File name:

CrossRider.exe

Full analysis: https://app.any.run/tasks/e97ffcdd-5b1a-44f0-adf2-c0f40eb167df
Verdict: Malicious activity
Analysis date: February 20, 2024, 03:16:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C359B1996E911B652B42011BD6BBFD87

SHA1:

2C5D8B895473A78584A551DB80E39AAE5325FCED

SHA256:

0CAE1EF0A97EAE1E8F061E9015FCDE96B48E7F8491FD70534B5E373B87EB4B4C

SSDEEP:

98304:KljTD6TNdnEeyLtrjgAMEUYyLqEa22q/5j:6M

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CrossRider.exe (PID: 2848)
      • 9328.exe (PID: 2752)
      • CrossRider.exe (PID: 3308)
      • CrossRider.exe (PID: 2632)
      • 9403.exe (PID: 1644)
      • 9599.exe (PID: 844)
  • SUSPICIOUS

    • Searches for installed software

      • CrossRider.exe (PID: 2848)
      • 9328.exe (PID: 2752)
      • CrossRider.exe (PID: 3308)
      • 9403.exe (PID: 1644)
      • 9599.exe (PID: 844)
      • CrossRider.exe (PID: 2632)
    • Executable content was dropped or overwritten

      • CrossRider.exe (PID: 2848)
      • CrossRider.exe (PID: 3308)
      • 9328.exe (PID: 2752)
      • 9403.exe (PID: 1644)
      • CrossRider.exe (PID: 2632)
      • 9599.exe (PID: 844)
    • Reads the Internet Settings

      • 9328.exe (PID: 2752)
      • 9403.exe (PID: 1644)
      • 9599.exe (PID: 844)
    • Starts itself from another location

      • CrossRider.exe (PID: 2848)
      • CrossRider.exe (PID: 3308)
      • CrossRider.exe (PID: 2632)
    • Reads security settings of Internet Explorer

      • 9328.exe (PID: 2752)
      • 9403.exe (PID: 1644)
      • 9599.exe (PID: 844)
  • INFO

    • Checks supported languages

      • CrossRider.exe (PID: 2848)
      • 9328.exe (PID: 2752)
      • CrossRider.exe (PID: 3308)
      • 9403.exe (PID: 1644)
      • CrossRider.exe (PID: 2632)
      • 9599.exe (PID: 844)
    • Reads the computer name

      • CrossRider.exe (PID: 2848)
      • 9328.exe (PID: 2752)
      • CrossRider.exe (PID: 3308)
      • 9403.exe (PID: 1644)
      • CrossRider.exe (PID: 2632)
      • 9599.exe (PID: 844)
    • Checks proxy server information

      • 9328.exe (PID: 2752)
      • 9403.exe (PID: 1644)
      • 9599.exe (PID: 844)
    • Create files in a temporary directory

      • CrossRider.exe (PID: 2848)
      • CrossRider.exe (PID: 3308)
      • 9328.exe (PID: 2752)
      • 9403.exe (PID: 1644)
      • CrossRider.exe (PID: 2632)
      • 9599.exe (PID: 844)
    • Reads the machine GUID from the registry

      • 9328.exe (PID: 2752)
      • 9403.exe (PID: 1644)
      • 9599.exe (PID: 844)
    • Creates files or folders in the user directory

      • 9328.exe (PID: 2752)
      • 9403.exe (PID: 1644)
      • 9599.exe (PID: 844)
    • Manual execution by a user

      • explorer.exe (PID: 1692)
      • CrossRider.exe (PID: 3308)
      • CrossRider.exe (PID: 3540)
      • CrossRider.exe (PID: 2632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:09:03 13:33:26+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 1447424
InitializedDataSize: 566272
UninitializedDataSize: -
EntryPoint: 0x132ffe
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 106.0.0.0
ProductVersionNumber: 106.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: -
FileDescription: -
FileVersion: 106.0.0.0
InternalName: -
ProductName: -
LegalCopyright: -
ProductVersion: 106.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
9
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start crossrider.exe 9328.exe explorer.exe no specs crossrider.exe 9403.exe crossrider.exe no specs crossrider.exe 9599.exe crossrider.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
844"C:\Users\admin\AppData\Local\Temp\\9599.exe" /asruC:\Users\admin\AppData\Local\Temp\9599.exe
CrossRider.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
106.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\9599.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
1644"C:\Users\admin\AppData\Local\Temp\\9403.exe" /asruC:\Users\admin\AppData\Local\Temp\9403.exe
CrossRider.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
106.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\9403.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
1692"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2160"C:\Users\admin\AppData\Local\Temp\CrossRider.exe" C:\Users\admin\AppData\Local\Temp\CrossRider.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
106.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\crossrider.exe
c:\windows\system32\ntdll.dll
2632"C:\Users\admin\Desktop\CrossRider.exe" C:\Users\admin\Desktop\CrossRider.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
106.0.0.0
Modules
Images
c:\users\admin\desktop\crossrider.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
2752"C:\Users\admin\AppData\Local\Temp\\9328.exe" /asruC:\Users\admin\AppData\Local\Temp\9328.exe
CrossRider.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
106.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\9328.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
2848"C:\Users\admin\AppData\Local\Temp\CrossRider.exe" C:\Users\admin\AppData\Local\Temp\CrossRider.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
106.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\crossrider.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
3308"C:\Users\admin\Desktop\CrossRider.exe" C:\Users\admin\Desktop\CrossRider.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
106.0.0.0
Modules
Images
c:\users\admin\desktop\crossrider.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
3540"C:\Users\admin\Desktop\CrossRider.exe" C:\Users\admin\Desktop\CrossRider.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
106.0.0.0
Modules
Images
c:\users\admin\desktop\crossrider.exe
c:\windows\system32\ntdll.dll
Total events
11 809
Read events
11 407
Write events
331
Delete events
71

Modification events

(PID) Process:(2848) CrossRider.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Crossbrowse
Operation:writeName:PreInstall
Value:
1
(PID) Process:(2848) CrossRider.exeKey:HKEY_CURRENT_USER\Software\Crossbrowse
Operation:writeName:PreInstall
Value:
1
(PID) Process:(2752) 9328.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Crossbrowse
Operation:writeName:PreInstall
Value:
1
(PID) Process:(2752) 9328.exeKey:HKEY_CURRENT_USER\Software\Crossbrowse
Operation:writeName:PreInstall
Value:
1
(PID) Process:(2752) 9328.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2752) 9328.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(2752) 9328.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(2752) 9328.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(2752) 9328.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(2752) 9328.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
6
Suspicious files
0
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
27529328.exeC:\Users\admin\AppData\Local\2CBAB28E-B0C0-4BD3-88AB-70A82C8C31F4\2CBAB28E-B0C0-4BD3-88AB-70A82C8C31F4.exeexecutable
MD5:C359B1996E911B652B42011BD6BBFD87
SHA256:0CAE1EF0A97EAE1E8F061E9015FCDE96B48E7F8491FD70534B5E373B87EB4B4C
27529328.exeC:\Users\admin\AppData\Local\Temp\9407.txttext
MD5:8B1B62FC541EF1207C7838C4C3268A4D
SHA256:21CC69AF0D2E37023C223022BAFA1CA3B260D0BB415F44D970F18DB4EEB7E1E3
27529328.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\XE1G5O87.txttext
MD5:9F47F297BBC0877E8E42C22DBC59AAB6
SHA256:A8562918D2FEE66A3EC085A7E913DE163A136E94CB17938451AC38F58949AEA3
3308CrossRider.exeC:\Users\admin\AppData\Local\Temp\9403.exeexecutable
MD5:C359B1996E911B652B42011BD6BBFD87
SHA256:0CAE1EF0A97EAE1E8F061E9015FCDE96B48E7F8491FD70534B5E373B87EB4B4C
16449403.exeC:\Users\admin\AppData\Local\Temp\5958.txttext
MD5:8B1B62FC541EF1207C7838C4C3268A4D
SHA256:21CC69AF0D2E37023C223022BAFA1CA3B260D0BB415F44D970F18DB4EEB7E1E3
2848CrossRider.exeC:\Users\admin\AppData\Local\Temp\9328.exeexecutable
MD5:C359B1996E911B652B42011BD6BBFD87
SHA256:0CAE1EF0A97EAE1E8F061E9015FCDE96B48E7F8491FD70534B5E373B87EB4B4C
16449403.exeC:\Users\admin\AppData\Local\8F1FE8EC-7E6E-4784-9A55-4E25C79FF9AE\8F1FE8EC-7E6E-4784-9A55-4E25C79FF9AE.exeexecutable
MD5:C359B1996E911B652B42011BD6BBFD87
SHA256:0CAE1EF0A97EAE1E8F061E9015FCDE96B48E7F8491FD70534B5E373B87EB4B4C
16449403.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\PS0F26EK.htmhtml
MD5:C04F63FBE8F4DF5C76C36DDB4B471D98
SHA256:F747459546866CA4019E6640204AB4C4AB4F26A0DE0762A36E7E6E5CC92592F9
2632CrossRider.exeC:\Users\admin\AppData\Local\Temp\9599.exeexecutable
MD5:C359B1996E911B652B42011BD6BBFD87
SHA256:0CAE1EF0A97EAE1E8F061E9015FCDE96B48E7F8491FD70534B5E373B87EB4B4C
8449599.exeC:\Users\admin\AppData\Local\Temp\3613.txttext
MD5:8B1B62FC541EF1207C7838C4C3268A4D
SHA256:21CC69AF0D2E37023C223022BAFA1CA3B260D0BB415F44D970F18DB4EEB7E1E3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
7
DNS requests
8
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
844
9599.exe
GET
200
93.115.28.104:80
http://ipgeoapi.com/
unknown
html
473 b
unknown
1644
9403.exe
GET
200
93.115.28.104:80
http://ipgeoapi.com/
unknown
html
473 b
unknown
2752
9328.exe
GET
302
93.115.28.104:80
http://ipgeoapi.com/
unknown
text
11 b
unknown
2752
9328.exe
GET
200
199.59.243.225:80
http://survey-smiles.com/
unknown
html
1.03 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
2752
9328.exe
93.115.28.104:80
ipgeoapi.com
UAB Cherry Servers
LT
unknown
2752
9328.exe
199.59.243.225:80
survey-smiles.com
AMAZON-02
US
unknown
1644
9403.exe
93.115.28.104:80
ipgeoapi.com
UAB Cherry Servers
LT
unknown
844
9599.exe
93.115.28.104:80
ipgeoapi.com
UAB Cherry Servers
LT
unknown

DNS requests

Domain
IP
Reputation
ipgeoapi.com
  • 93.115.28.104
unknown
survey-smiles.com
  • 199.59.243.225
whitelisted
err.rgbdomsrv.com
unknown
logs.rgbdomsrv.com
unknown
mystats.rgbdomsrv.com
unknown
zip.rgbdomsrv.com
unknown
zipf.rgbdomsrv.com
unknown
dl.gencloudex.com
unknown

Threats

Found threats are available for the paid subscriptions
3 ETPRO signatures available at the full report
No debug info