File name:

absetup.exe

Full analysis: https://app.any.run/tasks/657dfef2-a121-415d-b700-ed29665baf50
Verdict: Malicious activity
Analysis date: February 12, 2024, 21:51:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

3A238B86A855B32364587C61C0ADDC16

SHA1:

92BC8C8287F081624223A0EA83B563C05371F6AF

SHA256:

2E7D7D9CC4413EB746B52C2BDFFDBF9CEF40E5A90A3F671950F13F9F5CF7FC50

SSDEEP:

98304:8SyvF8v1+9AHc1gTnEC4cadforkPluJ/4YuVBUKEmjykNAMMvLhqpitTkpbMo3qd:UPlPRxWZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • absetup.exe (PID: 2840)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • absetup.exe (PID: 2840)
    • The process creates files with name similar to system file names

      • absetup.exe (PID: 2840)
    • Reads the date of Windows installation

      • avantvw.exe (PID: 2648)
    • Changes the title of the Internet Explorer window

      • avant.exe (PID: 864)
    • Executable content was dropped or overwritten

      • absetup.exe (PID: 2840)
    • Creates a software uninstall entry

      • absetup.exe (PID: 2840)
    • Reads the Internet Settings

      • avant.exe (PID: 2340)
      • avant.exe (PID: 1348)
      • avant.exe (PID: 2744)
      • ybrowser.exe (PID: 3508)
    • Changes the Home page of Internet Explorer

      • avant.exe (PID: 864)
    • Reads security settings of Internet Explorer

      • avant.exe (PID: 2340)
      • avant.exe (PID: 1348)
      • avant.exe (PID: 2744)
      • ybrowser.exe (PID: 3508)
    • Changes Internet Explorer settings (feature browser emulation)

      • avant.exe (PID: 1348)
    • Application launched itself

      • avant.exe (PID: 2756)
      • avant.exe (PID: 1348)
    • Process requests binary or script from the Internet

      • avant.exe (PID: 2744)
      • ybrowser.exe (PID: 3508)
    • Reads Microsoft Outlook installation path

      • ybrowser.exe (PID: 3508)
    • Reads Internet Explorer settings

      • ybrowser.exe (PID: 3508)
  • INFO

    • Checks supported languages

      • absetup.exe (PID: 2840)
      • avant.exe (PID: 3948)
      • avant.exe (PID: 2328)
      • avant.exe (PID: 864)
      • avantvw.exe (PID: 2648)
      • avant.exe (PID: 2340)
      • SetDefault.exe (PID: 4008)
      • avantvw.exe (PID: 1740)
      • avant.exe (PID: 2756)
      • avant.exe (PID: 1348)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Reads the computer name

      • absetup.exe (PID: 2840)
      • avantvw.exe (PID: 2648)
      • avant.exe (PID: 2340)
      • avant.exe (PID: 1348)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Create files in a temporary directory

      • absetup.exe (PID: 2840)
      • avant.exe (PID: 2744)
      • avant.exe (PID: 1348)
    • Reads the machine GUID from the registry

      • avantvw.exe (PID: 2648)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Creates files in the program directory

      • absetup.exe (PID: 2840)
    • Creates files or folders in the user directory

      • absetup.exe (PID: 2840)
      • avant.exe (PID: 1348)
      • avantvw.exe (PID: 2648)
      • ybrowser.exe (PID: 3508)
      • avant.exe (PID: 2744)
    • Checks proxy server information

      • avant.exe (PID: 1348)
      • avant.exe (PID: 2744)
      • ybrowser.exe (PID: 3508)
    • Process checks whether UAC notifications are on

      • ybrowser.exe (PID: 3508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 22:50:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 119808
UninitializedDataSize: 1024
EntryPoint: 0x323c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.5.0.0
ProductVersionNumber: 12.5.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
Comments: -
CompanyName: Avant Force
FileDescription: Avant Browser 2017 build 5
FileVersion: 12.5.0.0
LegalCopyright: Copyright (c) Avant Force
LegalTrademarks: Avant Browser is a trademark of Avant Force
ProductName: Avant Browser
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
13
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start absetup.exe avant.exe no specs avant.exe no specs avant.exe no specs avant.exe no specs setdefault.exe no specs avantvw.exe no specs avant.exe no specs avant.exe avantvw.exe no specs ybrowser.exe avant.exe absetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\Program Files\Avant Browser\tmp\avant.exe" -sethpgC:\Program Files\Avant Browser\tmp\avant.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\tmp\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1348"C:\Program Files\Avant Browser\avant.exe"C:\Program Files\Avant Browser\avant.exe
avant.exe
User:
admin
Company:
Avant Force
Integrity Level:
MEDIUM
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1740"C:\Program Files\Avant Browser\avantvw.exe" 1114416C:\Program Files\Avant Browser\avantvw.exeavant.exe
User:
admin
Company:
Avant Force
Integrity Level:
MEDIUM
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avantvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2328"C:\Program Files\Avant Browser\tmp\avant.exe" -txC:\Program Files\Avant Browser\tmp\avant.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\tmp\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2340"C:\Program Files\Avant Browser\avant.exe" -SetDefaultC:\Program Files\Avant Browser\avant.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2648"C:\Program Files\Avant Browser\avantvw.exe" -PinTaskBarC:\Program Files\Avant Browser\avantvw.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avantvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2744"C:\Program Files\Avant Browser\avant.exe" -helper 1114416C:\Program Files\Avant Browser\avant.exe
avant.exe
User:
admin
Company:
Avant Force
Integrity Level:
MEDIUM
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2756"C:\Program Files\Avant Browser\avant.exe" -runC:\Program Files\Avant Browser\avant.exeabsetup.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\avant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2840"C:\Users\admin\AppData\Local\Temp\absetup.exe" C:\Users\admin\AppData\Local\Temp\absetup.exe
explorer.exe
User:
admin
Company:
Avant Force
Integrity Level:
HIGH
Description:
Avant Browser 2017 build 5
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\absetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3508"C:\Program Files\Avant Browser\ybrowser.exe" 262660 1114416 -1622289913 11000C:\Program Files\Avant Browser\ybrowser.exe
avant.exe
User:
admin
Company:
Avant Force
Integrity Level:
MEDIUM
Description:
Avant Browser
Exit code:
0
Version:
12.5.0.0
Modules
Images
c:\program files\avant browser\ybrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
11 801
Read events
11 389
Write events
386
Delete events
26

Modification events

(PID) Process:(3948) avant.exeKey:HKEY_CURRENT_USER\Software\Avant Browser
Operation:writeName:SetupLangID
Value:
1033
(PID) Process:(864) avant.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:Start Page
Value:
http://search.yahoo.com/?fr=avantsearch6
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:DisplayName
Value:
Avant Browser (remove only)
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:UninstallString
Value:
"C:\Program Files\Avant Browser\uninst.exe"
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:InstallLocation
Value:
C:\Program Files\Avant Browser
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:Publisher
Value:
Avant Force
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:InstallSource
Value:
C:\Program Files\Avant Browser
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:ProductID
Value:
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:RegOwner
Value:
(PID) Process:(2840) absetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvantBrowser
Operation:writeName:RegCompany
Value:
Executable files
37
Suspicious files
16
Text files
143
Unknown types
14

Dropped files

PID
Process
Filename
Type
2840absetup.exeC:\Users\admin\AppData\Local\Temp\nssFBD6.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
2840absetup.exeC:\Program Files\Avant Browser\Lang\chs.lngtext
MD5:D1BC7A185A33DD0CFAE7A1BD96017803
SHA256:8F7E7D51DCCE5C04CC10E5CB01C9E48BD739EAAB68B5C8AC0A0432EF9FCD7FFA
2840absetup.exeC:\Program Files\Avant Browser\Lang\ara.lngini
MD5:61038F502A6715FBA33AE1AB40E26A56
SHA256:8AAF90789E1E99AD332BB1DB9EB3AD30270E6D661E06113DD7B01B791B3E07C5
2840absetup.exeC:\Users\admin\AppData\Local\Temp\avant.exeexecutable
MD5:C4438B733238D03BC149418382216E5C
SHA256:191A847C4A197ED1222129375647079C9EFEB7FEED0669B4563C1DA08341F5A4
2840absetup.exeC:\Program Files\Avant Browser\Lang\cht.lngtext
MD5:F34CFB99AF19E7603C86CEE5CB704037
SHA256:8E55DD4B368333884BF3F51F9D07398EA394129AF28F6B719CD9849D550908EC
2840absetup.exeC:\Users\admin\AppData\Local\Temp\nssFBD6.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
2840absetup.exeC:\Program Files\Avant Browser\Lang\bul.lngtext
MD5:A83F81C9C379A84945DFC4F3B1B75725
SHA256:20C86F148F968E9B241A6DD0182784816F1E978010A44C87B23EB9DDA4899D4B
2840absetup.exeC:\Program Files\Avant Browser\Lang\cro.lngtext
MD5:2BFD515B21BC0E654A1482BE811A2356
SHA256:BFF446A5FF830FAC56A4CB81E0A6D0807FD8BA801A3B9BBCB5CFD14F97C8C649
2840absetup.exeC:\Program Files\Avant Browser\Lang\fre.lngtext
MD5:F838086C21CB3B492326BE6A201A659D
SHA256:1C8BFA2C37E064062FD7D3C21BCEBF1399D55E86ED5D7B39ACE565AF6EEF0369
2840absetup.exeC:\Program Files\Avant Browser\Lang\cat.lngini
MD5:9B222A510940D7F36C3D431D46FA7F89
SHA256:3C6596772AC8D54D9597D1FDF4BAAAA514C1695ACEE2C5687605D04F3EF9C4B9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
76
TCP/UDP connections
26
DNS requests
8
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1348
avant.exe
GET
200
67.229.65.251:80
http://cn.avantbrowser.com/CheckUpdate/newupgrade.txt
unknown
text
5.05 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/UpdateCongratulations.aspx
unknown
html
10.5 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/UpdateCongratulations.aspx
unknown
html
10.5 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/images/cc.gif
unknown
image
9.02 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/js/dd_belatedPNG_0.0.8a-min.js
unknown
text
4.36 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/css/style3.css?ver=20120910
unknown
text
16.4 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/js/pngfix.js
unknown
text
1.21 Kb
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/js/InitPage.js
unknown
text
938 b
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/images/downloader.png
unknown
image
817 b
unknown
3508
ybrowser.exe
GET
200
67.229.65.251:80
http://www.avantbrowser.com/js/dd_belatedPNG_0.0.8a-min.js
unknown
text
4.36 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1348
avant.exe
67.229.65.251:80
cn.avantbrowser.com
VPLSNET
US
unknown
3508
ybrowser.exe
67.229.65.251:80
cn.avantbrowser.com
VPLSNET
US
unknown
2744
avant.exe
67.229.65.251:80
cn.avantbrowser.com
VPLSNET
US
unknown

DNS requests

Domain
IP
Reputation
testing.avantbrowser.comn
unknown
cn.avantbrowser.com
  • 67.229.65.251
unknown
www.avantbrowser.com
  • 67.229.65.251
unknown
dl1.avantbrowser.com
  • 67.229.65.251
unknown

Threats

PID
Process
Class
Message
2744
avant.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info