ap10013.exe

AP Suggestor silent installer

Think Tank Labs, LLC

The application ap10013.exe, “AP Suggestor silent installer for Internet Explorer, Mozilla Firefox and Google Chrome” by Think Tank Labs has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory.
Publisher:
Think Tank Labs, LLC  (signed and verified)

Product:
AP Suggestor silent installer

Description:
AP Suggestor silent installer for Internet Explorer, Mozilla Firefox and Google Chrome

Version:
1.0.8.1

MD5:
c511f85af78bfe938254e4fa30f814a7

SHA-1:
6261bc27fcab21db41f01d2dba2893026d6c3950

SHA-256:
b9ba9ab124a90a714d011595b57f69f80782898929021f9116b717c8ff342be8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 5:57:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ThinkTankLabs.Installer (M)
15.10.16.8

File size:
371 KB (379,896 bytes)

Product version:
2011.11.10.2343

Copyright:
© 2011 Think Tank Labs, LLC

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\ap10013.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
4/13/2011 4:47:41 PM

Valid to:
4/11/2012 4:41:13 PM

Subject:
CN="Think Tank Labs, LLC", O="Think Tank Labs, LLC", L=Newport, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B68DF215AD36D

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:6e34ZWL8Y33Z5To7bEoaMrG9SHicPrY42GkZ6qiJJlxuj8t8rk0Yk+fUU:8WgSnTokQrG9SpPrniZ65LJtKk0x+sU

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9160

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove ap10013.exe - Powered by Reason Core Security