ax_bonline_x86.ocx

Stkh.BossOnline

LLC

The file ax_bonline_x86.ocx, “Boss Online ActiveX control” by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
PBL  (signed by LLC )

Product:
Stkh.BossOnline

Description:
Boss Online ActiveX control

Version:
1,0,0,535

MD5:
227cfa4f6e48e0cffa85f5bf5d04793b

SHA-1:
6b179e0cfbdc9b86315b24cf03c3e857a46c32db

SHA-256:
acb9b7293ff9d3e46d6357119a04f01e5041bfa7c551dfedda40db5d1784cd56

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
10/25/2021 12:54:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize
16.11.4.23

File size:
1.9 MB (2,033,768 bytes)

Product version:
1,0,0,535

Original file name:
ax_bonline.dll

File type:
OLE control extension (Win32 OCX)

Common path:
C:\windows\downloaded Program Files\ax_bonline_x86.ocx

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/22/2014 5:00:00 AM

Valid to:
8/22/2017 4:59:59 AM

Subject:
CN="LLC ""Stakhanovets""", O="LLC ""Stakhanovets""", STREET="2-nd Roschinskaya str., 4, office 503", L=Moscow, S=Moscow, PostalCode=115191, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F7244EEE637B20E588B65F59A244BFE1

File PE Metadata
Compilation timestamp:
3/24/2015 4:31:18 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:xLSJJFbfAV1oGDaay96m4TqltyoAMMMMM7MMMvX3:tSJbz4Dzy9p4T0t7AMMMMM7MMMvn

Entry address:
0x307FA

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, A7, 95, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 6A, 10, 68, 30, D9, 1C, 10, E8, 07, 20, 00, 00, 8B, 5D, 08, 85, DB, 75, 0E, FF, 75, 0C, E8, 3D, E4, FF, FF, 59, E9, CC, 01, 00, 00, 8B, 75, 0C, 85, F6, 75, 0C, 53, E8, F4, E4, FF, FF, 59, E9, B7, 01, 00, 00, 83, 3D, 44, 33, 1D, 10, 03, 0F, 85, 93, 01, 00, 00, 33, FF, 89, 7D, E4, 83, FE, E0, 0F, 87, 8A, 01, 00, 00, 6A, 04, E8, 1B, 6A, 00, 00, 59, 89, 7D, FC, 53, E8, 44...
 
[+]

Code size:
276.5 KB (283,136 bytes)

ActiveX Install
Name:
{94FBC66E-8230-47D3-B7CA-66F19B04231D}


Remove ax_bonline_x86.ocx - Powered by Reason Core Security