9873.exe

CinemaPlus-4.5vV08.07

Digit Network (Extreme White Limited)

The application 9873.exe, “CinemaPlus-4.5vV08.07 exe” by Digit Network (Extreme White Limited) has been detected as adware by 20 anti-malware scanners. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address tlb.hwcdn.net on port 80 using the HTTP protocol.
Publisher:
Cinema PlusV08.07  (signed by Digit Network (Extreme White Limited))

Product:
CinemaPlus-4.5vV08.07

Description:
CinemaPlus-4.5vV08.07 exe

Version:
1000.1000.1000.1000

MD5:
2f54cc626c199b6af7009a2183cdeefc

SHA-1:
9cee121c32cfab97a88c2a91d014b4f6bd998b70

SHA-256:
7f4bd2a81d28a4d47498cdecf8b866e2082f59b1aae3b11074db2ab93ba4a678

Scanner detections:
20 / 68

Status:
Adware

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage).

Analysis date:
4/25/2024 8:53:39 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.188636
572

AhnLab V3 Security
PUP/Win32.CrossRider
2015.07.09

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.1.6

Arcabit
Trojan.Adware.Graftor.D2E0DC
1.0.0.425

avast!
Win32:Adware-CMH [PUP]
2014.9-150712

AVG
Crossrider_r
2016.0.3050

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15712

Bitdefender
Gen:Variant.Adware.Graftor.188636
1.0.20.965

Bkav FE
W32.HfsAdware
1.3.0.6979

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.188636
8.15.07.12.04

ESET NOD32
Win32/Toolbar.CrossRider.CO potentially unwanted (variant)
9.11909

F-Secure
Gen:Variant.Adware.Graftor
11.2015-12-07_1

G Data
Gen:Variant.Adware.Graftor.188636
15.7.25

K7 AntiVirus
Unwanted-Program
13.205.16500

Kaspersky
not-a-virus:WebToolbar.Win32.CrossRider
14.0.0.1747

Malwarebytes
v2015.07.12.04

MicroWorld eScan
Gen:Variant.Adware.Graftor.188636
16.0.0.579

Panda Antivirus
Trj/Genetic.gen
15.07.12.04

Reason Heuristics
PUP.ExtremeWhite.DigitNetworkExtremeWhiteLimited (M)
15.7.12.16

SUPERAntiSpyware
Adware.CrossRider/Variant
9758

File size:
1.4 MB (1,504,848 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
CinemaPlus-4.5vV08.07.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\9873.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2015 8:00:00 AM

Valid to:
4/15/2016 7:59:59 AM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
7/8/2015 6:05:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:ai643Ji7iCKtapDC9wxkVywvkmMkdxR7JEt4+T0pSipiBti767I3qUmgo:l6JjwZM2E2+T0pSipiBti767I37mgo

Entry address:
0xC86AD

Entry point:
E8, 51, 06, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, B8, 09, 55, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 58, D1, 54, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, B8, 09, 55, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8...
 
[+]

Entropy:
6.4427

Code size:
978.5 KB (1,001,984 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.10:80)

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.49.106:80)

Remove 9873.exe - Powered by Reason Core Security