2ef1708f-c754-4133-bd21-61d2fd7cc161-64.exe

CinemaPlus-3.2cV17.10

Digit Network (Extreme White Limited)

The application 2ef1708f-c754-4133-bd21-61d2fd7cc161-64.exe, “CinemaPlus-3.2cV17.10 exe” by Digit Network (Extreme White Limited) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address hwcdn.net on port 80 using the HTTP protocol.
Publisher:
Cinema PlusV17.10  (signed by Digit Network (Extreme White Limited))

Product:
CinemaPlus-3.2cV17.10

Description:
CinemaPlus-3.2cV17.10 exe

Version:
1000.1000.1000.1000

MD5:
8bc22f96fa21a46480bbe1d19480ed6b

SHA-1:
45877133012f91058c6282aaca7f2091d51f513f

SHA-256:
2796487224167913f328791c116c45ab5b19c88459ccd4db3e77b46ba4b29532

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
5/8/2024 5:22:49 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider.ExtremeWhite (M)
15.10.17.19

File size:
1.8 MB (1,893,968 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2016

Original file name:
CinemaPlus-3.2cV17.10.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cinemaplus-3.2cv17.10\2ef1708f-c754-4133-bd21-61d2fd7cc161-64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2015 3:00:00 AM

Valid to:
4/15/2016 2:59:59 AM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
10/17/2015 4:03:22 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:AF8xli/ge0jxn6DjwaNeZHoEayAkPm7zBTA120zWzgJPV/CZAf:jxli/4jJ6DjBeZHos27FTA12/gJP9f

Entry address:
0xCCE8C

Entry point:
48, 83, EC, 28, E8, 33, F9, 00, 00, 48, 83, C4, 28, E9, 02, 00, 00, 00, CC, CC, 48, 89, 5C, 24, 10, 48, 89, 74, 24, 18, 57, 48, 83, EC, 30, E8, B0, 5C, 00, 00, 0F, B7, F0, B9, 02, 00, 00, 00, E8, BF, F8, 00, 00, B8, 4D, 5A, 00, 00, 48, 8D, 3D, 33, 31, F3, FF, 66, 39, 05, 2C, 31, F3, FF, 74, 04, 33, DB, EB, 31, 48, 63, 05, 5B, 31, F3, FF, 48, 03, C7, 81, 38, 50, 45, 00, 00, 75, EA, B9, 0B, 02, 00, 00, 66, 39, 48, 18, 75, DF, 33, DB, 83, B8, 84, 00, 00, 00, 0E, 76, 09, 39, 98, F8, 00, 00, 00, 0F, 95, C3, 89...
 
[+]

Code size:
1.1 MB (1,101,312 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.81.82:80)

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.10:80)

Remove 2ef1708f-c754-4133-bd21-61d2fd7cc161-64.exe - Powered by Reason Core Security