6ed44528f8594ac0b14f.dll

Air Globe

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module 6ed44528f8594ac0b14f.dll by Air Globe has been detected as adware by 26 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Air Globe  (signed and verified)

MD5:
d3fdf0ffb490b64179350d02c44be1ad

SHA-1:
1b632c4794bda313ece319c3d754a1c9fe48ff26

SHA-256:
2dbae9f333531a23456d1d43917bca2d20a8e63af2b18742b106a9a9a022f170

Scanner detections:
26 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/28/2024 10:32:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.BB
688

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.BrowseFox
2015.03.19

Avira AntiVirus
ADWARE/BrowseFox.Gen7
7.11.218.106

AVG
Adware AdPlugin.CVY
2014.0.4257

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.15319

Bitdefender
Adware.BrowseFox.BB
1.0.20.390

Clam AntiVirus
Win.Adware.Browsefox-220
0.98/21511

Comodo Security
Application.Win32.AltBrowse.OABP
20896

Dr.Web
Trojan.BPlug.892
9.0.1.05190

Emsisoft Anti-Malware
Adware.BrowseFox.BB
8.15.03.19.03

ESET NOD32
Win32/BrowseFox.N potentially unwanted application
7.0.302.0

F-Prot
W32/S-de5f2e52
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor
11.2015-19-03_5

G Data
Gen:Variant.Adware.Graftor.173094
15.3.25

herdProtect (fuzzy)
2015.6.24.19

K7 AntiVirus
Unwanted-Program
13.193.14805

McAfee
Program.BrowseFox-FWV
16.8.708.2

MicroWorld eScan
Adware.BrowseFox.BB
16.0.0.234

NANO AntiVirus
Trojan.Win32.BPlug.dmjozr
0.30.0.65070

nProtect
Adware.BrowseFox.BB
15.01.30.01

Panda Antivirus
Generic Suspicious
15.03.19.03

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.19.3

Vba32 AntiVirus
AdWare.Win64.Kranet
3.12.26.3

VIPRE Antivirus
Threat.4150696
38552

Zillya! Antivirus
Adware.Agent.Win32.38120
2.0.0.2049

File size:
192.7 KB (197,360 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\air globe\bin\6ed44528f8594ac0b14f.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/10/2015 4:00:00 PM

Valid to:
1/11/2016 3:59:59 PM

Subject:
CN=Air Globe, O=Air Globe, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C68EFA725DB8110CE807489DAC03553

File PE Metadata
Compilation timestamp:
1/11/2015 3:50:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:FNbpOnPsGqQTruHLD7RcQxKrrdNU0VAtrOpOOWxOv4Kn7qbjx7T/HrmO:FNbqaLD7RcukVAtSQOWcgWqbV77LmO

Entry address:
0x115D2

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 0C, 91, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 9C, 53, 02, 10, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 34, 50, 02, 10, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64...
 
[+]

Entropy:
6.5641

Code size:
143.5 KB (146,944 bytes)

Remove 6ed44528f8594ac0b14f.dll - Powered by Reason Core Security