File name:

absetup.exe

Full analysis: https://app.any.run/tasks/657dfef2-a121-415d-b700-ed29665baf50
Verdict: Malicious activity
Analysis date: February 12, 2024, 21:51:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

3A238B86A855B32364587C61C0ADDC16

SHA1:

92BC8C8287F081624223A0EA83B563C05371F6AF

SHA256:

2E7D7D9CC4413EB746B52C2BDFFDBF9CEF40E5A90A3F671950F13F9F5CF7FC50

SSDEEP:

98304:8SyvF8v1+9AHc1gTnEC4cadforkPluJ/4YuVBUKEmjykNAMMvLhqpitTkpbMo3qd:UPlPRxWZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • absetup.exe (PID: 2840)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • absetup.exe (PID: 2840)
    • The process creates files with name similar to system file names

      • absetup.exe (PID: 2840)
    • Executable content was dropped or overwritten

      • absetup.exe (PID: 2840)
    • Changes the title of the Internet Explorer window

      • avant.exe (PID: 864)
    • Changes the Home page of Internet Explorer

      • avant.exe (PID: 864)
    • Creates a software uninstall entry

      • absetup.exe (PID: 2840)
    • Reads the Internet Settings

      • avant.exe (PID: 2340)
      • avant.exe (PID: 1348)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Reads security settings of Internet Explorer

      • avant.exe (PID: 2340)
      • avant.exe (PID: 1348)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Application launched itself

      • avant.exe (PID: 2756)
      • avant.exe (PID: 1348)
    • Changes Internet Explorer settings (feature browser emulation)

      • avant.exe (PID: 1348)
    • Reads Microsoft Outlook installation path

      • ybrowser.exe (PID: 3508)
    • Reads the date of Windows installation

      • avantvw.exe (PID: 2648)
    • Reads Internet Explorer settings

      • ybrowser.exe (PID: 3508)
    • Process requests binary or script from the Internet

      • avant.exe (PID: 2744)
      • ybrowser.exe (PID: 3508)
  • INFO

    • Reads the computer name

      • absetup.exe (PID: 2840)
      • avant.exe (PID: 2340)
      • avantvw.exe (PID: 2648)
      • avant.exe (PID: 1348)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Checks supported languages

      • absetup.exe (PID: 2840)
      • avant.exe (PID: 3948)
      • avant.exe (PID: 2328)
      • avant.exe (PID: 864)
      • avant.exe (PID: 2340)
      • SetDefault.exe (PID: 4008)
      • avantvw.exe (PID: 2648)
      • avant.exe (PID: 1348)
      • ybrowser.exe (PID: 3508)
      • avantvw.exe (PID: 1740)
      • avant.exe (PID: 2744)
      • avant.exe (PID: 2756)
    • Create files in a temporary directory

      • absetup.exe (PID: 2840)
      • avant.exe (PID: 1348)
      • avant.exe (PID: 2744)
    • Creates files in the program directory

      • absetup.exe (PID: 2840)
    • Creates files or folders in the user directory

      • absetup.exe (PID: 2840)
      • avantvw.exe (PID: 2648)
      • avant.exe (PID: 1348)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Reads the machine GUID from the registry

      • avantvw.exe (PID: 2648)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Checks proxy server information

      • avant.exe (PID: 1348)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Process checks whether UAC notifications are on

      • ybrowser.exe (PID: 3508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 22:50:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 119808
UninitializedDataSize: 1024
EntryPoint: 0x323c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.5.0.0
ProductVersionNumber: 12.5.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
Comments: -
CompanyName: Avant Force
FileDescription: Avant Browser 2017 build 5
FileVersion: 12.5.0.0
LegalCopyright: Copyright (c) Avant Force
LegalTrademarks: Avant Browser is a trademark of Avant Force
ProductName: Avant Browser
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
13
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start absetup.exe avant.exe no specs avant.exe no specs avant.exe no specs avant.exe no specs setdefault.exe no specs avantvw.exe no specs avant.exe no specs avant.exe avantvw.exe no specs ybrowser.exe avant.exe absetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\Program Files\Avant Browser\tmp\avant.exe" -sethpgC:\Program Files\Avant Browser\tmp\avant.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\tmp\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1348"C:\Program Files\Avant Browser\avant.exe"C:\Program Files\Avant Browser\avant.exe
avant.exe
User:
admin
Company:
Avant Force
Integrity Level:
MEDIUM
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1740"C:\Program Files\Avant Browser\avantvw.exe" 1114416C:\Program Files\Avant Browser\avantvw.exeavant.exe
User:
admin
Company:
Avant Force
Integrity Level:
MEDIUM
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avantvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2328"C:\Program Files\Avant Browser\tmp\avant.exe" -txC:\Program Files\Avant Browser\tmp\avant.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\tmp\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2340"C:\Program Files\Avant Browser\avant.exe" -SetDefaultC:\Program Files\Avant Browser\avant.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2648"C:\Program Files\Avant Browser\avantvw.exe" -PinTaskBarC:\Program Files\Avant Browser\avantvw.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avantvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2744"C:\Program Files\Avant Browser\avant.exe" -helper 1114416C:\Program Files\Avant Browser\avant.exe
avant.exe
User:
admin
Company:
Avant Force
Integrity Level:
MEDIUM
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2756"C:\Program Files\Avant Browser\avant.exe" -runC:\Program Files\Avant Browser\avant.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2840"C:\Users\admin\AppData\Local\Temp\absetup.exe" C:\Users\admin\AppData\Local\Temp\absetup.exe
explorer.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser 2017 build 5
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\absetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3508"C:\Program Files\Avant Browser\ybrowser.exe" 262660 1114416 -1622289913 11000C:\Program Files\Avant Browser\ybrowser.exe
avant.exe
User:
admin
Company:
Avant Force
Integrity Level:
MEDIUM
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\ybrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
11 801
Read events
11 389
Write events
386
Delete events
26

Modification events

(PID) Process:(3948) avant.exeKey:HKEY_CURRENT_USER\Software\Avant Browser
Operation:writeName:SetupLangID
Value:
1033
(PID) Process:(864) avant.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:Start Page
Value:
http://search.yahoo.com/?fr=avantsearch6
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:DisplayName
Value:
Avant Browser (remove only)
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:UninstallString
Value:
"C:\Program Files\Avant Browser\uninst.exe"
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:InstallLocation
Value:
C:\Program Files\Avant Browser
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:Publisher
Value:
Avant Force
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:InstallSource
Value:
C:\Program Files\Avant Browser
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:ProductID
Value:
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:RegOwner
Value:
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:RegCompany
Value:
Executable files
37
Suspicious files
16
Text files
143
Unknown types
14

Dropped files

PID
Process
Filename
Type
2840absetup.exeC:\Users\admin\AppData\Local\Temp\nssFBD6.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
2840absetup.exeC:\Users\admin\AppData\Local\Temp\avant.exeexecutable
MD5:C4438B733238D03BC149418382216E5C
SHA256:191A847C4A197ED1222129375647079C9EFEB7FEED0669B4563C1DA08341F5A4
2840absetup.exeC:\Program Files\Avant Browser\Lang\cat.lngini
MD5:9B222A510940D7F36C3D431D46FA7F89
SHA256:3C6596772AC8D54D9597D1FDF4BAAAA514C1695ACEE2C5687605D04F3EF9C4B9
2840absetup.exeC:\Users\admin\AppData\Local\Temp\nssFBD6.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
2840absetup.exeC:\Users\admin\AppData\Local\Temp\nssFBD6.tmp\nsDialogs.dllexecutable
MD5:C10E04DD4AD4277D5ADC951BB331C777
SHA256:E31AD6C6E82E603378CB6B80E67D0E0DCD9CF384E1199AC5A65CB4935680021A
2840absetup.exeC:\Program Files\Avant Browser\tmp\avant.exeexecutable
MD5:C4438B733238D03BC149418382216E5C
SHA256:191A847C4A197ED1222129375647079C9EFEB7FEED0669B4563C1DA08341F5A4
2840absetup.exeC:\Program Files\Avant Browser\Lang\ara.lngini
MD5:61038F502A6715FBA33AE1AB40E26A56
SHA256:8AAF90789E1E99AD332BB1DB9EB3AD30270E6D661E06113DD7B01B791B3E07C5
2840absetup.exeC:\Program Files\Avant Browser\Lang\bul.lngtext
MD5:A83F81C9C379A84945DFC4F3B1B75725
SHA256:20C86F148F968E9B241A6DD0182784816F1E978010A44C87B23EB9DDA4899D4B
2840absetup.exeC:\Users\admin\AppData\Local\Temp\nssFBD6.tmp\welcome.bmpimage
MD5:5A6957261731632E7BFA495AE9599D0F
SHA256:EE2322F4317DE0B5BC1EC7FA90A2F353432094BDE9F71D488B26ECC1EC68C71A
2840absetup.exeC:\Program Files\Avant Browser\Lang\cze.lngtext
MD5:95D86F2BEEE534803018F8A31527BC3A
SHA256:8F52861972F40AF8C8868B4D20AE0618C826DF8169936B867C2091E66BDBC2CB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
76
TCP/UDP connections
26
DNS requests
8
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1348
avant.exe
GET
200
67.229.65.251:80
http://cn.avantbrowser.com/CheckUpdate/newupgrade.txt
unknown
text
5.05 Kb
unknown
2744
avant.exe
GET
302
67.229.65.251:80
http://www.avantbrowser.com/downloads/findfile.aspx?file=aupgrade.exe
unknown
html
157 b
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/images/cc.gif
unknown
image
9.02 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/images/facebook.png
unknown
image
3.44 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/images/clientbg.jpg
unknown
image
38.9 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/fonts/DroidSerif-Bold-webfont.eot?
unknown
binary
41.5 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/UpdateCongratulations.aspx
unknown
html
10.5 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/UpdateCongratulations.aspx
unknown
html
10.5 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/images/cc.gif
unknown
image
9.02 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/js/dd_belatedPNG_0.0.8a-min.js
unknown
text
4.36 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1348
avant.exe
67.229.65.251:80
cn.avantbrowser.com
VPLSNET
US
unknown
3508
ybrowser.exe
67.229.65.251:80
cn.avantbrowser.com
VPLSNET
US
unknown
2744
avant.exe
67.229.65.251:80
cn.avantbrowser.com
VPLSNET
US
unknown

DNS requests

Domain
IP
Reputation
testing.avantbrowser.comn
unknown
cn.avantbrowser.com
  • 67.229.65.251
unknown
www.avantbrowser.com
  • 67.229.65.251
unknown
dl1.avantbrowser.com
  • 67.229.65.251
unknown

Threats

PID
Process
Class
Message
2744
avant.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info