fraven 1.1-nova.exe

Fraven 1.1

Bright circle investments Ltd.

This adware utilizes the Crossrider extension platform and will inject advertisiments in the Internet browser and may modify core browser settings. Ads will be delivered as banners and contextual text-links and may promote other potentially unwanted software. The application fraven 1.1-nova.exe by Bright circle investments has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
setup  (signed by Bright circle investments Ltd.)

Product:
Fraven 1.1

Description:
Fraven 1.1 exe

Version:
1000.1000.1000.1000

MD5:
4ecc67a45f0078ef3d150d8f92fd8247

SHA-1:
66fa6732b6794f73ef07f2fdf8451fe65d940cc7

SHA-256:
8db70fb46cbd09367cfa06cebf13aa2bd8e57efd65265eea5456354679a7b664

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
9/18/2020 10:36:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.BrightCircle.setup (M)
16.7.11.12

File size:
602 KB (616,432 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2016

Original file name:
Fraven 1.1.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\fraven 1.1\fraven 1.1-nova.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/19/2014 3:30:00 AM

Valid to:
6/20/2015 3:29:59 AM

Subject:
CN=Bright circle investments Ltd., O=Bright circle investments Ltd., STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EF90FEF9AC8E258E5D30D0E08C84D37E

File PE Metadata
Compilation timestamp:
6/22/2014 1:37:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:p5BZ8pqYNR+XtF+iuaN0ehPxsVR0pTb9qLu6aJIMU:z/p/saN1KRoTMqJJhU

Entry address:
0x47599

Entry point:
E8, 5D, DF, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B8, D2, 47, 00, E8, E1, 4E, 00, 00, E8, 9D, 29, 00, 00, 0F, B7, F0, 6A, 02, E8, F0, DE, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 3B, 67, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.3241

Code size:
427 KB (437,248 bytes)

Scheduled Task
Task name:
8f6ceed5-cbdf-42f0-8419-4c7bf8318158-7

Trigger:
Logon (Runs on logon)


Remove fraven 1.1-nova.exe - Powered by Reason Core Security