CrossriderApp0023917.exe

CloudLoad staging

Webedge Advertising Corporation

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#23917) alex at http://crossrider.com/install/23917. As part of the installing of the extensions, Crossrider may offer changes to your Internet browser settings. The application CrossriderApp0023917.exe, “CloudLoad staging Installer” by Webedge Advertising has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer.
Publisher:
alex  (signed by Webedge Advertising Corporation)

Product:
CloudLoad staging

Description:
CloudLoad staging Installer

Version:
1.34.5.12

MD5:
fec17eaef5a11dbe9b9606e9f5a1fb1b

SHA-1:
65cb9e2508be904c6ea5ffdb9d4b11a59c22e4fa

SHA-256:
bbd0c2e5c6b19cb69e71054d3185c8951920a5b25a2a24de4881f4d9f6b65649

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Webedge Advertising Corporation.

Analysis date:
2/26/2025 8:35:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.WebedgeAdvertisingCorporation.U
14.5.13.6

File size:
3.4 MB (3,577,576 bytes)

Copyright:
Copyright alex

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0023917.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/18/2013 4:00:00 PM

Valid to:
2/19/2015 3:59:59 PM

Subject:
CN=Webedge Advertising Corporation, O=Webedge Advertising Corporation, STREET="18 Place Triad #200", L=Pointe-claire, S=Quebec, PostalCode=h9r0a2, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1C229D17E12AF493353933D23C1F7D96

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:AZhp+mi7yjQgL3aaaNbKeIbf7r/zyCLj1:AZXGejXLavIbf7rLyCn1

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9883  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0023917.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

TCP (HTTP):
Connects to crossrider.com  (199.83.134.103:80)

 
http://crossrider.com/apps/23917/thank_you_page

Remove CrossriderApp0023917.exe - Powered by Reason Core Security