bca0778f-2663-4b49-a8bb-c8b1bb0592af-10.exe

I - Cinema

iCinema

The application bca0778f-2663-4b49-a8bb-c8b1bb0592af-10.exe has been detected as adware by 18 anti-malware scanners. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address tlb.hwcdn.net on port 80 using the HTTP protocol.
Publisher:
iCinema

Product:
I - Cinema

Description:
I - Cinema exe

Version:
1000.1000.1000.1000

MD5:
32172728a5d4264f8635d1ebe4d8335a

SHA-1:
8f8df3e2d23ead03b44f5cb6b94c46e80e5dcf7c

SHA-256:
512377d95de04d94c9fdcecd8801d338a8fe91c8f358b70fa7373ddd2434cbd1

Scanner detections:
18 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/19/2024 8:23:59 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.188636
576

AhnLab V3 Security
PUP/Win32.CrossRider
2015.07.07

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.1.6

Arcabit
Trojan.Adware.Graftor.D2E0DC
1.0.0.425

avast!
Win32:Adware-CMH [PUP]
2014.9-150709

AVG
Generic_r
2016.0.3054

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.1579

Bitdefender
Gen:Variant.Adware.Graftor.188636
1.0.20.950

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.188636
8.15.07.09.07

ESET NOD32
Win32/Toolbar.CrossRider.CO potentially unwanted (variant)
9.11900

F-Secure
Gen:Variant.Adware.Graftor
11.2015-09-07_5

G Data
Gen:Variant.Adware.Graftor.188636
15.7.25

Malwarebytes
PUP.Optional.iCinema.A
v2015.07.09.07

MicroWorld eScan
Gen:Variant.Adware.Graftor.188636
16.0.0.570

Panda Antivirus
Generic Suspicious
15.07.09.07

Reason Heuristics
Adware.Crossrider.iCinema (M)
15.7.9.7

SUPERAntiSpyware
Adware.CrossRider/Variant
9764

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
41782

File size:
1.2 MB (1,276,416 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
I - Cinema.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\i - cinema\bca0778f-2663-4b49-a8bb-c8b1bb0592af-10.exe

File PE Metadata
Compilation timestamp:
7/6/2015 5:07:21 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:vbdd06xzepltBiGeSo/9fxGlM4RTJ1/YgeXy9HAjTWpSgOo1EQUoeBUqRP1:BTQRT7Yg+jTWpSgOo1EQhOUmP1

Entry address:
0x9FA7D

Entry point:
E8, D1, 06, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, B8, B9, 51, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 58, 81, 51, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, B8, B9, 51, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8...
 
[+]

Code size:
810 KB (829,440 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (52.216.226.234:80)

TCP (HTTP):
Connects to ip-50-63-202-62.ip.secureserver.net  (50.63.202.62:80)

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.42:80)

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.10:80)

Remove bca0778f-2663-4b49-a8bb-c8b1bb0592af-10.exe - Powered by Reason Core Security