boxrock.ffupdate.dll

Purchase Time

FFUpdate is the Mozilla Firefox plugin manager for the Purchase Time branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module boxrock.ffupdate.dll by Purchase Time has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Purchase Time  (signed and verified)

Version:
1.0.5964.39348

MD5:
b304e834e2dcfad5558a4b0e9c6b1a7f

SHA-1:
073451d96eb23d1bec7f73c1dcc4807173f5af7c

SHA-256:
abf930c4f947df18af294273d228e7fc061ebb2f70a649f6767ed851fa7a1d93

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
11/27/2024 3:53:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.8.10

File size:
565.2 KB (578,760 bytes)

Product version:
1.0.5964.39348

Original file name:
2016050105.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\box rock\bin\plugins\boxrock.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/2/2015 2:00:00 AM

Valid to:
9/2/2016 1:59:59 AM

Subject:
CN=Purchase Time, O=Purchase Time, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2C18DC2083776C69B87EDA69E9A50527

File PE Metadata
Compilation timestamp:
5/1/2016 7:51:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x8D282

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5100

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
557 KB (570,368 bytes)

Remove boxrock.ffupdate.dll - Powered by Reason Core Security