sbar.exe

SearchBar

Iminent Technology

The application sbar.exe by Iminent Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program SearchBar by Iminent Technology which is a potentially unwanted software program.
Publisher:
Iminent Technology  (signed and verified)

Product:
SearchBar

Version:
1.0.0.4

MD5:
2d1346230229e2afdfb593809c3202be

SHA-1:
b9602e61108852947272ef96dc772c51a6aeffcb

SHA-256:
b4ca7e12dfc6c622b61b392870de42cc16da00b00c1aed9c658f6beced996d35

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 9:35:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.IminentTechnology (M)
15.11.1.15

File size:
371.1 KB (379,984 bytes)

Product version:
1.0.0.4

Copyright:
Copyright Sien 2015

Original file name:
sbar.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\searchbar\sbar.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/13/2015 1:28:47 PM

Valid to:
4/13/2016 1:28:47 PM

Subject:
CN=Iminent Technology, O=Iminent Technology, L=Bucharest, C=RO

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216E98BE0313CB080B54DD5D79DCC3BF0D

File PE Metadata
Compilation timestamp:
9/21/2015 4:05:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:sf/jlETtKfQktztJiNy7C1NL4krjS6BGgTqoGjbmk8XoLGCzhG3Xuyv5B49IuBBQ:2jSyQkNtJiNz1NL4DvBBNcwJUBnAr3I

Entry address:
0x23765

Entry point:
E8, 0B, 60, 00, 00, E9, 89, FE, FF, FF, 6A, 0C, 68, 28, A5, 43, 00, E8, E5, 2F, 00, 00, 6A, 0E, E8, 08, 62, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, BC, FD, 43, 00, BA, B8, FD, 43, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, BF, EA, FF, FF, 59, FF, 76, 04, E8, B6, EA, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, D4, 2F, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, D4, 60, 00, 00, 59, C3, CC, 8B, 54, 24, 04, 8B...
 
[+]

Entropy:
6.6196

Code size:
191 KB (195,584 bytes)

The file sbar.exe has been discovered within the following program.

SearchBar  by Iminent Technology
www.iminent.com
81% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-50-19-125-7.compute-1.amazonaws.com  (50.19.125.7:80)

TCP (HTTP):
Connects to ec2-54-243-144-249.compute-1.amazonaws.com  (54.243.144.249:80)

TCP (HTTP):
Connects to ec2-54-235-187-72.compute-1.amazonaws.com  (54.235.187.72:80)

TCP (HTTP):
Connects to ec2-23-23-219-183.compute-1.amazonaws.com  (23.23.219.183:80)

Remove sbar.exe - Powered by Reason Core Security