Cantataweb.FFUpdate.dll

Cantataweb

FFUpdate is the Mozilla Firefox plugin manager for the Cantataweb branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module Cantataweb.FFUpdate.dll by Cantataweb has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Cantataweb  (signed and verified)

Version:
1.0.5404.8297

MD5:
36950aea7a740865c55112485e0cee68

SHA-1:
abad2a05e9603e41b460940041f491ab161465e6

SHA-256:
84b2b383b852f71a9bbe81cc33eae19fc327b21a7a129d0dfa45eff5066a3e5f

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
12/24/2024 11:21:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.14.17

File size:
546.2 KB (559,344 bytes)

Product version:
1.0.5404.8297

Original file name:
Cantataweb.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\cantataweb\bin\plugins\cantataweb.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/6/2014 9:00:00 PM

Valid to:
10/7/2015 8:59:59 PM

Subject:
CN=Cantataweb, O=Cantataweb, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
51FE05E2A96412C5062E1F77B3A16598

File PE Metadata
Compilation timestamp:
10/18/2014 9:36:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

Entry address:
0x885E2

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 6F, 00, 00, 00, 24, 86, 08, 00, 24, 68, 08, 00, 52, 53, 44, 53, B2, 8C, 0A, CA, 32, 9F, 10, 4F, 88, 29, 31, 18, D2, 59, 6B, 66, 01, 00, 00, 00, 44, 3A, 5C, 55, 74, 69, 6C, 69, 74, 69, 65, 73, 5C, 31, 69, 77, 6E, 32, 79, 6B, 77, 2E, 65, 32, 61, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 44, 65, 73, 6B...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
538 KB (550,912 bytes)

Remove Cantataweb.FFUpdate.dll - Powered by Reason Core Security