8713568343434a1aa4aa8b424769f1b8.dll

outobox

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module 8713568343434a1aa4aa8b424769f1b8.dll, “TODO: <File description>” by outobox has been detected as adware by 24 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
TODO: <Company name>  (signed by outobox)

Description:
TODO: <File description>

Version:
4.0.0.3

MD5:
c12a48f8c6c8a511a4a11b2259e0cf79

SHA-1:
be5e2c4f8fe3e81f4251042330a529482b531761

SHA-256:
e24b74aa9770016cbb45fe10a85a26c5fd1abe857ff2cf525982c5c443c6ebfb

Scanner detections:
24 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/18/2024 3:04:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.AU
6505014

AhnLab V3 Security
Win-PUP/BrowseFox.Gen
2015.02.01

Avira AntiVirus
ADWARE/BrowseFox.Gen
7.11.206.68

avast!
Win32:BrowseFox-EP [PUP]
150129-1

AVG
Generic
2016.0.3212

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1521

Bitdefender
Adware.BrowseFox.AU
1.0.20.160

Clam AntiVirus
Win.Adware.Browsefox-205
0.98/21511

Comodo Security
TrojWare.Win32.BrowseFox.FY
20920

Dr.Web
Trojan.BPlug.891
9.0.1.05190

Emsisoft Anti-Malware
Adware.BrowseFox.AU
9.0.0.4799

ESET NOD32
Win32/BrowseFox.M potentially unwanted application
7.0.302.0

F-Prot
W32/S-34ddbcc5
v6.4.7.1.166

F-Secure
Adware.BrowseFox.AU
5.13.68

G Data
Adware.BrowseFox.AU
15.2.25

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.193.14824

MicroWorld eScan
Adware.BrowseFox.AU
16.0.0.96

NANO AntiVirus
Trojan.Win32.BPlug.dmjqza
0.30.0.65070

nProtect
Adware.BrowseFox.AU
15.01.30.01

Reason Heuristics
PUP.Yontoo
15.2.1.2

Vba32 AntiVirus
AdWare.Kranet
3.12.26.3

VIPRE Antivirus
Threat.4150696
36666

Zillya! Antivirus
Adware.Agent.Win32.37670
2.0.0.2050

File size:
278.7 KB (285,416 bytes)

Product version:
4.0.0.3

Copyright:
TODO: (c) <Company name>. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\outobox\bin\8713568343434a1aa4aa8b424769f1b8.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/30/2014 3:00:00 AM

Valid to:
10/31/2015 1:59:59 AM

Subject:
CN=outobox, O=outobox, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3308B48A98D635F50AF4E52B1D5E6168

File PE Metadata
Compilation timestamp:
1/11/2015 1:51:00 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:wfcmhLlsosuE23UtV3s7wuBlCwjHdixnibVWajAnP0gQyez6Xjt6AlWEZ7Tfd5ns:wUmhJ/su3UPqXdiPa+0dZOTt6AToE2

Entry address:
0x20437

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, A1, 7E, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, B8, 2D, 8E, 02, 10, A3, 98, F2, 03, 10, C7, 05, 9C, F2, 03, 10, 23, 85, 02, 10, C7, 05, A0, F2, 03, 10, D7, 84, 02, 10, C7, 05, A4, F2, 03, 10, 10, 85, 02, 10, C7, 05, A8, F2, 03, 10, 79, 84, 02, 10, A3, AC, F2, 03, 10, C7, 05, B0, F2, 03, 10, A5, 8D, 02, 10, C7, 05, B4, F2, 03, 10, 95, 84, 02, 10, C7, 05, B8, F2, 03, 10, F7, 83, 02, 10, C7, 05, BC, F2, 03, 10, 83, 83...
 
[+]

Entropy:
6.4996

Code size:
196 KB (200,704 bytes)

Remove 8713568343434a1aa4aa8b424769f1b8.dll - Powered by Reason Core Security