| File name: | Avira Phantom VPN 2.41.1.25731.exe |
| Full analysis: | https://app.any.run/tasks/c0bb6622-d595-4056-8030-b072093a8dcb |
| Verdict: | Malicious activity |
| Analysis date: | November 10, 2023, 05:26:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BF245B7DB7637E6B2991105F62CC76DE |
| SHA1: | 1D7252929D5C4CB404A34E553B72757729C701D5 |
| SHA256: | C414E764C53A81C6BEB2C393635044661DA238380492C182162B37F3E82A8C89 |
| SSDEEP: | 196608:cI+4fSWrh9ry+5jCyVCavZ7jnEDHGV6uXVM4Fz6Krg:cIBZrXryiC8fnImV1zIKrg |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 37888 |
| InitializedDataSize: | 25600 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9c14 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.41.1.25731 |
| ProductVersionNumber: | 2.41.1.25731 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | lrepacks.net |
| FileDescription: | Avira Phantom VPN Setup |
| FileVersion: | 2.41.1.25731.0 |
| LegalCopyright: | Copyright 2007-2022 LRepacks |
| ProductName: | Avira Phantom VPN |
| ProductVersion: | 2.41.1.25731 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2280 --field-trial-handle=1284,i,6784269326518285386,12519589245995382326,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 528 | "C:\Program Files\Avira\VPN\Avira.NetworkBlocker.exe" | C:\Program Files\Avira\VPN\Avira.NetworkBlocker.exe | — | Avira.VpnService.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 668 | openvpn --verb 3 --register-dns --rdns-internal | C:\Program Files\Avira\VPN\OpenVpn\phantomvpn.exe | — | phantomvpn.exe | |||||||||||
User: SYSTEM Company: The OpenVPN Project Integrity Level: SYSTEM Description: OpenVPN Daemon Exit code: 0 Version: 2.4.9.0 Modules
| |||||||||||||||
| 680 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 888 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3464 --field-trial-handle=1284,i,6784269326518285386,12519589245995382326,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 908 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 988 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2292 --field-trial-handle=1284,i,6784269326518285386,12519589245995382326,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1616 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1024 --field-trial-handle=1360,i,11212838366787982066,2850925021777715291,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1640 | C:\Windows\system32\netsh.exe interface ipv6 add route 2000::/4 interface=18 fe80::8 store=active | C:\Windows\System32\netsh.exe | — | phantomvpn.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1644 | "C:\Program Files\Avira\VPN\Avira.NetworkBlocker.exe" delete | C:\Program Files\Avira\VPN\Avira.NetworkBlocker.exe | — | Avira.VpnService.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3832) Avira.VpnService.exe | Key: | HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3832) Avira.VpnService.exe | Key: | HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3964) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3964) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3964) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3964) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3764) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3728) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3744) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3764) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\tsgqec.dll,-100 |
Value: RD Gateway Quarantine Enforcement Client | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3564 | Avira Phantom VPN 2.41.1.25731.tmp | C:\Program Files\Avira\VPN\Avira.WebAppHost.exe | executable | |
MD5:15251F271169251E9B962C57DD763D31 | SHA256:F3F28506D8419457640BB4E623DB9E78906051FA179180634D3DABDDB6D4F9DB | |||
| 3564 | Avira Phantom VPN 2.41.1.25731.tmp | C:\Users\admin\AppData\Local\Temp\is-AS171.tmp\VclStylesInno.dll | executable | |
MD5:B0CA93CEB050A2FEFF0B19E65072BBB5 | SHA256:0E93313F42084D804B9AC4BE53D844E549CFCAF19E6F276A3B0F82F01B9B2246 | |||
| 3564 | Avira Phantom VPN 2.41.1.25731.tmp | C:\Program Files\Avira\VPN\is-DAK9N.tmp | executable | |
MD5:604479CA6F96A609AF4E655A264EBB4A | SHA256:08BF986A2CA137DA66933C6F6652B3AD6C6BF82293B6DBBE5F685ECBD0180102 | |||
| 3228 | Avira Phantom VPN 2.41.1.25731.exe | C:\Users\admin\AppData\Local\Temp\is-DBCVL.tmp\Avira Phantom VPN 2.41.1.25731.tmp | executable | |
MD5:02C5691AF81933CE36735946E3ED1EA4 | SHA256:E1F5E87796C015E567153DB6B994A35A34B0819B1093D1EA12064EE35102C42D | |||
| 3564 | Avira Phantom VPN 2.41.1.25731.tmp | C:\Users\admin\AppData\Local\Temp\is-AS171.tmp\WizardForm.BitmapImage1.bmp | image | |
MD5:48386BC24D46A3FAC0056AB765A597A1 | SHA256:55E4D15D42D4983C2D3A4E0ABD07EFF703929FAE4DD33115F008BE346D501036 | |||
| 3564 | Avira Phantom VPN 2.41.1.25731.tmp | C:\Users\admin\AppData\Local\Temp\is-AS171.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 3564 | Avira Phantom VPN 2.41.1.25731.tmp | C:\Users\admin\AppData\Local\Temp\is-AS171.tmp\ISTask.dll | executable | |
MD5:86A1311D51C00B278CB7F27796EA442E | SHA256:E916BDF232744E00CBD8D608168A019C9F41A68A7E8390AA48CFB525276C483D | |||
| 3564 | Avira Phantom VPN 2.41.1.25731.tmp | C:\Users\admin\AppData\Local\Temp\is-AS171.tmp\MetroBlue.vsf | binary | |
MD5:295D085196B3DA13BFCD53373F82F8EE | SHA256:CBDC95EB9E7269E0C3E3BDDFD37B0918962795D80BDBA932E46EA16FF5E6CDBF | |||
| 3564 | Avira Phantom VPN 2.41.1.25731.tmp | C:\Program Files\Avira\VPN\Avira.Acp.Resources.dll | executable | |
MD5:093D314F56C72CC419162CF7A5CA7C30 | SHA256:E5C1E86DDB3C64BFB0DC7E2F5CFE4663A87AFE6BBD6DBA1A7EF89BF8147B85F2 | |||
| 3564 | Avira Phantom VPN 2.41.1.25731.tmp | C:\Program Files\Avira\VPN\is-630OT.tmp | executable | |
MD5:918DE89F7BE9C39F437AD6C0951460CD | SHA256:001CA545FF3419F0520E54107A3862AA54E23B540921DA01E2BE10F47F785095 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
3832 | Avira.VpnService.exe | GET | 200 | 2.21.20.155:80 | http://www.msftncsi.com/ncsi.txt | unknown | text | 14 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3832 | Avira.VpnService.exe | 18.196.240.35:443 | api.phantom.avira-vpn.com | AMAZON-02 | DE | unknown |
3832 | Avira.VpnService.exe | 130.211.34.183:443 | api.mixpanel.com | GOOGLE | US | whitelisted |
1856 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2388 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2388 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2388 | msedge.exe | 5.44.221.96:443 | lrepacks.net | Sia Nano IT | LV | unknown |
Domain | IP | Reputation |
|---|---|---|
api.phantom.avira-vpn.com |
| unknown |
api.mixpanel.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
lrepacks.net |
| unknown |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
data-edge.smartscreen.microsoft.com |
| whitelisted |
streetuptowind.com |
| unknown |
lrepacks.ru |
| whitelisted |
translate.google.com |
| whitelisted |