crimsolite.FFUpdate.dll

crimsolite

FFUpdate is the Mozilla Firefox plugin manager for the crimsolite branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module crimsolite.FFUpdate.dll by crimsolite has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
crimsolite  (signed and verified)

Version:
1.0.5403.10868

MD5:
5a14aba5de49cec2b4090218e6a78bc2

SHA-1:
8b8b26576c9df32bb3fa8ae27ccb571268015718

SHA-256:
c1a6811ef9be6f6c3158f8b40f5ca26984c75885b99e1a756655f99e28038518

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
4/26/2024 11:45:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo.crimsolite (M)
16.2.4.18

File size:
546.3 KB (559,392 bytes)

Product version:
1.0.5403.10868

Original file name:
crimsolite.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\crimsolite\bin\plugins\crimsolite.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/27/2013 12:00:00 AM

Valid to:
11/27/2014 11:59:59 PM

Subject:
CN=crimsolite, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=crimsolite, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
02CCA1F2B8F504106134601E82CFA150

File PE Metadata
Compilation timestamp:
10/17/2014 3:02:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:dPfdRwQdtFPfn1kNXW6LJJfydvApuafQCTpupoFf:dFHPI0vYtQCTLf

Entry address:
0x88606

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 6F, 00, 00, 00, 48, 86, 08, 00, 48, 68, 08, 00, 52, 53, 44, 53, 82, CB, 23, 01, C9, 60, A5, 41, A6, CD, 50, 09, E2, C2, E5, 76, 01, 00, 00, 00, 44, 3A, 5C, 55, 74, 69, 6C, 69, 74, 69, 65, 73, 5C, 71, 69, 73, 34, 63, 77, 79, 30, 2E, 6E, 77, 6B, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 44, 65, 73, 6B...
 
[+]

Entropy:
7.4966

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
538 KB (550,912 bytes)

Remove crimsolite.FFUpdate.dll - Powered by Reason Core Security