0fcf82ed-b5d1-488f-a627-18864879300c

Bright circle investments Ltd.

This adware utilizes the Crossrider extension platform and will inject advertisiments in the Internet browser and may modify core browser settings. Ads will be delivered as banners and contextual text-links and may promote other potentially unwanted software. The file 0fcf82ed-b5d1-488f-a627-18864879300c by Bright circle investments has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Plus-HD-V1.5  (signed by Bright circle investments Ltd.)

Product:
Plus-HD-V1.5

Description:
Plus-HD-V1.5 exe

Version:
1000.1000.1000.1000

MD5:
36dcfa7cc92c3501cd8bf6088e3701fb

SHA-1:
768d917a29fb1984b763c8e629c07cb756d0142d

SHA-256:
bbb64c36f22d807d4d50f1705994f43367f2e07e6334167d80cc6029588b8f2c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
9/30/2020 4:07:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.BrightCircle.PlusHDV1 (M)
16.7.12.6

File size:
630.5 KB (645,616 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2016

Original file name:
Plus-HD-V1.5.exe

Language:
English (United States)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/19/2014 2:00:00 AM

Valid to:
6/20/2015 1:59:59 AM

Subject:
CN=Bright circle investments Ltd., O=Bright circle investments Ltd., STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EF90FEF9AC8E258E5D30D0E08C84D37E

File PE Metadata
Compilation timestamp:
6/20/2014 12:08:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:84XsIUMXVkO7GmFOXFCxZcT+lIeaTQN3ZQnCApTcMmdwuXF/vgS:jzUNVFT+lrdZiCMT3ywuXFZ

Entry address:
0x4A379

Entry point:
E8, 55, DF, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 90, 39, 48, 00, E8, E1, 4E, 00, 00, E8, 9D, 29, 00, 00, 0F, B7, F0, 6A, 02, E8, E8, DE, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 3B, 67, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
451 KB (461,824 bytes)

Remove 0fcf82ed-b5d1-488f-a627-18864879300c - Powered by Reason Core Security