CrossriderApp0033679.exe

Relog staging

yarin

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#33679) yarin at http://crossrider.com/install/33679. The application CrossriderApp0033679.exe, “Relog staging Installer” has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source.
Publisher:
yarin

Product:
Relog staging

Description:
Relog staging Installer

Version:
1.34.5.29

MD5:
72cd2bb0a36bb98153da1a743fb5b595

SHA-1:
7faf1b874f9a40b16065a2e52f10bf238817fe73

SHA-256:
e4c4d29a4c1525ea89da991b3f21035b8ce2876dee89c4f7b55b2c413126b1b8

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/27/2024 1:47:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Downloader.Installer.U
14.6.9.2

File size:
3.4 MB (3,578,156 bytes)

Copyright:
Copyright yarin

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0033679.exe

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:u4PDGkeeH06VImHd9zG5jyUss92YSMSQHq:JceU6mJCsnNK

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9915  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0033679.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/33679/manifest/1_34_5_29/ie9/manifest.xml?ver=15&rnd=6340

Remove CrossriderApp0033679.exe - Powered by Reason Core Security