CrossriderApp0020900.exe

Ghostery IE

Evidon, Inc.

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#20900) Evidon Inc. at http://crossrider.com/install/20900. The application CrossriderApp0020900.exe, “Ghostery IE Installer” by Evidon has been detected as a potentially unwanted program by 13 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Evidon Inc.  (signed by Evidon, Inc.)

Product:
Ghostery IE

Description:
Ghostery IE Installer

Version:
1.34.4.10

MD5:
4ede14f0dfc53135491aa40b7c53c8c1

SHA-1:
3f47dc15c6159f7dbb1d960ac8168ea2369fe628

SHA-256:
a46c532387ef63e532103d4b5b7c53d4708ade2514643bb4587c8251afbded7e

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Evidon, Inc..

Analysis date:
11/27/2024 9:28:53 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
Trojan.Crossrider.10029
9.0.1.0132

ESET NOD32
Win32/Packed.ScrambleWrapper
8.9787

Fortinet FortiGate
Adware/Agent
5/12/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3879

Malwarebytes
PUP.Optional.CrossRider
v2014.05.12.06

McAfee
Adware-Crossrider
5600.7133

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.Evidon.U
14.5.13.4

Trend Micro House Call
TROJ_GE.F05D327E
7.2.132

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Crossrider
29118

File size:
3.6 MB (3,726,224 bytes)

Copyright:
Copyright Evidon Inc.

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0020900.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/13/2011 5:00:00 PM

Valid to:
3/13/2014 4:59:59 PM

Subject:
CN="Evidon, Inc.", O="Evidon, Inc.", STREET=28 W. 44th St., STREET=Ste. 800, L=New York, S=NY, PostalCode=10036, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00A360D17B416CE4A553A541F18C27640A

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:HcheljSDmKshuwROa07VDnOMexT0vbgHUdL5mmnTu5IJQk4HWeloNTbUO18RZjJp:Qij3AEOd8MexT0vbgHUL5NTGf29RCFEa

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9899  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0020900.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/20900/manifest/1_34_4_10/ie9/manifest.xml?ver=15&rnd=4925

Remove CrossriderApp0020900.exe - Powered by Reason Core Security