cc0a0cb8-2d36-468e-9a41-cf5258516521-1-6.exe

Digit Network (Extreme White Limited)

The application cc0a0cb8-2d36-468e-9a41-cf5258516521-1-6.exe, “CinePlus-1.44V14.09 exe” by Digit Network (Extreme White Limited) has been detected as adware by 27 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address hwcdn.net on port 80 using the HTTP protocol.
Publisher:
CinePlus-1.44V14.09  (signed by Digit Network (Extreme White Limited))

Product:
CinePlus-1.44V14.09

Description:
CinePlus-1.44V14.09 exe

Version:
1000.1000.1000.1000

MD5:
cb82d2bdd4ef5775304839f9962ebd45

SHA-1:
f4736c2435001455c8789c46e197c8644fd65214

SHA-256:
8f09d8abca6a1418952a584e8bb44de5dff8148e126923e26a0aea5d3980af7f

Scanner detections:
27 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
7/4/2025 10:40:14 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.yz1@myYYAfki
507

AhnLab V3 Security
PUP/Win32.CrossRider
2015.09.15

Avira AntiVirus
ADWARE/CrossRider.Gen4
8.3.2.2

Arcabit
Application.Heur.E60C44
1.0.0.527

AVG
Generic_r
2016.0.2985

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15916

Bitdefender
Gen:Application.Heur.yz1@myYYAfki
1.0.20.1295

Comodo Security
Application.Win32.CrossRider.ALO
23234

Dr.Web
Trojan.Crossrider1.42770
9.0.1.0259

ESET NOD32
Win32/Toolbar.CrossRider.CD potentially unwanted (variant)
9.12250

F-Prot
W32/Crossrider.L.gen
v6.4.7.1.166

F-Secure
Gen:Application.Heur.yz1@myYYAfki
11.2015-16-09_4

G Data
Gen:Application.Heur.yz1@myYYAfki
15.9.25

IKARUS anti.virus
PUA.CrossRider
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.210.17208

Kaspersky
not-a-virus:WebToolbar.Win32.CrossRider
14.0.0.1419

Malwarebytes
PUP.Optional.CinePlus
v2015.09.16.03

McAfee
Artemis!CB82D2BDD4EF
5600.6641

MicroWorld eScan
Gen:Application.Heur.yz1@myYYAfki
16.0.0.777

NANO AntiVirus
Trojan.Win32.Agent.dvtooz
0.30.24.3283

Panda Antivirus
Trj/Genetic.gen
15.09.16.03

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Quick Heal
PUA.Adwapper.07976
9.15.14.00

Reason Heuristics
Adware.Crossrider.ExtremeWhite (M)
15.9.16.3

Rising Antivirus
PE:Malware.CrossRider!6.1CE1[F1]
23.00.65.15914

Sophos
Generic PUA PE (PUA)
4.98

VIPRE Antivirus
Crossrider
43746

File size:
1.4 MB (1,450,576 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2016

Original file name:
CinePlus-1.44V14.09.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cineplus-1.44v14.09\cc0a0cb8-2d36-468e-9a41-cf5258516521-1-6.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/14/2015 9:00:00 PM

Valid to:
4/14/2016 8:59:59 PM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
9/14/2015 1:06:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:PhV1kvxDUx5ZqwjpWLJcgKnVXEE+cTqpSJx/f53zgLXE5d7+kJY:Psq5wYpNLXTqpSJh5MDE5d7+kJY

Entry address:
0xAC827

Entry point:
E8, BE, 58, 01, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 28, 99, 52, 00, E8, B3, 93, 00, 00, E8, 6A, 61, 00, 00, 0F, B7, F0, 6A, 02, E8, 51, 58, 01, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 38, C5, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
935 KB (957,440 bytes)

Scheduled Task
Task name:
cc0a0cb8-2d36-468e-9a41-cf5258516521-1-6

Trigger:
Logon (Runs on logon)


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.10:80)

TCP (HTTP):
Connects to ec2-54-243-221-235.compute-1.amazonaws.com  (54.243.221.235:80)

Remove cc0a0cb8-2d36-468e-9a41-cf5258516521-1-6.exe - Powered by Reason Core Security