kasimos.FFUpdate.dll

kasimos

FFUpdate is the Mozilla Firefox plugin manager for the kasimos branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module kasimos.FFUpdate.dll by kasimos has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
kasimos  (signed and verified)

Description:
kasimos.FFUpdate

Version:
1.0.5043.22682

MD5:
cbf7f6d2c7a2fb496e1349fa9d6b01fa

SHA-1:
dce007e207bc0c4b6206f334f3184c9fa0d177f4

SHA-256:
b2a2ff7b8dd943eaecd913136abcf2c5df3b50422d6988541bccabb0c7a5017e

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
4/27/2024 1:27:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo.kasimos (M)
16.2.8.18

File size:
390.3 KB (399,640 bytes)

Product version:
1.0.5043.22682

Original file name:
kasimos.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\kasimos\bin\plugins\kasimos.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/20/2013 9:00:00 PM

Valid to:
8/20/2015 8:59:59 PM

Subject:
CN=kasimos, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=kasimos, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3C08AFE75FB61C990505B01BEE5FDDBD

File PE Metadata
Compilation timestamp:
10/22/2013 11:36:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:uzSPC4hx1R6ZMhLhFZUkQU4U+Z66Z/qmr3r5x78JVgsbD6C97wAPJp8dILOv/JWL:CCC4hxUgzukH+5q85xGVgsbz7w40d2DL

Entry address:
0x617CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 10, 00, 00, 00, 18, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 30, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 48, 00, 00, 00, 54, 20, 06, 00, EC, 02...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
382 KB (391,168 bytes)

Remove kasimos.FFUpdate.dll - Powered by Reason Core Security