1fba1993-cdaf-4223-a198-744448cdb7cf-6.exe

CinamHDPureV9.5

Stampede Technologies

The application 1fba1993-cdaf-4223-a198-744448cdb7cf-6.exe, “CinamHDPureV9.5 exe” by Stampede Technologies has been detected as adware by 18 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address hwcdn.net on port 80 using the HTTP protocol.
Publisher:
CinamHDPure  (signed by Stampede Technologies)

Product:
CinamHDPureV9.5

Description:
CinamHDPureV9.5 exe

Version:
1000.1000.1000.1000

MD5:
d9bd2aebdbd1b6bbf1d52ce0fe731781

SHA-1:
256d7a6f58a9f0e455125dfed6e8a31184073710

SHA-256:
63e03b77915707aed4907920a2b121cf8df80913963dbad286e2cbd067e41448

Scanner detections:
18 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/26/2024 11:35:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Symmi.27213
879

AVG
Stampede
2015.0.3357

Baidu Antivirus
Adware.Win32.GoogUpdate
4.0.3.1499

Bitdefender
Gen:Variant.Adware.Symmi.27213
1.0.20.1260

Emsisoft Anti-Malware
Gen:Variant.Adware.Symmi.27213
14.09.09

ESET NOD32
Win32/Toolbar.CrossRider.AE potentially unwanted application
7.0.302.0

F-Secure
Gen:Variant.Adware.Symmi.27213
11.2014-09-09_3

G Data
Gen:Variant.Adware.Symmi.27213
14.9.24

IKARUS anti.virus
PUA.PlusHD
t3scan.1.7.5.0

Kaspersky
Trojan.NSIS.GoogUpdate
15.0.0.494

Malwarebytes
PUP.Optional.CinemaHD.A
v2014.09.09.12

MicroWorld eScan
Gen:Variant.Adware.Symmi.27213
15.0.0.756

NANO AntiVirus
Riskware.Win32.CrossRider.dednub
0.28.2.61942

Panda Antivirus
Trj/Genetic.gen
14.09.09.12

Reason Heuristics
PUP.Crossrider.StampedeTechnologies.g
14.9.9.0

Vba32 AntiVirus
AdWare.Adwapper
3.12.26.3

VIPRE Antivirus
Threat.4789396
32938

Zillya! Antivirus
Trojan.GoogUpdate.Win32.1558
2.0.0.1915

File size:
669.4 KB (685,432 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2016

Original file name:
CinamHDPureV9.5.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cinamhdpurev9.5\1fba1993-cdaf-4223-a198-744448cdb7cf-6.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/28/2014 4:00:00 AM

Valid to:
7/29/2015 3:59:59 AM

Subject:
CN=Stampede Technologies, O=Stampede Technologies, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0CC7970117FD591A57609D71BEE0FCB8

File PE Metadata
Compilation timestamp:
8/26/2014 2:06:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:0iyjY9/xOAm2V6YY8y6+oqm+4/KJJpTx71Pb6yvfWmG:jyMprohVzHTFJb6yvfFG

Entry address:
0x4FBFC

Entry point:
E8, 04, E0, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 38, BE, 48, 00, E8, DE, 4E, 00, 00, E8, 9A, 29, 00, 00, 0F, B7, F0, 6A, 02, E8, 97, DF, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 13, 68, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
482.5 KB (494,080 bytes)

Scheduled Task
Task name:
1fba1993-cdaf-4223-a198-744448cdb7cf-6

Trigger:
Logon (Runs on logon)

Action:
1fba1993-cdaf-4223-a198-744448cdb7cf-6.exe \agentregpath='cinamhdpurev9.5-nv' \appid=61792 \s


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.10:80)

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.1.124:80)

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.42:80)

Remove 1fba1993-cdaf-4223-a198-744448cdb7cf-6.exe - Powered by Reason Core Security