f77056a6-54df-48d7-b91d-842cbb1c6277-1-7.exe

Cinem Plus 2.4cV25.05

Digit Network (Extreme White Limited)

The application f77056a6-54df-48d7-b91d-842cbb1c6277-1-7.exe, “Cinem Plus 2.4cV25.05 exe” by Digit Network (Extreme White Limited) has been detected as adware by 20 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address sage.parklogic.com on port 80 using the HTTP protocol.
Publisher:
Cinema Plus ProV25.05  (signed by Digit Network (Extreme White Limited))

Product:
Cinem Plus 2.4cV25.05

Description:
Cinem Plus 2.4cV25.05 exe

Version:
1000.1000.1000.1000

MD5:
aedcf364420bbe02f5bcaa09c4a6c5cd

SHA-1:
1e07bcba23116dc226b7d00f375e890536f7e01d

SHA-256:
32307756d9289d93c7e9a7aa3f10835401513b327767830b257af9e3f3512219

Scanner detections:
20 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/23/2024 1:23:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.cv1@muyDVaoO
617

AhnLab V3 Security
PUP/Win32.CrossRider
2015.05.28

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.1.6

AVG
Generic_r
2016.0.3095

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15528

Bitdefender
Gen:Application.Heur.cv1@muyDVaoO
1.0.20.740

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.CrossRider.CK
22250

ESET NOD32
Win32/Toolbar.CrossRider.CD potentially unwanted (variant)
9.11694

F-Prot
W32/S-dbad4651
v6.4.7.1.166

F-Secure
Gen:Application.Heur.cv1@muyDVaoO
11.2015-28-05_5

G Data
Gen:Application.Heur.cv1@muyDVaoO
15.5.25

Malwarebytes
v2015.05.28.03

McAfee
Artemis!AEDCF364420B
5600.6751

MicroWorld eScan
Gen:Application.Heur.cv1@muyDVaoO
16.0.0.444

Qihoo 360 Security
Win32/Virus.Adware.a87
1.0.0.1015

Reason Heuristics
Adware.Crossrider.ExtremeWhite
15.5.28.15

Rising Antivirus
PE:Trojan.GoogUpdate!6.1E39
23.00.65.15526

SUPERAntiSpyware
Adware.CrossRider/Variant
9848

VIPRE Antivirus
Threat.4150696
40552

File size:
1 MB (1,093,712 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Cinem Plus 2.4cV25.05.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cinem plus 2.4cv25.05\f77056a6-54df-48d7-b91d-842cbb1c6277-1-7.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2015 3:00:00 AM

Valid to:
4/15/2016 2:59:59 AM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
5/25/2015 9:04:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:wyV53uxuL1F8kK77EQxKcVjsk1WY8jVJthF5dR+K2Cu6myvjXL/znbgMoUQ8YEBL:XjCh7RK1Y8jVJthF5dR+K2Cu6myvjXLx

Entry address:
0x9BE9B

Entry point:
E8, D4, 00, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 0C, 57, 85, C9, 0F, 84, 92, 00, 00, 00, 56, 53, 8B, D9, 8B, 74, 24, 14, F7, C6, 03, 00, 00, 00, 8B, 7C, 24, 10, 75, 0B, C1, E9, 02, 0F, 85, 85, 00, 00, 00, EB, 27, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 83, E9, 01, 74, 2B, 84, C0, 74, 2F, F7, C6, 03, 00, 00, 00, 75, E5, 8B, D9, C1, E9, 02, 75, 61, 83, E3, 03, 74, 13, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 84, C0, 74, 37, 83, EB, 01, 75, ED, 8B, 44, 24, 10, 5B...
 
[+]

Code size:
774 KB (792,576 bytes)

Scheduled Task
Task name:
f77056a6-54df-48d7-b91d-842cbb1c6277-1-7

Trigger:
Logon (Runs on logon)


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to sage.parklogic.com  (69.39.236.56:80)

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.90:80)

Remove f77056a6-54df-48d7-b91d-842cbb1c6277-1-7.exe - Powered by Reason Core Security