e844e1710702480aabc8.dll

PursuePoint

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module e844e1710702480aabc8.dll by PursuePoint has been detected as adware by 15 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
PursuePoint  (signed and verified)

MD5:
adaac4df498c349a9e951ef4e3a38082

SHA-1:
3df1a265588ae3fac0373cba291007da5a383d6a

SHA-256:
b9ef6143a301018071c4f7030924db7615030150b1bcd87d4f1fe4d5b6498f9c

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/24/2024 3:36:45 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.182.172

AVG
Adware AdInstaller.WebCake
2014.0.4189

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.141031

Clam AntiVirus
Win.Adware.Swiftbrowse-546
0.98/21411

Dr.Web
Trojan.BPlug.301
9.0.1.0304

ESET NOD32
Win32/BrowseFox (variant)
8.10653

K7 AntiVirus
Unwanted-Program
13.185.13866

McAfee
BrowseFox
5600.6960

NANO AntiVirus
Riskware.Win32.Kranet.dgstaw
0.28.6.62995

Reason Heuristics
PUP.PursuePoint.U
14.10.31.21

Sophos
Browse Fox
4.98

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Adware.BrowseFox
34416

Zillya! Antivirus
Adware.Kranet.Win32.486
2.0.0.1973

File size:
190.3 KB (194,848 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\pursuepoint\bin\e844e1710702480aabc8.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/26/2013 7:00:00 PM

Valid to:
11/27/2014 6:59:59 PM

Subject:
CN=PursuePoint, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PursuePoint, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
65588529ED634E296695EE3328858CB2

File PE Metadata
Compilation timestamp:
10/13/2014 7:32:14 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:3P37RBT2symmM3xx0y9dH0Xhk7IQ0Li41iTzYG5vVkc7qzX9PfDqds5W:3PLjrX9dH0Xhe8i41EzYGNVVGz9nDasg

Entry address:
0x11BED

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 81, 7C, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, D0, 45, 02, 10, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 34, 40, 02, 10, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64...
 
[+]

Entropy:
6.5607

Code size:
139.5 KB (142,848 bytes)

Remove e844e1710702480aabc8.dll - Powered by Reason Core Security