File name:

AdBlock360Setup.exe

Full analysis: https://app.any.run/tasks/4136b8ea-76d7-4a77-bf4e-b122bf191c46
Verdict: No threats detected
Analysis date: October 31, 2025, 08:27:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

56B83384475B682AA397B291B0FBB088

SHA1:

ADA408E211B87FA1C145141D3B312EB2128D845B

SHA256:

2B2BF0E2474C2055136ABEA292A55152DEE6D69232F5BB9D6475D77292B10129

SSDEEP:

12288:mDG979mzR1i9oQltf3R5zTBZmDPYY54G7AfBpfR5TtMd8V:mDG9YR1i9oQltzXMPVV7yBpfR5Ttz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • AdBlock360Setup.exe (PID: 7428)
      • AdBlock360Setup.exe (PID: 7620)
      • msiexec.exe (PID: 7872)
    • Reads the date of Windows installation

      • AdBlock360Setup.exe (PID: 7428)
    • Application launched itself

      • AdBlock360Setup.exe (PID: 7428)
  • INFO

    • The sample compiled with english language support

      • AdBlock360Setup.exe (PID: 7428)
    • Checks supported languages

      • AdBlock360Setup.exe (PID: 7428)
      • AdBlock360Setup.exe (PID: 7620)
      • msiexec.exe (PID: 7872)
      • msiexec.exe (PID: 7836)
    • Process checks computer location settings

      • AdBlock360Setup.exe (PID: 7428)
    • Reads the computer name

      • AdBlock360Setup.exe (PID: 7428)
      • AdBlock360Setup.exe (PID: 7620)
      • msiexec.exe (PID: 7836)
      • msiexec.exe (PID: 7872)
    • Reads the machine GUID from the registry

      • AdBlock360Setup.exe (PID: 7620)
      • msiexec.exe (PID: 7872)
    • Reads the software policy settings

      • AdBlock360Setup.exe (PID: 7620)
      • msiexec.exe (PID: 7772)
    • Create files in a temporary directory

      • AdBlock360Setup.exe (PID: 7620)
      • msiexec.exe (PID: 7772)
      • msiexec.exe (PID: 7872)
    • Checks proxy server information

      • AdBlock360Setup.exe (PID: 7620)
      • msiexec.exe (PID: 7772)
    • Creates files or folders in the user directory

      • AdBlock360Setup.exe (PID: 7620)
      • msiexec.exe (PID: 7772)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 7772)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7772)
      • msiexec.exe (PID: 7872)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:10:21 11:20:37+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.44
CodeSize: 280064
InitializedDataSize: 169984
UninitializedDataSize: -
EntryPoint: 0x220ac
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.0.0.0
ProductVersionNumber: 4.0.0.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: ADBLOCK LIMITED
FileDescription: AdBlock360 Web Installer
FileVersion: 4.0.0
InternalName: AdBlock360 Web Installer
LegalCopyright: Copyright (c) 2025 ADBLOCK LIMITED
OriginalFileName: AdBlock360.exe
ProductName: AdBlock360
ProductVersion: 4.0.0.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start adblock360setup.exe no specs adblock360setup.exe msiexec.exe msiexec.exe no specs msiexec.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7192C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7428"C:\Users\admin\AppData\Local\Temp\AdBlock360Setup.exe" C:\Users\admin\AppData\Local\Temp\AdBlock360Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\adblock360setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7620"C:\Users\admin\AppData\Local\Temp\AdBlock360Setup.exe" C:\Users\admin\AppData\Local\Temp\AdBlock360Setup.exe
AdBlock360Setup.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\adblock360setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7772msiexec /i "C:\Users\admin\AppData\Local\Temp\D69BB574-E533-4232-990B-A7FABF9452E4\AdBlock360-Setup_4.0.1.0110.msi" /L*V "C:\Users\admin\AppData\Local\Temp\AdBlock360-Installer.log"C:\Windows\System32\msiexec.exe
AdBlock360Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7836C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7872C:\Windows\syswow64\MsiExec.exe -Embedding 754C0679D59288E08C4BBAAACC3AA9D9 UC:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
8 842
Read events
8 831
Write events
11
Delete events
0

Modification events

(PID) Process:(7428) AdBlock360Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(7428) AdBlock360Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(7428) AdBlock360Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(7428) AdBlock360Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(7620) AdBlock360Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7620) AdBlock360Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7620) AdBlock360Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
14
Suspicious files
8
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
7620AdBlock360Setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\AdBlock360-Setup_4.0.1.0110[1].msi
MD5:
SHA256:
7620AdBlock360Setup.exeC:\Users\admin\AppData\Local\Temp\D69BB574-E533-4232-990B-A7FABF9452E4\AdBlock360-Setup_4.0.1.0110.msi
MD5:
SHA256:
7620AdBlock360Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:C74A03B12710D7802C5B1865F9DCE324
SHA256:4288BF96B66CFCD9291E95365912760D6BB6120B3E14BF39ADA8670792CEC205
7772msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_16C89CE78CC9E46E9E5FC013C79851B1binary
MD5:880A840C3B63245A26897D1D581C6FD2
SHA256:B27CF02BE6DB8B9B829ABF16EF0C9ED8171AB389CC929AC7487703DCF1BF5EE3
7772msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:A5D9BE7B5E694B276724045144C00E50
SHA256:7E4C39B33A0F3AEF37EC1A830ADCABA1B70D525FFB09D2DB53BB94761D2B173A
7772msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:89319A7A649F14CAE50125ADAF237DB4
SHA256:6F3C03A677D5EC4CF2D4598AA8055875332080FF72BD285BCB6EC387F2F515C9
7772msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_16C89CE78CC9E46E9E5FC013C79851B1binary
MD5:9BB0BE866B9A68B8353526090DC4F6D1
SHA256:9722F89CD734FAD96392E771C9B41A8481F1F63F6233E626DEF0950F96E47610
7772msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:A72F4AC63DCB156F2B9C9247F77AC5A0
SHA256:2AACF43C3FCA64EEDE0C23FC26F8B5BFE5EC5002EB82E025A876B8EA85077AFC
7772msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:F49915BFFCAA51FC62D071EB7DF2A06C
SHA256:21689FA213BF4E212B60183682AD400FB6340BC7DB1638F6D63AA467B34F2DFF
7872msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI19631\SharpVectors.Core.dllexecutable
MD5:46216455CED8183B73638E2DFA006A9A
SHA256:B3AACBF6629B29677E7836E4A9236410B5EC57D24B5EFFBD30D9E31CEA2B9A15
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
25
DNS requests
16
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7620
AdBlock360Setup.exe
GET
200
18.245.38.235:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
whitelisted
7772
msiexec.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
7772
msiexec.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
7772
msiexec.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAEldo4y1XhTxXnw4hY%2Bw5A%3D
unknown
whitelisted
2396
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7248
SIHClient.exe
GET
200
72.246.29.11:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl
unknown
whitelisted
2348
svchost.exe
GET
200
23.195.23.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7248
SIHClient.exe
GET
200
72.246.29.11:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
7248
SIHClient.exe
GET
200
72.246.29.11:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.3.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2348
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4056
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5596
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7620
AdBlock360Setup.exe
65.9.66.3:443
api.adblock360.com
AMAZON-02
US
whitelisted
4
System
192.168.100.255:138
whitelisted
7620
AdBlock360Setup.exe
18.245.38.235:80
ocsp.rootca1.amazontrust.com
US
whitelisted
7772
msiexec.exe
23.63.118.230:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2396
svchost.exe
20.190.160.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2396
svchost.exe
23.63.118.230:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.78
whitelisted
api.adblock360.com
  • 65.9.66.3
  • 65.9.66.73
  • 65.9.66.55
  • 65.9.66.120
unknown
ocsp.rootca1.amazontrust.com
  • 18.245.38.235
whitelisted
ocsp.digicert.com
  • 23.63.118.230
whitelisted
login.live.com
  • 20.190.160.4
  • 20.190.160.128
  • 40.126.32.72
  • 20.190.160.66
  • 40.126.32.136
  • 40.126.32.76
  • 40.126.32.68
  • 40.126.32.133
whitelisted
crl.microsoft.com
  • 23.195.23.211
  • 23.195.23.164
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted
www.microsoft.com
  • 72.246.29.11
whitelisted

Threats

PID
Process
Class
Message
Misc activity
ET INFO Observed UA-CPU Header
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info