File name:

Avogadro-1.2.0n-win32.exe

Full analysis: https://app.any.run/tasks/12839f1a-0b06-4c34-b20c-8c6729711c7b
Verdict: Malicious activity
Analysis date: December 19, 2019, 17:40:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

2E0D593147C0A7748C25E9A78E2EE3F5

SHA1:

9B23BB56695A92AB4EE9A0AE87702CB4DCFE44F3

SHA256:

BB15E67FC527C0D28DE32ABB2D0D0EE161829A64F3BF4887B8D786E3B0DAF270

SSDEEP:

196608:Za5Ksqa8AzfAcpuZRyMnTZFcQvyxyLPBDTwUqX8EvY/1nEJbu2eS1kAwlDeHs:Za5KsgRPHLPBoU28j1EJRZSAw9Cs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Avogadro-1.2.0n-win32.exe (PID: 912)
      • avogadro.exe (PID: 3316)
    • Application was dropped or rewritten from another process

      • avogadro.exe (PID: 3316)
  • SUSPICIOUS

    • Modifies the open verb of a shell class

      • Avogadro-1.2.0n-win32.exe (PID: 912)
    • Creates a software uninstall entry

      • Avogadro-1.2.0n-win32.exe (PID: 912)
    • Executable content was dropped or overwritten

      • Avogadro-1.2.0n-win32.exe (PID: 912)
    • Creates files in the program directory

      • Avogadro-1.2.0n-win32.exe (PID: 912)
  • INFO

    • Manual execution by user

      • avogadro.exe (PID: 3316)
    • Dropped object may contain Bitcoin addresses

      • Avogadro-1.2.0n-win32.exe (PID: 912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 23:50:41+01:00
PEType: PE32
LinkerVersion: 6
CodeSize: 23040
InitializedDataSize: 119808
UninitializedDataSize: 1024
EntryPoint: 0x30cb
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 05-Dec-2009 22:50:41
Detected languages:
  • English - United States

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 05-Dec-2009 22:50:41
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000058D2
0x00005A00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.4331
.rdata
0x00007000
0x00001190
0x00001200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.17976
.data
0x00009000
0x0001AF78
0x00000400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.6178
.ndata
0x00024000
0x0000C000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00030000
0x0004E8A0
0x0004EA00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
2.3445

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.21482
958
UNKNOWN
English - United States
RT_MANIFEST
2
2.9398
16936
UNKNOWN
English - United States
RT_ICON
3
3.61392
9640
UNKNOWN
English - United States
RT_ICON
4
3.76809
4264
UNKNOWN
English - United States
RT_ICON
5
4.56744
2440
UNKNOWN
English - United States
RT_ICON
6
4.63448
1128
UNKNOWN
English - United States
RT_ICON
7
0
296
UNKNOWN
English - United States
RT_ICON
102
2.71813
180
UNKNOWN
English - United States
RT_DIALOG
103
2.44281
104
UNKNOWN
English - United States
RT_GROUP_ICON
105
2.67385
512
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
VERSION.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start avogadro-1.2.0n-win32.exe avogadro.exe avogadro-1.2.0n-win32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
912"C:\Users\admin\Desktop\Avogadro-1.2.0n-win32.exe" C:\Users\admin\Desktop\Avogadro-1.2.0n-win32.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\avogadro-1.2.0n-win32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3316"C:\Program Files\Avogadro\bin\avogadro.exe" C:\Program Files\Avogadro\bin\avogadro.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\avogadro\bin\avogadro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avogadro\bin\qtopengl4.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3852"C:\Users\admin\Desktop\Avogadro-1.2.0n-win32.exe" C:\Users\admin\Desktop\Avogadro-1.2.0n-win32.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\avogadro-1.2.0n-win32.exe
c:\systemroot\system32\ntdll.dll
Total events
478
Read events
171
Write events
306
Delete events
1

Modification events

(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Humanity\Avogadro
Operation:writeName:
Value:
C:\Program Files\Avogadro
(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Avogadro
Operation:writeName:DisplayName
Value:
Avogadro
(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Avogadro
Operation:writeName:DisplayVersion
Value:
1.2.0
(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Avogadro
Operation:writeName:Publisher
Value:
Humanity
(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Avogadro
Operation:writeName:UninstallString
Value:
C:\Program Files\Avogadro\Uninstall.exe
(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Avogadro
Operation:writeName:NoRepair
Value:
1
(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Avogadro
Operation:writeName:NoModify
Value:
1
(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Avogadro
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Avogadro\bin\\Avogadro.exe
(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Avogadro
Operation:writeName:HelpLink
Value:
http:\\avogadro.cc
(PID) Process:(912) Avogadro-1.2.0n-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Avogadro
Operation:writeName:URLInfoAbout
Value:
http:\\avogadro.cc
Executable files
89
Suspicious files
0
Text files
1 113
Unknown types
5

Dropped files

PID
Process
Filename
Type
912Avogadro-1.2.0n-win32.exeC:\Users\admin\AppData\Local\Temp\nsbBDEC.tmp\ioSpecial.initext
MD5:
SHA256:
912Avogadro-1.2.0n-win32.exeC:\Users\admin\AppData\Local\Temp\nsbBDEC.tmp\NSIS.InstallOptions.initext
MD5:
SHA256:
912Avogadro-1.2.0n-win32.exeC:\Program Files\Avogadro\bin\QtNetwork4.dllexecutable
MD5:B02101ED0160F8A2F604D94B5E4F10CE
SHA256:817B2F43D119B88E14A7AFFFF00FCF8FBCDE96E8A3A37D8BC7F23742A0247950
912Avogadro-1.2.0n-win32.exeC:\Program Files\Avogadro\bin\SMARTS_InteLigand.txttext
MD5:B051E264E2244F2C3C0BBC6AE5584BA0
SHA256:3A34895F4A8E0805CB6077D4649CBBD994FC6164DC0FEDD60DAA065C8A280770
912Avogadro-1.2.0n-win32.exeC:\Users\admin\AppData\Local\Temp\nsbBDEC.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
912Avogadro-1.2.0n-win32.exeC:\Program Files\Avogadro\bin\UFF.prmtext
MD5:83A015F12C8FBA357166539B39169DAD
SHA256:D9A4FE7415E9D9DB2FB14B0B1B141EB6B51F71A1114A107866F2337E26C46609
912Avogadro-1.2.0n-win32.exeC:\Program Files\Avogadro\bin\atomtyp.txttext
MD5:A245CB78B08E3552DBBED7D26EDB94EC
SHA256:C6C3C06AA36F2605D78DCD8BC4ED77C160C35F24D2CF75A18A28EDCFE4B372B4
912Avogadro-1.2.0n-win32.exeC:\Users\admin\AppData\Local\Temp\nsbBDEC.tmp\modern-header.bmpimage
MD5:940C56737BF9BB69CE7A31C623D4E87A
SHA256:766A893FE962AEFD27C574CB05F25CF895D3FC70A00DB5A6FA73D573F571AEFC
912Avogadro-1.2.0n-win32.exeC:\Users\admin\AppData\Local\Temp\nsbBDEC.tmp\UserInfo.dllexecutable
MD5:7579ADE7AE1747A31960A228CE02E666
SHA256:564C80DEC62D76C53497C40094DB360FF8A36E0DC1BDA8383D0F9583138997F5
912Avogadro-1.2.0n-win32.exeC:\Users\admin\AppData\Local\Temp\nsbBDEC.tmp\InstallOptions.dllexecutable
MD5:325B008AEC81E5AAA57096F05D4212B5
SHA256:C9CD5C9609E70005926AE5171726A4142FFBCCCC771D307EFCD195DAFC1E6B4B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
avogadro.exe
"Avogadro version: 1.2.0 Git: LibAvogadro version: 1.2.0 Git: "
avogadro.exe
BABEL_LIBDIR C:/Program Files/Avogadro/bin/../lib/openbabel
avogadro.exe
Locale: "en_US"
avogadro.exe
Libavogadro translations not found.
avogadro.exe
About to test OpenGL capabilities.
avogadro.exe
System has OpenGL support.
avogadro.exe
Searching for plugins in "C:/Program Files/Avogadro/lib/avogadro/1_2"
avogadro.exe
Searching for plugins in "C:/Program Files/Avogadro/lib/avogadro/1_2/colors"
avogadro.exe
Loading plugins: "C:/Program Files/Avogadro/bin/../lib/avogadro/1_2"
avogadro.exe
Searching for plugins in "C:/Program Files/Avogadro/lib/avogadro/1_2/engines"