CrossriderApp0022734.exe

Senddr

Senddr Software Limited

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#22734) Morgan Lynch at http://crossrider.com/install/22734. As part of the installing of the extensions, Crossrider may offer changes to your Internet browser settings. The application CrossriderApp0022734.exe by Senddr Software Limited has been detected as a potentially unwanted program by 13 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Morgan Lynch  (signed by Senddr Software Limited)

Product:
Senddr

Description:
Senddr Installer

Version:
1.34.4.10

MD5:
b0c0d8c618c689ecd90f3bc73593b492

SHA-1:
f3cf3ea613d6cd69bdac1114a831c05e0b0247e1

SHA-256:
4acc4ddcc3a2c633f657f69d1f582516e019441c64bc6b789531d19bb858d1b5

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Senddr Software Limited.

Analysis date:
4/23/2024 11:16:23 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
Trojan.Crossrider.10029
9.0.1.0133

ESET NOD32
Win32/Packed.ScrambleWrapper
8.9791

Fortinet FortiGate
Adware/Agent
5/13/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3875

Malwarebytes
PUP.Optional.CrossRider
v2014.05.13.12

McAfee
Adware-Crossrider
5600.7132

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.SenddrSoftwareLimited.U
14.5.13.7

Trend Micro House Call
TROJ_GE.F05D327E
7.2.133

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Crossrider
29146

File size:
3.5 MB (3,658,528 bytes)

Copyright:
Copyright Morgan Lynch

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0022734.exe

Digital Signature
Authority:
Senddr Software Limited

Valid from:
2/15/2013 2:28:19 AM

Valid to:
2/13/2023 2:28:19 AM

Subject:
E=info@senddr.com, CN=secure.senddr.com, OU=Senddr Software Limited, O=Senddr Software Limited, L=Dublin, S=Dublin, C=IE

Issuer:
E=info@senddr.com, CN=secure.senddr.com, OU=Senddr Software Limited, O=Senddr Software Limited, L=Dublin, S=Dublin, C=IE

Serial number:
00EEEBE9F3CAAAEF97

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:8SDo8KkzuWAmN9md+x47mBp1yWfQYv5J7:Zo8Kkz5AKe1iT/B5

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9897  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0022734.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

TCP (HTTP):
Connects to crossrider.com  (199.83.134.103:80)

 
http://crossrider.com/apps/22734/thank_you_page

Remove CrossriderApp0022734.exe - Powered by Reason Core Security