aab72157-141a-4b3a-9bef-b0a5112fd240-1-7.exe

CinemaPlus-3.2cV21.05

Digit Network (Extreme White Limited)

The application aab72157-141a-4b3a-9bef-b0a5112fd240-1-7.exe, “CinemaPlus-3.2cV21.05 exe” by Digit Network (Extreme White Limited) has been detected as adware by 16 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address sage.parklogic.com on port 80 using the HTTP protocol.
Publisher:
Cinema PlusV21.05  (signed by Digit Network (Extreme White Limited))

Product:
CinemaPlus-3.2cV21.05

Description:
CinemaPlus-3.2cV21.05 exe

Version:
1000.1000.1000.1000

MD5:
0310357b594cd02cb7513c27b6664b82

SHA-1:
47d87f799ab50f0f002086103d4d3b2a257cd03e

Scanner detections:
16 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/23/2024 2:00:01 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.iv1@mW7ALZjO
623

AhnLab V3 Security
PUP/Win32.CrossRider
2015.05.22

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.1.6

AVG
Generic_r
2016.0.3101

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15522

Bitdefender
Gen:Application.Heur.iv1@mW7ALZjO
1.0.20.710

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.CrossRider.CK
22200

ESET NOD32
Win32/Toolbar.CrossRider.CD potentially unwanted (variant)
9.11664

F-Secure
Gen:Application.Heur.iv1@mW7ALZjO
11.2015-22-05_6

G Data
Gen:Application.Heur.iv1@mW7ALZjO
15.5.25

IKARUS anti.virus
Gen.Application.Heur
t3scan.1.8.9.0

Malwarebytes
v2015.05.22.07

MicroWorld eScan
Gen:Application.Heur.iv1@mW7ALZjO
16.0.0.426

Reason Heuristics
Adware.Crossrider.ExtremeWhite
15.5.22.19

Rising Antivirus
PE:Trojan.GoogUpdate!6.1E39
23.00.65.15520

File size:
1.1 MB (1,188,944 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
CinemaPlus-3.2cV21.05.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cinemaplus-3.2cv21.05\aab72157-141a-4b3a-9bef-b0a5112fd240-1-7.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2015 3:00:00 AM

Valid to:
4/15/2016 2:59:59 AM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
5/21/2015 3:04:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:3EHT2QWO481xofIYiyeza6bYIEb2H8ZUT7pSpCATgu:3EHSQWO4syIR5TbzT7pSpCATz

Entry address:
0x9FA9B

Entry point:
E8, D4, 00, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 0C, 57, 85, C9, 0F, 84, 92, 00, 00, 00, 56, 53, 8B, D9, 8B, 74, 24, 14, F7, C6, 03, 00, 00, 00, 8B, 7C, 24, 10, 75, 0B, C1, E9, 02, 0F, 85, 85, 00, 00, 00, EB, 27, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 83, E9, 01, 74, 2B, 84, C0, 74, 2F, F7, C6, 03, 00, 00, 00, 75, E5, 8B, D9, C1, E9, 02, 75, 61, 83, E3, 03, 74, 13, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 84, C0, 74, 37, 83, EB, 01, 75, ED, 8B, 44, 24, 10, 5B...
 
[+]

Code size:
805 KB (824,320 bytes)

Scheduled Task
Task name:
aab72157-141a-4b3a-9bef-b0a5112fd240-1-7

Path:
C:\WINDOWS\Tasks\aab72157-141a-4b3a-9bef-b0a5112fd240-1-7.job

Trigger:
Logon (Runs on logon)


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to sage.parklogic.com  (69.39.236.56:80)

TCP (HTTP):
Connects to ec2-54-72-9-115.eu-west-1.compute.amazonaws.com  (54.72.9.115:80)

TCP (HTTP):
Connects to ip-184-168-221-50.ip.secureserver.net  (184.168.221.50:80)

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.90:80)

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.42:80)

Remove aab72157-141a-4b3a-9bef-b0a5112fd240-1-7.exe - Powered by Reason Core Security