File name:

Activator.zip

Full analysis: https://app.any.run/tasks/71407c8e-5148-40e6-9252-386127ebf2be
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 28, 2024, 20:39:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
spam
python
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

947CA5995D64DD08CCC29CC08D85827F

SHA1:

357198BBD1A7E9C4D9463ECC259E28C5D8F70C21

SHA256:

4E822F20531E250D774ABF6D1173B07A1BD9EC658C9263FDFA908B1691E659B0

SSDEEP:

98304:PGW7WFvSqUebg162+pdUHxbm2KR0ny+hE7c4YHky/98jL6Fkn/0GfDqzU+a0DnYH:rhB4eccftX+gIunx6ZLeo5Wbr7CNjv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • avast_premium_security_setup_online.exe (PID: 5488)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 5812)
      • aswOfferTool.exe (PID: 2856)
      • aswOfferTool.exe (PID: 5696)
      • instup.exe (PID: 5080)
    • Changes the autorun value in the registry

      • instup.exe (PID: 5080)
    • Modifies hosts file to block updates

      • cmd.exe (PID: 4608)
  • SUSPICIOUS

    • Process drops python dynamic module

      • WinRAR.exe (PID: 2116)
    • Loads Python modules

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Potential Corporate Privacy Violation

      • avast_premium_security_setup_online.exe (PID: 5488)
    • Executable content was dropped or overwritten

      • avast_premium_security_setup_online.exe (PID: 5488)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 5812)
      • aswOfferTool.exe (PID: 2856)
      • aswOfferTool.exe (PID: 5696)
      • instup.exe (PID: 5080)
    • Searches for installed software

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Process requests binary or script from the Internet

      • avast_premium_security_setup_online.exe (PID: 5488)
    • Reads security settings of Internet Explorer

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
    • Starts itself from another location

      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 2856)
    • Process checks presence of unattended files

      • instup.exe (PID: 5080)
    • Likely accesses (executes) a file from the Public directory

      • aswOfferTool.exe (PID: 5696)
    • Reads the date of Windows installation

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
    • Starts CMD.EXE for commands execution

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
    • Executing commands from a ".bat" file

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
    • Process drops legitimate windows executable

      • instup.exe (PID: 5080)
    • The process drops C-runtime libraries

      • instup.exe (PID: 5080)
    • Creates files in the driver directory

      • instup.exe (PID: 5080)
    • The process verifies whether the antivirus software is installed

      • instup.exe (PID: 5080)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2116)
    • Checks proxy server information

      • slui.exe (PID: 6804)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Reads the software policy settings

      • slui.exe (PID: 6804)
      • avast_premium_security_setup_online.exe (PID: 5488)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Manual execution by a user

      • avast_premium_security_setup_online.exe (PID: 5700)
      • avast_premium_security_setup_online.exe (PID: 5488)
      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 4316)
      • Antivirus Activation Assistant.exe (PID: 6788)
    • Reads the computer name

      • avast_premium_security_setup_online.exe (PID: 5488)
      • Antivirus Activation Assistant.exe (PID: 1644)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 2856)
      • instup.exe (PID: 5080)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Reads the machine GUID from the registry

      • avast_premium_security_setup_online.exe (PID: 5488)
      • Antivirus Activation Assistant.exe (PID: 1644)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Checks supported languages

      • avast_premium_security_setup_online.exe (PID: 5488)
      • Antivirus Activation Assistant.exe (PID: 1644)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 2856)
      • aswOfferTool.exe (PID: 5812)
      • instup.exe (PID: 5080)
      • aswOfferTool.exe (PID: 6260)
      • aswOfferTool.exe (PID: 5696)
      • sbr.exe (PID: 4832)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2116)
    • Reads CPU info

      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Creates files in the program directory

      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Reads Environment values

      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Dropped object may contain TOR URL's

      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 2856)
      • instup.exe (PID: 5080)
    • Process checks computer location settings

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (36.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:05:01 13:05:18
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Activator/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
193
Monitored processes
50
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe slui.exe avast_premium_security_setup_online.exe no specs avast_premium_security_setup_online.exe antivirus activation assistant.exe no specs avast_premium_security_setup_online_x64.exe instup.exe instup.exe aswoffertool.exe no specs aswoffertool.exe aswoffertool.exe aswoffertool.exe sbr.exe no specs cmd.exe no specs conhost.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs antivirus activation assistant.exe cmd.exe no specs conhost.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs antivirus activation assistant.exe no specs antivirus activation assistant.exe

Process information

PID
CMD
Path
Indicators
Parent process
1000FIND /C /I "75.126.120.203" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1292FIND /C /I "46.4.28.80" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1328\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1428FIND /C /I "46.4.62.150" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1516FIND /C /I "46.4.58.71" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1644"C:\Users\admin\Desktop\Activator\Antivirus Activation Assistant.exe" C:\Users\admin\Desktop\Activator\Antivirus Activation Assistant.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Antivirus Activation Assistant
Exit code:
0
Version:
2.1.0.0
Modules
Images
c:\users\admin\desktop\activator\antivirus activation assistant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1716FIND /C /I "46.4.28.80" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1780FIND /C /I "46.4.62.150" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1992FIND /C /I "www.pns.avast.com" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
2116"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Activator.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
36 289
Read events
29 196
Write events
7 074
Delete events
19

Modification events

(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Activator.zip
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(5488) avast_premium_security_setup_online.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\WINDOWS\Temp\asw.9f8c54cb9ab51ac1
Executable files
420
Suspicious files
674
Text files
1 495
Unknown types
2

Dropped files

PID
Process
Filename
Type
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Premium_Security\10-2025\license.avastlictext
MD5:FFE0DC435DFC1A80641D2E4AD9540B1D
SHA256:36CB4F1250F8340655289DA9E3A25AA4565AA6F0197DDFE993F778742A2D379F
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Ultimate\8-2025\license.avastlictext
MD5:1F8DAECFB92EB36444F62EEF5BE73F5A
SHA256:29AF8F2D93A78FCE91F7751A98DE6F795065D6F54D345D5E641336092459D24D
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Premium_Security\11-2025\license.avastlictext
MD5:3843E8AB17ACD3043F96F966B4C52299
SHA256:762A6D596BFB75DAE31A63C30F7FA061B2232B27E10F97E683DA238AD4E3C323
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Ultimate\11-2024\license.avastlictext
MD5:A578CB4C743A4216E9AFFBC882065A66
SHA256:E22028E336B7755FDBDB53FE845B9603D9FC6CB8FA60D1D7B6D17E4FB0A25095
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Premium_Security\11-2024\license.avastlictext
MD5:A10FE0164ABEA9AAEBA4A96024635F06
SHA256:8E70299409561B2EEE76D69EC5F25D9996ABF6091FA10195F2244D6D97B6336E
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Premium_Security\12-2024\license.avastlictext
MD5:0575568CCE73B015FA1A1853C89B9C81
SHA256:B69F8B2D5D4B1F67C06AD0A7F56570A48A3264EACC03DDFCCBD48158801D9B9D
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Ultimate\11-2026\license.avastlictext
MD5:76E8369A53F4A176867EB6836257BF8D
SHA256:5C1A3AF3CC5BE5E921505885A2EC6E2172F9DAE7BE4777556C3A7D9F7573FD2B
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\Avast Security Premium\2038\license.avastlictext
MD5:4D84D3CFFAC3093369C158B08975922B
SHA256:EC666ECFF26C9E5538431D78B70F37FAC1828EDF59897688CDAAE00258869D74
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Ultimate\6_2-2025\license.avastlictext
MD5:90E29F6C5423DEDCBAFD3C9A980CB34C
SHA256:92C0E29B94FBB70E2131A668874F6CDA358AEF91A21A73FA2A28572C05D3488D
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Premium_Security\9-2025\license.avastlictext
MD5:134864CD6782CEBBC0033DF6F5E6AC1C
SHA256:D355464705213F5074E3D22F0043466ED177CB860336B705AE81A8D1EB30507F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
54
TCP/UDP connections
102
DNS requests
110
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3676
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5608
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5488
avast_premium_security_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
5488
avast_premium_security_setup_online.exe
POST
200
172.217.18.14:80
http://www.google-analytics.com/collect
unknown
unknown
5488
avast_premium_security_setup_online.exe
GET
200
2.19.126.143:80
http://iavs9x.u.avcdn.net/iavs9x/avast_premium_security_setup_online_x64.exe
unknown
whitelisted
5488
avast_premium_security_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
3620
Instup.exe
GET
23.48.23.20:80
http://j0294597.iavs9x.u.avast.com/iavs9x/avbugreport_x64_ais-a45.vpx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
996
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6012
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2856
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
92.123.104.67:443
www.bing.com
Akamai International B.V.
DE
unknown
1516
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
5452
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
www.bing.com
  • 92.123.104.67
  • 92.123.104.4
  • 92.123.104.66
  • 92.123.104.10
  • 92.123.104.64
  • 92.123.104.8
  • 92.123.104.63
  • 92.123.104.62
  • 92.123.104.6
  • 92.123.104.23
  • 92.123.104.33
  • 92.123.104.31
  • 92.123.104.29
  • 92.123.104.32
  • 92.123.104.26
  • 92.123.104.30
  • 92.123.104.28
  • 92.123.104.34
whitelisted
google.com
  • 142.250.185.110
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.45
whitelisted
login.live.com
  • 20.190.159.68
  • 40.126.31.71
  • 40.126.31.73
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.67
  • 20.190.159.4
  • 20.190.159.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

PID
Process
Class
Message
5488
avast_premium_security_setup_online.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:55.923] [info ] [sfxinst ] [ 4520: 4028] [F8CC93: 395] Running SFX 'C:\WINDOWS\Temp\asw.9f8c54cb9ab51ac1\avast_premium_security_setup_online_x64.exe'
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:56.188] [info ] [sfxinst ] [ 4520: 4028] [F8CC93: 629] Moved extra data file 'ecoo.edat' to 'C:\WINDOWS\Temp\asw.7ef673c8a8f4fd47\cookie.bin'.
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:56.313] [notice ] [burger_rep ] [ 4520: 7040] [DC075C: 64] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:56.313] [info ] [sfxstats ] [ 4520: 3976] [9A143C: 149] Statistics sent successfully.
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:57.063] [info ] [sfxinst ] [ 4520: 4028] [F8CC93: 919] Starting installer/updater executable 'C:\WINDOWS\Temp\asw.7ef673c8a8f4fd47\instup.exe'
Instup.exe
[2024-07-28 20:41:57.454] [info ] [instup ] [ 3620: 3840] [EE4A6B:2703] DISKs: C:\ - 218486MB free / 254GB total
Instup.exe
[2024-07-28 20:41:57.454] [info ] [instup ] [ 3620: 3840] [EE4A6B:2719] Running module version: instup.exe - '24.7.9311.0'
Instup.exe
[2024-07-28 20:41:57.454] [info ] [instup ] [ 3620: 3840] [EE4A6B:2734] Running module version: Instup.dll - '24.7.9311.0'
Instup.exe
[2024-07-28 20:41:57.454] [debug ] [repsup ] [ 3620: 3840] [84102E: 58] PfroMutant: \PendingRenameMutex mutant has been successfully opened.
Instup.exe
[2024-07-28 20:41:57.454] [info ] [instup ] [ 3620: 3840] [EE4A6B:2658] Command: '"C:\WINDOWS\Temp\asw.7ef673c8a8f4fd47\instup.exe" /sfx:lite /sfxstorage:C:\WINDOWS\Temp\asw.7ef673c8a8f4fd47 /edition:12 /prod:ais /stub_context:f4627aa5-7106-4ee4-8e2d-bb9f0f4456a6:9931888 /guid:5bfe25cc-9691-403f-89ef-54b7eff91fa0 /ga_clientid:01b081a0-7227-4224-a363-b551a383edd7 /cookie:mmm_prw_998_999_000_m /ga_clientid:01b081a0-7227-4224-a363-b551a383edd7 /edat_dir:C:\WINDOWS\Temp\asw.9f8c54cb9ab51ac1'