surfslide_setup.exe

surf slide

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application surfslide_setup.exe by surf slide has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address api.yontoo.com on port 80 using the HTTP protocol.
Publisher:
surf slide  (signed and verified)

MD5:
14ab55d0a59897d8f4605ca2f226f003

SHA-1:
e467cbce2955efa71907a236c7ada725eb2e478f

SHA-256:
5c83e3bf516328d546579656a2c384e5666f7d1150466881085205d3be759b40

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 4:07:00 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Could be an adware BrowseFox
2014.0.4040

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.141019

Comodo Security
Application.Win32.Ciorik.RWLZ
19852

ESET NOD32
Win32/BrowseFox.C potentially unwanted application
7.0.302.0

Malwarebytes
PUP.Optional.SurfSlide.A
v2014.10.19.04

McAfee
Artemis!6F4957B2F68F
5600.6972

Reason Heuristics
PUP.Installer.surfslide.P
14.10.19.16

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.141017

SUPERAntiSpyware
Adware.BrowseFox/Variant
10290

File size:
2.3 MB (2,420,600 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\surfslide_setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/1/2014 5:00:00 PM

Valid to:
9/2/2015 4:59:59 PM

Subject:
CN=surf slide, O=surf slide, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
40C4725F1712C4789A4BDCEA560D5BE2

File PE Metadata
Compilation timestamp:
12/5/2009 2:52:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:uBYj8W30pz0gDcqAORTHmRn+kU2wOQWdCps1CPbb:uBYoHpz0FLO9mkRW4ps1CPf

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 6F, 44, 00, E8, F1, 2B, 00, 00, A3, 84, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 2E, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9982

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove surfslide_setup.exe - Powered by Reason Core Security