0ca298513273497eb859b648c9a6fe3a.dll

Jump Flip

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module 0ca298513273497eb859b648c9a6fe3a.dll, “TODO: <File description>” by Jump Flip has been detected as adware by 22 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
TODO: <Company name>  (signed by Jump Flip)

Description:
TODO: <File description>

Version:
4.0.0.3

MD5:
814073ebb5aed5d648a1222a9c60eca5

SHA-1:
effaff45ba06174ab8ec6f91d25236bd04a5c584

SHA-256:
9e60804920242be7f3af305df93c8ec15b0a3c331d1c9f3ae6c0815f7e7a1237

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/20/2024 12:53:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.BJ
6484727

Avira AntiVirus
ADWARE/BrowseFox.Gen
7.11.205.236

avast!
Win32:BrowseFox-DZ [PUP]
150126-0

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.15129

Bitdefender
Adware.BrowseFox.BJ
1.0.20.145

Clam AntiVirus
Win.Adware.Browsefox-205
0.98/21511

Comodo Security
TrojWare.Win32.BrowseFox.FY
20894

Dr.Web
Trojan.BPlug.891
9.0.1.05190

Emsisoft Anti-Malware
Adware.BrowseFox.BJ
9.0.0.4799

ESET NOD32
Win32/BrowseFox.M potentially unwanted application
7.0.302.0

F-Prot
W32/S-e0317559
v6.4.7.1.166

F-Secure
Adware.BrowseFox.BJ
5.13.68

G Data
Adware.BrowseFox.BJ
15.1.25

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.193.14803

MicroWorld eScan
Adware.BrowseFox.BJ
16.0.0.87

NANO AntiVirus
Trojan.Win32.BPlug.dmjqza
0.30.0.65070

nProtect
Adware.BrowseFox.BJ
15.01.29.01

Reason Heuristics
PUP.Yontoo
15.1.29.21

Vba32 AntiVirus
AdWare.Kranet
3.12.26.3

VIPRE Antivirus
Threat.4741131
36666

Zillya! Antivirus
Adware.Agent.Win32.37670
2.0.0.2049

File size:
278.8 KB (285,472 bytes)

Product version:
4.0.0.3

Copyright:
TODO: (c) <Company name>. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\jump flip\bin\0ca298513273497eb859b648c9a6fe3a.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/21/2013 7:00:00 PM

Valid to:
8/22/2015 6:59:59 PM

Subject:
CN=Jump Flip, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Jump Flip, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
144CF0B61216826C7F439B5C91A6ABD6

Registration
CLSID:
{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
1/11/2015 5:51:00 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:ZfcmhLlsosuE23UtV3s7wuBlCwjHdixnibVWajAnP0gQyez6Xjt6AlWEZ7Tfd5n0:ZUmhJ/su3UPqXdiPa+0dZOTt6AToEK

Entry address:
0x20437

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, A1, 7E, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, B8, 2D, 8E, 02, 10, A3, 98, F2, 03, 10, C7, 05, 9C, F2, 03, 10, 23, 85, 02, 10, C7, 05, A0, F2, 03, 10, D7, 84, 02, 10, C7, 05, A4, F2, 03, 10, 10, 85, 02, 10, C7, 05, A8, F2, 03, 10, 79, 84, 02, 10, A3, AC, F2, 03, 10, C7, 05, B0, F2, 03, 10, A5, 8D, 02, 10, C7, 05, B4, F2, 03, 10, 95, 84, 02, 10, C7, 05, B8, F2, 03, 10, F7, 83, 02, 10, C7, 05, BC, F2, 03, 10, 83, 83...
 
[+]

Entropy:
6.4999

Code size:
196 KB (200,704 bytes)

Remove 0ca298513273497eb859b648c9a6fe3a.dll - Powered by Reason Core Security