CrossriderApp0033678.exe

Relog

yarin

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#33678) yarin at http://crossrider.com/install/33678. As part of the installing of the extensions, Crossrider may offer changes to your Internet browser settings. The application CrossriderApp0033678.exe has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
yarin

Product:
Relog

Description:
Relog Installer

Version:
1.34.5.29

MD5:
15078ab75cf32bdebf386a83eabf73a6

SHA-1:
1a1a35f04ce189ccfe605164a3e16d67424385a0

SHA-256:
2656a1baf94edf8f4df4622efd68c979c1d47b48c25c1d52e439a91d746b0e60

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
5/10/2024 11:51:51 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Bkav FE
HW32.CDB
1.3.0.4959

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Malwarebytes
v2014.06.09.03

McAfee
Adware-Crossrider
5600.7105

Reason Heuristics
PUP.Downloader.Installer.U
14.6.9.2

VIPRE Antivirus
Threat.4789396
30086

File size:
3.4 MB (3,567,582 bytes)

Copyright:
Copyright yarin

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0033678.exe

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:c4TT34AhzEZWH3dTblrEDfS7T9QucTBFfoPe7QXSCutn/2weogzoVEJl3suIWe:JT34yiKhr4K7TFYgzSRn/1eoAGq8uIT

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9914  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0033678.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

TCP (HTTP):
Connects to crossrider.com  (199.83.134.103:80)

 
http://crossrider.com/apps/33678/thank_you_page

Remove CrossriderApp0033678.exe - Powered by Reason Core Security