plushd8.1-bg.exe

plushd8.1

The application plushd8.1-bg.exe has been detected as adware by 4 anti-malware scanners. Part of the Corssrider web browser platform, the BG executable is a background process that manage various function of the installed extensions in user's browser including managing installation, updates and remote code downloads. While running, it connects to the Internet address hwcdn.net on port 80 using the HTTP protocol.
Publisher:
plushd8.1

Product:
plushd8.1

Description:
plushd8.1 exe

Version:
1000.1000.1000.1000

MD5:
93d71b195f306b3a4c9369dc699ba7fa

SHA-1:
c2d07731e0612d1077ee840489a164e6838fa652

SHA-256:
bcbd1a3f6d0f7acfa66750effa8c0f39445711f74bbc787465c0e693927217d3

Scanner detections:
4 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/26/2024 5:10:51 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.CrossRider
4.0.3.14311

ESET NOD32
Win32/Toolbar.CrossRider.AA (variant)
8.9518

Reason Heuristics
PUP.Crossrider.plushd81.L
14.3.11.6

VIPRE Antivirus
Crossrider
27222

File size:
515.5 KB (527,872 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
plushd8.1.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\plushd8.1\plushd8.1-bg.exe

File PE Metadata
Compilation timestamp:
3/6/2014 5:58:44 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:HO32pCBTNxJ/9uM6ENsmUuDd7S5O7rgO1iIg12r349TBsy3qsLov:umpCBTNxJ/4H857OOvTm2r349TZ

Entry address:
0x45FDD

Entry point:
E8, 6D, B1, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, A9, 47, 00, E8, 6D, 01, 00, 00, E8, 0A, 13, 00, 00, 0F, B7, F0, 6A, 02, E8, 00, B1, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, A2, 11, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
400 KB (409,600 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.42:80)

Remove plushd8.1-bg.exe - Powered by Reason Core Security