size Percentage
RT_ICON 18 128,104 bytes
97.7%
RT_STRING 1 46 bytes
0%
RT_GROUP_ICON 7 294 bytes
0.2%
RT_VERSION 1 1,012 bytes
0.8%
RT_MANIFEST 1 1,692 bytes
1.3%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.00040033 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.00040033 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware