CrossriderApp0051984.exe

MD5:
6192250c2096f6cc449bf6709580d74f

SHA-1:
fe823ec3a246c4d8a493f48e1d3a7bc492efb06e

SHA-256:
fc7f8624d676a88b3d2ea7c8ca83d2a37791f29dceeba764b2173c099565b389

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
8/11/2020 3:51:44 PM UTC  (today)

Scan engine
Detection
Engine version

nProtect
Trojan.Script.604972
14.07.04.01

File size:
1.2 KB (1,240 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\crossriderapp0051984.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
24:hMNmwHkMxC3vPDi9aQj143vPDi9aQjxXtR/g6R:ImOxU29aH29aUVT

Entry point:
3C, 21, 44, 4F, 43, 54, 59, 50, 45, 20, 68, 74, 6D, 6C, 20, 50, 55, 42, 4C, 49, 43, 20, 22, 2D, 2F, 2F, 57, 33, 43, 2F, 2F, 44, 54, 44, 20, 58, 48, 54, 4D, 4C, 20, 31, 2E, 30, 20, 54, 72, 61, 6E, 73, 69, 74, 69, 6F, 6E, 61, 6C, 2F, 2F, 45, 4E, 22, 20, 22, 68, 74, 74, 70, 3A, 2F, 2F, 77, 77, 77, 2E, 77, 33, 2E, 6F, 72, 67, 2F, 54, 52, 2F, 78, 68, 74, 6D, 6C, 31, 2F, 44, 54, 44, 2F, 78, 68, 74, 6D, 6C, 31, 2D, 74, 72, 61, 6E, 73, 69, 74, 69, 6F, 6E, 61, 6C, 2E, 64, 74, 64, 22, 3E, 3C, 68, 74, 6D, 6C, 3E, 3C...
 
[+]

Entropy:
5.5332

The file CrossriderApp0051984.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/51984/manifest//ie9/manifest.xml?ver=15&rnd=7386

Scan CrossriderApp0051984.exe - Powered by Reason Core Security