CrossriderApp0024829.exe

INSZoom Visa Stat staging

INSZoom.com Inc

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#24829) INSZoom at http://crossrider.com/install/24829. As part of the installing of the extensions, Crossrider may offer changes to your Internet browser settings. The application CrossriderApp0024829.exe, “INSZoom Visa Stat staging Installer” by INSZoom.com Inc has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
INSZoom  (signed by INSZoom.com Inc)

Product:
INSZoom Visa Stat staging

Description:
INSZoom Visa Stat staging Installer

Version:
1.34.5.12

MD5:
409e4e78eeb0a5b558e982b806fa76b9

SHA-1:
bfecdf1e52463043277e0809de41696d61ea9f36

SHA-256:
ff4b7f1a7b607154be8639ecefcb7360e32295692c60c78efdfc7de8663716c5

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is INSZoom.com Inc.

Analysis date:
8/7/2020 2:19:45 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
infected with Trojan.Crossrider.10029
9.0.1.05190

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3834

Malwarebytes
PUP.Optional.CrossRider
v2014.05.21.06

McAfee
Adware-Crossrider
5600.7124

NANO AntiVirus
Riskware.Win32.Agent.cxphnr
0.28.0.59921

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.INSZoom.U
14.12.4.0

Trend Micro House Call
TROJ_GE.F05D327E
7.2.141

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Threat.4789396
29418

File size:
3.4 MB (3,571,112 bytes)

Copyright:
Copyright INSZoom

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0024829.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/1/2012 5:00:00 PM

Valid to:
6/28/2013 4:59:59 PM

Subject:
CN=INSZoom.com Inc, OU=IT Infrastructure / Security, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=INSZoom.com Inc, L=San Ramon, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5082FE068F6C3EAEE70CC3D9355D2677

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:4QnMhpdyt8NXBzz2H+7VhaQL0euGdlOHqgQRnjNZrRL6JZ2/pGrZqImtT0oqswhI:jSytkUexEzGGKJRnjNRVgghGdqImGJyb

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9900  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0024829.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

TCP (HTTP):
Connects to crossrider.com  (199.83.134.103:80)

 
http://crossrider.com/apps/24829/thank_you_page

Remove CrossriderApp0024829.exe - Powered by Reason Core Security