ApnSetup.exe

Stub Installer

APN LLC

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The application ApnSetup.exe by APN has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the APN Stub installer. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension. It is also typically executed from the user's temporary directory.
Publisher:
Ask Partner Network  (signed by APN LLC)

Product:
Stub Installer

Version:
7.9.0.111

MD5:
a5551d04205a2631ec77531b300b1eaa

SHA-1:
34d624ad20db9e60e4cb8b9a686a8d2e2ce499a3

SHA-256:
82eb757ed8c4b7ea5d11ee855d88675e7167a09d9b598e943cc01dcd6b78724d

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Analysis date:
4/19/2024 3:22:43 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Ask
4.0.3.14728

Bkav FE
HW32.Pedka
1.3.0.4959

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
8.10130

G Data
Win32.Trojan.Agent.YA0M5C
14.7.24

IKARUS anti.virus
Win32.Malware
t3scan.2.2.29

Reason Heuristics
PUP.Installer.APN.I
14.8.7.21

Trend Micro House Call
TROJ_GEN.F47V0301
7.2.209

File size:
533.9 KB (546,712 bytes)

Product version:
7.9.0.111

Copyright:
Copyright © 2013 Ask Partner Network. All rights reserved.

Original file name:
ApnSetup.exe

File type:
Executable application (Win32 EXE)

Installer:
APN Stub

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\apnsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/22/2014 10:00:00 PM

Valid to:
4/8/2015 8:59:59 PM

Subject:
CN=APN LLC, OU=Distribution, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=APN LLC, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2F4E343161BC7EB67514D3DCEC434EA0

File PE Metadata
Compilation timestamp:
6/25/2014 10:40:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:Oik4Ha0tSp6etUgVeXkBSkBx+vAg2qmXAXAZCFZfl+:OgHHS04KkBcvxmXAXAZCF9k

Entry address:
0x43495

Entry point:
E8, 2A, 5A, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 84, 4D, 47, 00, 75, 02, F3, C3, E9, AC, 5A, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, D7, 1A, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 21, 60, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 68, 5B, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 37, 20, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Code size:
374 KB (382,976 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to a23-204-28-130.deploy.static.akamaitechnologies.com  (23.204.28.130:80)

Remove ApnSetup.exe - Powered by Reason Core Security