Newtonsoft.Json.dll

Json.NET

Hike Zone Plus

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. Newtonsoft.Json.dll is the assembly provides support for JSON parsing for .NET applications and is recompiled by Hike Zone Plus. The module Newtonsoft.Json.dll, “Json.NET .NET 2.0” by Hike Zone Plus has been detected as adware by 7 anti-malware scanners. The library is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. Although a detection has been made for this resource, it is generally a commonly distributed 3rd-party library and is typically safe by itself. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Newtonsoft  (signed by Hike Zone Plus)

Product:
Json.NET

Description:
Json.NET .NET 2.0

Version:
6.0.3.17227

MD5:
8883f8c21ade65b9cd333bbc82c0e730

SHA-1:
bad7d08627fb04825d564ce57db74c213d23a34e

SHA-256:
d976c9116df26ca1b9ceed16403a081a97f78ba859b7e107d2b68e0443cbefb3

Scanner detections:
7 / 68

Status:
Adware

Explanation:
This is the assembly provides support for JSON parsing for .NET applications. While the file itself is not dangerous, it is part of a program that has been detected.

Analysis date:
4/26/2024 3:37:03 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Crossrider-Z [PUP]
2014.9-141022

AVG
Generic
2015.0.3313

Kaspersky
Trojan.NSIS.GoogUpdate
14.0.0.3062

nProtect
Trojan-Clicker/W32.Agent.495512
14.10.12.01

Panda Antivirus
Trj/Chgt.I
14.10.22.03

Qihoo 360 Security
Win32/Trojan.93d
1.0.0.1015

Reason Heuristics
Common.PUP.HikeZonePlus.O
14.10.22.15

File size:
483.9 KB (495,512 bytes)

Product version:
6.0.3.17227

Copyright:
Copyright © James Newton-King 2008

Original file name:
Newtonsoft.Json.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\hd01-v2.1v25.09\newtonsoft.json.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Subject:
CN=Hike Zone Plus, O=Hike Zone Plus, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7DF4D8EF200BAB292519E3CF5597AD86

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:U14RIXwj5Ga4BztxXRKSPJtvKlJ3EQo5WyscPcDT:UK4JzlvEEQo5WyscPY

Entry address:
0x7930E

Entry point:
FF, 25, 00, 20, 00, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8777

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
477 KB (488,448 bytes)

Remove Newtonsoft.Json.dll - Powered by Reason Core Security