34.0.5.dll

Sale Clipper

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module 34.0.5.dll by Sale Clipper has been detected as adware by 6 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Sale Clipper  (signed and verified)

Version:
1.0.5692.9808

MD5:
e03ba85b1fe9952ee3985f63ba16b367

SHA-1:
3d3c629aa3cf3f04f5a099a637aab3134e37995d

SHA-256:
bd29c71d8b9c25aba4067a9b39d720876a7cd19a855d742a4057957e0955490a

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/25/2024 10:26:39 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen
8.3.1.6

Dr.Web
Trojan.Yontoo.2167
9.0.1.0219

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
14.0.0.1620

Malwarebytes
PUP.Optional.WanderBurst.A
v2015.08.07.01

McAfee
Multiplug-FAN
5600.6681

Reason Heuristics
PUP.Yontoo.SaleClipper (M)
15.8.2.16

File size:
49.2 KB (50,400 bytes)

Product version:
1.0.5692.9808

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\ProgramData\application data\f43a0a22-b5b9-43e4-9c6f-705bf4e40c7b\plugins\7\resources\34.0.5.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/7/2015 9:00:00 PM

Valid to:
6/7/2016 8:59:59 PM

Subject:
CN=Sale Clipper, O=Sale Clipper, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6013DDC8434F3973136CC636D85A6451

File PE Metadata
Compilation timestamp:
8/2/2015 9:26:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:WJzeHH2AtdsgIFkqdTlv8H11Uu5OBV2DGhxo06Ws5pOZpdXaafYen:WJzKLtds9FkIlvE1uBV2LOZrJf

Entry address:
0x7B5B

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 93, 05, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, FF, 25, 44, 91, 00, 10, FF, 25, 40, 91, 00, 10, FF, 25, 3C, 91, 00, 10, 6A, 14, 68, 20, A0, 00, 10, E8, E4, 04, 00, 00, FF, 35, 44, B6, 00, 10, 8B, 35, 30, 90, 00, 10, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, F4, 90, 00, 10, 59, EB, 64, 6A, 08, E8, E1, 05, 00, 00, 59, 83, 65, FC, 00, FF, 35, 44, B6, 00, 10, FF, D6, 89, 45, E4, FF, 35, 40, B6, 00, 10...
 
[+]

Code size:
29.5 KB (30,208 bytes)

Remove 34.0.5.dll - Powered by Reason Core Security