789c24d7-b520-4824-83ac-9bc2fbb7f58b-10.exe

I - Cinema

iCinema

The application 789c24d7-b520-4824-83ac-9bc2fbb7f58b-10.exe has been detected as adware by 18 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address tlb.hwcdn.net on port 80 using the HTTP protocol.
Publisher:
iCinema

Product:
I - Cinema

Description:
I - Cinema exe

Version:
1000.1000.1000.1000

MD5:
f4a62b8ab1bc09704dce633e29a6aa95

SHA-1:
b72f1892c0211ca042e556470ad6ee805b85da59

SHA-256:
3cd8b1ffb378b35f50216b70e127b0a8779ec8cde37000633975fc7b502e9935

Scanner detections:
18 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/22/2024 9:15:51 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.188636
594

AhnLab V3 Security
PUP/Win32.CrossRider
2015.06.20

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.1.6

Arcabit
Trojan.Adware.Graftor.D2E0DC
1.0.0.425

avast!
Win32:Adware-CMH [PUP]
2014.9-150621

AVG
Crossrider
2016.0.3072

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15621

Bitdefender
Gen:Variant.Adware.Graftor.188636
1.0.20.860

Clam AntiVirus
Win.Adware.Graftor-967
0.98/21511

Dr.Web
Trojan.Crossrider1.37322
9.0.1.0172

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.188636
8.15.06.21.12

ESET NOD32
Win32/Toolbar.CrossRider.CO potentially unwanted (variant)
9.11814

G Data
Gen:Variant.Adware.Graftor.188636
15.6.25

Malwarebytes
PUP.Optional.iCinema.A
v2015.06.21.12

MicroWorld eScan
Gen:Variant.Adware.Graftor.188636
16.0.0.516

Panda Antivirus
Generic Suspicious
15.06.21.12

Reason Heuristics
Adware.Crossrider.iCinema (M)
15.6.21.0

SUPERAntiSpyware
PUP.CrossRider/Variant
9801

File size:
1.5 MB (1,542,144 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
I - Cinema.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\i - cinema\789c24d7-b520-4824-83ac-9bc2fbb7f58b-10.exe

File PE Metadata
Compilation timestamp:
6/18/2015 4:05:34 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:W8vzC5r2Nm7MNr7ivkOkZ8HxCWWJIwinjd9r8O9DTapSsWoNJCx9/7cqFrh:9srR0JejvDTapSsdNJCx9/7cirh

Entry address:
0xCDD1D

Entry point:
E8, 4B, 06, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, B8, 99, 55, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 58, 61, 55, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, B8, 99, 55, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8...
 
[+]

Code size:
1016 KB (1,040,384 bytes)

Scheduled Task
Task name:
789c24d7-b520-4824-83ac-9bc2fbb7f58b-10_user

Trigger:
Logon (Runs on logon)


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ip-50-63-202-62.ip.secureserver.net  (50.63.202.62:80)

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.42:80)

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (52.216.1.226:80)

Remove 789c24d7-b520-4824-83ac-9bc2fbb7f58b-10.exe - Powered by Reason Core Security