e29193b0-b61f-4d86-ada8-6277dd849368-5.exe

PlusHD-V1.9

Bright circle investments Ltd.

This adware utilizes the Crossrider extension platform and will inject advertisiments in the Internet browser and may modify core browser settings. Ads will be delivered as banners and contextual text-links and may promote other potentially unwanted software. The application e29193b0-b61f-4d86-ada8-6277dd849368-5.exe by Bright circle investments has been detected as adware by 22 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. While running, it connects to the Internet address ip-50-63-202-57.ip.secureserver.net on port 80 using the HTTP protocol. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
PlusHDv1.9  (signed by Bright circle investments Ltd.)

Product:
PlusHD-V1.9

Description:
PlusHD-V1.9 exe

Version:
1000.1000.1000.1000

MD5:
c4d0d091484bccef1e24a374b46f1938

SHA-1:
cd45715c313f54e69b52e13f7c99e266d1d39863

SHA-256:
171d836550bae55ef666317c239865c4d56f8049d5520b99c486f84461c6ba3c

Scanner detections:
22 / 68

Status:
Adware

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage). Distributed through the Brightcircle investments brand.

Analysis date:
12/25/2024 5:31:35 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Kazy.374109
873

AhnLab V3 Security
PUP/Win32.CrossRider
2014.07.25

Avira AntiVirus
Adware/CrossRider.A.15278
7.11.163.234

AVG
Brightcircle
2015.0.3366

Baidu Antivirus
Adware.Win32.AdLoad
4.0.3.14915

Bitdefender
Gen:Variant.Adware.Kazy.374109
1.0.20.1290

Comodo Security
ApplicUnwnt
18965

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.374109
8.14.09.15.11

ESET NOD32
Win32/Toolbar.CrossRider.AH potentially unwanted application
8.7.0.302.0

F-Secure
Gen:Variant.Adware.Kazy.374109
11.2014-15-09_2

G Data
Gen:Variant.Adware.Kazy.374109
14.9.24

IKARUS anti.virus
not-a-virus:WebToolbar.CrossRider
t3scan.1.6.1.0

MicroWorld eScan
Gen:Variant.Adware.Kazy.374109
15.0.0.774

NANO AntiVirus
Riskware.Win32.AdLoad.dbskrg
0.28.2.60990

Panda Antivirus
Trj/Genetic.gen
14.07.01.04

Qihoo 360 Security
HEUR/Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
PUP.Task.Brightcircleinvestments.g
14.7.17.9

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.14629

Sophos
Generic PUA BN
4.98

Trend Micro House Call
TROJ_GEN.R0C1H07FR14
7.2.258

VIPRE Antivirus
Threat.4789396
31208

File size:
459.6 KB (470,584 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
PlusHD-V1.9.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\plushd-v1.9\e29193b0-b61f-4d86-ada8-6277dd849368-5.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/20/2014 3:00:00 AM

Valid to:
6/21/2015 2:59:59 AM

Subject:
CN=Bright circle investments Ltd., O=Bright circle investments Ltd., STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4347D0F2AD67F1767C932B3BFBEA7713

File PE Metadata
Compilation timestamp:
6/27/2014 1:02:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:bTMlgkhn/mnvbmaGl2ZMYuTJj7nIEliMaR9dNwsaLpTBIwFvb0:bQJn/mnvbdZM5Nj7nIEaR9ULpTewi

Entry address:
0x3B436

Entry point:
E8, FF, CA, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 78, FF, 46, 00, E8, 04, 4A, 00, 00, E8, 78, 1D, 00, 00, 0F, B7, F0, 6A, 02, E8, 92, CA, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 5C, 52, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4755

Code size:
364.5 KB (373,248 bytes)

Scheduled Task
Task name:
e29193b0-b61f-4d86-ada8-6277dd849368-5

Trigger:
Logon (Runs on logon)

Action:
e29193b0-b61f-4d86-ada8-6277dd849368-5.exe \qoolzdvwe \bwwze='plushd-v1.9' \qhwatmw=59570 \sc


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ip-50-63-202-57.ip.secureserver.net  (50.63.202.57:80)

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.10:80)

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.42:80)

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (52.216.80.234:80)

Remove e29193b0-b61f-4d86-ada8-6277dd849368-5.exe - Powered by Reason Core Security