ee1f8c53-7399-48b7-8865-7a6c2dd961e7-4.exe

CinemaPlus-3.2cV19.05

Digit Network (Extreme White Limited)

The application ee1f8c53-7399-48b7-8865-7a6c2dd961e7-4.exe, “CinemaPlus-3.2cV19.05 exe” by Digit Network (Extreme White Limited) has been detected as adware by 23 anti-malware scanners. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address sage.parklogic.com on port 80 using the HTTP protocol.
Publisher:
Cinema PlusV19.05  (signed by Digit Network (Extreme White Limited))

Product:
CinemaPlus-3.2cV19.05

Description:
CinemaPlus-3.2cV19.05 exe

Version:
1000.1000.1000.1000

MD5:
1770fee18000cde59b86b554866dbc50

SHA-1:
0c9544905036bb0c246c95ee615f9d706b5d13e9

SHA-256:
ca84ea0469e39f00c134f87d18ad4530d61d7d9338c460cd0d4b732e27cdb841

Scanner detections:
23 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/18/2024 1:26:03 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.Bv1@muzGnllO
5517893

AhnLab V3 Security
PUP/Win32.CrossRider
2015.05.20

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.1.6

avast!
Win32:Evo-gen [Susp]
2014.9-150522

AVG
Crossrider
2016.0.3104

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.15519

Bitdefender
Gen:Application.Heur.Bv1@muzGnllO
1.0.20.695

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.CrossRider.CK
22174

Dr.Web
Trojan.Crossrider1.31167
9.0.1.0142

Emsisoft Anti-Malware
Gen:Application.Heur.Bv1@muzGnllO
10.0.0.5366

ESET NOD32
Win32/Toolbar.CrossRider.CH potentially unwanted (variant)
9.11651

F-Secure
Riskware.Gen:Application.Heur.Bv1@muzGnllO
5.13.68

G Data
Gen:Application.Heur.Bv1@muzGnllO
15.5.25

IKARUS anti.virus
PUA.Plush
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.204.15960

Kaspersky
Trojan.NSIS.GoogUpdate
14.0.0.2002

Malwarebytes
v2015.05.19.03

MicroWorld eScan
Gen:Application.Heur.Bv1@muzGnllO
16.0.0.417

Norman
Gen:Application.Heur.Bv1@kuzGnllO
03.12.2014 13:20:04

Reason Heuristics
Adware.Crossrider.ExtremeWhite
15.5.19.11

Sophos
Generic PUA PK
4.98

VIPRE Antivirus
Threat.4150696
40418

File size:
1.4 MB (1,495,120 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
CinemaPlus-3.2cV19.05.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cinemaplus-3.2cv19.05\ee1f8c53-7399-48b7-8865-7a6c2dd961e7-4.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2015 2:00:00 AM

Valid to:
4/15/2016 1:59:59 AM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
5/19/2015 9:04:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:gvpxERwouUi2PGxG5R4la04xz3v0/lBiv73kUCd5gxCzH6pSOVTgFEL:gvDtj1g5R4w0oz/Eu7CMCzH6pSOVT3L

Entry address:
0xE693A

Entry point:
E8, 3C, FE, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 78, 09, E8, 6F, FF, 00, 00, 3B, 30, 7C, 07, E8, 66, FF, 00, 00, 8B, 30, E8, 59, FF, 00, 00, 8B, 04, B0, 5E, 5D, C3, 55, 8B, EC, 56, E8, CA, 5C, 00, 00, 8B, F0, 85, F6, 75, 07, B8, 90, 57, 54, 00, EB, 26, 53, 57, 33, FF, BB, 86, 00, 00, 00, 39, 7E, 24, 75, 1B, 6A, 01, 53, E8, 14, 2F, 00, 00, 59, 59, 89, 46, 24, 85, C0, 75, 0A, B8, 90, 57, 54, 00, 5F, 5B, 5E, 5D, C3, FF, 75, 08, 8B, 76, 24, E8, 90, FF, FF, FF, 50, 53, 56, E8, D3, EB...
 
[+]

Code size:
1 MB (1,092,608 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to sage.parklogic.com  (69.39.236.56:80)

Remove ee1f8c53-7399-48b7-8865-7a6c2dd961e7-4.exe - Powered by Reason Core Security