CrossriderApp0031023.exe

BigLoot staging

BeeStripe LLC

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#31023) bstp at http://crossrider.com/install/31023. The application CrossriderApp0031023.exe, “BigLoot staging Installer” by BeeStripe has been detected as a potentially unwanted program by 16 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
bstp  (signed by BeeStripe LLC)

Product:
BigLoot staging

Description:
BigLoot staging Installer

Version:
1.34.5.12

MD5:
5b1a95c7d845f9d25197ea9181ce3120

SHA-1:
07eae20b0218b08a8fb8944a6d5b4ddc942b621f

SHA-256:
b07ddb9a31f9ee2cbb61cd7ce9c2616c5d99a45ec8b7eee2c9e9d983cc23b228

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is BeeStripe LLC.

Analysis date:
4/24/2024 11:48:31 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
infected with Trojan.Crossrider.10029
9.0.1.05190

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Agent
5/27/2014

K7 AntiVirus
Trojan
13.178.12212

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3803

Malwarebytes
PUP.Optional.CrossRider
v2014.05.27.07

McAfee
Adware-Crossrider
5600.7118

NANO AntiVirus
Riskware.Win32.Agent.cxphnr
0.28.0.59921

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.BeeStripe.U
14.5.27.7

Sophos
Generic PUA HI
4.98

Trend Micro House Call
TROJ_GE.F05D327E
7.2.147

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Threat.4789396
29560

File size:
3.4 MB (3,598,496 bytes)

Copyright:
Copyright bstp

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0031023.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
4/26/2013 8:15:14 PM

Valid to:
4/26/2014 8:15:14 PM

Subject:
CN=BeeStripe LLC, O=BeeStripe LLC, L=Honolulu, S=HI, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2802B3C5D8C636

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:qmX41AvnkKjKD4QNv4Vwy3Rs5HiKW4zdSg:qmXMZKjKFRubhsliV45Sg

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9887  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0031023.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/31023/manifest/1_34_5_12/ie9/manifest.xml?ver=15&rnd=5847

Remove CrossriderApp0031023.exe - Powered by Reason Core Security