inboxacecrx.b41913dd-5868-49ae-a2e5-88454a235e31.exe

Mindspark Interactive Network

The application inboxacecrx.b41913dd-5868-49ae-a2e5-88454a235e31.exe by Mindspark Interactive Network has been detected as a potentially unwanted program by 8 anti-malware scanners. This version of the file will bundle a Mindspark/MyWebSearch Toolbar, a potentially unwanted web browser extension. The file has been seen being downloaded from ak.dl.inboxace.com and multiple other hosts. While running, it connects to the Internet address anx.mindspark.com on port 80 using the HTTP protocol.
Publisher:
InboxAce  (signed by Mindspark Interactive Network)

Product:
InboxAce

Version:
2.4.0.3

MD5:
c62544d189b6a7b1cabed8547ec06a2a

SHA-1:
db6b79431923e55632b25e8c51bdc296efc0624e

SHA-256:
152819566f7afc46cbefaaaa1ebf7c38a39fadfea5a75e873b5714b4923d6842

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 2:55:32 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Mindspark-A [PUP]
2014.9-140505

AVG
Zango
2015.0.3484

Dr.Web
9.0.1.0125

Fortinet FortiGate
Adware/FunWeb
5/5/2014

Reason Heuristics
PUP.Installer.MindsparkInteractiveNetwork.p
14.8.8.2

Rising Antivirus
PE:Trojan.Win32.Generic.14BC5C6C!347888748
23.00.65.14503

Trend Micro House Call
TROJ_GEN.F47V0415
7.2.125

VIPRE Antivirus
28862

File size:
1.3 MB (1,391,480 bytes)

Product version:
2.4.0.3

Copyright:
Copyright © 2012 - 2014

Original file name:
1gSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\aarons\inboxacecrx.b41913dd-5868-49ae-a2e5-88454a235e31.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2012 8:00:00 PM

Valid to:
5/6/2015 7:59:59 PM

Subject:
CN=Mindspark Interactive Network, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mindspark Interactive Network, L=White Plains, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098417F7EA6406EC7B320590E17A65B7

File PE Metadata
Compilation timestamp:
4/14/2014 11:30:00 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:AocDchSdCy5HmsuI/i5zLDtSFDwy++ijRlrvbAYV/BK8V:KIhSUy5rr/i5zFSFEy++EznV

Entry address:
0x21618

Entry point:
E8, 71, 8B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, D0, 66, 8B, 08, 83, C0, 02, 66, 85, C9, 75, F5, 66, 8B, 4D, 0C, 83, E8, 02, 3B, C2, 74, 05, 66, 39, 08, 75, F4, 66, 39, 08, 74, 02, 33, C0, 5D, C3, 8B, 44, 24, 0C, 53, 85, C0, 74, 52, 8B, 54, 24, 08, 33, DB, 8A, 5C, 24, 0C, F7, C2, 03, 00, 00, 00, 74, 16, 8A, 0A, 83, C2, 01, 32, CB, 74, 72, 83, E8, 01, 74, 32, F7, C2, 03, 00, 00, 00, 75, EA, 83, E8, 04, 72, 12, 57, 8B, FB, C1, E3, 08, 03, DF, 8B, FB, C1, E3, 10, 03, DF, EB, 1B, 5F...
 
[+]

Entropy:
5.8566

Code size:
218 KB (223,232 bytes)

The file inboxacecrx.b41913dd-5868-49ae-a2e5-88454a235e31.exe has been seen being distributed by the following 11 URLs.

http://ak.dl.inboxace.com/images/nocache/vicinio/installers/100000448.S09548.1/247798-140414142322-S09548.1/.../InboxAceCrx.DDB03FCB-2EED-41E6-9D40-F316978B3604.exe

http://ak.dl.inboxace.com/images/nocache/vicinio/installers/100000448.S09548.1/247798-140414142322-S09548.1/.../InboxAceCrx.F1AFCBC9-B063-4E6D-A828-AD01EA4809F3.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www187.mindspark.com  (74.113.233.187:80)

TCP (HTTP):
Connects to anx.mindspark.com  (74.113.233.187:80)