CrankWeb is a brand of the Sambreel/Yontoo group, a web advertising company located in Carlsbad, CA. The company is a primary distributor of unwanted software. It is part of the Yontoo/Sambreel group and distributes web browser add-ons, typically potentially unwanted and adware in nature, that are designed to modify a user's typical search beahvior as well as display context and popup advertising. There is one additional code signing certificate issued to this publisher.
1/2/2014 10:00:00 PM
1/3/2015 9:59:59 PM
CN=CrankWeb, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=CrankWeb, L=San Diego, S=California, C=US
Detections (100% detected)
Adware.Yontoo.CrankWeb.V, Adware.Yontoo.CrankWeb.BB, PUP.CrankWeb.W, Adware.Yontoo.CrankWeb.Q, PUP.Service.CrankWeb.K, PUP.CrankWeb.n, PUP.CrankWeb.N, Adware.Yontoo.CrankWeb (M), PUP.Yontoo.CrankWeb (M)
Threat.4741131, Yontoo, Threat.4150696, Trojan.Win32.Generic
W32/A-db42cb3b, W32/A-1c37adca, W64/A-59c9c70a, W64/A-e967bae2, W32/A-c99f2d8b
MSIL/BrowseFox.B potentially unwanted application, MSIL/BrowseFox.G potentially unwanted application, MSIL/BrowseFox.E potentially unwanted application
Trojan-Clicker/W32.Agent.398104, Adware.SwiftBrowse.CF, Adware.SwiftBrowse.CH, Adware.NetFilter.E, Adware.Mplug.DC
Adware.Kranet.Win32.12, Adware.Kranet.Win32.476, Adware.Yotoon.Win64.14, Adware.Yotoon.Win64.3
Trojan.BPlug.33, Trojan.BPlug.20, Trojan.BPlug.281, hacktool program Tool.NetFilter.313, Trojan.BPlug.123
McAfee Web Gateway
Artemis!PUP, BehavesLike.Win64.PUPAmonetize.ph, BehavesLike.Win64.PUPAmonetize.qm, BehavesLike.Win32.PUPAmonetize.qh, BehavesLike.Win32.BadFile.qh
The following certificate is also signed by CrankWeb.
The following publishers (by Authenticode signature organization name) are related.
* Note, the details and description above are based on the code signing digital signature issued to CrankWeb by VeriSign, Inc. on January 02, 2014 with the serial number '6fa2ae19bf84914123c143239e738403'.