avgb0e9.exe

The application avgb0e9.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup program which is used to install the application. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. The file has been seen being downloaded from dwmastpozz77a.cloudfront.net.
MD5:
5e41347007d012bedda29c42294074ad

SHA-1:
9bc169251b5332ca775b1940592c58685948ddd8

SHA-256:
a48d395bed58b929782877c9e94bb183bf73d865481e67894603b27db54a1679

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/27/2024 4:43:24 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Crossrider1.56918
9.0.1.05190

Reason Heuristics
Adware.Crossrider (M)
16.8.2.0

File size:
314 KB (321,536 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\avgb0e9.exe

File PE Metadata
Compilation timestamp:
12/7/2015 12:41:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:+WFZT8qbTR7SvuD4L8vioH/X8i9DLnHWcefjVo8bS5VBixFlL5:RZwgV4Gq86oH/MKvnolggXB5

Entry address:
0x4F42E

Entry point:
6D, 6C, 20, 76, 65, 72, 73, 69, 6F, 6E, 3D, 22, 31, 2E, 30, 22, 20, 65, 6E, 63, 6F, 64, 69, 6E, 67, 3D, 22, 75, 74, 66, 2D, 38, 22, 3F, 3E, 0D, 0A, 3C, 61, 73, 6D, 76, 31, 3A, 61, 73, 73, 65, 6D, 62, 6C, 79, 20, 6D, 61, 6E, 69, 66, 65, 73, 74, 56, 65, 72, 73, 69, 6F, 6E, 3D, 22, 31, 2E, 30, 22, 20, 78, 6D, 6C, 6E, 73, 3D, 22, 75, 72, 6E, 3A, 73, 63, 68, 65, 6D, 61, 73, 2D, 6D, 69, 63, 72, 6F, 73, 6F, 66, 74, 2D, 63, 6F, 6D, 3A, 61, 73, 6D, 2E, 76, 31, 22, 20, 78, 6D, 6C, 6E, 73, 3A, 61, 73, 6D, 76, 31, 3D...
 
[+]

Code size:
309.5 KB (316,928 bytes)

The file avgb0e9.exe has been seen being distributed by the following URL.

Remove avgb0e9.exe - Powered by Reason Core Security