top title background image
flash

SetupImgBurn_2.5.6.0.exe

Status: finished
Submission Time: 2019-10-25 14:43:03 +02:00
Suspicious
Spyware
Evader

Comments

Tags

Details

  • Analysis ID:
    185356
  • API (Web) ID:
    269207
  • Analysis Started:
    2019-10-25 14:43:04 +02:00
  • Analysis Finished:
    2019-10-25 15:04:54 +02:00
  • MD5:
    26b4243db442d797e817c44953544e55
  • SHA1:
    b662ee7df1e0b040b8b6ba986c73a278647b94d9
  • SHA256:
    276fb9aaa5891fa085559bd168176203d14a1c97df09f05fd496fa060d79cb10
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
suspicious
Score: 26
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
suspicious
Score: 34
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Cmdline fuzzy

Third Party Analysis Engines

malicious
Score: 17/70

IPs

IP Country Detection
2.5.6.0
France
199.36.101.106
United States
74.113.237.50
United States

Domains

Name IP Detection
websearch.ask.com
199.36.101.106
img.apnanalytics.com
74.113.237.50
cdn.onenote.net
0.0.0.0
Click to see the 1 hidden entries
apnmedia.ask.com
0.0.0.0

URLs

Name Detection
http://apnmedia.ask.com/media/toolbar/stub/1.0.0.0/ApnIC.dll?tb=%s&version=%s
http://www.imgburn.com/index.php?act=installation_complete-1
https://store.uniblue.com/278/cookie?affiliate=8721&xat=ib-sp-dsk&redirectto=http%3a%2f%2fww
Click to see the 48 hidden entries
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=ewrap&cb=
http://nsis.sf.net/NSIS_ErrorError
http://www.imgburn.com/index.php?act=installation_completeopen
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=ewrap&p2=
http://sp.ask.com/en/docs/about/terms_of_service.shtml
http://websearch.ask.com/report/install?tb=FATALERRORWARNINFODEBUGbad
http://apnmedia.ask.com/media/toolbar/stub/1.0.0.0/Ap/tb=IMB/timeout=6
http://websearch.ask.com/installed?client=ic&tb=IMB&dtid=&id=78136235-65df-48ff-b1a1-85caee1031b4&ipid=&iev=9.11.17134.0&iedis=1&ielu=-2&fflu=-2&iv=&nv=&clientv=9.9.9.9&said=4f2e76c3-d288-46ff-958e-eb3002897cca&browser-lang=en&apn_dbr=Null_64_9.11.17134.0&cr=1
http://apnmedia.ask.com/mAPN_Download_Package.0.0/ApnIC.dll?tb=IMB&version=1.0.0.0
http://apnmedia.ask.com/media/toolbar/supertoolbar/profile-ask/wrapper/2.3.0/EverestWrapper.exe
http://img.apnanalytics.com/f
http://nsis.sf.net/NSIS_Error
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=ewrap&
http://forum.imgburn.com/InstallDate
http://ec2-184-73-146-163.compute-1.amazonaws.com/?ev=eafsu&idreg=
http://websearch.ask.com/installed?client=
http://www.winimage.com/zLibDll
http://apnmedia.ask.com/media/toolbar/stub/1.0.0.0/ApnIC.dll?tb=IMB&version=1.0.0.0
http://www.search.ask.com/?l=dis&o=15788
http://img.apnanalytics.com/images/noc
http://apnmedia.ask.com/media/toolbar/stub/1.0.0.0/Ap
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^HQ^YYYYYY^YY^CH&encb=&chk=sucof&ts=Qfyol&guid=78136235-65df-48ff-b1a1-85caee1031b4&dt=200&wft=remote&inst=200&tb=IMB&hos=6.2.1.sp0.x64&harch=64&hloc=en-US&iv=9.11.17134.0&fv=63.0.3%20(x86%20en-US)&dbr=164&vb=&msi=&dot=6
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&cb=
http://www.imgburn.com/
http://ec2-184-73-146-163.compute-1.amazonaws.com/?ev=eb4su&idreg=
http://about.ask.com/en/docs/about/privacy.shtml
http://www.imgburn.com/Numfields12031204
http://https://%d&repguid=&type=logfile&retcode=http://s3.amazonaws.com/apnanalyticsProductName
http://www.installshield.com/isetup/ProErrorCentral.asp?ErrorCode=%d
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=einst&p2=
https://store.uniblue.com/278/cookie?affiliate=8721&xat=ib-rb-dsk&redirectto=http%3a%2f%2fww
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=einst&p2=
http://sp.ask.com/en/docs/about/terms_of_service.shtml0
http://forum.imgburn.com/
http://s3.amazonaws.com/apn-stub
https://store.uniblue.com/278/cookie?affiliate=8721&xat=ib-ds-dsk&redirectto=http%3a%2f%2fww
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=einst&cb=
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=ewrap&p2=
http://websearch.ask.com/preinstall?client=%s&tb=%s&ipid=%s&iev=%s&iedis=%d&ielu=%d&fflu=%d&iv=%s&nv
http://www.imgburn.com/index.php?act=installation_complete
http://www.search.ask.com/?l=dis&o=15788
http://about.ask.com/en/docs/about/ask_eula.shtml
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=ewrap
http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk
http://www.winimage.com/zLibDll1.2.3-SOFTWARE
http://s3.amazonaws.com/apn-stubewogICJleHBpcmF0aW9uIjogIjIwMjAtMTItMzFUMTI6MDA6MDAuMDAwWiIsCiAgImNv

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\ApnStub.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#