techgilesetup.exe

techgile

This is the installer and setup program from the techgile branded Yontoo adware web browser extension. This adware injects various forms of advertisements in the user's web browser based on the HTML content and URLs viewed. Ad include banners, in-line context text links, coupons, and search. The program will install an auto-updating Windows service that will update the software with additional features. The application techgilesetup.exe by techgile has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
techgile  (signed and verified)

MD5:
a7d3990a19b2006fcf12e53d9a9ea9e3

SHA-1:
cb951c01c0716472c15ff8dc5e0c590263751aee

SHA-256:
765c7a0c833c329e2b869f1bca9186fc8e3d227837d57b28fb3ca23f68ecfad6

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/20/2024 2:01:49 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.BrowseFox
2014.10.22

AVG
Generic
2015.0.3312

Baidu Antivirus
Adware.Win64.BrowseFox
4.0.3.141024

Dr.Web
Trojan.BPlug.181
9.0.1.0297

ESET NOD32
Win64/BrowseFox.AA (variant)
8.10600

Fortinet FortiGate
Adware/BrowseFox
10/24/2014

G Data
NSIS.Application.BrowseFox
14.10.24

Malwarebytes
PUP.Optional.BPlug
v2014.10.24.03

McAfee
Artemis!A7D3990A19B2
5600.6968

NANO AntiVirus
Trojan.Win32.BPlug.dfsehz
0.28.2.62841

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.141022

VIPRE Antivirus
Trojan.Win32.Generic
34136

File size:
569.1 KB (582,760 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\techgilesetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/4/2014 4:00:00 AM

Valid to:
9/5/2015 3:59:59 AM

Subject:
CN=techgile, O=techgile, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
73F8CC58517F3D5D8C50DFEA9B1C4816

File PE Metadata
Compilation timestamp:
12/6/2009 1:52:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:aRulxQNXR1s15Ap/G/8/3D0Fw/tN8dkmLtpHHHrh7CaFMJII:aGsXR6j8/z0FmcLbH1bYII

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 6F, 44, 00, E8, F1, 2B, 00, 00, A3, 84, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 2E, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9814

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file techgilesetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove techgilesetup.exe - Powered by Reason Core Security