CrossriderApp0030528.exe

IntelliConne staging 8940

Wolters Kluwer U.S Corporation

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#30528) CCH Tax and Accounting at http://crossrider.com/install/30528. The application CrossriderApp0030528.exe, “IntelliConne staging 8940 Installer” by Wolters Kluwer U.S has been detected as a potentially unwanted program by 15 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
CCH Tax and Accounting  (signed by Wolters Kluwer U.S Corporation)

Product:
IntelliConne staging 8940

Description:
IntelliConne staging 8940 Installer

Version:
1.34.5.12

MD5:
29c7f070bf756981d498a60379cc89b1

SHA-1:
37e026b53e720ba243a4bc6c93090771647eb2a4

SHA-256:
587b20e1d84d99bcef9b617461945bb8d13401fd7eea68dc4b6e05104495bb8f

Scanner detections:
15 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Wolters Kluwer U.S Corporation.

Analysis date:
11/24/2024 9:46:25 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Dr.Web
infected with Trojan.Crossrider.10029
9.0.1.05190

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Agent
5/27/2014

K7 AntiVirus
Trojan
13.178.12203

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3805

Malwarebytes
PUP.Optional.CrossRider
v2014.05.27.12

McAfee
Adware-Crossrider
5600.7118

NANO AntiVirus
Riskware.Win32.Agent.cxphnr
0.28.0.59921

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.WoltersKluwerUSCorporation.U
14.5.26.23

Sophos
Generic PUA HI
4.98

Trend Micro House Call
TROJ_GE.F05D327E
7.2.147

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Threat.4789396
29560

File size:
3.4 MB (3,598,712 bytes)

Copyright:
Copyright CCH Tax and Accounting

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0030528.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/20/2011 5:00:00 PM

Valid to:
10/1/2014 4:59:59 PM

Subject:
CN=Wolters Kluwer U.S Corporation, OU=CCH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wolters Kluwer U.S Corporation, L=Cedar Rapids, S=Iowa, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2F9E53FA481802756658FD00E69311B0

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:9wRy5kTg/5WFvMtq+j4epaRzLmi9lNlihkG:d4yq+j4ep2ugrG

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9903  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0030528.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/30528/manifest/1_34_5_12/ie9/manifest.xml?ver=15&rnd=5833

Remove CrossriderApp0030528.exe - Powered by Reason Core Security