easyburner-setup.exe

Easy Burner

Aedge Performance BCN, S.L.U.

The application easyburner-setup.exe by Aedge Performance BCN, S.L.U has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from app.easy-burner.com.
Publisher:
Aedge Performance BCN SL  (signed by Aedge Performance BCN, S.L.U.)

Product:
Easy Burner

Version:
2.6001.00011

MD5:
339fd5b1795128158961c11bc482164a

SHA-1:
5ffc737e72cc3b32c442c7e0ac1b395926f295d9

SHA-256:
f2c89a1f8693fd90c166004998341bce92f259091d75c45f44a50aa0094e9d1a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 2:14:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Adedge (M)
16.7.31.17

File size:
1.4 MB (1,497,456 bytes)

Product version:
2.6001.00011

Copyright:
Copyright (C) 2011 Aedge Performance BCN SL

Original file name:
InstallShield Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\easyburner-setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/24/2012 9:00:00 PM

Valid to:
6/21/2013 8:59:59 PM

Subject:
CN="Aedge Performance BCN, S.L.U.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Aedge Performance BCN, S.L.U.", L=BARCELONA, S=CATALUNYA, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D6D2F7CC0B7C31DA645A5A1A2078139

File PE Metadata
Compilation timestamp:
10/5/2010 5:40:22 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:1IsNmFAA/Lhat8/jsukOIFVchkXlg8brp3bOUwEBdRpTifHAJtQW39D:1IsNQ3ht40SXlxJrWEBNTwH6tZND

Entry address:
0x95C40

Entry point:
E8, 49, 28, 01, 00, E9, 79, FE, FF, FF, 85, C0, 74, 0D, 33, C9, 85, C0, 0F, 9F, C1, 8D, 4C, 09, FF, 8B, C1, C3, 0F, B6, 00, 0F, B6, 09, 2B, C1, 74, 0D, 33, C9, 85, C0, 0F, 9F, C1, 8D, 4C, 09, FF, 8B, C1, C3, 66, 8B, 06, 66, 3B, 01, 74, 35, 0F, B6, 11, 0F, B6, C0, 2B, C2, 74, 11, 33, D2, 85, C0, 0F, 9F, C2, 8D, 54, 12, FF, 8B, C2, 85, C0, 75, 1C, 0F, B6, 46, 01, 0F, B6, 49, 01, 2B, C1, 74, 10, 33, C9, 85, C0, 0F, 9F, C1, 8D, 4C, 09, FF, 8B, C1, C3, 33, C0, C3, 8B, 06, 3B, 01, 74, 6F, 0F, B6, 11, 0F, B6, C0...
 
[+]

Code size:
893.5 KB (914,944 bytes)

The file easyburner-setup.exe has been seen being distributed by the following URL.

Remove easyburner-setup.exe - Powered by Reason Core Security