apnsetup1.exe

Stub Installer

APN LLC

This installer is part of the Ask.com (APN) network which will install the Ask.com branded toolbar or browser extension which will take control of the web browser's search functions. The application apnsetup1.exe by APN has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the APN Stub installer. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from 113.171.224.214.
Publisher:
Ask Partner Network  (signed by APN LLC)

Product:
Stub Installer

Version:
7.5.0.5

MD5:
b763782beb7d4be135b493a66ae2c841

SHA-1:
b506b2465fd10608020d30ed9047b5e11de63fa0

SHA-256:
01d0c3e9722ed6979335f50c8791b46529caa1ad62a2774a7261af3618e7291a

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Analysis date:
11/27/2024 7:38:31 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Bundled.Toolbar.Ask
8.9252

Reason Heuristics
PUP.Startup.APN.J
14.8.7.21

File size:
497.9 KB (509,872 bytes)

Product version:
7.5.0.5

Copyright:
Copyright © 2013 Ask Partner Network. All rights reserved.

Original file name:
ApnSetup.exe

File type:
Executable application (Win32 EXE)

Installer:
APN Stub

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\apnsetup1.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/16/2012 7:00:00 AM

Valid to:
4/9/2015 6:59:59 AM

Subject:
CN=APN LLC, OU=Distribution, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=APN LLC, L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
27EAB3DE0B03D88D5C4A2AE477B84DFA

File PE Metadata
Compilation timestamp:
10/4/2013 9:55:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:4EpLMX/GiR5VQhYgvEfUDLPB2AA/AVzKi:4MC/GiRlUDl2AA/AV2i

Entry address:
0x3D852

Entry point:
E8, 2E, 5A, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 84, BD, 46, 00, 75, 02, F3, C3, E9, B0, 5A, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, D7, 1A, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 34, 60, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 7B, 5B, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 3A, 20, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Entropy:
6.3817

Code size:
348 KB (356,352 bytes)

Startup File (All Users Run Once)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Name:
APN-Stub_AVIRA-V7C

Command:
"C:\ProgramData\apn\apn-stub\avira-v7c\apnsetup.exe" \hpr=1 \sa=1 \install=avira-v7c \dtid=yyyyyyyy \trgb=all \trga=cr \type=secure \runonce


The file apnsetup1.exe has been seen being distributed by the following URL.

http://113.171.224.214/.../APNSetup.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to a23-199-145-119.deploy.static.akamaitechnologies.com  (23.199.145.119:80)

TCP (HTTP):
Connects to 199.36.102.106.df.iacapn.com  (199.36.102.106:80)

TCP (HTTP):
Connects to 199.36.100.106.df.iacapn.com  (199.36.100.106:80)

TCP (HTTP):
Connects to a23-67-177-113.deploy.static.akamaitechnologies.com  (23.67.177.113:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):
Connects to 74.113.237.189.lv.iaccap.com  (74.113.237.189:80)

TCP (HTTP):
Connects to 74.113.233.187.df.iaccap.com  (74.113.233.187:80)

TCP (HTTP):
Connects to a72-247-218-230.deploy.akamaitechnologies.com  (72.247.218.230:80)

TCP (HTTP):
Connects to a118-214.131-135.deploy.akamaitechnologies.com  (118.214.131.135:80)

TCP (HTTP):
Connects to a23-57-200-172.deploy.static.akamaitechnologies.com  (23.57.200.172:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):
Connects to a23-211-201-51.deploy.static.akamaitechnologies.com  (23.211.201.51:80)

TCP (HTTP):

TCP (HTTP):
Connects to a104-66-73-137.deploy.static.akamaitechnologies.com  (104.66.73.137:80)

TCP (HTTP):
Connects to a23-74-208-101.deploy.static.akamaitechnologies.com  (23.74.208.101:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

Remove apnsetup1.exe - Powered by Reason Core Security