File name:

avast_free_antivirus_setup_online.exe

Full analysis: https://app.any.run/tasks/9b5a4491-ee09-429a-a273-1eb0815f40fc
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: February 12, 2025, 17:22:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

AC5652B281D8371D77C67FCE5DAAE07A

SHA1:

0C426C842AA412C4F5D79896CF420CD621C9D066

SHA256:

29DBBA0C7A71CB01A10DC2F4E6729D82BC8F9C73594EA92C97F018081788E5C4

SSDEEP:

6144:3IuaJEM/Jt1zJR+c0mbOoDTqu1hVs9zKn:3IuaJEiH+cBdDWu1hVDn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • aswEngSrv.exe (PID: 6152)
      • AvastSvc.exe (PID: 3840)
      • engsup.exe (PID: 7416)
    • Steals credentials from Web Browsers

      • AvastSvc.exe (PID: 3840)
      • aswEngSrv.exe (PID: 6152)
      • engsup.exe (PID: 7416)
    • Antivirus name has been found in the command line (generic signature)

      • AvastUI.exe (PID: 5448)
      • AvastUI.exe (PID: 7372)
      • AvastUI.exe (PID: 6312)
      • AvastUI.exe (PID: 6936)
      • AvastUI.exe (PID: 5460)
      • AvastUI.exe (PID: 6776)
      • AvastUI.exe (PID: 8124)
      • AvastUI.exe (PID: 6188)
    • Changes the autorun value in the registry

      • icarus.exe (PID: 2612)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • avast_free_antivirus_setup_online.exe (PID: 6620)
      • avast_free_antivirus_online_setup.exe (PID: 6744)
      • icarus.exe (PID: 6984)
      • icarus.exe (PID: 2612)
      • icarus.exe (PID: 3224)
      • engsup.exe (PID: 2776)
      • AvEmUpdate.exe (PID: 2788)
      • AvastSvc.exe (PID: 3840)
      • aswOfferTool.exe (PID: 8124)
    • Checks for external IP

      • avast_free_antivirus_setup_online.exe (PID: 6620)
      • AvEmUpdate.exe (PID: 2788)
      • aswToolsSvc.exe (PID: 432)
      • AvastSvc.exe (PID: 3840)
    • Starts itself from another location

      • icarus.exe (PID: 6984)
    • Reads security settings of Internet Explorer

      • icarus_ui.exe (PID: 7056)
      • AvastSvc.exe (PID: 3840)
    • Checks Windows Trust Settings

      • icarus_ui.exe (PID: 7056)
    • The process creates files with name similar to system file names

      • icarus.exe (PID: 2612)
    • Process drops legitimate windows executable

      • icarus.exe (PID: 2612)
    • The process drops C-runtime libraries

      • icarus.exe (PID: 2612)
    • Drops a system driver (possible attempt to evade defenses)

      • icarus.exe (PID: 2612)
      • engsup.exe (PID: 2776)
    • The process verifies whether the antivirus software is installed

      • SetupInf.exe (PID: 6944)
      • SetupInf.exe (PID: 6712)
      • SetupInf.exe (PID: 2464)
      • engsup.exe (PID: 2776)
      • SetupInf.exe (PID: 4804)
      • SetupInf.exe (PID: 1876)
      • SetupInf.exe (PID: 1868)
      • AvEmUpdate.exe (PID: 6156)
      • RegSvr.exe (PID: 6632)
      • icarus.exe (PID: 3224)
      • RegSvr.exe (PID: 6752)
      • SetupInf.exe (PID: 7000)
      • AvEmUpdate.exe (PID: 2788)
      • wsc_proxy.exe (PID: 488)
      • wsc_proxy.exe (PID: 3888)
      • afwServ.exe (PID: 6428)
      • aswEngSrv.exe (PID: 6152)
      • AvastSvc.exe (PID: 3840)
      • aswToolsSvc.exe (PID: 432)
      • aswidsagent.exe (PID: 3920)
      • AvastUI.exe (PID: 5448)
      • icarus.exe (PID: 2612)
      • overseer.exe (PID: 2904)
      • engsup.exe (PID: 7416)
    • Creates files in the driver directory

      • engsup.exe (PID: 2776)
      • icarus.exe (PID: 2612)
    • Creates or modifies Windows services

      • icarus.exe (PID: 2612)
    • Creates a software uninstall entry

      • icarus.exe (PID: 2612)
    • Creates/Modifies COM task schedule object

      • icarus.exe (PID: 2612)
      • RegSvr.exe (PID: 6632)
      • RegSvr.exe (PID: 6752)
    • Process checks presence of unattended files

      • icarus.exe (PID: 2612)
    • Executes as Windows Service

      • wsc_proxy.exe (PID: 3888)
      • afwServ.exe (PID: 6428)
      • AvastSvc.exe (PID: 3840)
      • aswToolsSvc.exe (PID: 432)
      • aswidsagent.exe (PID: 3920)
    • Adds/modifies Windows certificates

      • AvastSvc.exe (PID: 3840)
    • Reads the date of Windows installation

      • aswidsagent.exe (PID: 3920)
    • Read startup parameters

      • aswidsagent.exe (PID: 3920)
    • Checks for Java to be installed

      • AvastSvc.exe (PID: 3840)
    • Searches for installed software

      • overseer.exe (PID: 2904)
    • Connects to unusual port

      • AvastSvc.exe (PID: 3840)
    • Application launched itself

      • AvastUI.exe (PID: 5448)
  • INFO

    • The sample compiled with english language support

      • avast_free_antivirus_setup_online.exe (PID: 6620)
      • avast_free_antivirus_online_setup.exe (PID: 6744)
      • icarus.exe (PID: 6984)
      • icarus.exe (PID: 2612)
      • icarus.exe (PID: 3224)
      • engsup.exe (PID: 2776)
      • AvEmUpdate.exe (PID: 2788)
      • AvastSvc.exe (PID: 3840)
      • aswOfferTool.exe (PID: 8124)
    • Reads the machine GUID from the registry

      • avast_free_antivirus_setup_online.exe (PID: 6620)
      • avast_free_antivirus_online_setup.exe (PID: 6744)
      • icarus.exe (PID: 6984)
      • icarus.exe (PID: 2612)
      • icarus_ui.exe (PID: 7056)
      • icarus.exe (PID: 3224)
      • wsc_proxy.exe (PID: 488)
      • afwServ.exe (PID: 6428)
      • AvastSvc.exe (PID: 3840)
      • aswToolsSvc.exe (PID: 432)
      • aswidsagent.exe (PID: 3920)
      • AvastUI.exe (PID: 5448)
      • icarus.exe (PID: 7636)
      • overseer.exe (PID: 2904)
      • icarus.exe (PID: 8164)
    • Checks supported languages

      • avast_free_antivirus_setup_online.exe (PID: 6620)
      • avast_free_antivirus_online_setup.exe (PID: 6744)
      • icarus.exe (PID: 6984)
      • icarus_ui.exe (PID: 7056)
      • icarus.exe (PID: 2612)
      • icarus.exe (PID: 3224)
      • engsup.exe (PID: 2776)
      • SetupInf.exe (PID: 6944)
      • SetupInf.exe (PID: 6712)
      • SetupInf.exe (PID: 1876)
      • SetupInf.exe (PID: 4804)
      • SetupInf.exe (PID: 1868)
      • SetupInf.exe (PID: 2464)
      • AvEmUpdate.exe (PID: 6156)
      • RegSvr.exe (PID: 6632)
      • AvEmUpdate.exe (PID: 2788)
      • RegSvr.exe (PID: 6752)
      • wsc_proxy.exe (PID: 488)
      • SetupInf.exe (PID: 7000)
      • wsc_proxy.exe (PID: 3888)
      • afwServ.exe (PID: 6428)
      • AvastSvc.exe (PID: 3840)
      • aswToolsSvc.exe (PID: 432)
      • aswEngSrv.exe (PID: 6152)
      • aswidsagent.exe (PID: 3920)
      • AvastNM.exe (PID: 6756)
      • engsup.exe (PID: 7416)
      • icarus.exe (PID: 7636)
      • overseer.exe (PID: 2904)
      • AvastUI.exe (PID: 5448)
      • icarus.exe (PID: 8164)
      • AvastUI.exe (PID: 7372)
      • AvastUI.exe (PID: 6188)
      • aswOfferTool.exe (PID: 6764)
    • Reads the computer name

      • avast_free_antivirus_setup_online.exe (PID: 6620)
      • avast_free_antivirus_online_setup.exe (PID: 6744)
      • icarus.exe (PID: 6984)
      • icarus.exe (PID: 3224)
      • icarus_ui.exe (PID: 7056)
      • icarus.exe (PID: 2612)
      • engsup.exe (PID: 2776)
      • SetupInf.exe (PID: 6944)
      • SetupInf.exe (PID: 6712)
      • SetupInf.exe (PID: 2464)
      • SetupInf.exe (PID: 1876)
      • SetupInf.exe (PID: 4804)
      • SetupInf.exe (PID: 1868)
      • AvEmUpdate.exe (PID: 6156)
      • RegSvr.exe (PID: 6632)
      • AvEmUpdate.exe (PID: 2788)
      • RegSvr.exe (PID: 6752)
      • SetupInf.exe (PID: 7000)
      • wsc_proxy.exe (PID: 488)
      • wsc_proxy.exe (PID: 3888)
      • afwServ.exe (PID: 6428)
      • AvastSvc.exe (PID: 3840)
      • aswToolsSvc.exe (PID: 432)
      • aswidsagent.exe (PID: 3920)
      • engsup.exe (PID: 7416)
      • icarus.exe (PID: 7636)
      • AvastUI.exe (PID: 5448)
      • AvastUI.exe (PID: 6188)
    • Reads the software policy settings

      • avast_free_antivirus_setup_online.exe (PID: 6620)
      • avast_free_antivirus_online_setup.exe (PID: 6744)
      • icarus.exe (PID: 6984)
      • icarus_ui.exe (PID: 7056)
      • AvEmUpdate.exe (PID: 2788)
      • AvastSvc.exe (PID: 3840)
      • icarus.exe (PID: 7844)
    • Create files in a temporary directory

      • avast_free_antivirus_online_setup.exe (PID: 6744)
      • engsup.exe (PID: 7416)
    • Creates files in the program directory

      • avast_free_antivirus_online_setup.exe (PID: 6744)
      • icarus.exe (PID: 6984)
      • icarus_ui.exe (PID: 7056)
      • icarus.exe (PID: 2612)
      • icarus.exe (PID: 3224)
      • engsup.exe (PID: 2776)
      • AvEmUpdate.exe (PID: 6156)
      • AvEmUpdate.exe (PID: 2788)
      • wsc_proxy.exe (PID: 488)
      • afwServ.exe (PID: 6428)
      • AvastSvc.exe (PID: 3840)
      • aswToolsSvc.exe (PID: 432)
    • Checks proxy server information

      • avast_free_antivirus_online_setup.exe (PID: 6744)
      • icarus.exe (PID: 6984)
      • icarus_ui.exe (PID: 7056)
      • AvEmUpdate.exe (PID: 2788)
      • AvEmUpdate.exe (PID: 6156)
      • AvastUI.exe (PID: 5448)
    • Reads CPU info

      • icarus.exe (PID: 6984)
      • icarus_ui.exe (PID: 7056)
      • icarus.exe (PID: 3224)
      • icarus.exe (PID: 2612)
      • engsup.exe (PID: 2776)
      • SetupInf.exe (PID: 6944)
      • SetupInf.exe (PID: 2464)
      • SetupInf.exe (PID: 1876)
      • SetupInf.exe (PID: 4804)
      • SetupInf.exe (PID: 6712)
      • SetupInf.exe (PID: 1868)
      • RegSvr.exe (PID: 6632)
      • AvEmUpdate.exe (PID: 2788)
      • AvEmUpdate.exe (PID: 6156)
      • RegSvr.exe (PID: 6752)
      • SetupInf.exe (PID: 7000)
      • wsc_proxy.exe (PID: 488)
      • wsc_proxy.exe (PID: 3888)
      • afwServ.exe (PID: 6428)
      • AvastSvc.exe (PID: 3840)
      • aswToolsSvc.exe (PID: 432)
      • aswEngSrv.exe (PID: 6152)
      • aswidsagent.exe (PID: 3920)
      • AvastNM.exe (PID: 6756)
      • AvastUI.exe (PID: 5448)
      • engsup.exe (PID: 7416)
      • icarus.exe (PID: 7636)
      • icarus.exe (PID: 8164)
      • AvastUI.exe (PID: 6188)
    • Reads Environment values

      • icarus.exe (PID: 2612)
      • AvEmUpdate.exe (PID: 6156)
      • AvEmUpdate.exe (PID: 2788)
      • afwServ.exe (PID: 6428)
      • AvastSvc.exe (PID: 3840)
      • aswToolsSvc.exe (PID: 432)
      • aswidsagent.exe (PID: 3920)
    • Creates files or folders in the user directory

      • icarus_ui.exe (PID: 7056)
    • The sample compiled with czech language support

      • icarus.exe (PID: 2612)
    • Manual execution by a user

      • AvastUI.exe (PID: 5448)
      • AvastUI.exe (PID: 7372)
    • Reads the time zone

      • aswidsagent.exe (PID: 3920)
    • Process checks computer location settings

      • AvastUI.exe (PID: 5448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:20 07:47:50+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 142336
InitializedDataSize: 97792
UninitializedDataSize: -
EntryPoint: 0x1020
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.1.133.0
ProductVersionNumber: 2.1.133.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Gen Digital Inc.
Edition: 1
FileDescription: Avast Installer
FileVersion: 2.1.133.0
InternalName: microstub
LegalCopyright: Copyright © 2024 Gen Digital Inc. All rights reserved.
OriginalFileName: microstub.exe
ProductName: Avast
ProductVersion: 2.1.133.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
45
Malicious processes
26
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
432"C:\Program Files\Avast Software\Avast\aswToolsSvc.exe" /runassvcC:\Program Files\Avast Software\Avast\aswToolsSvc.exe
services.exe
User:
SYSTEM
Company:
Gen Digital Inc.
Integrity Level:
SYSTEM
Description:
Avast Antivirus
Version:
25.1.9816.0
488"C:\Program Files\Avast Software\Avast\wsc_proxy.exe" /svc /register /ppl_svcC:\Program Files\Avast Software\Avast\wsc_proxy.exeicarus.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast remediation exe
Exit code:
0
Version:
21.4.6162.0
Modules
Images
c:\program files\avast software\avast\wsc_proxy.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files\avast software\avast\wsc.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1868"C:\Program Files\Avast Software\Avast\SetupInf.exe" /uninstall /catalog:aswRvrt.catC:\Program Files\Avast Software\Avast\SetupInf.exeicarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
25.1.9816.0
Modules
Images
c:\program files\avast software\avast\setupinf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1876"C:\Program Files\Avast Software\Avast\SetupInf.exe" /uninstall /catalog:aswHwid.catC:\Program Files\Avast Software\Avast\SetupInf.exeicarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
25.1.9816.0
Modules
Images
c:\program files\avast software\avast\setupinf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
2464"C:\Program Files\Avast Software\Avast\SetupInf.exe" /uninstall /catalog:aswRdr2.catC:\Program Files\Avast Software\Avast\SetupInf.exeicarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
25.1.9816.0
Modules
Images
c:\program files\avast software\avast\setupinf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
2612C:\WINDOWS\Temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\avast-av\icarus.exe /cookie:mmm_ava_998_999_000_m:dlid_FAV-ONLINE-HP /edat_dir:C:\WINDOWS\Temp\asw.df202ef09d5db95a /geo:DE /track-guid:5cad847d-86c4-47a3-b6e7-b84ad14e39ab /sssid:6744 /er_master:master_ep_f04466a8-2a83-4fb9-9f59-b984bcdcdcdf /er_ui:ui_ep_31b817eb-0fbb-480d-a59e-296d8db33f8e /er_slave:avast-av_slave_ep_e8fb371a-b984-4533-97e7-ac185c44493d /slave:avast-avC:\Windows\Temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\avast-av\icarus.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Installer
Exit code:
0
Version:
25.1.8538.0
Modules
Images
c:\windows\temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\avast-av\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\ucrtbase.dll
2776"C:\Program Files\Avast Software\Avast\defs\25021208\engsup.exe" /prepare_definitions_folderC:\Program Files\Avast Software\Avast\defs\25021208\engsup.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus vps tool
Exit code:
0
Version:
18.0.2119.0
Modules
Images
c:\program files\avast software\avast\defs\25021208\engsup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2788"C:\Program Files\Avast Software\Avast\AvEmUpdate.exe" /installerC:\Program Files\Avast Software\Avast\AvEmUpdate.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Emergency Update
Exit code:
0
Version:
25.1.9816.0
Modules
Images
c:\program files\avast software\avast\avemupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\ucrtbase.dll
2904"C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe" /skip_uptime /skip_remediationsC:\Program Files\Common Files\Avast Software\Overseer\overseer.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Overseer
Version:
1.0.498.0
3224C:\WINDOWS\Temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\avast-av-vps\icarus.exe /cookie:mmm_ava_998_999_000_m:dlid_FAV-ONLINE-HP /edat_dir:C:\WINDOWS\Temp\asw.df202ef09d5db95a /geo:DE /track-guid:5cad847d-86c4-47a3-b6e7-b84ad14e39ab /sssid:6744 /er_master:master_ep_f04466a8-2a83-4fb9-9f59-b984bcdcdcdf /er_ui:ui_ep_31b817eb-0fbb-480d-a59e-296d8db33f8e /er_slave:avast-av-vps_slave_ep_43bca81f-7bc0-4bd5-84c1-4fba3e2b7bc6 /slave:avast-av-vpsC:\Windows\Temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\avast-av-vps\icarus.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Installer
Exit code:
0
Version:
25.1.8538.0
Modules
Images
c:\windows\temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\avast-av-vps\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
60 196
Read events
58 907
Write events
1 173
Delete events
116

Modification events

(PID) Process:(6744) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:5FD38555-4B16-40AE-9A09-E2C969CB74AF
Value:
F6D4F52220BB5A3D7246A004278BB23F
(PID) Process:(6744) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F
Operation:writeName:7CCD586D-2ABC-42FF-A23B-3731F4F183D9
Value:
F6D4F52220BB5A3D7246A004278BB23F
(PID) Process:(6744) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:8C5CFDF4-AB05-4EB0-8EF6-7B4620DC2CF3
Value:
AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAUCoDSwlqJkW4XcOsM/cLiwQAAAACAAAAAAAQZgAAAAEAACAAAADMtbK63c5+pM/6aAopT4QJ/uzMIV6phPYjhkPavxTd6gAAAAAOgAAAAAIAACAAAAD3n3n/srRUPJr1Piyv5ohyRCLPPKlCN5kNV9jQ5Piuh1AAAAAHXFzCKmeq1U2VTT6kbv8Fsc6D2XsWiZ3EQnfYhfEq8KvvwVqub1s5LzPV4Lhw1UNdGhKq7Niz2s9UwoBQWnyzUxy5ZP8DjNQ5lR1KZcpmb0AAAADRfcEVSI34+KtDmzO+kbxJ7lcKGAiGHb6J202nx0i5NwGyGnZayNOuiDh+RDTsjUyFYWdOhBy+nNbZ6DJQDbT1
(PID) Process:(6744) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F
Operation:writeName:5E1D6A55-0134-486E-A166-38C2E4919BB1
Value:
AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAUCoDSwlqJkW4XcOsM/cLiwQAAAACAAAAAAAQZgAAAAEAACAAAADMtbK63c5+pM/6aAopT4QJ/uzMIV6phPYjhkPavxTd6gAAAAAOgAAAAAIAACAAAAD3n3n/srRUPJr1Piyv5ohyRCLPPKlCN5kNV9jQ5Piuh1AAAAAHXFzCKmeq1U2VTT6kbv8Fsc6D2XsWiZ3EQnfYhfEq8KvvwVqub1s5LzPV4Lhw1UNdGhKq7Niz2s9UwoBQWnyzUxy5ZP8DjNQ5lR1KZcpmb0AAAADRfcEVSI34+KtDmzO+kbxJ7lcKGAiGHb6J202nx0i5NwGyGnZayNOuiDh+RDTsjUyFYWdOhBy+nNbZ6DJQDbT1
(PID) Process:(6744) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:144807F0-DE37-4C62-9C05-EB4CC64A7A2F
Value:
d3ba261a-f28e-4bc8-affe-040d984f99fb
(PID) Process:(6744) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F
Operation:writeName:56C7A9DA-4B11-406A-8B1A-EFF157C294D6
Value:
d3ba261a-f28e-4bc8-affe-040d984f99fb
(PID) Process:(6984) icarus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:144807F0-DE37-4C62-9C05-EB4CC64A7A2F
Value:
d3ba261a-f28e-4bc8-affe-040d984f99fb
(PID) Process:(6984) icarus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:5FD38555-4B16-40AE-9A09-E2C969CB74AF
Value:
F6D4F52220BB5A3D7246A004278BB23F
(PID) Process:(7056) icarus_ui.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7056) icarus_ui.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
702
Suspicious files
1 571
Text files
316
Unknown types
0

Dropped files

PID
Process
Filename
Type
6744avast_free_antivirus_online_setup.exeC:\Users\admin\AppData\Local\Temp\6358C710-B89F-46B9-93F2-F6CAC44F5286binary
MD5:00BDC7D60D809856B91670B6B794DF2C
SHA256:1A73F66D8A905FC3B69563722956C2017683849EDD6448E082D46C8D35753C18
6744avast_free_antivirus_online_setup.exeC:\Users\admin\AppData\Local\Temp\D566D7D7-DCD6-471C-8109-BE0AD33199E3binary
MD5:51CACEA0FBAE8346C20FB94EFEEF8809
SHA256:5749457FC3E5EE160FE41B6BC0743A890B38FD3F09965828BD19FE269E5BD434
6744avast_free_antivirus_online_setup.exeC:\Windows\Temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\common\630bf157-e372-43f2-8616-9b919132d5b8compressed
MD5:2FB5E654EE20981454F67DE127A69712
SHA256:D4E53C210EF8DCE6A81E0925E2233534A45F7AFA75E9B87B834741B45C64C8D3
6744avast_free_antivirus_online_setup.exeC:\Users\admin\AppData\Local\Temp\F07D8C6A-04B6-4025-869C-70A788D7B5C0binary
MD5:CFB22998C6F316EDC64166692B966BDF
SHA256:98660F91FE4D5642C9E44BE0717FBF8B7617DB72B165D1CA019BC539C67966BF
6744avast_free_antivirus_online_setup.exeC:\Windows\Temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\common\icarus_mod.dllexecutable
MD5:92B56F882D892BD0D7D3042DD687E71E
SHA256:98AAD90F040FC070386B8FD41911560FDDFEE4BE5DCAB5E60E1D4985C0285F77
6744avast_free_antivirus_online_setup.exeC:\Windows\Temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\common\product-info.xmlxml
MD5:4D7FB7B0E1E232D412AD0EC42EADB761
SHA256:FD11EFC88135C1272C52935338116F24A53EF984BBEF32E89CF0F2142088BB2C
6620avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.df202ef09d5db95a\avast_free_antivirus_online_setup.exeexecutable
MD5:65B3E838C7204CEAD5A177A64330CEFB
SHA256:2CDF57D72CB0911F6A18491AAB4240CE41AAC476D213D3C5AEEDD5A1B4407AE0
6744avast_free_antivirus_online_setup.exeC:\Windows\Temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\common\icarus_ui.exeexecutable
MD5:665EA9F9AB600BC84CF2C3B96EA1EA84
SHA256:898E902FEDA5BDCBF1E941D7D07E901EA1D8E30F91297663D92F463E71EF2A03
6744avast_free_antivirus_online_setup.exeC:\Windows\Temp\asw-7e26e6ea-b258-49c9-b2b7-abe19225119b\common\product-def.xmlxml
MD5:A5DF1E9DFD23D5A5316E814CA7390EEE
SHA256:E93DD3EDF9B661C1AB8E32C2FDEF3960521FD6AA0A543FD1CC6C4200EC49E03B
6620avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.df202ef09d5db95a\ecoo.edattext
MD5:0C3FB92E76191DB5CAF5B0B3FAA37CE5
SHA256:C0B918FFF0C176E58CB694AD6B830EDDB0F987F3558583FC339B49681D5D3B46
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
51
TCP/UDP connections
339
DNS requests
273
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5340
svchost.exe
GET
200
184.85.144.229:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
FI
binary
973 b
whitelisted
6620
avast_free_antivirus_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
US
whitelisted
6620
avast_free_antivirus_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
US
whitelisted
5064
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
7056
icarus_ui.exe
GET
200
172.217.18.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
binary
1.41 Kb
whitelisted
7056
icarus_ui.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
DE
binary
471 b
whitelisted
6816
SIHClient.exe
GET
200
184.85.144.229:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
FI
binary
408 b
whitelisted
6328
backgroundTaskHost.exe
GET
200
23.67.160.244:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
JP
binary
471 b
whitelisted
2788
AvEmUpdate.exe
HEAD
200
62.115.252.145:80
http://emupdate.avcdn.net/files/emupdate/pong.txt
ES
whitelisted
2788
AvEmUpdate.exe
GET
200
62.115.252.145:80
http://emupdate.avcdn.net/files/emupdate/updates.xml
ES
xml
124 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
62.115.253.10:80
crl.microsoft.com
Telia Company AB
ES
whitelisted
4712
MoUsoCoreWorker.exe
184.85.144.229:80
www.microsoft.com
AKAMAI-AS
FI
whitelisted
5340
svchost.exe
184.85.144.229:80
www.microsoft.com
AKAMAI-AS
FI
whitelisted
5064
SearchApp.exe
95.100.248.212:443
www.bing.com
Akamai International B.V.
NL
whitelisted
6620
avast_free_antivirus_setup_online.exe
34.117.223.223:80
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
6620
avast_free_antivirus_setup_online.exe
34.111.175.102:443
ip-info.ff.avast.com
GOOGLE
US
whitelisted
6620
avast_free_antivirus_setup_online.exe
142.250.74.206:80
www.google-analytics.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.142
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 62.115.253.10
  • 62.115.253.40
whitelisted
www.microsoft.com
  • 184.85.144.229
whitelisted
www.bing.com
  • 95.100.248.212
  • 95.100.248.219
  • 2.23.227.215
  • 2.23.227.208
whitelisted
www.google-analytics.com
  • 142.250.74.206
  • 172.217.16.206
whitelisted
ip-info.ff.avast.com
  • 34.111.175.102
whitelisted
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
go.microsoft.com
  • 23.219.150.9
whitelisted
honzik.avcdn.net
  • 2.19.100.183
  • 2a02:26f0:e600:584::240d
  • 2a02:26f0:e600:589::240d
  • 2a02:26f0:3500:f9c::240d
  • 2a02:26f0:3500:f92::240d
  • 184.30.237.157
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
6620
avast_free_antivirus_setup_online.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
2192
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
2788
AvEmUpdate.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
2192
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
432
aswToolsSvc.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
3840
AvastSvc.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
3840
AvastSvc.exe
Not Suspicious Traffic
INFO [ANY.RUN] BootstrapCDN (maxcdn .bootstrapcdn .com)
3840
AvastSvc.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
3840
AvastSvc.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
No debug info