uhnpvdbgokmqp.exe

CinemaPlus-3.2cV08.06

Digit Network (Extreme White Limited)

The application uhnpvdbgokmqp.exe, “CinemaPlus-3.2cV08.06 Installer” by Digit Network (Extreme White Limited) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address tlb.hwcdn.net on port 80 using the HTTP protocol.
Publisher:
Cinema PlusV08.06  (signed by Digit Network (Extreme White Limited))

Product:
CinemaPlus-3.2cV08.06

Description:
CinemaPlus-3.2cV08.06 Installer

Version:
1.36.01.22

MD5:
9d943284eabe3087eeaddbde4115cf24

SHA-1:
3b1d255de93c703a6a60df5f0f532c9744f8e088

SHA-256:
d0e2c500144defb74b5a20994b5523d83f6e7dd30750c53975178e92f7e4066c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/24/2024 3:44:27 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ExtremeWhite.Installer
15.6.9.4

File size:
13.2 MB (13,890,840 bytes)

Copyright:
Copyright Cinema PlusV08.06

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\uhnpvdbgokmqp.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/14/2015 5:00:00 PM

Valid to:
4/14/2016 4:59:59 PM

Subject:
CN=Digit Network (Extreme White Limited), O=Digit Network (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F39F5E5096779B72822CF8381166A432

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
393216:8zG7kPfirip530bhL4rr59AxujcNz21gLIJ:8zG7kSrC530dLEixujckgLs

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9993  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.10:80)

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.0.228:80)

TCP (HTTP):
Connects to ec2-54-235-114-210.compute-1.amazonaws.com  (54.235.114.210:80)

Remove uhnpvdbgokmqp.exe - Powered by Reason Core Security