3d8a4763-2a81-4784-8f04-7f4227a2f40c-7.exe.66776.gzquar

TheTorntv V10

Naruto Source

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The file 3d8a4763-2a81-4784-8f04-7f4227a2f40c-7.exe.66776.gzquar, “TheTorntv V10 exe” by Naruto Source has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address ip-184-168-221-56.ip.secureserver.net on port 80 using the HTTP protocol. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
esc  (signed by Naruto Source)

Product:
TheTorntv V10

Description:
TheTorntv V10 exe

Version:
1000.1000.1000.1000

MD5:
d53e28fe6c40054571403cae5722d4fa

SHA-1:
9a96bb387a6f884bc8ebeaab63077c15662b7944

SHA-256:
60702437d6b64a0918fe77bed9ff92d768ea270a06c0476d5c0cda8ed3c2e2fa

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 1:53:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle.NarutoSource (M)
16.2.24.20

File size:
518.9 KB (531,304 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
TheTorntv V10.exe

Language:
English (United States)

Common path:
C:\Program Files\thetorntv v10\3d8a4763-2a81-4784-8f04-7f4227a2f40c-7.exe.66776.gzquar

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/28/2014 5:30:00 AM

Valid to:
7/29/2015 5:29:59 AM

Subject:
CN=Naruto Source, O=Naruto Source, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1CE82906A7F364268F66771839675655

File PE Metadata
Compilation timestamp:
8/25/2014 3:35:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:KNgwPCh1ngY5WVKdDmjShpbTX7n0KbXfkz5yMLsYpTBvEBaOW390:KNgwKnn3WVoDm+XXfkz5jwYpTREB5

Entry address:
0x4476A

Entry point:
E8, 83, DE, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 10, F7, F1, 8B, D3, EB, 41, 8B, D8, 8B, 4C, 24, 18, 8B, 54, 24, 14, 8B, 44, 24, 10, D1, EB, D1...
 
[+]

Entropy:
6.4194

Code size:
403.5 KB (413,184 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ip-184-168-221-56.ip.secureserver.net  (184.168.221.56:80)