ApnSetup.exe

Stub Installer

APN LLC

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The application ApnSetup.exe by APN has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the APN Stub installer. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension. While running, it connects to the Internet address 199.36.102.106.df.iacapn.com on port 80 using the HTTP protocol.
Publisher:
Ask Partner Network  (signed by APN LLC)

Product:
Stub Installer

Version:
7.20.1.27

MD5:
78ea7b91ea620d9a2af88e1e42ea9cda

SHA-1:
449724f2543aa6626d716046e49678411f6a9a44

SHA-256:
8e234febe856d950049c9f1b13de630376ef637ea0a03893217c120386b323bc

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Analysis date:
4/26/2024 5:34:14 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Kukacka
2014.9-150522

Dr.Web
Adware.Toolbar.579
9.0.1.090

ESET NOD32
Win32/Bundled.Toolbar.Ask.E potentially unsafe (variant)
9.11377

Microsoft Security Essentials
Threat.Undefined
1.199.375.0

Reason Heuristics
PUP.Ask.Installer
15.4.24.16

VIPRE Antivirus
Threat.4721115
40432

File size:
636.9 KB (652,168 bytes)

Product version:
7.20.1.27

Copyright:
Copyright © 2014 APN LLC. All rights reserved.

Original file name:
ApnSetup.exe

File type:
Executable application (Win32 EXE)

Installer:
APN Stub

Language:
English (United States)

Common path:
C:\Program Files\askpartnernetwork\toolbar\apnsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/25/2015 7:00:00 PM

Valid to:
5/27/2018 7:59:59 PM

Subject:
CN=APN LLC, O=APN LLC, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
74BAC30967391B08242D79F7F79449E2

File PE Metadata
Compilation timestamp:
3/11/2015 8:23:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:CnJM8vZGgYUOXbU27+on0+8wKz6jxYxexjyQrHYB9A8AXAZCk0:CnJ+UOggnBLOex+QrHYzA8AXAZCk0

Entry address:
0x4B535

Entry point:
E8, 2A, 5A, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 84, FD, 47, 00, 75, 02, F3, C3, E9, AC, 5A, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, F2, 1C, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 21, 60, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 68, 5B, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 37, 20, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Entropy:
6.3995

Code size:
408.5 KB (418,304 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 199.36.102.106.df.iacapn.com  (199.36.102.106:80)

TCP (HTTP):
Connects to a23-76-206-214.deploy.static.akamaitechnologies.com  (23.76.206.214:80)

TCP (HTTP):

TCP (HTTP):
Connects to a23-59-120-107.deploy.static.akamaitechnologies.com  (23.59.120.107:80)

TCP (HTTP):
Connects to a23-213-116-78.deploy.static.akamaitechnologies.com  (23.213.116.78:80)

TCP (HTTP):

TCP (HTTP):
Connects to a104-113-6-125.deploy.static.akamaitechnologies.com  (104.113.6.125:80)

Remove ApnSetup.exe - Powered by Reason Core Security