nanosurfer.ffupdate.dll

Nano Surfer

FFUpdate is the Mozilla Firefox plugin manager for the Nano Surfer branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module nanosurfer.ffupdate.dll by Nano Surfer has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Nano Surfer  (signed and verified)

Version:
1.0.5730.22511

MD5:
1d42c636e761553c8b79a8db7c4f7614

SHA-1:
cccdcbaf49988fa8a5a9062561cc151893134ccd

SHA-256:
b0a4450556a5ec8327c1e917f48c6a0ab95888245d2a93e52da6ef12df179075

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
5/1/2024 10:22:09 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo (M)
17.3.14.3

File size:
528.7 KB (541,432 bytes)

Product version:
1.0.5730.22511

Original file name:
2015090920.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\nano surfer\bin\plugins\nanosurfer.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/17/2014 12:00:00 AM

Valid to:
12/17/2015 11:59:59 PM

Subject:
CN=Nano Surfer, O=Nano Surfer, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4C3408B948BFE38825B699D7ED92B282

File PE Metadata
Compilation timestamp:
9/9/2015 9:30:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x8414E

Entry point:
FF, 25, 00, 20, 00, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7683

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
520.5 KB (532,992 bytes)

Remove nanosurfer.ffupdate.dll - Powered by Reason Core Security