9c344b1f-489f-498e-9973-0cf45b907b3b-5.exe

CinemaPlus-3.2cV28.09

Digit Network (Extreme White Limited)

The application 9c344b1f-489f-498e-9973-0cf45b907b3b-5.exe, “CinemaPlus-3.2cV28.09 exe” by Digit Network (Extreme White Limited) has been detected as adware by 25 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address tlb.hwcdn.net on port 80 using the HTTP protocol.
Publisher:
Cinema PlusV28.09  (signed by Digit Network (Extreme White Limited))

Product:
CinemaPlus-3.2cV28.09

Description:
CinemaPlus-3.2cV28.09 exe

Version:
1000.1000.1000.1000

MD5:
1d0da886a63dee2c01312c4494f13427

SHA-1:
35ee5d95cfbae1571cf427bfcca3af7926f444b0

SHA-256:
14e712a8141580ff0fac0ea22f9bfd8c73adc50254aa1419856fa027646619d7

Scanner detections:
25 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/25/2024 1:15:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.nv1@mauK2CeO
494

AhnLab V3 Security
PUP/Win32.CrossRider
2015.09.29

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.2.2

Arcabit
PUP.WebToolbar.CrossRider.eai
1.0.0.567

AVG
Crossrider_r
2016.0.2972

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15928

Bitdefender
Gen:Application.Heur.nv1@mauK2CeO
1.0.20.1355

Bkav FE
W32.HfsAdware
1.3.0.7237

Comodo Security
Application.Win32.CrossRider.ABZ
23318

Dr.Web
Trojan.Crossrider1.42770
9.0.1.0271

ESET NOD32
Win32/Toolbar.CrossRider.CC potentially unwanted (variant)
9.12323

F-Secure
Gen:Application.Heur.nv1@mauK2CeO
11.2015-28-09_2

G Data
Gen:Application.Heur.nv1@mauK2CeO
15.9.25

K7 AntiVirus
Unwanted-Program
13.210.17355

Kaspersky
not-a-virus:WebToolbar.Win32.CrossRider
14.0.0.1355

Malwarebytes
PUP.Optional.CinemaPlus
v2015.09.28.09

McAfee
PUP-FRD
5600.6622

MicroWorld eScan
Gen:Application.Heur.nv1@mauK2CeO
16.0.0.813

NANO AntiVirus
Trojan.Win32.Crossrider1.dskyyu
0.30.26.3725

Panda Antivirus
Trj/Genetic.gen
15.09.28.09

Reason Heuristics
Adware.Crossrider.ExtremeWhite (M)
15.9.28.21

Rising Antivirus
PE:PUF.CrossRider!1.A157[F1]
23.00.65.15926

Sophos
Generic PUA GI (PUA)
4.98

SUPERAntiSpyware
Adware.CrossRider/Variant
9601

VIPRE Antivirus
Crossrider
44126

File size:
1.2 MB (1,272,400 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
CinemaPlus-3.2cV28.09.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cinemaplus-3.2cv28.09\9c344b1f-489f-498e-9973-0cf45b907b3b-5.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2015 3:00:00 AM

Valid to:
4/15/2016 2:59:59 AM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
9/28/2015 4:04:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:P99t8n942hfjWvpmxb42vqlCra6oi+VWr4J+aLEpSKPtT8lsaB:VD8n942tWvwLvqMaDWE8aLEpSKPtT8lh

Entry address:
0xADC38

Entry point:
E8, 74, F8, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 0C, 57, 85, C9, 0F, 84, 92, 00, 00, 00, 56, 53, 8B, D9, 8B, 74, 24, 14, F7, C6, 03, 00, 00, 00, 8B, 7C, 24, 10, 75, 0B, C1, E9, 02, 0F, 85, 85, 00, 00, 00, EB, 27, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 83, E9, 01, 74, 2B, 84, C0, 74, 2F, F7, C6, 03, 00, 00, 00, 75, E5, 8B, D9, C1, E9, 02, 75, 61, 83, E3, 03, 74, 13, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 84, C0, 74, 37, 83, EB, 01, 75, ED, 8B, 44...
 
[+]

Entropy:
6.5569

Code size:
874.5 KB (895,488 bytes)

Scheduled Task
Task name:
9c344b1f-489f-498e-9973-0cf45b907b3b-5

Trigger:
Logon (Runs on logon)


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.42:80)

Remove 9c344b1f-489f-498e-9973-0cf45b907b3b-5.exe - Powered by Reason Core Security