CrossriderApp0021728.exe

Shop-Engel

Inphorms GmbH

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#21728) Schulengel.de at http://crossrider.com/install/21728. The application CrossriderApp0021728.exe, “Shop-Engel Installer” by Inphorms GmbH has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Schulengel.de  (signed by Inphorms GmbH)

Product:
Shop-Engel

Description:
Shop-Engel Installer

Version:
1.34.4.10

MD5:
03d5e22513ec73a160ea278d61d21c72

SHA-1:
45cf80968d797b6b13fa61f157ba6ac9395b9349

SHA-256:
942231cc26a23c431eb25028f9a588dedeba94ca8a0772c98a9d6078bd74b27d

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Inphorms GmbH.

Analysis date:
6/20/2018 6:45:37 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/Win32.Agent
0.1.0.1

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
Trojan.Crossrider.10029
9.0.1.0132

ESET NOD32
Win32/Packed.ScrambleWrapper
8.9789

Fortinet FortiGate
Adware/Agent
5/12/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3877

Malwarebytes
PUP.Optional.ShopEngel.A
v2014.05.12.01

McAfee
Adware-Crossrider
5600.7132

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.InphormsGmbH.U
14.5.13.2

Trend Micro House Call
TROJ_GE.F05D327E
7.2.132

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Crossrider
29128

File size:
3.5 MB (3,680,920 bytes)

Copyright:
Copyright Schulengel.de

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0021728.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/19/2012 4:00:00 PM

Valid to:
12/20/2013 3:59:59 PM

Subject:
CN=Inphorms GmbH, O=Inphorms GmbH, STREET=Ackerstraße 76, L=Berlin, S=Deutschland, PostalCode=13355, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E41D9B4807DCA5D89E7DE79E1152E632

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:ic2Ljtn1PwzjKU5NACdpPJmaiib+vzpP43NKdIrzk50:ELj9KzHldHExl44doI50

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9905  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0021728.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/21728/manifest/1_34_4_10/ie9/manifest.xml?ver=15&rnd=4937

Remove CrossriderApp0021728.exe - Powered by Reason Core Security