| File name: | avastclear.exe |
| Full analysis: | https://app.any.run/tasks/b89e5c52-5ef2-467c-9aef-8bce98f1aa89 |
| Verdict: | Malicious activity |
| Analysis date: | June 08, 2024, 20:29:41 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F5A3E69A5A2457C3FA2AA6FC284055A5 |
| SHA1: | 61ED7E59F296BE4D7B36E6086F2F0FA3A7D97B75 |
| SHA256: | 3CAC2FCE120E9244D4EA7B7CDBFCDC6E2A950C0702C21438319FBB699DF25C3E |
| SSDEEP: | 98304:6geSZ9Lc8zZJX73CTTYr2P/ECO82EX7c5wvosxQJXVjyTh9IawDPj6fTkms5KpSt:z6tgAYCoVR/t9qtfbxdna+ |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:02:01 15:01:26+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 14.38 |
| CodeSize: | 980480 |
| InitializedDataSize: | 522752 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x3f1b0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 24.1.8821.0 |
| ProductVersionNumber: | 24.1.8821.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | AVAST Software |
| LegalCopyright: | Copyright (c) 2024 AVAST Software |
| FileDescription: | Avast Antivirus |
| FileVersion: | 24.1.8821.0 |
| InternalName: | SfxInst |
| OriginalFileName: | SfxInst.exe |
| ProductName: | Avast Antivirus |
| ProductVersion: | 24.1.8821.0 |
| ProductId: | avast-av |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1008 | "C:\WINDOWS\system32\bcdedit.exe" /bootsequence {current} | C:\Windows\System32\bcdedit.exe | — | Instup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3656 | "C:\WINDOWS\Temp\asw.09d88a8094f43751\instup.exe" /sfx:clear /sfxstorage:C:\WINDOWS\Temp\asw.09d88a8094f43751 /prod:ais /wait /stub_mapping_guid:6013a6b9-6469-4a51-8b32-dc11f0663ed5:14160480 | C:\Windows\Temp\asw.09d88a8094f43751\Instup.exe | avastclear.exe | ||||||||||||
User: admin Company: AVAST Software Integrity Level: HIGH Description: Avast Antivirus Installer Exit code: 40963 Version: 24.1.8821.0 Modules
| |||||||||||||||
| 3692 | "C:\Users\admin\Desktop\avastclear.exe" | C:\Users\admin\Desktop\avastclear.exe | — | explorer.exe | |||||||||||
User: admin Company: AVAST Software Integrity Level: MEDIUM Description: Avast Antivirus Exit code: 3221226540 Version: 24.1.8821.0 Modules
| |||||||||||||||
| 4196 | "C:\WINDOWS\system32\bcdedit.exe" /v | C:\Windows\System32\bcdedit.exe | — | Instup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4620 | "C:\WINDOWS\system32\bcdedit.exe" /copy {{current}} /d "Avast Antivirus Clear Uninstall" | C:\Windows\System32\bcdedit.exe | — | Instup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4988 | "C:\Users\admin\Desktop\avastclear.exe" | C:\Users\admin\Desktop\avastclear.exe | explorer.exe | ||||||||||||
User: admin Company: AVAST Software Integrity Level: HIGH Description: Avast Antivirus Exit code: 40963 Version: 24.1.8821.0 Modules
| |||||||||||||||
| 4996 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | bcdedit.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5528 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | bcdedit.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5716 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | bcdedit.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5836 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | bcdedit.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avast Software |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avast Software |
| Operation: | write | Name: | SymbolicLinkValue |
Value: \Registry\MACHINE\SOFTWARE\Avast Software | |||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage |
| Operation: | write | Name: | SfxInstProgress |
Value: 0 | |||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage |
| Operation: | write | Name: | SfxInstProgress |
Value: 5 | |||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage |
| Operation: | write | Name: | SfxInstProgress |
Value: 11 | |||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage |
| Operation: | write | Name: | SfxInstProgress |
Value: 16 | |||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage |
| Operation: | write | Name: | SfxInstProgress |
Value: 22 | |||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage |
| Operation: | write | Name: | SfxInstProgress |
Value: 27 | |||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage |
| Operation: | write | Name: | SfxInstProgress |
Value: 33 | |||
| (PID) Process: | (4988) avastclear.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage |
| Operation: | write | Name: | SfxInstProgress |
Value: 38 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4988 | avastclear.exe | C:\WINDOWS\Temp\asw.09d88a8094f43751\part-prg_ais-180117d3.vpx | binary | |
MD5:C9AB86327CC6D1B698906C6B42364040 | SHA256:918DFC9B513535FDA13A3A1F1BB3741728936BD9B355958288A395F68090B81F | |||
| 4988 | avastclear.exe | C:\WINDOWS\Temp\asw.09d88a8094f43751\Instup.exe | executable | |
MD5:DE156A9DF037FF5EEB191C4328A7D0AE | SHA256:B23972A413A0C1BFA3FAA284F89F5BA811BCEE156CC6E4DA96E3E7325530798D | |||
| 4988 | avastclear.exe | C:\ProgramData\Avast Software\Persistent Data\Avast\Logs\Clear.log | text | |
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA | SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5 | |||
| 4988 | avastclear.exe | C:\WINDOWS\Temp\asw.09d88a8094f43751\config.def.vpx | binary | |
MD5:65A94D643E10FFC9156EE8F1BAE43C25 | SHA256:2C9559A99BB1859206D554D1C3984787E5B4F347C5C55E8C05D3C6350EBFB760 | |||
| 4988 | avastclear.exe | C:\WINDOWS\Temp\asw.09d88a8094f43751\uat64.vpx | binary | |
MD5:33B91876562EAB512A99946D2AB1B250 | SHA256:5B17357093F667242CAE0A263A6232C61BDA86E7B91034C566BD730C64633198 | |||
| 4988 | avastclear.exe | C:\WINDOWS\Temp\asw.09d88a8094f43751\part-jrog2-132c.vpx | binary | |
MD5:F757934C2D28D322FCA999FFAFDB4584 | SHA256:09C79062FED78B3BB7BB1DA546014D812FE77904A3F161B4908DC5724FF86A12 | |||
| 4988 | avastclear.exe | C:\WINDOWS\Temp\asw.09d88a8094f43751\part-setup_ais-180117d3.vpx | binary | |
MD5:72FEEE470E611C17FCB9494E9BF08B7D | SHA256:DED1EDCAD352CB5236D924F34FEEDEE238DA2B510B36701DE35F1C001D3A5697 | |||
| 3656 | Instup.exe | C:\WINDOWS\Temp\asw.09d88a8094f43751\setup.def | text | |
MD5:DE92EEF2373598A2775BDF25FCE19585 | SHA256:9C1B73C1FE42B957332F3D827D107EE359B695FB82FD8AB4AD0315CC00637CBD | |||
| 4988 | avastclear.exe | C:\WINDOWS\Temp\asw.09d88a8094f43751\prod-vps.vpx | binary | |
MD5:7366BD32AA01DC9CA58F78F895D87EB4 | SHA256:CD07142FB15B5537BA82395C1420089D1A844D8F62F199FEE1D4FEBFA45270DC | |||
| 4988 | avastclear.exe | C:\WINDOWS\Temp\asw.09d88a8094f43751\HTMLayout.dll | executable | |
MD5:D9E2BF6B55D8B8D83B70CEA456F31D01 | SHA256:FD9815A1FA6C7D4792BE31A1EB11540063FB80E1C7D800F1242CA9B2FA72DD5C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5952 | svchost.exe | GET | 200 | 2.17.147.64:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
2384 | RUXIMICS.exe | GET | 200 | 2.17.147.64:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
5140 | MoUsoCoreWorker.exe | GET | 200 | 2.19.217.218:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
5140 | MoUsoCoreWorker.exe | GET | 200 | 2.17.147.64:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
2384 | RUXIMICS.exe | GET | 200 | 2.19.217.218:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
5952 | svchost.exe | GET | 200 | 2.19.217.218:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
— | — | POST | 204 | 34.117.223.223:443 | https://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | — |
— | — | POST | 204 | 34.117.223.223:443 | https://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | — |
— | — | POST | 204 | 34.117.223.223:443 | https://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | — |
— | — | POST | 204 | 2.19.173.75:443 | https://www.bing.com/threshold/xls.aspx | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 239.255.255.250:1900 | — | — | — | unknown |
2384 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5140 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2384 | RUXIMICS.exe | 2.17.147.64:80 | crl.microsoft.com | Akamai International B.V. | CZ | unknown |
5952 | svchost.exe | 2.17.147.64:80 | crl.microsoft.com | Akamai International B.V. | CZ | unknown |
5140 | MoUsoCoreWorker.exe | 2.17.147.64:80 | crl.microsoft.com | Akamai International B.V. | CZ | unknown |
5140 | MoUsoCoreWorker.exe | 2.19.217.218:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
2384 | RUXIMICS.exe | 2.19.217.218:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
5952 | svchost.exe | 2.19.217.218:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
analytics.avcdn.net |
| unknown |
v7event.stats.avast.com |
| whitelisted |
shepherd.ff.avast.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
r.bing.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Generic Protocol Command Decode | SURICATA HTTP Request abnormal Content-Encoding header |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request abnormal Content-Encoding header |
Process | Message |
|---|---|
avastclear.exe | [2024-06-08 20:29:56.682] [info ] [sfxinst ] [ 4988: 3916] [7361C5: 370] Running SFX 'C:\Users\admin\Desktop\avastclear.exe'
|
avastclear.exe | [2024-06-08 20:30:01.104] [info ] [sfxstats ] [ 4988: 1112] [03AC9E: 149] Statistics sent successfully.
|
avastclear.exe | [2024-06-08 20:30:12.276] [notice ] [burger_rep ] [ 4988: 4108] [64A1D8: 66] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
|
avastclear.exe | [2024-06-08 20:30:13.276] [info ] [sfxinst ] [ 4988: 3916] [7361C5: 881] Starting installer/updater executable 'C:\WINDOWS\Temp\asw.09d88a8094f43751\instup.exe'
|
Instup.exe | [2024-06-08 20:30:13.588] [info ] [instup ] [ 3656: 4128] [87A008:2686] Memory: 34% load. Phys:2725436/4188620K free, Page:3686208/4194303K free, Virt:3987972/4194176K free
|
Instup.exe | [2024-06-08 20:30:13.588] [info ] [instup ] [ 3656: 4128] [87A008:2672] setup: x86
|
Instup.exe | [2024-06-08 20:30:13.588] [info ] [instup ] [ 3656: 4128] [87A008:2734] Running module version: Instup.dll - '24.1.8821.0'
|
Instup.exe | [2024-06-08 20:30:13.588] [info ] [instup ] [ 3656: 4128] [87A008:2719] Running module version: instup.exe - '24.1.8821.0'
|
Instup.exe | [2024-06-08 20:30:13.588] [debug ] [repsup ] [ 3656: 4128] [B909FF: 58] PfroMutant: \PendingRenameMutex mutant has been successfully opened.
|
Instup.exe | [2024-06-08 20:30:13.588] [info ] [instup ] [ 3656: 4128] [87A008:2658] Command: '"C:\WINDOWS\Temp\asw.09d88a8094f43751\instup.exe" /sfx:clear /sfxstorage:C:\WINDOWS\Temp\asw.09d88a8094f43751 /prod:ais /wait /stub_mapping_guid:6013a6b9-6469-4a51-8b32-dc11f0663ed5:14160480'
|