CrossriderApp0029481.exe

Mein Gutscheincode

Mein Gutscheincode GmbH

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#29481) Mein Gutscheincode GmbH at http://crossrider.com/install/29481. The application CrossriderApp0029481.exe, “Mein Gutscheincode Installer” by Mein Gutscheincode GmbH has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Mein Gutscheincode GmbH  (signed and verified)

Product:
Mein Gutscheincode

Description:
Mein Gutscheincode Installer

Version:
1.34.5.12

MD5:
2c574666228951cfe53028f71dcabfb2

SHA-1:
5dc5fd1cfd8514d09530708cc2168cd276b18b65

SHA-256:
6336fb5c1aeaea186c3eaa60581ae03c4c5a3de56f3cc70f985e586371e6bb45

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Mein Gutscheincode GmbH.

Analysis date:
4/23/2024 7:38:42 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Dr.Web
infected with Trojan.Crossrider.10029
9.0.1.05190

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Agent
5/23/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3824

Malwarebytes
PUP.Optional.MeinGutscheincode.A
v2014.05.23.05

McAfee
Adware-Crossrider
5600.7122

NANO AntiVirus
Riskware.Win32.Agent.cxphnr
0.28.0.59921

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.MeinGutscheincodeGmbH.U
14.7.17.10

Trend Micro House Call
TROJ_GE.F05D327E
7.2.143

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Threat.4789396
29418

File size:
3.4 MB (3,574,272 bytes)

Copyright:
Copyright Mein Gutscheincode GmbH

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0029481.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/24/2013 5:00:00 PM

Valid to:
3/25/2015 4:59:59 PM

Subject:
CN=Mein Gutscheincode GmbH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mein Gutscheincode GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6DC967C1E9C4DBE86E88DB14D51147D4

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:G8foswU7XUXa/MFnZake5sXjY+XRYlaWjceSItz1CVHrfJzaLEq9T7S+vbO:1foLaXUoEa15sXsEkJSOZmLBzvqdvbO

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9896  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0029481.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/29481/manifest/1_34_5_12/ie9/manifest.xml?ver=15&rnd=5669

Remove CrossriderApp0029481.exe - Powered by Reason Core Security