tmp00000053

Bright circle investments Ltd.

This adware utilizes the Crossrider extension platform and will inject advertisiments in the Internet browser and may modify core browser settings. Ads will be delivered as banners and contextual text-links and may promote other potentially unwanted software. The file tmp00000053 by Bright circle investments has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Plus-HD-V1.5  (signed by Bright circle investments Ltd.)

Product:
Plus-HD-V1.5

Description:
Plus-HD-V1.5 exe

Version:
1000.1000.1000.1000

MD5:
b19347f8218a67cc2bc5321b67df97a7

SHA-1:
f57eeaa6eb457601f000f1b2d1364dfb1b072150

SHA-256:
473d8f769937294003a3bdadb2ca93bfd05b9d6dcddc35bd5b9989c742e922eb

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
7/3/2020 7:49:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.BrightCircle (M)
16.10.21.18

File size:
553.5 KB (566,768 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Plus-HD-V1.5.exe

Language:
English (United States)

Common path:
C:\windows\temp\tmp00005060\tmp00000053

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/19/2014 2:00:00 AM

Valid to:
6/20/2015 1:59:59 AM

Subject:
CN=Bright circle investments Ltd., O=Bright circle investments Ltd., STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EF90FEF9AC8E258E5D30D0E08C84D37E

File PE Metadata
Compilation timestamp:
6/20/2014 12:06:48 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:HHOdXoZY8DFLZfHFcq4Y0piYCBi1tIRNhS/Q6syUY5HyHLC8ypTBn2oFrbNsE:HwoVLPj0p9CUnIRq/QvYteLC8ypTtJtJ

Entry address:
0x492E8

Entry point:
E8, 2A, CB, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, C0, 5F, 48, 00, E8, 02, 4A, 00, 00, E8, 76, 1D, 00, 00, 0F, B7, F0, 6A, 02, E8, BD, CA, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, B0, 87, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
441 KB (451,584 bytes)

Remove tmp00000053 - Powered by Reason Core Security