CrossriderApp0017472.exe

BrowseReport

Browse Report LLC

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#17472) BrowseReport LLC. at http://crossrider.com/install/17472. The application CrossriderApp0017472.exe, “BrowseReport Installer” by Browse Report has been detected as a potentially unwanted program by 12 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
BrowseReport LLC.  (signed by Browse Report LLC)

Product:
BrowseReport

Description:
BrowseReport Installer

Version:
1.34.4.10

MD5:
8f8bc7ce5249e2f6a6051ae96564902b

SHA-1:
7c5e9a7d2e90513797fe983c07b61e68967d204d

SHA-256:
9932a04b134781f902bdfdf90fca0b558fbbb65eee2311467a7ff82549c01152

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Browse Report LLC.

Analysis date:
11/24/2024 9:55:29 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Dr.Web
Trojan.Crossrider.10029
9.0.1.0131

ESET NOD32
Win32/Packed.ScrambleWrapper
8.9784

Fortinet FortiGate
Adware/Agent
5/11/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3884

Malwarebytes
PUP.Optional.CrossRider
v2014.05.11.07

McAfee
Adware-Crossrider
5600.7134

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.BrowseReport.U
14.5.13.6

Trend Micro House Call
TROJ_GE.F05D327E
7.2.131

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Crossrider
29082

File size:
3.5 MB (3,691,528 bytes)

Copyright:
Copyright BrowseReport LLC.

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0017472.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/20/2014 4:00:00 PM

Valid to:
1/21/2015 3:59:59 PM

Subject:
CN=Browse Report LLC, O=Browse Report LLC, STREET=28908 6th Ave. S., L=Federal Way, S=Washington, PostalCode=98003, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00820B1611A72A1127BDC3B725184A575A

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:RTDpXBgUFnW0iO3va9LAvp0/xQDSAn3t6zU:R/eiPQiDSc6Q

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9892  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0017472.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/17472/manifest/1_34_4_10/ie9/manifest.xml?ver=15&rnd=4897

Remove CrossriderApp0017472.exe - Powered by Reason Core Security