File name:

foca-3.4.7.1-installer_MHc3-91.exe

Full analysis: https://app.any.run/tasks/5cdcc339-e88a-4de6-82e7-2107b798784f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 14, 2025, 00:38:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
loader
evasion
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

C1FE2147288DF9F805ADD851B0A250FB

SHA1:

BBD4CF561810B2A5F6B57FBC4878CA27B11620B6

SHA256:

02E032F5112CC1AAAB727F99B059736F0B4C30B4895C66D93CA29B2ACBDAADAF

SSDEEP:

98304:wyRr3UJ1IqsdPDMJoPvpyUwyFgS8S7ce/Unba+O+CB3jD9hl:y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • avg_secure_browser_setup.exe (PID: 7856)
      • AVGBrowser.exe (PID: 7520)
    • Actions looks like stealing of personal data

      • avg_secure_browser_setup.exe (PID: 7856)
      • AVGBrowser.exe (PID: 7520)
    • Changes the autorun value in the registry

      • setup.exe (PID: 1912)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 7520)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
    • Executable content was dropped or overwritten

      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • avg_secure_browser_setup.exe (PID: 7856)
      • saBSI.exe (PID: 7812)
      • saBSI.exe (PID: 7968)
      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
      • setup.exe (PID: 1912)
      • AVGBrowserInstaller.exe (PID: 5112)
    • Reads security settings of Internet Explorer

      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • saBSI.exe (PID: 7968)
      • avg_secure_browser_setup.exe (PID: 7856)
      • saBSI.exe (PID: 7812)
      • AVGBrowserUpdate.exe (PID: 6032)
      • AVGBrowserProtect.exe (PID: 7104)
      • chrmstp.exe (PID: 680)
    • The process verifies whether the antivirus software is installed

      • avg_secure_browser_setup.exe (PID: 7856)
      • saBSI.exe (PID: 7968)
      • AVGBrowserUpdate.exe (PID: 6032)
      • AVGBrowserUpdate.exe (PID: 4980)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 2392)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 536)
      • AVGBrowserUpdate.exe (PID: 780)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 5392)
      • AVGBrowserUpdate.exe (PID: 5416)
      • AVGBrowserUpdate.exe (PID: 1180)
      • AVGBrowserUpdate.exe (PID: 6744)
      • AVGBrowserInstaller.exe (PID: 5112)
      • setup.exe (PID: 2564)
      • AVGBrowserCrashHandler.exe (PID: 7384)
      • AVGBrowserCrashHandler64.exe (PID: 7344)
      • AVGBrowser.exe (PID: 5352)
      • setup.exe (PID: 1912)
      • AVGBrowser.exe (PID: 7012)
      • AVGBrowser.exe (PID: 1096)
      • elevation_service.exe (PID: 6752)
      • AVGBrowser.exe (PID: 5400)
      • elevation_service.exe (PID: 6044)
      • AVGBrowser.exe (PID: 6656)
      • AVGBrowser.exe (PID: 968)
      • AVGBrowser.exe (PID: 4740)
      • AVGBrowser.exe (PID: 7976)
      • AVGBrowser.exe (PID: 7988)
      • AVGBrowser.exe (PID: 6828)
      • AVGBrowser.exe (PID: 8052)
      • AVGBrowser.exe (PID: 4408)
      • AVGBrowser.exe (PID: 2088)
      • AVGBrowser.exe (PID: 4164)
      • AVGBrowser.exe (PID: 8036)
      • elevation_service.exe (PID: 7544)
      • AVGBrowser.exe (PID: 7048)
      • AVGBrowser.exe (PID: 6456)
      • AVGBrowser.exe (PID: 5968)
      • AVGBrowser.exe (PID: 2104)
      • AVGBrowser.exe (PID: 4628)
      • AVGBrowser.exe (PID: 3804)
      • AVGBrowser.exe (PID: 1600)
      • AVGBrowser.exe (PID: 7468)
      • AVGBrowser.exe (PID: 7380)
      • AVGBrowser.exe (PID: 5548)
      • AVGBrowser.exe (PID: 7364)
      • AVGBrowser.exe (PID: 7360)
      • AVGBrowser.exe (PID: 660)
      • AVGBrowser.exe (PID: 4880)
      • AVGBrowser.exe (PID: 7768)
      • AVGBrowser.exe (PID: 728)
      • AVGBrowser.exe (PID: 1676)
      • AVGBrowser.exe (PID: 5332)
      • AVGBrowser.exe (PID: 8000)
      • AVGBrowser.exe (PID: 7848)
      • AVGBrowser.exe (PID: 7936)
      • AVGBrowser.exe (PID: 7968)
      • AVGBrowser.exe (PID: 6972)
      • AVGBrowser.exe (PID: 8164)
      • AVGBrowser.exe (PID: 1568)
      • AVGBrowser.exe (PID: 7684)
      • AVGBrowser.exe (PID: 7700)
      • AVGBrowser.exe (PID: 7192)
      • AVGBrowser.exe (PID: 7556)
      • AVGBrowser.exe (PID: 632)
      • AVGBrowser.exe (PID: 2772)
      • AVGBrowser.exe (PID: 7716)
      • AVGBrowser.exe (PID: 7672)
      • AVGBrowser.exe (PID: 6300)
      • AVGBrowser.exe (PID: 8092)
      • AVGBrowser.exe (PID: 2084)
      • AVGBrowser.exe (PID: 7084)
      • AVGBrowser.exe (PID: 4012)
      • AVGBrowser.exe (PID: 4180)
      • AVGBrowserProtect.exe (PID: 7104)
      • AVGBrowser.exe (PID: 4784)
      • AVGBrowser.exe (PID: 7416)
      • AVGBrowser.exe (PID: 3192)
      • AVGBrowser.exe (PID: 7424)
      • setup.exe (PID: 7360)
      • setup.exe (PID: 6736)
      • AVGBrowser.exe (PID: 2616)
      • AVGBrowser.exe (PID: 6740)
      • AVGBrowser.exe (PID: 7520)
      • AVGBrowser.exe (PID: 7668)
      • AVGBrowser.exe (PID: 7712)
      • elevation_service.exe (PID: 7800)
      • AVGBrowser.exe (PID: 968)
      • AVGBrowser.exe (PID: 7532)
      • AVGBrowser.exe (PID: 7204)
      • AVGBrowser.exe (PID: 3976)
      • AVGBrowser.exe (PID: 8092)
      • AVGBrowser.exe (PID: 872)
      • AVGBrowser.exe (PID: 2064)
      • AVGBrowser.exe (PID: 3800)
      • AVGBrowser.exe (PID: 5864)
      • AVGBrowser.exe (PID: 1052)
      • AVGBrowser.exe (PID: 6044)
      • AVGBrowser.exe (PID: 5984)
      • chrmstp.exe (PID: 5868)
      • chrmstp.exe (PID: 680)
      • chrmstp.exe (PID: 664)
      • chrmstp.exe (PID: 1228)
      • AVGBrowser.exe (PID: 5324)
      • AVGBrowser.exe (PID: 6940)
      • AVGBrowser.exe (PID: 7688)
      • AVGBrowser.exe (PID: 5408)
      • AVGBrowser.exe (PID: 7644)
      • AVGBrowser.exe (PID: 2136)
      • AVGBrowser.exe (PID: 2984)
      • AVGBrowser.exe (PID: 2092)
    • Reads the BIOS version

      • avg_secure_browser_setup.exe (PID: 7856)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 7520)
    • Adds/modifies Windows certificates

      • saBSI.exe (PID: 7812)
    • Searches for installed software

      • avg_secure_browser_setup.exe (PID: 7856)
      • setup.exe (PID: 1912)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 8036)
      • setup.exe (PID: 7360)
      • AVGBrowser.exe (PID: 7520)
      • chrmstp.exe (PID: 680)
      • chrmstp.exe (PID: 664)
    • Disables SEHOP

      • AVGBrowserUpdate.exe (PID: 6032)
    • Creates/Modifies COM task schedule object

      • AVGBrowserUpdateComRegisterShell64.exe (PID: 536)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 2392)
      • AVGBrowserUpdate.exe (PID: 780)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 5392)
      • AVGBrowserUpdate.exe (PID: 6032)
    • Starts itself from another location

      • AVGBrowserUpdate.exe (PID: 6032)
    • Executes as Windows Service

      • AVGBrowserUpdate.exe (PID: 6744)
      • elevation_service.exe (PID: 6044)
      • elevation_service.exe (PID: 6752)
      • elevation_service.exe (PID: 7544)
      • elevation_service.exe (PID: 7800)
    • Process requests binary or script from the Internet

      • AVGBrowserUpdate.exe (PID: 6744)
    • There is functionality for taking screenshot (YARA)

      • avg_secure_browser_setup.exe (PID: 7856)
      • AVGBrowserUpdate.exe (PID: 1180)
      • AVGBrowserUpdate.exe (PID: 6032)
      • AVGBrowserUpdate.exe (PID: 6744)
    • Potential Corporate Privacy Violation

      • AVGBrowserUpdate.exe (PID: 6744)
    • Application launched itself

      • setup.exe (PID: 1912)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 4180)
      • setup.exe (PID: 7360)
      • AVGBrowser.exe (PID: 7520)
      • chrmstp.exe (PID: 664)
      • chrmstp.exe (PID: 680)
      • AVGBrowser.exe (PID: 5324)
    • Creates a software uninstall entry

      • setup.exe (PID: 1912)
      • avg_secure_browser_setup.exe (PID: 7856)
      • elevation_service.exe (PID: 6044)
      • elevation_service.exe (PID: 7544)
      • elevation_service.exe (PID: 7800)
    • The process checks if it is being run in the virtual environment

      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 7520)
    • Reads the date of Windows installation

      • AVGBrowser.exe (PID: 2616)
      • AVGBrowser.exe (PID: 6044)
      • chrmstp.exe (PID: 680)
      • AVGBrowser.exe (PID: 5408)
    • Reads Mozilla Firefox installation path

      • AVGBrowser.exe (PID: 7520)
    • Likely accesses (executes) a file from the Public directory

      • AVGBrowser.exe (PID: 6044)
    • Checks for external IP

      • AVGBrowser.exe (PID: 7204)
  • INFO

    • Checks supported languages

      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • avg_secure_browser_setup.exe (PID: 7856)
      • saBSI.exe (PID: 7812)
      • saBSI.exe (PID: 7968)
      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 4980)
      • AVGBrowserUpdate.exe (PID: 780)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 536)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 2392)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 5392)
      • AVGBrowserUpdate.exe (PID: 5416)
      • AVGBrowserUpdate.exe (PID: 6032)
      • AVGBrowserUpdate.exe (PID: 1180)
      • AVGBrowserUpdate.exe (PID: 6744)
      • AVGBrowserInstaller.exe (PID: 5112)
      • setup.exe (PID: 1912)
      • setup.exe (PID: 2564)
      • AVGBrowserCrashHandler64.exe (PID: 7344)
      • AVGBrowserCrashHandler.exe (PID: 7384)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 7012)
      • AVGBrowser.exe (PID: 1096)
      • elevation_service.exe (PID: 6752)
      • AVGBrowser.exe (PID: 4740)
      • AVGBrowser.exe (PID: 6656)
      • elevation_service.exe (PID: 6044)
      • AVGBrowser.exe (PID: 968)
      • AVGBrowser.exe (PID: 5400)
      • AVGBrowser.exe (PID: 6828)
      • AVGBrowser.exe (PID: 7988)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 8052)
      • AVGBrowser.exe (PID: 7976)
      • AVGBrowser.exe (PID: 4408)
      • AVGBrowser.exe (PID: 4164)
      • AVGBrowser.exe (PID: 2088)
      • elevation_service.exe (PID: 7544)
      • AVGBrowser.exe (PID: 1600)
      • AVGBrowser.exe (PID: 2104)
      • AVGBrowser.exe (PID: 6456)
      • AVGBrowser.exe (PID: 5968)
      • AVGBrowser.exe (PID: 3804)
      • AVGBrowser.exe (PID: 4628)
      • AVGBrowser.exe (PID: 7768)
      • AVGBrowser.exe (PID: 728)
      • AVGBrowser.exe (PID: 7048)
      • AVGBrowser.exe (PID: 1676)
      • AVGBrowser.exe (PID: 7468)
      • AVGBrowser.exe (PID: 7380)
      • AVGBrowser.exe (PID: 7364)
      • AVGBrowser.exe (PID: 7360)
      • AVGBrowser.exe (PID: 660)
      • AVGBrowser.exe (PID: 4880)
      • AVGBrowser.exe (PID: 5548)
      • AVGBrowser.exe (PID: 1568)
      • AVGBrowser.exe (PID: 7936)
      • AVGBrowser.exe (PID: 5332)
      • AVGBrowser.exe (PID: 8000)
      • AVGBrowser.exe (PID: 7848)
      • AVGBrowser.exe (PID: 7968)
      • AVGBrowser.exe (PID: 6972)
      • AVGBrowser.exe (PID: 8164)
      • AVGBrowser.exe (PID: 7672)
      • AVGBrowser.exe (PID: 7556)
      • AVGBrowser.exe (PID: 7700)
      • AVGBrowser.exe (PID: 6300)
      • AVGBrowser.exe (PID: 632)
      • AVGBrowser.exe (PID: 2772)
      • AVGBrowser.exe (PID: 7192)
      • AVGBrowser.exe (PID: 7684)
      • AVGBrowser.exe (PID: 2084)
      • AVGBrowser.exe (PID: 7084)
      • AVGBrowser.exe (PID: 4180)
      • AVGBrowser.exe (PID: 4012)
      • AVGBrowserProtect.exe (PID: 7104)
      • AVGBrowser.exe (PID: 7716)
      • AVGBrowser.exe (PID: 8092)
      • AVGBrowser.exe (PID: 7416)
      • AVGBrowser.exe (PID: 4784)
      • AVGBrowser.exe (PID: 7424)
      • AVGBrowser.exe (PID: 3192)
      • setup.exe (PID: 7360)
      • setup.exe (PID: 6736)
      • AVGBrowser.exe (PID: 2616)
      • AVGBrowser.exe (PID: 6740)
      • AVGBrowser.exe (PID: 7520)
      • AVGBrowser.exe (PID: 7668)
      • AVGBrowser.exe (PID: 7204)
      • AVGBrowser.exe (PID: 968)
      • AVGBrowser.exe (PID: 7712)
      • elevation_service.exe (PID: 7800)
      • AVGBrowser.exe (PID: 7532)
      • AVGBrowser.exe (PID: 872)
      • AVGBrowser.exe (PID: 3976)
      • AVGBrowser.exe (PID: 3800)
      • AVGBrowser.exe (PID: 8092)
      • AVGBrowser.exe (PID: 2064)
      • AVGBrowser.exe (PID: 1052)
      • AVGBrowser.exe (PID: 6044)
      • AVGBrowser.exe (PID: 5984)
      • AVGBrowser.exe (PID: 5864)
      • chrmstp.exe (PID: 5868)
      • chrmstp.exe (PID: 680)
      • chrmstp.exe (PID: 1228)
      • chrmstp.exe (PID: 664)
      • AVGBrowser.exe (PID: 7688)
      • AVGBrowser.exe (PID: 5324)
      • AVGBrowser.exe (PID: 5408)
      • AVGBrowser.exe (PID: 6940)
      • AVGBrowser.exe (PID: 2092)
      • AVGBrowser.exe (PID: 7644)
      • AVGBrowser.exe (PID: 2136)
      • AVGBrowser.exe (PID: 2984)
    • Create files in a temporary directory

      • avg_secure_browser_setup.exe (PID: 7856)
      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • saBSI.exe (PID: 7968)
      • AVGBrowserUpdate.exe (PID: 6744)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 7520)
    • Reads the machine GUID from the registry

      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • saBSI.exe (PID: 7812)
      • saBSI.exe (PID: 7968)
      • avg_secure_browser_setup.exe (PID: 7856)
      • AVGBrowserUpdate.exe (PID: 6032)
      • AVGBrowserUpdate.exe (PID: 6744)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 7520)
    • Checks proxy server information

      • saBSI.exe (PID: 7812)
      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • saBSI.exe (PID: 7968)
      • avg_secure_browser_setup.exe (PID: 7856)
      • AVGBrowserUpdate.exe (PID: 5416)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowserProtect.exe (PID: 7104)
      • AVGBrowser.exe (PID: 7520)
      • slui.exe (PID: 6068)
    • The sample compiled with english language support

      • avg_secure_browser_setup.exe (PID: 7856)
      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • saBSI.exe (PID: 7812)
      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
      • setup.exe (PID: 1912)
      • AVGBrowserInstaller.exe (PID: 5112)
    • The sample compiled with arabic language support

      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
      • avg_secure_browser_setup.exe (PID: 7856)
    • Reads the computer name

      • avg_secure_browser_setup.exe (PID: 7856)
      • saBSI.exe (PID: 7812)
      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • saBSI.exe (PID: 7968)
      • AVGBrowserUpdate.exe (PID: 6032)
      • AVGBrowserUpdate.exe (PID: 4980)
      • AVGBrowserUpdate.exe (PID: 780)
      • AVGBrowserUpdate.exe (PID: 5416)
      • AVGBrowserUpdate.exe (PID: 6744)
      • AVGBrowserUpdate.exe (PID: 1180)
      • AVGBrowserInstaller.exe (PID: 5112)
      • setup.exe (PID: 1912)
      • AVGBrowser.exe (PID: 5352)
      • elevation_service.exe (PID: 6752)
      • AVGBrowser.exe (PID: 5400)
      • AVGBrowser.exe (PID: 1096)
      • elevation_service.exe (PID: 6044)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 4164)
      • AVGBrowser.exe (PID: 4408)
      • elevation_service.exe (PID: 7544)
      • AVGBrowser.exe (PID: 7084)
      • AVGBrowser.exe (PID: 4180)
      • AVGBrowserProtect.exe (PID: 7104)
      • setup.exe (PID: 7360)
      • AVGBrowser.exe (PID: 2616)
      • AVGBrowser.exe (PID: 7520)
      • AVGBrowser.exe (PID: 7668)
      • elevation_service.exe (PID: 7800)
      • AVGBrowser.exe (PID: 7204)
      • AVGBrowser.exe (PID: 6044)
      • chrmstp.exe (PID: 664)
      • chrmstp.exe (PID: 680)
      • AVGBrowser.exe (PID: 7688)
      • AVGBrowser.exe (PID: 5408)
      • AVGBrowser.exe (PID: 5324)
      • AVGBrowser.exe (PID: 2092)
      • AVGBrowser.exe (PID: 7644)
    • Reads the software policy settings

      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • avg_secure_browser_setup.exe (PID: 7856)
      • saBSI.exe (PID: 7812)
      • saBSI.exe (PID: 7968)
      • AVGBrowserUpdate.exe (PID: 5416)
      • AVGBrowserUpdate.exe (PID: 6744)
      • slui.exe (PID: 7264)
      • slui.exe (PID: 6068)
    • Creates files in the program directory

      • saBSI.exe (PID: 7812)
      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
      • AVGBrowserUpdate.exe (PID: 6744)
      • setup.exe (PID: 1912)
      • AVGBrowserInstaller.exe (PID: 5112)
      • avg_secure_browser_setup.exe (PID: 7856)
      • setup.exe (PID: 7360)
    • Reads Environment values

      • avg_secure_browser_setup.exe (PID: 7856)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 7520)
    • Process checks computer location settings

      • avg_secure_browser_setup.exe (PID: 7856)
      • foca-3.4.7.1-installer_MHc3-91.exe (PID: 7180)
      • AVGBrowserUpdate.exe (PID: 6032)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 968)
      • AVGBrowser.exe (PID: 4740)
      • AVGBrowser.exe (PID: 7988)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 1600)
      • AVGBrowser.exe (PID: 728)
      • AVGBrowser.exe (PID: 5332)
      • AVGBrowser.exe (PID: 6300)
      • AVGBrowser.exe (PID: 7700)
      • AVGBrowser.exe (PID: 632)
      • AVGBrowser.exe (PID: 7672)
      • AVGBrowser.exe (PID: 3192)
      • AVGBrowser.exe (PID: 7424)
      • AVGBrowser.exe (PID: 7520)
      • AVGBrowser.exe (PID: 2616)
      • AVGBrowser.exe (PID: 3976)
      • AVGBrowser.exe (PID: 3800)
      • AVGBrowser.exe (PID: 8092)
      • AVGBrowser.exe (PID: 872)
      • AVGBrowser.exe (PID: 7532)
      • AVGBrowser.exe (PID: 968)
      • AVGBrowser.exe (PID: 1052)
      • AVGBrowser.exe (PID: 6044)
      • AVGBrowser.exe (PID: 5864)
      • AVGBrowser.exe (PID: 2064)
      • AVGBrowser.exe (PID: 5408)
      • AVGBrowser.exe (PID: 2136)
    • Creates files or folders in the user directory

      • avg_secure_browser_setup.exe (PID: 7856)
      • AVGBrowser.exe (PID: 5352)
      • AVGBrowser.exe (PID: 1096)
      • AVGBrowser.exe (PID: 8052)
      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 4408)
      • AVGBrowser.exe (PID: 4180)
      • setup.exe (PID: 7360)
      • AVGBrowser.exe (PID: 7520)
      • AVGBrowser.exe (PID: 6740)
      • AVGBrowser.exe (PID: 7204)
      • chrmstp.exe (PID: 680)
      • AVGBrowser.exe (PID: 5324)
    • The sample compiled with german language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with bulgarian language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with czech language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with japanese language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with Italian language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with french language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with Indonesian language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with korean language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with polish language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with slovak language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with portuguese language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with russian language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with swedish language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with turkish language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • The sample compiled with chinese language support

      • AVGBrowserUpdateSetup.exe (PID: 4880)
      • AVGBrowserUpdate.exe (PID: 6032)
    • Process checks whether UAC notifications are on

      • avg_secure_browser_setup.exe (PID: 7856)
    • Reads CPU info

      • AVGBrowser.exe (PID: 8036)
      • AVGBrowser.exe (PID: 7520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:10:14 12:00:04+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 2145792
InitializedDataSize: 2305536
UninitializedDataSize: -
EntryPoint: 0x1c2253
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.0.9.1
ProductVersionNumber: 3.0.9.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Softonic
FileDescription: Softonic
FileVersion: 3.0.9.1
LegalCopyright: (c) Softonic. All rights reserved.
ProductName: Softonic
ProductVersion: 3.0.9.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
257
Monitored processes
117
Malicious processes
109
Suspicious processes
1

Behavior graph

Click at the process to see the details
start foca-3.4.7.1-installer_mhc3-91.exe sppextcomobj.exe no specs slui.exe sabsi.exe avg_secure_browser_setup.exe sabsi.exe avgbrowserupdatesetup.exe avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe avgbrowserinstaller.exe slui.exe setup.exe setup.exe no specs avgbrowsercrashhandler.exe no specs avgbrowsercrashhandler64.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe elevation_service.exe no specs avgbrowser.exe no specs elevation_service.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs elevation_service.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowserprotect.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs setup.exe no specs setup.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs elevation_service.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs chrmstp.exe no specs chrmstp.exe no specs chrmstp.exe no specs chrmstp.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs foca-3.4.7.1-installer_mhc3-91.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Program Files (x86)\AVG\Browser\Update\1.8.1693.6\AVGBrowserUpdateComRegisterShell64.exe" C:\Program Files (x86)\AVG\Browser\Update\1.8.1693.6\AVGBrowserUpdateComRegisterShell64.exeAVGBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Browser Com Register Shell 64
Exit code:
0
Version:
1.8.1693.6
Modules
Images
c:\program files (x86)\avg\browser\update\1.8.1693.6\avgbrowserupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
632"C:\Program Files\AVG\Browser\Application\AVGBrowser.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=37 --field-trial-handle=4300,i,8505360522068964467,1464473476777482961,262144 --variations-seed-version --mojo-platform-channel-handle=5296 /prefetch:1C:\Program Files\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
133.0.29113.143
Modules
Images
c:\program files\avg\browser\application\avgbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avg\browser\application\133.0.29113.143\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
660"C:\Program Files\AVG\Browser\Application\AVGBrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --string-annotations --field-trial-handle=4908,i,8505360522068964467,1464473476777482961,262144 --variations-seed-version --mojo-platform-channel-handle=4828 /prefetch:8C:\Program Files\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
133.0.29113.143
Modules
Images
c:\program files\avg\browser\application\avgbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avg\browser\application\133.0.29113.143\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
664"C:\Program Files\AVG\Browser\Application\133.0.29113.143\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --force-configure-user-settingsC:\Program Files\AVG\Browser\Application\133.0.29113.143\Installer\chrmstp.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Secure Browser Installer
Exit code:
0
Version:
133.0.29113.143
Modules
Images
c:\program files\avg\browser\application\133.0.29113.143\installer\chrmstp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
680"C:\Program Files\AVG\Browser\Application\133.0.29113.143\Installer\chrmstp.exe" --system-level --verbose-logging --installerdata="C:\Program Files\AVG\Browser\Application\initial_preferences" --create-shortcuts=1 --install-level=0 --no-pin-startmenuC:\Program Files\AVG\Browser\Application\133.0.29113.143\Installer\chrmstp.exechrmstp.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Secure Browser Installer
Exit code:
73
Version:
133.0.29113.143
Modules
Images
c:\program files\avg\browser\application\133.0.29113.143\installer\chrmstp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
728"C:\Program Files\AVG\Browser\Application\AVGBrowser.exe" --type=renderer --string-annotations --extension-process --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --field-trial-handle=3572,i,8505360522068964467,1464473476777482961,262144 --variations-seed-version --mojo-platform-channel-handle=2984 /prefetch:2C:\Program Files\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
133.0.29113.143
Modules
Images
c:\program files\avg\browser\application\avgbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avg\browser\application\133.0.29113.143\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
780"C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe" /regserverC:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exeAVGBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Browser
Exit code:
0
Version:
1.8.1693.6
Modules
Images
c:\program files (x86)\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
872"C:\Program Files\AVG\Browser\Application\AVGBrowser.exe" --type=renderer --string-annotations --extension-process --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --field-trial-handle=4056,i,17050252378602659609,32145358304423707,262144 --variations-seed-version --mojo-platform-channel-handle=4008 /prefetch:2C:\Program Files\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
133.0.29113.143
Modules
Images
c:\program files\avg\browser\application\avgbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avg\browser\application\133.0.29113.143\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
968"C:\Program Files\AVG\Browser\Application\AVGBrowser.exe" --type=renderer --string-annotations --extension-process --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3440,i,1379893435242402447,17217701224352256996,262144 --variations-seed-version --mojo-platform-channel-handle=3452 /prefetch:2C:\Program Files\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
133.0.29113.143
Modules
Images
c:\program files\avg\browser\application\avgbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avg\browser\application\133.0.29113.143\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
968"C:\Program Files\AVG\Browser\Application\AVGBrowser.exe" --type=renderer --string-annotations --extension-process --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=3416,i,17050252378602659609,32145358304423707,262144 --variations-seed-version --mojo-platform-channel-handle=3412 /prefetch:2C:\Program Files\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
133.0.29113.143
Modules
Images
c:\program files\avg\browser\application\avgbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avg\browser\application\133.0.29113.143\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
30 954
Read events
29 019
Write events
1 857
Delete events
78

Modification events

(PID) Process:(7180) foca-3.4.7.1-installer_MHc3-91.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Operation:writeName:Implementing
Value:
1C00000001000000E907040001000E000000260025005003010000001E768127E028094199FEB9D127C57AFE
(PID) Process:(7180) foca-3.4.7.1-installer_MHc3-91.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
01000000000000006829D28FD5ACDB01
(PID) Process:(7812) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:UUID
Value:
{883E096B-5DA7-4666-9AF1-E5C668F7AB83}
(PID) Process:(7812) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor
Operation:writeName:InstallerFlags
Value:
1
(PID) Process:(7856) avg_secure_browser_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVG\Browser
Operation:writeName:installer_run_count
Value:
1
(PID) Process:(7856) avg_secure_browser_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\AVG\Browser
Operation:writeName:machine_id
Value:
0000B0E1009ABA5E95F7227E57434874
(PID) Process:(7856) avg_secure_browser_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVG\Browser
Operation:writeName:machine_id
Value:
0000B0E1009ABA5E95F7227E57434874
(PID) Process:(7812) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:4EFC31460C619ECAE59C1BCE2C008036D94C84B8
Value:
(PID) Process:(7812) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4EFC31460C619ECAE59C1BCE2C008036D94C84B8
Operation:writeName:Blob
Value:
040000000100000010000000E94FB54871208C00DF70F708AC47085B0F0000000100000030000000C130BBA37B8B350E89FD5ED76B4F78777FEEE220D3B9E729042BEF6AF46E8E4C1B252E32B3080C681BC9A8A1AFDD0A3C0300000001000000140000004EFC31460C619ECAE59C1BCE2C008036D94C84B809000000010000000C000000300A06082B060105050703031D00000001000000100000005467B0ADDE8D858E30EE517B1A19ECD91400000001000000140000001F00BF46800AFC7839B7A5B443D95650BBCE963B53000000010000001F000000301D301B060567810C010330123010060A2B0601040182373C0101030200C06200000001000000200000007B9D553E1C92CB6E8803E137F4F287D4363757F5D44B37D52F9FCA22FB97DF860B000000010000004200000047006C006F00620061006C005300690067006E00200043006F006400650020005300690067006E0069006E006700200052006F006F007400200052003400350000001900000001000000100000005D1B8FF2C30F63F5B536EDD400F7F9B4200000000100000076050000308205723082035AA00302010202107653FEAC75464893F5E5D74A483A4EF8300D06092A864886F70D01010C05003053310B300906035504061302424531193017060355040A1310476C6F62616C5369676E206E762D73613129302706035504031320476C6F62616C5369676E20436F6465205369676E696E6720526F6F7420523435301E170D3230303331383030303030305A170D3435303331383030303030305A3053310B300906035504061302424531193017060355040A1310476C6F62616C5369676E206E762D73613129302706035504031320476C6F62616C5369676E20436F6465205369676E696E6720526F6F742052343530820222300D06092A864886F70D01010105000382020F003082020A0282020100B62DC530DD7AE8AB903D0372B03A4B991661B2E5FFA5671D371CE57EEC9383AA84F5A3439B98458AB863575D9B00880425E9F868924B82D84BC94A03F3A87F6A8F8A6127BDA144D0FDF53F22C2A34F918DB305B22882915DFB5988050B9706C298F82CA73324EE503A41CCF0A0B07B1D4DD2A8583896E9DFF91B91BB8B102CD2C7431DA20974A180AF7BE6330A0C596B8EBCF4AB5A977B7FAE55FB84F080FE844CD7E2BABDC475A16FBD61107444B29807E274ABFF68DC6C263EE91FE5E00487AD30D30C8D037C55B816705C24782025EB676788ABBA4E34986B7011DE38CAD4BEA1C09CE1DF1E0201D83BE1674384B6CFFC74B72F84A3BFBA09373D676CB1455C1961AB4183F5AC1DEB770D464773CEBFBD9595ED9D2B8810FEFA58E8A757E1B3CFA85AE907259B12C49E80723D93DC8C94DF3B44E62680FCD2C303F08C0CD245D62EE78F989EE604EE426E677E42167162E704F960C664A1B69C81214E2BC66D689486C699747367317A91F2D48C796E7CA6BB7E466F4DC585122BCF9A224408A88537CE07615706171224C0C43173A1983557477E103A45D92DA4519098A9A00737C4651AAA1C6B1677F7A797EC3F1930996F31FBEA40B2E7D2C4FAC9D0F050767459FA8D6D1732BEF8E97E03F4E787759AD44A912C850313022B4280F2896A36CFC84CA0CE9EF8CB8DAD16A7D3DED59B18A7C6923AF18263F12E0E2464DF0203010001A3423040300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E041604141F00BF46800AFC7839B7A5B443D95650BBCE963B300D06092A864886F70D01010C050003820201005E2BBA749734445F764828408493EE016EE9A1B3D68025E67BE4BC09913D0FFC76ADD7D43020BB8F60D091D61CF29CEF781A2B943202C12496525202D0F3D1FCF29B396E99E11F8E43417D9A1E5BC95D9A84FC26E687F3747226ADA41BD93D3B6A52A03C091E2F1E7BB333B445C7F7ACB1AF9360AD76AEB8B21578EB836AEBFFDB46AB24E5EE02FA901F59C02F5DD6B75DA45C10B77253F8414ECCFA781A254ACAFE85624361C3B437AA81D2F4D63A0FBD8D597E3047DE2B6BE72150335FD4679BD4B8679F3C279903FF85438E7312CA20CDE861D5B166DC17D6396D0FDBCF2337A182894E1C6B3FD6A0CDAA079D3E4226AAD70CEEFA47BF1A527ED17581D3C98A62176D4F88A021A0263EAF6DD962301FE99828AE6E8DD58E4C726693808D2AE355C760679042565C22510FB3DC4E39EE4DDDD91D7810543B6ED0976F03B51EB22373C612B29A64D0FC958524A8FFDFA1B0DC9140AEDF0933ABB9DD92B7F1CC91743B69EB67971B90BFE7C7A06F71BB57BFB78F5AED7A406A16CD80842D2FE102D4249443B315FC0C2B1BFD716FFCCBBC75173A5E83D2C9B32F1BD59C8D7F54FE7E7EE456A387A79DE1595294418F6D5BBE86959AFF1A76DD40D2514A70B41F336323773FEC271E59E40887ED34824A0F3FFEA01DC1F56773458678F4AA29E92787C619DBC61314C33949874DA097E06513F59D7756E9DAB358C73AF2C0CD82
(PID) Process:(7812) saBSI.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4EFC31460C619ECAE59C1BCE2C008036D94C84B8
Operation:writeName:Blob
Value:
5C0000000100000004000000001000001900000001000000100000005D1B8FF2C30F63F5B536EDD400F7F9B40B000000010000004200000047006C006F00620061006C005300690067006E00200043006F006400650020005300690067006E0069006E006700200052006F006F007400200052003400350000006200000001000000200000007B9D553E1C92CB6E8803E137F4F287D4363757F5D44B37D52F9FCA22FB97DF8653000000010000001F000000301D301B060567810C010330123010060A2B0601040182373C0101030200C01400000001000000140000001F00BF46800AFC7839B7A5B443D95650BBCE963B1D00000001000000100000005467B0ADDE8D858E30EE517B1A19ECD909000000010000000C000000300A06082B060105050703030300000001000000140000004EFC31460C619ECAE59C1BCE2C008036D94C84B80F0000000100000030000000C130BBA37B8B350E89FD5ED76B4F78777FEEE220D3B9E729042BEF6AF46E8E4C1B252E32B3080C681BC9A8A1AFDD0A3C040000000100000010000000E94FB54871208C00DF70F708AC47085B200000000100000076050000308205723082035AA00302010202107653FEAC75464893F5E5D74A483A4EF8300D06092A864886F70D01010C05003053310B300906035504061302424531193017060355040A1310476C6F62616C5369676E206E762D73613129302706035504031320476C6F62616C5369676E20436F6465205369676E696E6720526F6F7420523435301E170D3230303331383030303030305A170D3435303331383030303030305A3053310B300906035504061302424531193017060355040A1310476C6F62616C5369676E206E762D73613129302706035504031320476C6F62616C5369676E20436F6465205369676E696E6720526F6F742052343530820222300D06092A864886F70D01010105000382020F003082020A0282020100B62DC530DD7AE8AB903D0372B03A4B991661B2E5FFA5671D371CE57EEC9383AA84F5A3439B98458AB863575D9B00880425E9F868924B82D84BC94A03F3A87F6A8F8A6127BDA144D0FDF53F22C2A34F918DB305B22882915DFB5988050B9706C298F82CA73324EE503A41CCF0A0B07B1D4DD2A8583896E9DFF91B91BB8B102CD2C7431DA20974A180AF7BE6330A0C596B8EBCF4AB5A977B7FAE55FB84F080FE844CD7E2BABDC475A16FBD61107444B29807E274ABFF68DC6C263EE91FE5E00487AD30D30C8D037C55B816705C24782025EB676788ABBA4E34986B7011DE38CAD4BEA1C09CE1DF1E0201D83BE1674384B6CFFC74B72F84A3BFBA09373D676CB1455C1961AB4183F5AC1DEB770D464773CEBFBD9595ED9D2B8810FEFA58E8A757E1B3CFA85AE907259B12C49E80723D93DC8C94DF3B44E62680FCD2C303F08C0CD245D62EE78F989EE604EE426E677E42167162E704F960C664A1B69C81214E2BC66D689486C699747367317A91F2D48C796E7CA6BB7E466F4DC585122BCF9A224408A88537CE07615706171224C0C43173A1983557477E103A45D92DA4519098A9A00737C4651AAA1C6B1677F7A797EC3F1930996F31FBEA40B2E7D2C4FAC9D0F050767459FA8D6D1732BEF8E97E03F4E787759AD44A912C850313022B4280F2896A36CFC84CA0CE9EF8CB8DAD16A7D3DED59B18A7C6923AF18263F12E0E2464DF0203010001A3423040300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E041604141F00BF46800AFC7839B7A5B443D95650BBCE963B300D06092A864886F70D01010C050003820201005E2BBA749734445F764828408493EE016EE9A1B3D68025E67BE4BC09913D0FFC76ADD7D43020BB8F60D091D61CF29CEF781A2B943202C12496525202D0F3D1FCF29B396E99E11F8E43417D9A1E5BC95D9A84FC26E687F3747226ADA41BD93D3B6A52A03C091E2F1E7BB333B445C7F7ACB1AF9360AD76AEB8B21578EB836AEBFFDB46AB24E5EE02FA901F59C02F5DD6B75DA45C10B77253F8414ECCFA781A254ACAFE85624361C3B437AA81D2F4D63A0FBD8D597E3047DE2B6BE72150335FD4679BD4B8679F3C279903FF85438E7312CA20CDE861D5B166DC17D6396D0FDBCF2337A182894E1C6B3FD6A0CDAA079D3E4226AAD70CEEFA47BF1A527ED17581D3C98A62176D4F88A021A0263EAF6DD962301FE99828AE6E8DD58E4C726693808D2AE355C760679042565C22510FB3DC4E39EE4DDDD91D7810543B6ED0976F03B51EB22373C612B29A64D0FC958524A8FFDFA1B0DC9140AEDF0933ABB9DD92B7F1CC91743B69EB67971B90BFE7C7A06F71BB57BFB78F5AED7A406A16CD80842D2FE102D4249443B315FC0C2B1BFD716FFCCBBC75173A5E83D2C9B32F1BD59C8D7F54FE7E7EE456A387A79DE1595294418F6D5BBE86959AFF1A76DD40D2514A70B41F336323773FEC271E59E40887ED34824A0F3FFEA01DC1F56773458678F4AA29E92787C619DBC61314C33949874DA097E06513F59D7756E9DAB358C73AF2C0CD82
Executable files
194
Suspicious files
1 303
Text files
491
Unknown types
8

Dropped files

PID
Process
Filename
Type
7856avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsh1481.tmp\FF.places.tmp
MD5:
SHA256:
7180foca-3.4.7.1-installer_MHc3-91.exeC:\Users\admin\AppData\Local\Temp\ISVB7D8.tmp\avg_secure_browser_setup.zipcompressed
MD5:6406ABC4EE622F73E9E6CB618190AF02
SHA256:FD83D239B00A44698959145449EBFCB8C52687327DEAC04455E77A710A3DFE1B
7812saBSI.exeC:\ProgramData\McAfee\WebAdvisor\saBSI.exe\log_00000057003F001D0006.txttext
MD5:7A6B179D472E730DD582C1C63F9F4B97
SHA256:158BCD1A3A447B4D99ACE4625B9D58BF085F7E8B8C48290D6BA48919F1F28538
7856avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsh1481.tmp\reboot.dllexecutable
MD5:0F3432346A273777B5F4D2E6A3BCA343
SHA256:4853D61601A860C628771993F3A57B5AB842C88D696235FEBFAA3CD890EBCD1E
7180foca-3.4.7.1-installer_MHc3-91.exeC:\Users\admin\Downloads\foca-3.4.7.1-installer.execompressed
MD5:22E6D94D033016C0A98832EBC6480A1B
SHA256:2B7F2CA60DC56245C0101BF171F13A1AE3E89AB93022A969011A08D06270E7FD
7856avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsh1481.tmp\JsisPlugins.dllexecutable
MD5:BD94620C8A3496F0922D7A443C750047
SHA256:C0AF9E25C35650F43DE4E8A57BB89D43099BEEAD4CA6AF6BE846319FF84D7644
7856avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsh1481.tmp\nsJSON.dllexecutable
MD5:DDB56A646AEA54615B29CE7DF8CD31B8
SHA256:07E602C54086A8FA111F83A38C2F3EE239F49328990212C2B3A295FADE2B5069
7180foca-3.4.7.1-installer_MHc3-91.exeC:\Users\admin\AppData\Local\Temp\ISVB7D8.tmp\saBSI.exeexecutable
MD5:143255618462A577DE27286A272584E1
SHA256:F5AA950381FBCEA7D730AA794974CA9E3310384A95D6CF4D015FBDBD9797B3E4
7856avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsh1481.tmp\Midex.dllexecutable
MD5:581C4A0B8DE60868B89074FE94EB27B9
SHA256:B13C23AF49DA0A21959E564CBCA8E6B94C181C5EEB95150B29C94FF6AFB8F9DD
7856avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsh1481.tmp\thirdparty.dllexecutable
MD5:070335E8E52A288BDB45DB1C840D446B
SHA256:C8CF0CF1C2B8B14CBEDFE621D81A79C80D70F587D698AD6DFB54BBE8E346FBBC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
108
DNS requests
106
Threats
27

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7612
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad75b3l6ifzhds2shjkt4plki3la_2025.4.9.0/niikhdgajlphfehepabhhblakbdgeefj_2025.04.09.00_all_npvw54ukij2olp3ypwysvazhva.crx3
unknown
whitelisted
6744
AVGBrowserUpdate.exe
GET
23.53.40.80:80
http://browser-update.avg.com/browser-avg/win/x64/133.0.29113.143/AVGBrowserInstaller.exe
unknown
whitelisted
1096
AVGBrowser.exe
GET
200
142.250.185.206:80
http://clients2.google.com/time/1/current?cup2key=8:K5A90f8jkwc3bJp9WU4svRjWJZ5m37Qo_GmVHzteAko&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
7612
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad75b3l6ifzhds2shjkt4plki3la_2025.4.9.0/niikhdgajlphfehepabhhblakbdgeefj_2025.04.09.00_all_npvw54ukij2olp3ypwysvazhva.crx3
unknown
whitelisted
7612
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad75b3l6ifzhds2shjkt4plki3la_2025.4.9.0/niikhdgajlphfehepabhhblakbdgeefj_2025.04.09.00_all_npvw54ukij2olp3ypwysvazhva.crx3
unknown
whitelisted
7612
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad75b3l6ifzhds2shjkt4plki3la_2025.4.9.0/niikhdgajlphfehepabhhblakbdgeefj_2025.04.09.00_all_npvw54ukij2olp3ypwysvazhva.crx3
unknown
whitelisted
7612
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad75b3l6ifzhds2shjkt4plki3la_2025.4.9.0/niikhdgajlphfehepabhhblakbdgeefj_2025.04.09.00_all_npvw54ukij2olp3ypwysvazhva.crx3
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
7180
foca-3.4.7.1-installer_MHc3-91.exe
18.245.78.188:443
di7e1j5f1plfo.cloudfront.net
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
google.com
  • 142.250.186.142
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.67
  • 40.126.31.3
  • 20.190.159.0
  • 40.126.31.128
  • 40.126.31.71
  • 20.190.159.64
  • 20.190.159.129
  • 40.126.31.129
  • 20.190.159.2
  • 20.190.159.130
  • 40.126.31.130
  • 20.190.159.68
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
di7e1j5f1plfo.cloudfront.net
  • 18.245.78.188
  • 18.245.78.145
  • 18.245.78.212
  • 18.245.78.185
whitelisted
images.sftcdn.net
  • 151.101.193.91
  • 151.101.1.91
  • 151.101.129.91
  • 151.101.65.91
whitelisted
gsf-fl.softonic.com
  • 151.101.65.91
  • 151.101.1.91
  • 151.101.129.91
  • 151.101.193.91
whitelisted
analytics.apis.mcafee.com
  • 34.218.143.134
  • 54.218.52.44
  • 52.24.199.124
  • 35.155.233.214
  • 35.81.71.5
  • 52.27.243.85
  • 52.40.105.164
  • 44.240.114.156
unknown

Threats

PID
Process
Class
Message
6744
AVGBrowserUpdate.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
4408
AVGBrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4408
AVGBrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4408
AVGBrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4408
AVGBrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4408
AVGBrowser.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Blob Storage (.blob .core .windows .net)
4408
AVGBrowser.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Blob Storage (.blob .core .windows .net)
4408
AVGBrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4408
AVGBrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7204
AVGBrowser.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
No debug info