avpagecurlpro22dx64.exe

AVSetup

AV Bros.

This is a setup and installation application. The file has been seen being downloaded from cdn-downloads.avbros.net.
Publisher:
AV Bros.  (signed and verified)

Product:
AVSetup

Description:
AV Bros. Setup Tool Ver. 2.5

Version:
2, 5, 0, 2

MD5:
04b37ed145c8a3719c70c5678e9acc71

SHA-1:
e90d4e692993b567ed6c9136b004fca6f61c7353

SHA-256:
ebcbda7b0f01c21812f0c3f2210882dc179fc51adb9412a5f1410abb67a65ecf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 3:05:30 AM UTC  (today)

File size:
3.3 MB (3,493,504 bytes)

Product version:
2, 5, 0, 2

Copyright:
Copyright (C) 2003-2009

Original file name:
AVSetup

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\avpagecurlpro22dx64.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/18/2009 2:00:00 AM

Valid to:
5/25/2010 1:59:59 AM

Subject:
CN=AV Bros., OU=SECURE APPLICATION DEVELOPMENT, O=AV Bros., L=Petah-Tiqwa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
3DF772FA0E6546EB571209D9B446C029

File PE Metadata
Compilation timestamp:
10/30/2009 2:34:52 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:IQMOQTtRSutFwZsGXWJGEpFeicLL13ndD64NFsmgym5IRt8cQr4iJp7sWdb2Nfgx:IzFwW7q93FB6+smgMUcQkq7sMbSfg8Y

Entry address:
0x30510

Entry point:
48, 83, EC, 28, E8, 47, 91, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 40, 53, 48, 83, EC, 30, 48, 8B, D9, B9, 0E, 00, 00, 00, E8, ED, 5F, 00, 00, 90, 48, 8B, 43, 08, 48, 85, C0, 74, 47, 48, 8B, 0D, 2C, 7D, 02, 00, 48, 89, 4C, 24, 20, 48, 8D, 15, 18, 7D, 02, 00, 48, 85, C9, 74, 1E, 48, 39, 01, 75, 0F, 48, 8B, 41, 08, 48, 89, 42, 08, E8, 79, DC, FF, FF, EB, 0A, 48, 8B, D1, 48, 89, 4C, 24, 20, EB, DD, 48, 8B, 4B, 08, E8, 64, DC, FF, FF, 48, C7, 43, 08...
 
[+]

Code size:
268 KB (274,432 bytes)

The file avpagecurlpro22dx64.exe has been seen being distributed by the following URL.

Scan avpagecurlpro22dx64.exe - Powered by Reason Core Security