CrossriderApp0023916.exe

CloudLoad

Webedge Advertising Corporation

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#23916) alex at http://crossrider.com/install/23916. The application CrossriderApp0023916.exe, “CloudLoad Installer” by Webedge Advertising has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer.
Publisher:
alex  (signed by Webedge Advertising Corporation)

Product:
CloudLoad

Description:
CloudLoad Installer

Version:
1.34.5.12

MD5:
0d8ac35c26c694420669cee1e7750077

SHA-1:
d933b937bfb72dcc6f6798ebca6ee64337cf6a9d

SHA-256:
cedac11a2868c819f932eb917b99240b1f9b0af7b273ac251256789b29651bea

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Webedge Advertising Corporation.

Analysis date:
11/24/2024 10:25:48 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.WebedgeAdvertisingCorporation.U
14.5.13.6

File size:
3.4 MB (3,583,792 bytes)

Copyright:
Copyright alex

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0023916.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/18/2013 4:00:00 PM

Valid to:
2/19/2015 3:59:59 PM

Subject:
CN=Webedge Advertising Corporation, O=Webedge Advertising Corporation, STREET="18 Place Triad #200", L=Pointe-claire, S=Quebec, PostalCode=h9r0a2, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1C229D17E12AF493353933D23C1F7D96

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:XCqje9zBj+xlFeU+xVxR4eSQ+eb59CC0vZ0D86pld2nrRRSnshrfQcNkkFEoLlUK:SpfQlI7HR0QCM3pi7MsRIceoLHOW

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9885  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0023916.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/23916/manifest/1_34_5_12/ie9/manifest.xml?ver=15&rnd=4999

Remove CrossriderApp0023916.exe - Powered by Reason Core Security