CrossriderApp0024332.exe

Internet Security Toolbar

VIDYA SOFTWARE DEVELOPMENT LTD

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#24332) vidya at http://crossrider.com/install/24332. The application CrossriderApp0024332.exe, “Internet Security Toolbar Installer” by VIDYA SOFTWARE DEVELOPMENT has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
vidya  (signed by VIDYA SOFTWARE DEVELOPMENT LTD)

Product:
Internet Security Toolbar

Description:
Internet Security Toolbar Installer

Version:
1.34.5.12

MD5:
96240c7b25568552ae08958f6ee3729b

SHA-1:
ff00053b6603c95d6ec9cddfa4d76a8e08727fb6

SHA-256:
122078c93544d53f4926f7e6de704dc03ec4f6f8b8aa72e6a6f62e7aa196e839

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is VIDYA SOFTWARE DEVELOPMENT LTD.

Analysis date:
4/19/2024 10:42:27 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Dr.Web
Trojan.Crossrider.10029
9.0.1.0133

ESET NOD32
Win32/Packed.ScrambleWrapper
8.9794

Fortinet FortiGate
Adware/Agent
5/13/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3871

Malwarebytes
PUP.Optional.CrossRider
v2014.05.13.05

McAfee
Adware-Crossrider
5600.7131

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.VIDYASOFTWAREDEVELOPMENT.U
14.5.13.9

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Crossrider
29170

File size:
3.4 MB (3,570,472 bytes)

Copyright:
Copyright vidya

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0024332.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/20/2013 5:00:00 PM

Valid to:
7/21/2014 4:59:59 PM

Subject:
CN=VIDYA SOFTWARE DEVELOPMENT LTD, O=VIDYA SOFTWARE DEVELOPMENT LTD, STREET=Abba Hillel 7, STREET=Silver Rd., L=Ramat Gan, S=IL, PostalCode=52522, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CDD037DC0129BE08882E186176526714

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:j/jKocefQhAm5Jz7imhUobYRiN1y/lYTs:jYefQV5N7/UMYRiIlqs

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9890  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0024332.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/24332/manifest/1_34_5_12/ie9/manifest.xml?ver=15&rnd=5017

Remove CrossriderApp0024332.exe - Powered by Reason Core Security