34.0.5.dll

Glass Bottle

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module 34.0.5.dll by Glass Bottle has been detected as adware by 19 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Glass Bottle  (signed and verified)

Version:
1.0.5666.35776

MD5:
b1c32727cfb4ef62ad479592b2397942

SHA-1:
f9dcc0a7b3bc775a0dd62285e8552b2919bc039b

SHA-256:
7369c21f71b65dc14c1412d619c2d190d06559a3c1c1fc09275966a2a7b5b91f

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/23/2024 8:43:30 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Avira AntiVirus
ADWARE/BrowseFox.30480.32
8.3.1.6

AVG
Generic
2016.0.3029

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1582

Bkav FE
W32.HfsAdware
1.3.0.6979

Clam AntiVirus
Win.Adware.Browsefox-1813
0.98/21511

Dr.Web
Trojan.Yontoo.1837
9.0.1.0214

ESET NOD32
Win32/BrowseFox.BP potentially unwanted (variant)
9.11979

Fortinet FortiGate
Riskware/BrowseFox
8/2/2015

K7 AntiVirus
Adware
13.207.16645

Malwarebytes
PUP.Optional.GlassBottle.A
v2015.08.02.12

McAfee
Artemis!B1C32727CFB4
5600.6685

NANO AntiVirus
Riskware.Win32.Agent.dtnyhh
0.30.24.2668

Panda Antivirus
PUP/GlassBottle
15.08.02.12

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Yontoo.GlassBottle (M)
15.8.2.12

Vba32 AntiVirus
AdWare.Agent
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
42230

Zillya! Antivirus
Adware.Agent.Win32.64652
2.0.0.2308

File size:
29.8 KB (30,480 bytes)

Product version:
1.0.5666.35776

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\ProgramData\51603d73-31f4-492f-a43e-5b71fef2ce15\plugins\7\resources\34.0.5.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/24/2015 5:00:00 PM

Valid to:
3/24/2016 4:59:59 PM

Subject:
CN=Glass Bottle, O=Glass Bottle, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7374DF7F72AEEA200CB610D087D39E6B

File PE Metadata
Compilation timestamp:
7/7/2015 7:52:36 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:1edICBf1XnjNI+qymAC1GmM2soOZhd0UF:gT9Xn1qymLGOOZw

Entry address:
0x36BE

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 20, 05, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, FF, 25, 1C, 41, 00, 10, FF, 25, 18, 41, 00, 10, 6A, 14, 68, 48, 49, 00, 10, E8, 76, 04, 00, 00, FF, 35, 80, 65, 00, 10, 8B, 35, 30, 40, 00, 10, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, EC, 40, 00, 10, 59, EB, 64, 6A, 08, E8, 73, 05, 00, 00, 59, 83, 65, FC, 00, FF, 35, 80, 65, 00, 10, FF, D6, 89, 45, E4, FF, 35, 7C, 65, 00, 10, FF, D6, 89, 45, E0...
 
[+]

Entropy:
6.3516

Code size:
12 KB (12,288 bytes)

Remove 34.0.5.dll - Powered by Reason Core Security