googlechromeextensionupdate_m4.exe

Google Chrome Extension Updater

Alactro LLC

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application googlechromeextensionupdate_m4.exe by Alactro has been detected as adware by 13 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. By plugging into the web browser, this extension will inject advertisements both banner and context hyperlinks based on the web sites being visited. It can be installed from the program's website or it may be bundled by third-party software installation programs.
Publisher:
Alactro LLC  (signed and verified)

Product:
Google Chrome Extension Updater

Description:
Installer

Version:
2013.1.31.2241

MD5:
5910af40fe883a37dfad54b018b70cb6

SHA-1:
b1dc51c9f3e499934918ae202da3a429bee5edd0

SHA-256:
02c98a2648ae46d6308148753fef3018208ad3748e9c756048b689afb1b2415b

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
11/14/2024 9:08:13 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Plugin
7.1.1

Avira AntiVirus
ADWARE/Yontoo.Gen2
7.11.133.86

AVG
AdInject.Alactro
2015.0.3528

Baidu Antivirus
Trojan.MSIL.WebCake
4.0.3.14322

Comodo Security
UnclassifiedMalware
17835

Dr.Web
Adware.Plugin.11
9.0.1.081

ESET NOD32
Win32/Adware.Yontoo (variant)
8.9460

IKARUS anti.virus
AdWare.Yontoo
t3scan.2.2.29

Reason Heuristics
PUP.Installer.Alactro.EE
14.8.8.0

Rising Antivirus
PE:Trojan.Win32.Generic.1418E4D8!337175768
23.00.65.14320

Trend Micro House Call
TROJ_FAKEAV.BMC
7.2.81

Trend Micro
TROJ_FAKEAV.BMC
10.465.22

VIPRE Antivirus
Yontoo
26766

File size:
591.9 KB (606,104 bytes)

Product version:
1.12.02

Copyright:
Copyright (c) 2013 Alactro LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\downloads\googlechromeextensionupdate_m4.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/15/2012 11:01:43 PM

Valid to:
5/27/2013 12:13:23 AM

Subject:
CN=Alactro LLC, O=Alactro LLC, L=Carlsbad, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
046CAA7E02C7FB

File PE Metadata
Compilation timestamp:
8/9/2011 1:55:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:a04OsDZc70sG9fNFgft6t3I4Eq0kYSgJXYoFU1/z0MooPQQKgSaSDN7:ZYU0wo3jECpgJIoI0MoQQQKgyx7

Entry address:
0x1627

Entry point:
55, 8B, EC, 81, EC, 58, 0B, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, A8, F4, FF, FF, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, B8, FC, FF, FF, 50, C7, 85, B8, FC, FF, FF, 14, 01, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, 30, 34, 40, 00, E8, 40, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, C5, 01, 00, 00, 68, 1C, 34, 40, 00, 68, 0C, 34, 40, 00, FF, 15, 68, 30, 40, 00, 50, FF, 15, 64, 30, 40, 00, 3B...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file googlechromeextensionupdate_m4.exe has been seen being distributed by the following 3 URLs.

Remove googlechromeextensionupdate_m4.exe - Powered by Reason Core Security