CrossriderApp0030325.exe

OSMViewer

Online Sheet Music, Inc.

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#30325) Tim Schroeder at http://crossrider.com/install/30325. As part of the installing of the extensions, Crossrider may offer changes to your Internet browser settings. The application CrossriderApp0030325.exe, “OSMViewer Installer” by Online Sheet Music has been detected as a potentially unwanted program by 13 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Tim Schroeder  (signed by Online Sheet Music, Inc.)

Product:
OSMViewer

Description:
OSMViewer Installer

Version:
1.34.5.12

MD5:
6c91122d8e65509e7c385f414bb009f2

SHA-1:
73d8c892704a286750a0e488ad9aaef8c31ce0aa

SHA-256:
bdeabc08dc486dc166a533ae1a1de62e150af6150ce628d0950af898e53e9931

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Online Sheet Music, Inc..

Analysis date:
7/2/2025 12:21:26 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
infected with Trojan.Crossrider.10029
9.0.1.05190

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Agent
5/26/2014

K7 AntiVirus
Trojan
13.178.12203

Malwarebytes
PUP.Optional.CrossRider
v2014.05.26.09

McAfee
Adware-Crossrider
5600.7118

NANO AntiVirus
Riskware.Win32.Agent.cxphnr
0.28.0.59921

Reason Heuristics
PUP.Installer.OnlineSheetMusic.U
14.5.26.20

Trend Micro House Call
TROJ_GE.F05D327E
7.2.146

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Threat.4789396
29560

File size:
3.4 MB (3,601,040 bytes)

Copyright:
Copyright Tim Schroeder

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0030325.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
10/18/2012 2:26:56 PM

Valid to:
10/20/2013 1:25:53 PM

Subject:
CN="Online Sheet Music, Inc.", OU=OnlineSheetMusic.com, O="Online Sheet Music, Inc.", L=Los Altos, S=CA, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B35E198F2CD82

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:ufS0LNBQd63sZcK3MQK+vU1SOJlHHJqmz5UbxC9/XH7ZFOBKzUaXjEOLr/c656X:8S0YfzMQjU1SOPHHJXz4c3+0xXBVsX

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9889  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0030325.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

TCP (HTTP):
Connects to crossrider.com  (199.83.134.103:80)

 
http://crossrider.com/apps/30325/thank_you_page

Remove CrossriderApp0030325.exe - Powered by Reason Core Security