CrossriderApp0033327.exe

Ford Racing Plug- staging

Wunderman pxp GmbH

This is the Crossrider web browser extension installer that contains the files for installing a plugin for IE, Chrome and Firefox. It was built by developer (#33327) DerSchwede at http://crossrider.com/install/33327. The application CrossriderApp0033327.exe, “Ford Racing Plug- staging Installer” by Wunderman pxp GmbH has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
DerSchwede  (signed by Wunderman pxp GmbH)

Product:
Ford Racing Plug- staging

Description:
Ford Racing Plug- staging Installer

Version:
1.34.5.22

MD5:
296842cb8662ad0944a6439734232401

SHA-1:
9f0bc9adbacb732a8f3ab4d56052ef303a63ecea

SHA-256:
ca236d8ec336e68b8013b8a41e704fe213b933a66d6b955e424b2a4e37bb3352

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Uses the Crossrider extension framework which may modify the browser's home, new tab and search pages as well as displays advertisements such as banner ads and text-links.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Wunderman pxp GmbH.

Analysis date:
11/28/2024 3:50:53 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Dr.Web
infected with Trojan.Crossrider.10029
9.0.1.05190

ESET NOD32
Win32/Packed.ScrambleWrapper.I potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Agent
5/31/2014

K7 AntiVirus
Trojan
13.178.12257

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3782

Malwarebytes
PUP.Optional.CrossRider
v2014.05.31.12

McAfee
Adware-Crossrider
5600.7113

NANO AntiVirus
Riskware.Win32.Agent.cxphnr
0.28.0.59921

Quick Heal
AdWare.Agent.r4 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.Installer.WundermanpxpGmbH.U
14.5.31.12

Sophos
Generic PUA HI
4.98

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Threat.4789396
29732

File size:
3.4 MB (3,607,456 bytes)

Copyright:
Copyright DerSchwede

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crossriderapp0033327.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/9/2013 5:00:00 PM

Valid to:
6/10/2014 4:59:59 PM

Subject:
CN=Wunderman pxp GmbH, O=Wunderman pxp GmbH, L=Wien, S=Wien, C=AT

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73DFFF399113375590A9A7E9983E1EF4

File PE Metadata
Compilation timestamp:
12/4/2012 5:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:dJOo8WqPHBy/drkiXpxLnizhea6rRzCo3chcra2D:dJPLF5BnY3Aeo3chSn

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9907  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file CrossriderApp0033327.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to stats.statsmyapp.com  (176.32.99.156:80)

TCP (HTTP):
Connects to staging-app.crossrider.com  (149.126.72.103:80)

 
http://staging-app.crossrider.com/plugin/apps/33327/manifest/1_34_5_22/ie9/manifest.xml?ver=15&rnd=6008

Remove CrossriderApp0033327.exe - Powered by Reason Core Security