MossNet.FFUpdate.dll

Moss Net

FFUpdate is the Mozilla Firefox plugin manager for the Moss Net branded Yontoo adware browser platform. The component is designed to install and keep Firefox connected to the adware updater. The module MossNet.FFUpdate.dll by Moss Net has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Moss Net  (signed and verified)

Version:
1.0.5379.11108

MD5:
2f6a317870da59e9345b902cfd64075f

SHA-1:
8a5fe19d7cca664851d902c7253cc92abd241084

SHA-256:
72fbfb054fb39f0a67faf09186665574851f5edefbf106a242bd4e4c87abe0b1

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser plugin for Firefox.

Analysis date:
11/23/2024 10:22:43 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.5.16

File size:
450.8 KB (461,592 bytes)

Product version:
1.0.5379.11108

Original file name:
MossNet.FFUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\mossnet\bin\plugins\mossnet.ffupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/22/2014 5:30:00 AM

Valid to:
1/23/2015 5:29:59 AM

Subject:
CN=Moss Net, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Moss Net, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4879C8045F587B91FC188D2BC822C526

File PE Metadata
Compilation timestamp:
9/23/2014 12:40:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x70932

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6733

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
442.5 KB (453,120 bytes)

Remove MossNet.FFUpdate.dll - Powered by Reason Core Security