CrossriderApp0016507.exe

TipRanks staging

TipRanks LTD

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#16507) TipRanks at http://crossrider.com/install/16507. The application CrossriderApp0016507.exe, “TipRanks staging Installer” by TipRanks has been detected as a potentially unwanted program by 13 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
TipRanks  (signed by TipRanks LTD)

Product:
TipRanks staging

Description:
TipRanks staging Installer

Version:
1.34.4.10

MD5:
d3174bbcb915fc9f01af32805012cadb

SHA-1:
c61661b9911f3398f1d91a94bf39ab4411c8987b

SHA-256:
030f70f7933c27e664d68a4cd9226f7713e8c153231dbe5ff845face122dd115

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is TipRanks LTD.

Analysis date:
4/19/2024 5:39:01 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
Trojan.Crossrider.10029
9.0.1.0130

ESET NOD32
Win32/Packed.ScrambleWrapper
8.9783

Fortinet FortiGate
Adware/Agent
5/10/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3885

Malwarebytes
PUP.Optional.TipRanks.A
v2014.05.10.11

McAfee
Adware-Crossrider
5600.7134

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.TipRanks.U
14.5.13.7

Trend Micro House Call
TROJ_GE.F05D327E
7.2.130

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Crossrider
29078

File size:
3.5 MB (3,682,120 bytes)

Copyright:
Copyright TipRanks

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0016507.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/24/2012 4:00:00 PM

Valid to:
12/25/2013 3:59:59 PM

Subject:
CN=TipRanks LTD, O=TipRanks LTD, STREET=27 Ahad Haam, L=Tel Aviv-Jaffa, S=Israel, PostalCode=65202, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
34B940819341EC8E12BDF055769AB0E5

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:xRx+AFG/WAQdKUt1CYp+H+WXCiN+CvYuqER6P:xXZFGO5tEYp+nxCuqOC

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9909  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0016507.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/16507/manifest/1_34_4_10/ie9/manifest.xml?ver=15&rnd=4889

Remove CrossriderApp0016507.exe - Powered by Reason Core Security