brasssearch.ffupdate.dll

Brass Search

FFUpdate is the Mozilla Firefox plugin manager for the Brass Search branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module brasssearch.ffupdate.dll by Brass Search has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Brass Search  (signed and verified)

Version:
1.0.5546.31175

MD5:
c158a032635b069780c80fe7e18db836

SHA-1:
ee85cf990b0e7195d0a58a28d1b9654ce67f259f

SHA-256:
e0fce6966d7f93ed156729b2550aeee5712633b9cb62a80edb8591134ee74ca5

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
11/23/2024 6:20:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.10.6

File size:
592.3 KB (606,504 bytes)

Product version:
1.0.5546.31175

Original file name:
BrassSearch.FFUpdate2015031001.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\brass search\bin\plugins\brasssearch.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/14/2014 3:00:00 AM

Valid to:
3/15/2015 2:59:59 AM

Subject:
CN=Brass Search, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Brass Search, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
79A7A4116AA48D85E401C00C69AD38D7

File PE Metadata
Compilation timestamp:
3/10/2015 4:19:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

Entry address:
0x93E52

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
584 KB (598,016 bytes)

Remove brasssearch.ffupdate.dll - Powered by Reason Core Security