ef197251-58ef-4b03-93bc-d55f50cc9812-7.exe

CinemaPlus-3.2cV06.06

Digit Network (Extreme White Limited)

The application ef197251-58ef-4b03-93bc-d55f50cc9812-7.exe, “CinemaPlus-3.2cV06.06 exe” by Digit Network (Extreme White Limited) has been detected as adware by 22 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address tlb.hwcdn.net on port 80 using the HTTP protocol.
Publisher:
Cinema PlusV06.06  (signed by Digit Network (Extreme White Limited))

Product:
CinemaPlus-3.2cV06.06

Description:
CinemaPlus-3.2cV06.06 exe

Version:
1000.1000.1000.1000

MD5:
92707e4cb044814ae717ba41e889912f

SHA-1:
179c4dd9a7f2d70acbc0950c3d93df7091ab890e

SHA-256:
d0afedd2d9a7b66a91724914dc63d989e30a36bd1d6d8b39bbf4860b0d238525

Scanner detections:
22 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/17/2024 3:57:45 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.ev1@mSO9KJkO
607

AhnLab V3 Security
PUP/Win32.CrossRider
2015.06.07

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.1.6

Arcabit
Application.Heur.EF03DC
1.0.0.425

AVG
Generic_r
2016.0.3085

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.1567

Bitdefender
Gen:Application.Heur.ev1@mSO9KJkO
1.0.20.790

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.CrossRider.CK
22360

Dr.Web
Trojan.Crossrider1.35381
9.0.1.0161

ESET NOD32
Win32/Toolbar.CrossRider.CD potentially unwanted (variant)
9.11745

F-Prot
W32/S-dbad4651
v6.4.7.1.166

F-Secure
Gen:Application.Heur.ev1@mSO9KJkO
11.2015-07-06_1

G Data
Gen:Application.Heur.ev1@mSO9KJkO
15.6.25

IKARUS anti.virus
Gen.Application.Heur
t3scan.1.9.5.0

Kaspersky
not-a-virus:WebToolbar.Win32.CrossRider
14.0.0.1922

Malwarebytes
v2015.06.07.02

MicroWorld eScan
Gen:Application.Heur.ev1@mSO9KJkO
16.0.0.474

Panda Antivirus
Trj/Genetic.gen
15.06.07.02

Reason Heuristics
Adware.Crossrider.ExtremeWhite
15.6.7.14

Rising Antivirus
PE:Trojan.GoogUpdate!6.1E39
23.00.65.15605

SUPERAntiSpyware
Adware.CrossRider/Variant
9828

File size:
1.1 MB (1,128,016 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
CinemaPlus-3.2cV06.06.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cinemaplus-3.2cv06.06\ef197251-58ef-4b03-93bc-d55f50cc9812-7.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/14/2015 6:00:00 PM

Valid to:
4/14/2016 5:59:59 PM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
6/6/2015 7:04:24 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:ZddG66HxOijaNblYtX/fZfA75bkdpStI8TJ3:xNsOlN2tq5IdpStdTJ3

Entry address:
0xA178B

Entry point:
E8, D4, 00, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 0C, 57, 85, C9, 0F, 84, 92, 00, 00, 00, 56, 53, 8B, D9, 8B, 74, 24, 14, F7, C6, 03, 00, 00, 00, 8B, 7C, 24, 10, 75, 0B, C1, E9, 02, 0F, 85, 85, 00, 00, 00, EB, 27, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 83, E9, 01, 74, 2B, 84, C0, 74, 2F, F7, C6, 03, 00, 00, 00, 75, E5, 8B, D9, C1, E9, 02, 75, 61, 83, E3, 03, 74, 13, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 84, C0, 74, 37, 83, EB, 01, 75, ED, 8B, 44, 24, 10, 5B...
 
[+]

Entropy:
6.5634

Code size:
814 KB (833,536 bytes)

Scheduled Task
Task name:
ef197251-58ef-4b03-93bc-d55f50cc9812-7

Trigger:
Logon (Runs on logon)


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.42:80)

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.40.97:80)

Remove ef197251-58ef-4b03-93bc-d55f50cc9812-7.exe - Powered by Reason Core Security