coupons64.dll

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The module coupons64.dll by Spigot has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Browser Extensions by Spigot, Inc. which is a potentially unwanted software program.
Publisher:
Spigot, Inc.  (signed and verified)

Version:
1, 8, 0, 1

MD5:
c721fecb7a649d7b36042f047a8d5526

SHA-1:
47cf49dcc1e95821bba596fac65058667c80d7d6

SHA-256:
a46338bcb1d99936d0ae419e3a567c222aa464f1e046b84ae2d496b59f591923

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/5/2024 2:41:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Spigot (M)
16.10.23.23

File size:
266 KB (272,368 bytes)

Product version:
1, 8, 0, 1

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\browserextensions\coupons64.dll

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
2/10/2015 8:00:00 AM

Valid to:
5/12/2018 7:59:59 AM

Subject:
CN="Spigot, Inc.", O="Spigot, Inc.", L=Incline Vilalge, S=Nevada, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0FE530445BDBABB00E24B3A1FD389919

Registration
CLSID:
{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
11/28/2015 1:47:55 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:Uq47RI3CwYZWNomNORQ9OyBtFTtoAL2SaBPg2UE+EJBXdU8SW7FxQY3KfZF:GI3CdWNoqOVUtFFySP2GKfpS5gK/

Entry address:
0x76600

Entry point:
48, 89, 4C, 24, 08, 48, 89, 54, 24, 10, 4C, 89, 44, 24, 18, 80, FA, 01, 0F, 85, 78, 02, 00, 00, 53, 56, 57, 55, 48, 8D, 35, DD, D9, FD, FF, 48, 8D, BE, 00, D0, FA, FF, 57, 31, DB, 31, C9, 48, 83, CD, FF, E8, 50, 00, 00, 00, 01, DB, 74, 02, F3, C3, 8B, 1E, 48, 83, EE, FC, 11, DB, 8A, 16, F3, C3, 48, 8D, 04, 2F, 83, F9, 05, 8A, 10, 76, 21, 48, 83, FD, FC, 77, 1B, 83, E9, 04, 8B, 10, 48, 83, C0, 04, 83, E9, 04, 89, 17, 48, 8D, 7F, 04, 73, EF, 83, C1, 04, 8A, 10, 74, 10, 48, FF, C0, 88, 17, 83, E9, 01, 8A, 10...
 
[+]

Entropy:
6.9950

Code size:
140 KB (143,360 bytes)

The file coupons64.dll has been discovered within the following programs.

Browser Extensions  by Spigot, Inc.
Publisher's description - “The toolbar communicates with our servers from time to time to check for available software updates such as bug fixes, patches, enhanced functions and new versions. By installing the toolbar, you agree to automatically request and receive updates.”
www.spigot.com
66% remove it
 
Powered by Should I Remove It?

Remove coupons64.dll - Powered by Reason Core Security