CrankWeb.FirstRun.exe

FirstRun

CrankWeb

The Yontoo branded FirstRun executable is distributed as part of a Yontoo product bundle and is desigend to install components of this ad-supported (injection) program as well as 'call home' to inform the server that the extension was installed and may request additional instructions. The application CrankWeb.FirstRun.exe by CrankWeb has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
CrankWeb  (signed and verified)

Product:
FirstRun

Version:
1.0.0.0

MD5:
c8922b86ee3200600b5321907bcdfdc6

SHA-1:
85a3a833a13e95ee0ae030ebe2b1c0fc8c42b391

SHA-256:
c7f4cb8bf7b2424f517138fd88f5e09eb8335b50ba4a32ca6cd4e7ece1fdb1fb

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo ad injection web browser add-on.

Analysis date:
4/25/2024 1:08:42 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo.CrankWeb (M)
16.2.12.1

File size:
1.6 MB (1,726,744 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
CrankWeb.FirstRun.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\crankweb\crankweb.firstrun.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/2/2014 10:00:00 PM

Valid to:
1/3/2015 9:59:59 PM

Subject:
CN=CrankWeb, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=CrankWeb, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6FA2AE19BF84914123C143239E738403

File PE Metadata
Compilation timestamp:
2/25/2014 6:18:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:rpu9l1NNab+Twkb8YgbDf62mo2yoyRwAUuwpsZqp+sS:rpu9lda6TwA8YgbDf6Tow4gzS

Entry address:
0x1A55BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, 2C, 03, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.6 MB (1,717,760 bytes)

Remove CrankWeb.FirstRun.exe - Powered by Reason Core Security