File name:

avg_secure_browser_setup.exe.zip

Full analysis: https://app.any.run/tasks/36cf8d94-339f-4706-a406-18fd1d439313
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 08, 2025, 17:14:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
loader
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

016C586857D83B0D8F483172A3CC8EFA

SHA1:

38DC7E51324F0809DC2C92907E035B3CE1D66E6B

SHA256:

026356E20CF36BEB59C08A4A9D8CE0B0FF10EC3CE501BA6EE90350A0FEFEE569

SSDEEP:

98304:QdAqd1x3bygRcc16Qn9SQY6pUFdCWdfIM6W8OoM3DccOL+h7NCI2xwd5dCy0FTe0:CZSj97fWvM9VL4+HqF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6240)
    • Changes the autorun value in the registry

      • setup.exe (PID: 1976)
      • setup.exe (PID: 7080)
      • setup.exe (PID: 4808)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserInstaller.exe (PID: 6344)
      • setup.exe (PID: 1976)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserInstaller.exe (PID: 6408)
      • setup.exe (PID: 7080)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
      • AVGBrowserInstaller.exe (PID: 3108)
      • setup.exe (PID: 4808)
    • The process verifies whether the antivirus software is installed

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdate.exe (PID: 5896)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 6748)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 5244)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7000)
      • AVGBrowserUpdate.exe (PID: 7060)
      • AVGBrowserUpdate.exe (PID: 5496)
      • AVGBrowserUpdate.exe (PID: 6788)
      • AVGBrowserUpdate.exe (PID: 2292)
      • setup.exe (PID: 3688)
      • AVGBrowserInstaller.exe (PID: 6344)
      • setup.exe (PID: 1976)
      • setup.exe (PID: 2596)
      • AVGBrowser.exe (PID: 6772)
      • AVGBrowserCrashHandler64.exe (PID: 2632)
      • AVGBrowserCrashHandler.exe (PID: 1300)
      • setup.exe (PID: 4088)
      • AVGBrowserUpdate.exe (PID: 1760)
      • AVGBrowserUpdate.exe (PID: 6896)
      • AVGBrowserUpdate.exe (PID: 1936)
      • AVGBrowserUpdate.exe (PID: 3724)
      • setup.exe (PID: 4400)
      • setup.exe (PID: 7080)
      • AVGBrowserUpdate.exe (PID: 5188)
      • AVGBrowserInstaller.exe (PID: 6408)
      • AVGBrowser.exe (PID: 2708)
      • AVGBrowserCrashHandler64.exe (PID: 3948)
      • AVGBrowserCrashHandler.exe (PID: 1740)
      • setup.exe (PID: 768)
      • setup.exe (PID: 5352)
      • AVGBrowserUpdate.exe (PID: 1636)
      • AVGBrowserUpdate.exe (PID: 2348)
      • AVGBrowserUpdate.exe (PID: 6672)
      • AVGBrowserInstaller.exe (PID: 3108)
      • setup.exe (PID: 4808)
      • AVGBrowserUpdate.exe (PID: 6700)
      • setup.exe (PID: 3900)
      • AVGBrowserUpdate.exe (PID: 1984)
      • setup.exe (PID: 5500)
      • AVGBrowserCrashHandler.exe (PID: 6520)
      • AVGBrowserCrashHandler64.exe (PID: 5172)
      • setup.exe (PID: 1704)
      • AVGBrowser.exe (PID: 6264)
    • Reads security settings of Internet Explorer

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowser.exe (PID: 6772)
      • AVGBrowserUpdate.exe (PID: 1760)
      • AVGBrowserUpdate.exe (PID: 1636)
    • Reads the BIOS version

      • ajC3EF.exe (PID: 2272)
    • Searches for installed software

      • ajC3EF.exe (PID: 2272)
      • setup.exe (PID: 4088)
      • setup.exe (PID: 1976)
      • setup.exe (PID: 7080)
      • setup.exe (PID: 5352)
      • setup.exe (PID: 1704)
      • setup.exe (PID: 4808)
    • Creates/Modifies COM task schedule object

      • AVGBrowserUpdateComRegisterShell64.exe (PID: 6748)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 5244)
      • AVGBrowserUpdate.exe (PID: 5896)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7000)
      • AVGBrowserUpdate.exe (PID: 2148)
    • Disables SEHOP

      • AVGBrowserUpdate.exe (PID: 2148)
    • Starts itself from another location

      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdate.exe (PID: 1760)
      • AVGBrowserUpdate.exe (PID: 1636)
    • Executes as Windows Service

      • AVGBrowserUpdate.exe (PID: 2292)
      • AVGBrowserUpdate.exe (PID: 5188)
      • AVGBrowserUpdate.exe (PID: 1984)
    • Potential Corporate Privacy Violation

      • AVGBrowserUpdate.exe (PID: 2292)
    • Process requests binary or script from the Internet

      • AVGBrowserUpdate.exe (PID: 2292)
    • Application launched itself

      • setup.exe (PID: 1976)
      • setup.exe (PID: 4088)
      • setup.exe (PID: 7080)
      • setup.exe (PID: 5352)
      • setup.exe (PID: 1704)
      • setup.exe (PID: 4808)
    • There is functionality for taking screenshot (YARA)

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
    • Creates a software uninstall entry

      • setup.exe (PID: 1976)
      • setup.exe (PID: 7080)
      • setup.exe (PID: 4808)
    • Reads the date of Windows installation

      • AVGBrowser.exe (PID: 6772)
      • AVGBrowser.exe (PID: 2708)
      • AVGBrowser.exe (PID: 6264)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6240)
    • The sample compiled with arabic language support

      • WinRAR.exe (PID: 6240)
      • avg_secure_browser_setup.exe (PID: 2468)
      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • setup.exe (PID: 7080)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • Reads the computer name

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdate.exe (PID: 5896)
      • AVGBrowserUpdate.exe (PID: 7060)
      • AVGBrowserUpdate.exe (PID: 6788)
      • AVGBrowserUpdate.exe (PID: 5496)
      • AVGBrowserUpdate.exe (PID: 2292)
      • AVGBrowserInstaller.exe (PID: 6344)
      • setup.exe (PID: 1976)
      • setup.exe (PID: 4088)
      • AVGBrowser.exe (PID: 6772)
      • AVGBrowserUpdate.exe (PID: 1760)
      • AVGBrowserUpdate.exe (PID: 3724)
      • AVGBrowserUpdate.exe (PID: 5188)
      • AVGBrowserUpdate.exe (PID: 1936)
      • AVGBrowserInstaller.exe (PID: 6408)
      • AVGBrowserUpdate.exe (PID: 6896)
      • setup.exe (PID: 7080)
      • setup.exe (PID: 5352)
      • AVGBrowser.exe (PID: 2708)
      • AVGBrowserUpdate.exe (PID: 1636)
      • AVGBrowserUpdate.exe (PID: 2348)
      • AVGBrowserUpdate.exe (PID: 6672)
      • AVGBrowserUpdate.exe (PID: 6700)
      • AVGBrowserUpdate.exe (PID: 1984)
      • AVGBrowserInstaller.exe (PID: 3108)
      • setup.exe (PID: 4808)
      • setup.exe (PID: 1704)
      • AVGBrowser.exe (PID: 6264)
    • Manual execution by a user

      • avg_secure_browser_setup.exe (PID: 2468)
    • Reads Environment values

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
    • Checks supported languages

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdate.exe (PID: 5896)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 6748)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 5244)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7000)
      • AVGBrowserUpdate.exe (PID: 7060)
      • AVGBrowserUpdate.exe (PID: 6788)
      • AVGBrowserUpdate.exe (PID: 5496)
      • AVGBrowserUpdate.exe (PID: 2292)
      • setup.exe (PID: 3688)
      • AVGBrowserInstaller.exe (PID: 6344)
      • setup.exe (PID: 1976)
      • setup.exe (PID: 4088)
      • setup.exe (PID: 2596)
      • AVGBrowser.exe (PID: 6772)
      • AVGBrowserCrashHandler64.exe (PID: 2632)
      • AVGBrowserCrashHandler.exe (PID: 1300)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdate.exe (PID: 1760)
      • AVGBrowserUpdate.exe (PID: 6896)
      • AVGBrowserUpdate.exe (PID: 1936)
      • AVGBrowserUpdate.exe (PID: 3724)
      • AVGBrowserUpdate.exe (PID: 5188)
      • setup.exe (PID: 7080)
      • setup.exe (PID: 4400)
      • AVGBrowserInstaller.exe (PID: 6408)
      • setup.exe (PID: 5352)
      • setup.exe (PID: 768)
      • AVGBrowser.exe (PID: 2708)
      • AVGBrowserCrashHandler64.exe (PID: 3948)
      • AVGBrowserCrashHandler.exe (PID: 1740)
      • AVGBrowserUpdate.exe (PID: 1636)
      • AVGBrowserUpdate.exe (PID: 6700)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
      • AVGBrowserUpdate.exe (PID: 2348)
      • AVGBrowserUpdate.exe (PID: 6672)
      • AVGBrowserInstaller.exe (PID: 3108)
      • setup.exe (PID: 4808)
      • AVGBrowserUpdate.exe (PID: 1984)
      • setup.exe (PID: 3900)
      • setup.exe (PID: 1704)
      • setup.exe (PID: 5500)
      • AVGBrowser.exe (PID: 6264)
      • AVGBrowserCrashHandler64.exe (PID: 5172)
      • AVGBrowserCrashHandler.exe (PID: 6520)
    • Create files in a temporary directory

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdate.exe (PID: 2292)
    • The sample compiled with english language support

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserInstaller.exe (PID: 6344)
      • setup.exe (PID: 1976)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserInstaller.exe (PID: 6408)
      • setup.exe (PID: 7080)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
      • AVGBrowserInstaller.exe (PID: 3108)
      • setup.exe (PID: 4808)
    • Process checks computer location settings

      • avg_secure_browser_setup.exe (PID: 2468)
      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowser.exe (PID: 6772)
      • AVGBrowserUpdate.exe (PID: 1760)
      • AVGBrowser.exe (PID: 2708)
      • AVGBrowserUpdate.exe (PID: 1636)
      • AVGBrowser.exe (PID: 6264)
    • Creates files or folders in the user directory

      • ajC3EF.exe (PID: 2272)
      • setup.exe (PID: 4088)
    • Checks proxy server information

      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdate.exe (PID: 6788)
      • AVGBrowserUpdate.exe (PID: 3724)
      • AVGBrowserUpdate.exe (PID: 6672)
      • slui.exe (PID: 4760)
    • Reads the machine GUID from the registry

      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdate.exe (PID: 2292)
      • AVGBrowserUpdate.exe (PID: 5188)
      • AVGBrowserUpdate.exe (PID: 1760)
      • AVGBrowserUpdate.exe (PID: 1636)
      • AVGBrowserUpdate.exe (PID: 1984)
    • Creates files in the program directory

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdate.exe (PID: 2292)
      • setup.exe (PID: 1976)
      • AVGBrowserInstaller.exe (PID: 6344)
      • setup.exe (PID: 4088)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdate.exe (PID: 5188)
      • AVGBrowserInstaller.exe (PID: 6408)
      • setup.exe (PID: 7080)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
      • setup.exe (PID: 5352)
      • AVGBrowserUpdate.exe (PID: 1984)
      • AVGBrowserInstaller.exe (PID: 3108)
      • setup.exe (PID: 4808)
      • setup.exe (PID: 1704)
    • Reads the software policy settings

      • ajC3EF.exe (PID: 2272)
      • AVGBrowserUpdate.exe (PID: 6788)
      • AVGBrowserUpdate.exe (PID: 2292)
      • AVGBrowserUpdate.exe (PID: 3724)
      • AVGBrowserUpdate.exe (PID: 5188)
      • AVGBrowserUpdate.exe (PID: 6672)
      • AVGBrowserUpdate.exe (PID: 1984)
      • slui.exe (PID: 4760)
    • The sample compiled with german language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with bulgarian language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with japanese language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with korean language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with slovak language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with russian language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with portuguese language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with polish language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with swedish language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with turkish language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with chinese language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with czech language support

      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with Indonesian language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with french language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • The sample compiled with Italian language support

      • AVGBrowserUpdateSetup.exe (PID: 2800)
      • AVGBrowserUpdate.exe (PID: 2148)
      • AVGBrowserUpdateSetup.exe (PID: 3800)
      • AVGBrowserUpdateSetup.exe (PID: 5708)
    • Launching a file from a Registry key

      • setup.exe (PID: 1976)
      • setup.exe (PID: 7080)
      • setup.exe (PID: 4808)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2025:07:08 17:13:22
ZipCRC: 0xd5cae935
ZipCompressedSize: 6144998
ZipUncompressedSize: 6240576
ZipFileName: avg_secure_browser_setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
186
Monitored processes
50
Malicious processes
44
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs avg_secure_browser_setup.exe no specs ajc3ef.exe avgbrowserupdatesetup.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe avgbrowserinstaller.exe no specs setup.exe no specs setup.exe no specs slui.exe setup.exe no specs setup.exe no specs avgbrowser.exe no specs avgbrowsercrashhandler.exe no specs avgbrowsercrashhandler64.exe no specs avgbrowserupdatesetup.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe avgbrowserinstaller.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs avgbrowser.exe no specs avgbrowsercrashhandler.exe no specs avgbrowsercrashhandler64.exe no specs avgbrowserupdatesetup.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe avgbrowserinstaller.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs avgbrowser.exe no specs avgbrowsercrashhandler.exe no specs avgbrowsercrashhandler64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
768"C:\Program Files (x86)\AVG\Browser\Update\Install\{3AD5CAD0-7AC2-4618-9451-1C81B13CA2E0}\CR_BE1C5.tmp\setup.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --url=fake_url --annotation=plat=Win64 --annotation=prod=AVG --annotation=ver=137.0.30835.121 --initial-client-data=0x240,0x244,0x248,0x21c,0x24c,0x7ff609a7c478,0x7ff609a7c484,0x7ff609a7c490C:\Program Files (x86)\AVG\Browser\Update\Install\{3AD5CAD0-7AC2-4618-9451-1C81B13CA2E0}\CR_BE1C5.tmp\setup.exesetup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Secure Browser Installer
Exit code:
0
Version:
137.0.30835.121
Modules
Images
c:\program files (x86)\avg\browser\update\install\{3ad5cad0-7ac2-4618-9451-1c81b13ca2e0}\cr_be1c5.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
1300"C:\Program Files (x86)\AVG\Browser\Update\1.8.1582.3\AVGBrowserCrashHandler.exe"C:\Program Files (x86)\AVG\Browser\Update\1.8.1582.3\AVGBrowserCrashHandler.exeAVGBrowserUpdate.exe
User:
SYSTEM
Company:
AVG Technologies
Integrity Level:
SYSTEM
Description:
AVG Browser Crash Handler
Exit code:
0
Version:
1.8.1582.3
Modules
Images
c:\program files (x86)\avg\browser\update\1.8.1582.3\avgbrowsercrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\kernel.appcore.dll
c:\windows\syswow64\msvcrt.dll
1636"C:\Program Files (x86)\GUM842F.tmp\AVGBrowserUpdate.exe" /silent /install "bundlename=AVG Secure Browser&appguid={48F69C39-1356-4A7B-A899-70E3539D4982}&appname=AVG Secure Browser&needsadmin=true&lang=en-US&brand=6103&installargs=--make-chrome-default --force-default-win10 --auto-import-data%3Dmsedge --import-cookies&hostprefix=3-"C:\Program Files (x86)\GUM842F.tmp\AVGBrowserUpdate.exeAVGBrowserUpdateSetup.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Browser
Exit code:
0
Version:
1.8.1582.3
Modules
Images
c:\program files (x86)\gum842f.tmp\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1704"C:\Program Files (x86)\AVG\Browser\Update\Install\{93319733-FE04-43D8-AAEC-CF4A4FD0365E}\CR_238EE.tmp\setup.exe" --system-level --verbose-logging --create-shortcuts=0 --install-level=1C:\Program Files (x86)\AVG\Browser\Update\Install\{93319733-FE04-43D8-AAEC-CF4A4FD0365E}\CR_238EE.tmp\setup.exesetup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Secure Browser Installer
Exit code:
73
Version:
137.0.30835.121
Modules
Images
c:\program files (x86)\avg\browser\update\install\{93319733-fe04-43d8-aaec-cf4a4fd0365e}\cr_238ee.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
1740"C:\Program Files (x86)\AVG\Browser\Update\1.8.1582.3\AVGBrowserCrashHandler.exe"C:\Program Files (x86)\AVG\Browser\Update\1.8.1582.3\AVGBrowserCrashHandler.exeAVGBrowserUpdate.exe
User:
SYSTEM
Company:
AVG Technologies
Integrity Level:
SYSTEM
Description:
AVG Browser Crash Handler
Exit code:
0
Version:
1.8.1582.3
Modules
Images
c:\program files (x86)\avg\browser\update\1.8.1582.3\avgbrowsercrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\kernel.appcore.dll
c:\windows\syswow64\msvcrt.dll
1760"C:\Program Files (x86)\GUM4002.tmp\AVGBrowserUpdate.exe" /silent /install "bundlename=AVG Secure Browser&appguid={48F69C39-1356-4A7B-A899-70E3539D4982}&appname=AVG Secure Browser&needsadmin=true&lang=en-US&brand=6103&installargs=--make-chrome-default --force-default-win10 --auto-import-data%3Dmsedge --import-cookies&hostprefix=2-"C:\Program Files (x86)\GUM4002.tmp\AVGBrowserUpdate.exeAVGBrowserUpdateSetup.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Browser
Exit code:
0
Version:
1.8.1582.3
Modules
Images
c:\program files (x86)\gum4002.tmp\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1936"C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe" /handoff "bundlename=AVG Secure Browser&appguid={48F69C39-1356-4A7B-A899-70E3539D4982}&appname=AVG Secure Browser&needsadmin=true&lang=en-US&brand=6103&installargs=--make-chrome-default --force-default-win10 --auto-import-data%3Dmsedge --import-cookies&hostprefix=2-" /installsource otherinstallcmd /sessionid "{F72F58AD-DAD9-4046-B99D-C3F4EC3DC132}" /silentC:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exeAVGBrowserUpdate.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Browser
Exit code:
0
Version:
1.8.1582.3
Modules
Images
c:\program files (x86)\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1976"C:\Program Files (x86)\AVG\Browser\Update\Install\{CF0789D8-6AD1-4FAF-8A23-7E65102084A4}\CR_A4DE2.tmp\setup.exe" --install-archive="C:\Program Files (x86)\AVG\Browser\Update\Install\{CF0789D8-6AD1-4FAF-8A23-7E65102084A4}\CR_A4DE2.tmp\SECURE.PACKED.7Z" --chrome --do-not-launch-chrome --hide-browser-override --show-developer-mode --suppress-first-run-bubbles --adblock-mode-default=0 --default-search-id=3 --default-search=bing.com --make-chrome-default --force-default-win10 --auto-import-data=msedge --import-cookies --system-levelC:\Program Files (x86)\AVG\Browser\Update\Install\{CF0789D8-6AD1-4FAF-8A23-7E65102084A4}\CR_A4DE2.tmp\setup.exeAVGBrowserInstaller.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Secure Browser Installer
Exit code:
0
Version:
137.0.30835.121
Modules
Images
c:\program files (x86)\avg\browser\update\install\{cf0789d8-6ad1-4faf-8a23-7e65102084a4}\cr_a4de2.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
1984"C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe" /svcC:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe
services.exe
User:
SYSTEM
Company:
AVG Technologies
Integrity Level:
SYSTEM
Description:
AVG Browser
Exit code:
0
Version:
1.8.1582.3
Modules
Images
c:\program files (x86)\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2148"C:\Program Files (x86)\GUME3C8.tmp\AVGBrowserUpdate.exe" /silent /install "bundlename=AVG Secure Browser&appguid={48F69C39-1356-4A7B-A899-70E3539D4982}&appname=AVG Secure Browser&needsadmin=true&lang=en-US&brand=6103&installargs=--make-chrome-default --force-default-win10 --auto-import-data%3Dmsedge --import-cookies"C:\Program Files (x86)\GUME3C8.tmp\AVGBrowserUpdate.exeAVGBrowserUpdateSetup.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Browser
Exit code:
0
Version:
1.8.1582.3
Modules
Images
c:\program files (x86)\gume3c8.tmp\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
22 582
Read events
20 464
Write events
1 962
Delete events
156

Modification events

(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\avg_secure_browser_setup.exe.zip
(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(6240) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
343
Suspicious files
24
Text files
13
Unknown types
10

Dropped files

PID
Process
Filename
Type
2468avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nshBA97.tmp\JsisPlugins.dllexecutable
MD5:3F4F65C3551435AA4F70B23DB238E027
SHA256:3D52F17598297580CC04E8698010D8234B199250803F826FA03031A8F8507E7F
6240WinRAR.exeC:\Users\admin\Desktop\avg_secure_browser_setup.exeexecutable
MD5:0EDCA42152E6AFE34FE2606C116504D5
SHA256:C287F9209D29778B326C66B9AC4AB2AC3A9BB249D14EB17F470CA4B053215DE9
2468avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nshBA97.tmp\inetc.dllexecutable
MD5:7FB1BBFF6382A4D6143C76A5453BEBB7
SHA256:90B21F42D547E2F1849ABE573A1E87353C9FA534EEFD4576FB6D4ED6B7A449DC
2468avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nshBA97.tmp\thirdparty.dllexecutable
MD5:080EEA7A54AEB7EA3D016645DEC05BD6
SHA256:84CAB1C6DF2EDDCED4E60FC1E158B772F7B766D0FAED27E33BD5F0EA69903BF4
2468avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nshBA97.tmp\nsJSON.dllexecutable
MD5:18662C1ACB667A9DB5FB9E90AA0F5DC8
SHA256:608D4AEFD5C5184BC109CBD94A5D4C8883A4AE6CEDF81CFC3028D2570A849A66
2468avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nshBA97.tmp\jsis.dllexecutable
MD5:465D5265BFE5B90F821235F0E13BA5E4
SHA256:ECCA190CE5307CEE4B4F02062BA0FCA6AE2D0FA0D5AC223C726EAB31D55B822D
2468avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nshBA97.tmp\Midex.dllexecutable
MD5:00FD199D6B8D08446F4862C31B191CA7
SHA256:1B2A0DE815E288161F0A156B4D1F17F06D2F4840B71D9D1903AD1284192CDE24
2272ajC3EF.exeC:\Users\admin\AppData\Local\Temp\nsxC67E.tmp\jsis.dllexecutable
MD5:465D5265BFE5B90F821235F0E13BA5E4
SHA256:ECCA190CE5307CEE4B4F02062BA0FCA6AE2D0FA0D5AC223C726EAB31D55B822D
2468avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nshBA97.tmp\sciterui.dllexecutable
MD5:9819A8217B853C8B7E2AA340BD0E9088
SHA256:FE2683CEAE74F486334A19BA4DC1A5ACA75FB79806E84FF44B0B5D263BA8B1CC
2272ajC3EF.exeC:\Users\admin\AppData\Local\Temp\nsxC67E.tmp\FF.places.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
32
DNS requests
22
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2212
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6336
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2272
ajC3EF.exe
GET
200
142.250.186.131:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
2272
ajC3EF.exe
GET
200
142.250.186.131:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6336
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2272
ajC3EF.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
2272
ajC3EF.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
2272
ajC3EF.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAQ1YD96iIrhbAWwDxU8xvw%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1976
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
1268
svchost.exe
2.16.253.202:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2212
svchost.exe
20.190.159.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2212
svchost.exe
23.63.118.230:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 2.16.253.202
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.159.130
  • 40.126.31.73
  • 20.190.159.128
  • 20.190.159.129
  • 20.190.159.0
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 23.63.118.230
  • 2.23.77.188
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.11
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
stats.avgbrowser.com
  • 172.67.41.145
  • 104.22.63.125
  • 104.22.62.125
unknown

Threats

PID
Process
Class
Message
2292
AVGBrowserUpdate.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
No debug info