CrossriderApp0028210.exe

UltiSend

Kinder-Rash Marketing, LLC

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#28210) Troy at http://crossrider.com/install/28210. The application CrossriderApp0028210.exe, “UltiSend Installer” by Kinder-Rash Marketing has been detected as a potentially unwanted program by 13 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Troy  (signed by Kinder-Rash Marketing, LLC)

Product:
UltiSend

Description:
UltiSend Installer

Version:
1.34.5.12

MD5:
dc44325115d687f867339ef1f413ee21

SHA-1:
593fe32fac4d485c68e1db88ebf65ff974f20da0

SHA-256:
1d40e5c997f6b2c372289f67f87017b43c81fae68c8fb4d7474f9ccfdb6eec65

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Kinder-Rash Marketing, LLC.

Analysis date:
11/24/2024 11:30:37 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Dr.Web
infected with Trojan.Crossrider.10029
9.0.1.05190

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Agent
5/22/2014

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3828

Malwarebytes
PUP.Optional.CrossRider
v2014.05.22.08

McAfee
Adware-Crossrider
5600.7123

NANO AntiVirus
Riskware.Win32.Agent.cxphnr
0.28.0.59921

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.KinderRashMarketing.U
14.5.22.8

Trend Micro House Call
TROJ_GE.F05D327E
7.2.142

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Threat.4789396
29418

File size:
3.4 MB (3,609,208 bytes)

Copyright:
Copyright Troy

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0028210.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
7/9/2013 12:36:51 PM

Valid to:
7/9/2014 12:36:51 PM

Subject:
CN="Kinder-Rash Marketing, LLC", O="Kinder-Rash Marketing, LLC", L=Ames, S=Iowa, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EA405C5F57D5A

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:Onh8YCZ7AQn5hS3f++3rk8r4ISLl4vSrkfGUG8UxxsoGWeaEI6CAURtoujhU:KjCZV5hS3yId6AUnsoGWv6Cz3

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9899  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0028210.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/28210/manifest/1_34_5_12/ie9/manifest.xml?ver=15&rnd=5617

Remove CrossriderApp0028210.exe - Powered by Reason Core Security