CrossriderApp0030493.exe

FatCatArcade

Xori Tech Ltd.

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#30493) alon at http://crossrider.com/install/30493. The application CrossriderApp0030493.exe, “FatCatArcade Installer” by Xori Tech has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
alon  (signed by Xori Tech Ltd.)

Product:
FatCatArcade

Description:
FatCatArcade Installer

Version:
1.34.5.12

MD5:
2643b118e75ac4ad0bcb3cc9918513a4

SHA-1:
1c53eb5f2585204ade70e2d4c57e0199b2cbfd5a

SHA-256:
cfac7367a7616898533065f112084c5382f95ea56143cca3f33bd4eb38ee0e33

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Xori Tech Ltd..

Analysis date:
4/26/2024 7:04:13 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Dr.Web
infected with Trojan.Crossrider.10029
9.0.1.05190

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Agent
5/26/2014

K7 AntiVirus
Trojan
13.178.12203

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3805

Malwarebytes
PUP.Optional.CrossRider
v2014.05.26.11

McAfee
Adware-Crossrider
5600.7118

NANO AntiVirus
Riskware.Win32.Agent.cxphnr
0.28.0.59921

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.XoriTech.U
14.5.26.23

Sophos
Generic PUA HI
4.98

Trend Micro House Call
TROJ_GE.F05D327E
7.2.146

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

File size:
7.2 MB (7,543,464 bytes)

Copyright:
Copyright alon

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0030493.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/2/2013 5:00:00 PM

Valid to:
9/3/2014 4:59:59 PM

Subject:
CN=Xori Tech Ltd., O=Xori Tech Ltd., POBox=61570, STREET=Itzhak Sade 28, L=Tel Aviv, S=Israel, PostalCode=67212, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008CCDB1868B45FF0B1800CE93D0A44C1B

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
196608:4XS0kzqzW30MD6atWAZTsPZMcG9SyKyESZY0hgHAa4iJo:R0MqOD6DZG9EsY0h7Ao

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9971  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0030493.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/30493/manifest/1_34_5_12/ie9/manifest.xml?ver=15&rnd=5832

Remove CrossriderApp0030493.exe - Powered by Reason Core Security