laflurla.ffupdate.dll

Laflurla

FFUpdate is the Mozilla Firefox plugin manager for the Laflurla branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module laflurla.ffupdate.dll by Laflurla has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Laflurla  (signed and verified)

Version:
1.0.5450.12579

MD5:
a248d4f57ee1a6ee037db8561b728888

SHA-1:
c9c9959398c3ae3d354539f33de7016054754e19

SHA-256:
e47b845785e300f01b0a52fef78413181999a41527ab2bec4a038d1e1bad1418

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
12/24/2024 3:24:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.2.7.5

File size:
546.8 KB (559,904 bytes)

Product version:
1.0.5450.12579

Original file name:
Laflurla.FFUpdate2014120314.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\laflurla\bin\plugins\laflurla.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/3/2014 5:00:00 PM

Valid to:
2/4/2015 4:59:59 PM

Subject:
CN=Laflurla, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Laflurla, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0541E25DBE69A2BC84C39AB35093A301

File PE Metadata
Compilation timestamp:
12/3/2014 7:59:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

Entry address:
0x8890A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4971

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
538.5 KB (551,424 bytes)

Remove laflurla.ffupdate.dll - Powered by Reason Core Security