color my facebook-codedownloader.exe

Color My Facebook

Safari Developer: (ZMLURJCR77) duvalaugustin@gmail.com

The application color my facebook-codedownloader.exe, “Color My Facebook exe” by Safari Developer: (ZMLURJCR77) duvalaugustin@gmail.com has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. Built using the Crossrider web brower toolkit the CodeDownloader component will automatically connnect to the remote API server and download additional code/components for Duval extension/toolbar. The component makes a number of requests to the host app-static.crossrider.com/plugins/.../monetization/monetizationLoader.js.
Publisher:
Duval  (signed by Safari Developer: (ZMLURJCR77) duvalaugustin@gmail.com)

Product:
Color My Facebook

Description:
Color My Facebook exe

Version:
1000.1000.1000.1000

MD5:
4aba8c47559aabaf6e8f4a3aaa3582fe

SHA-1:
3237a56e8a2daa65360e2199024242cc9e8accda

SHA-256:
53dc4dea5b02287ee5ac03b05079b0dee5a17d2d272f5c2c7b00c565949ee19d

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Safari Developer: (ZMLURJCR77) duvalaugustin@gmail.com.

Analysis date:
4/20/2024 2:00:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider (M)
17.1.25.18

File size:
478.1 KB (489,560 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Color My Facebook.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\color my facebook\color my facebook-codedownloader.exe

Digital Signature
Authority:
Apple Inc.

Valid from:
7/16/2012 4:25:00 AM

Valid to:
7/16/2013 4:25:00 AM

Subject:
C=FR, CN=Safari Developer: (ZMLURJCR77) duvalaugustin@gmail.com, OID.0.9.2342.19200300.100.1.1=3MV9W8EA58

Issuer:
CN=Apple Worldwide Developer Relations Certification Authority, OU=Apple Worldwide Developer Relations, O=Apple Inc., C=US

Serial number:
24A43EE61F285A43

File PE Metadata
Compilation timestamp:
8/12/2013 5:43:01 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x45249

Entry point:
E8, FA, B4, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 10, F7, F1, 8B, D3, EB, 41, 8B, D8, 8B, 4C, 24, 18, 8B, 54, 24, 14, 8B, 44, 24, 10, D1, EB...
 
[+]

Entropy:
6.5127

Code size:
382 KB (391,168 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.srvstatsdata.com  (69.16.175.42:80)

 
http://update.srvstatsdata.com/installer_updates/006195/update.json

TCP (HTTP):
Connects to stats.srvstatsdata.com  (176.32.99.41:80)

TCP (HTTP):
Connects to app-static.crossrider.com  (69.16.175.10:80)

Remove color my facebook-codedownloader.exe - Powered by Reason Core Security