hd-v1.9-nova.exe

HD-V1.9

Motoko Group

This adware utilizes the Crossrider extension platform and will inject advertisiments in the Internet browser and may modify core browser settings. Ads will be delivered as banners and contextual text-links and may promote other potentially unwanted software. The application hd-v1.9-nova.exe by Motoko Group has been detected as adware by 9 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
InfoHD-V1.8  (signed by Motoko Group)

Product:
HD-V1.9

Description:
HD-V1.9 exe

Version:
1000.1000.1000.1000

MD5:
3750ab6d6c9274d49df0a2b74ae41528

SHA-1:
19d76f95b6ac8423ca944ebb14c85a5972d19541

SHA-256:
89a85b4299a59023680be419fa46ca1383be9c858789193b5f417f91e6491a62

Scanner detections:
9 / 68

Status:
Adware

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage).

Analysis date:
4/26/2024 11:20:18 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Toolbar
2014.08.05

Avira AntiVirus
ADWARE/CrossRider.Gen2
7.11.165.68

AVG
Generic
2015.0.3392

Baidu Antivirus
Trojan.Win32.GoogUpdate
4.0.3.1485

ESET NOD32
Win32/Toolbar.CrossRider.AE potentially unwanted application
7.0.302.0

Kaspersky
Trojan.NSIS.GoogUpdate
14.0.0.3453

Panda Antivirus
Trj/Genetic.gen
14.08.05.07

Reason Heuristics
PUP.Task.MotokoGroup.L
14.7.27.13

VIPRE Antivirus
Threat.4789396
31208

File size:
574.4 KB (588,136 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2016

Original file name:
HD-V1.9.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\hd-v1.9\hd-v1.9-nova.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/18/2014 3:00:00 AM

Valid to:
7/19/2015 2:59:59 AM

Subject:
CN=Motoko Group, O=Motoko Group, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00AAFC4F8011F7FD7C00748C990950D28A

File PE Metadata
Compilation timestamp:
7/22/2014 1:08:46 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:9N67efeerJWBzKT7BU3WyB1NeiqpT9ifEex:HNEBdpmT9CEex

Entry address:
0x442EC

Entry point:
E8, 7A, DF, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, E8, 6C, 47, 00, E8, FE, 4E, 00, 00, E8, 9A, 29, 00, 00, 0F, B7, F0, 6A, 02, E8, 0D, DF, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, D1, 67, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
402.5 KB (412,160 bytes)

Scheduled Task
Task name:
ca9f61e7-52b6-468d-8e67-8d2712eae4a9-7

Trigger:
Logon (Runs on logon)

Action:
hd-v1.9-nova.exe \vmuhvtt='hd-v1.9' \ppaxqaj=60548 \lbdgis='001859'


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.114.233:80)

Remove hd-v1.9-nova.exe - Powered by Reason Core Security