CrossriderApp0028485.exe

SFYC Shopping Reminder

Shop for your Cause LLC

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#28485) SFYC at http://crossrider.com/install/28485. The application CrossriderApp0028485.exe, “SFYC Shopping Reminder Installer” by Shop for your Cause has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
SFYC  (signed by Shop for your Cause LLC)

Product:
SFYC Shopping Reminder

Description:
SFYC Shopping Reminder Installer

Version:
1.34.5.12

MD5:
afeb381d6426db7ff295e1f97ba4ceee

SHA-1:
9f5cae42124434e7f92c60fc5f3e42ce402803be

SHA-256:
f2ec7b0156d2ef7dcb1cad6a1d937f12163b054afbb4e9b385d5762defa8dcb3

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Shop for your Cause LLC.

Analysis date:
8/7/2020 3:25:49 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
infected with Trojan.Crossrider.10029
9.0.1.05190

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Agent
5/22/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3827

Malwarebytes
PUP.Optional.CrossRider
v2014.05.22.01

McAfee
Adware-Crossrider
5600.7122

NANO AntiVirus
Riskware.Win32.Agent.cxphnr
0.28.0.59921

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.ShopforyourCause.U
14.11.20.9

Trend Micro House Call
TROJ_GE.F05D327E
7.2.142

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Threat.4789396
29418

File size:
3.4 MB (3,597,464 bytes)

Copyright:
Copyright SFYC

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0028485.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/3/2013 5:00:00 PM

Valid to:
4/4/2014 4:59:59 PM

Subject:
CN=Shop for your Cause LLC, O=Shop for your Cause LLC, STREET=118b N Bedford Street, L=Arlington, S=VA, PostalCode=22201, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009E1D6EBC5F89B379BD78DC23D859414E

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:lpPenL/O6AY98Ql6WxPwZhdSlKXZzpPnyHuVKWpKSa+ib/:+m1YjpP0hd1ZpPnyOVKYa+A

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9905  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0028485.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/28485/manifest/1_34_5_12/ie9/manifest.xml?ver=15&rnd=5628

Remove CrossriderApp0028485.exe - Powered by Reason Core Security