koala personal search-chromeinstaller.exe

Skyter Technologies Ltd.

The application koala personal search-chromeinstaller.exe, “Koala Personal Search exe” by Skyter Technologies has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file utilizes the Crossrider browser extension platform. ChromeInstaller is the component designed to install and manage the extension's Google Chrome integration. While running, it connects to the Internet address stats.srvstatsdata.com on port 80 using the HTTP protocol.
Publisher:
Koala Personal Search  (signed by Skyter Technologies Ltd.)

Product:
Koala Personal Search

Description:
Koala Personal Search exe

Version:
1000.1000.1000.1000

MD5:
ae4a9d78a08fc6fb96c8e1b18eb8771f

SHA-1:
b524bdd5a525dcb207d1df0c625137218af9c5e1

SHA-256:
216f7517addf7454c3ecba7de9cbbc2d989c8a3758e1ca2a65f318c9904ce7ce

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. It will download and install the extension for Gogole Chrome.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Skyter Technologies Ltd..

Analysis date:
1/12/2025 5:13:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider.SkyterTechnologies (M)
15.12.19.12

File size:
904.4 KB (926,104 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Koala Personal Search.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\koala personal search\koala personal search-chromeinstaller.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/22/2012 5:00:00 PM

Valid to:
8/23/2014 4:59:59 PM

Subject:
CN=Skyter Technologies Ltd., O=Skyter Technologies Ltd., L=Tel Aviv-Jaffa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
436F5CF769692509772EC6E9ED6B3227

File PE Metadata
Compilation timestamp:
1/1/2014 11:32:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:CkXJU91usvzOpsAov9bIcuPxmeKWHRjcNEIF0jTxwG33OOvTmqdwMVpTJBp:CkXJUr/CEvJIcuPxmzlOTxwK9vCyT/p

Entry address:
0x97A72

Entry point:
E8, DE, F3, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, 8B, 7B, 08, 33, 3D, 48, 11, 4E, 00, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 8D, 73, 10, 83, F8, FE, 74, 0D, 8B, 4F, 04, 03, CE, 33, 0C, 30, E8, 8C, AA, FF, FF, 8B, 4F, 0C, 8B, 47, 08, 03, CE, 33, 0C, 30, E8, 7C, AA, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, D0, 00, 00, 00, 89, 45, E8, 8B, 45, 10, 89, 45, EC, 8D, 45, E8, 89, 43, FC, 8B, 43, 0C, 89, 45, F8, 83, F8, FE, 0F, 84, EE, 00, 00, 00...
 
[+]

Entropy:
6.5570

Code size:
738 KB (755,712 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.srvstatsdata.com  (69.16.175.42:80)

 
http://update.srvstatsdata.com/installer_updates/009347/update.json

TCP (HTTP):
Connects to stats.srvstatsdata.com  (176.32.99.41:80)

TCP (HTTP):
Connects to app-static.crossrider.com  (69.16.175.10:80)

Remove koala personal search-chromeinstaller.exe - Powered by Reason Core Security