CrossriderApp0016150.exe

DKB-Cashback

Deutsche Kreditbank Aktiengesellschaft

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#16150) dkbbrowserextension at http://crossrider.com/install/16150. As part of the installing of the extensions, Crossrider may offer changes to your Internet browser settings. The application CrossriderApp0016150.exe, “DKB-Cashback Installer” by Deutsche Kreditbank Aktiengesellschaft has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
dkbbrowserextension  (signed by Deutsche Kreditbank Aktiengesellschaft)

Product:
DKB-Cashback

Description:
DKB-Cashback Installer

Version:
1.34.4.10

MD5:
5b8ed4ec65619766a24091226a08113e

SHA-1:
58d8d7fcb73973679333f80c695d03e174b53e86

SHA-256:
44e10faa969bb335d89980994aca9bb42f46fd77a519ce0fb364793a25c3243c

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Deutsche Kreditbank Aktiengesellschaft.

Analysis date:
7/7/2020 9:32:42 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Dr.Web
Trojan.Crossrider.10029
9.0.1.0130

ESET NOD32
Win32/Packed.ScrambleWrapper
8.9783

Fortinet FortiGate
Adware/Agent
5/10/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3886

Malwarebytes
PUP.Optional.CrossRider
v2014.05.10.07

McAfee
Adware-Crossrider
5600.7134

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.DeutscheKreditbankAktiengesellschaft.U
14.7.17.10

Trend Micro House Call
TROJ_GE.F05D327E
7.2.130

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Crossrider
29066

File size:
3.5 MB (3,672,992 bytes)

Copyright:
Copyright dkbbrowserextension

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0016150.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/1/2012 5:00:00 PM

Valid to:
11/2/2014 3:59:59 PM

Subject:
CN=Deutsche Kreditbank Aktiengesellschaft, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Deutsche Kreditbank Aktiengesellschaft, L=Berlin, S=Berlin, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4264838238A7BFA682EE90E7AFFF1D32

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:2TnYnChlmeCuh15i9UQrzAchkwTAtIHDzCMXCvmmZRjuagq:4n8QmJIynzglMyXbCS

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9906  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0016150.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

TCP (HTTP):
Connects to crossrider.com  (199.83.134.103:80)

 
http://crossrider.com/apps/16150/thank_you_page

Remove CrossriderApp0016150.exe - Powered by Reason Core Security