File name:

Activator.zip

Full analysis: https://app.any.run/tasks/71407c8e-5148-40e6-9252-386127ebf2be
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 28, 2024, 20:39:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
spam
python
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

947CA5995D64DD08CCC29CC08D85827F

SHA1:

357198BBD1A7E9C4D9463ECC259E28C5D8F70C21

SHA256:

4E822F20531E250D774ABF6D1173B07A1BD9EC658C9263FDFA908B1691E659B0

SSDEEP:

98304:PGW7WFvSqUebg162+pdUHxbm2KR0ny+hE7c4YHky/98jL6Fkn/0GfDqzU+a0DnYH:rhB4eccftX+gIunx6ZLeo5Wbr7CNjv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • avast_premium_security_setup_online.exe (PID: 5488)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 5812)
      • aswOfferTool.exe (PID: 2856)
      • aswOfferTool.exe (PID: 5696)
      • instup.exe (PID: 5080)
    • Changes the autorun value in the registry

      • instup.exe (PID: 5080)
    • Modifies hosts file to block updates

      • cmd.exe (PID: 4608)
  • SUSPICIOUS

    • Process drops python dynamic module

      • WinRAR.exe (PID: 2116)
    • Potential Corporate Privacy Violation

      • avast_premium_security_setup_online.exe (PID: 5488)
    • Loads Python modules

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Executable content was dropped or overwritten

      • avast_premium_security_setup_online.exe (PID: 5488)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 5812)
      • aswOfferTool.exe (PID: 5696)
      • aswOfferTool.exe (PID: 2856)
      • instup.exe (PID: 5080)
    • Searches for installed software

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Process requests binary or script from the Internet

      • avast_premium_security_setup_online.exe (PID: 5488)
    • Reads security settings of Internet Explorer

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
    • Starts itself from another location

      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 2856)
    • Process checks presence of unattended files

      • instup.exe (PID: 5080)
    • Likely accesses (executes) a file from the Public directory

      • aswOfferTool.exe (PID: 5696)
    • Reads the date of Windows installation

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
    • Starts CMD.EXE for commands execution

      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 1644)
    • Executing commands from a ".bat" file

      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 1644)
    • Process drops legitimate windows executable

      • instup.exe (PID: 5080)
    • The process drops C-runtime libraries

      • instup.exe (PID: 5080)
    • Creates files in the driver directory

      • instup.exe (PID: 5080)
    • The process verifies whether the antivirus software is installed

      • instup.exe (PID: 5080)
  • INFO

    • Checks proxy server information

      • slui.exe (PID: 6804)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2116)
    • Manual execution by a user

      • avast_premium_security_setup_online.exe (PID: 5700)
      • avast_premium_security_setup_online.exe (PID: 5488)
      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Reads the software policy settings

      • slui.exe (PID: 6804)
      • avast_premium_security_setup_online.exe (PID: 5488)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Reads the machine GUID from the registry

      • avast_premium_security_setup_online.exe (PID: 5488)
      • Antivirus Activation Assistant.exe (PID: 1644)
      • Instup.exe (PID: 3620)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • instup.exe (PID: 5080)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Checks supported languages

      • avast_premium_security_setup_online.exe (PID: 5488)
      • Antivirus Activation Assistant.exe (PID: 1644)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
      • aswOfferTool.exe (PID: 6260)
      • aswOfferTool.exe (PID: 5812)
      • aswOfferTool.exe (PID: 2856)
      • sbr.exe (PID: 4832)
      • aswOfferTool.exe (PID: 5696)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Reads the computer name

      • avast_premium_security_setup_online.exe (PID: 5488)
      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • Antivirus Activation Assistant.exe (PID: 1644)
      • instup.exe (PID: 5080)
      • aswOfferTool.exe (PID: 2856)
      • Antivirus Activation Assistant.exe (PID: 4212)
      • Antivirus Activation Assistant.exe (PID: 6788)
      • Antivirus Activation Assistant.exe (PID: 4316)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2116)
    • Creates files in the program directory

      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Reads CPU info

      • avast_premium_security_setup_online_x64.exe (PID: 4520)
      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Reads Environment values

      • Instup.exe (PID: 3620)
      • instup.exe (PID: 5080)
    • Dropped object may contain TOR URL's

      • Instup.exe (PID: 3620)
      • aswOfferTool.exe (PID: 2856)
      • instup.exe (PID: 5080)
    • Process checks computer location settings

      • Antivirus Activation Assistant.exe (PID: 1644)
      • Antivirus Activation Assistant.exe (PID: 4212)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (36.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:05:01 13:05:18
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Activator/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
193
Monitored processes
50
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe slui.exe avast_premium_security_setup_online.exe no specs avast_premium_security_setup_online.exe antivirus activation assistant.exe no specs avast_premium_security_setup_online_x64.exe instup.exe instup.exe aswoffertool.exe no specs aswoffertool.exe aswoffertool.exe aswoffertool.exe sbr.exe no specs cmd.exe no specs conhost.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs antivirus activation assistant.exe cmd.exe no specs conhost.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs antivirus activation assistant.exe no specs antivirus activation assistant.exe

Process information

PID
CMD
Path
Indicators
Parent process
1000FIND /C /I "75.126.120.203" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1292FIND /C /I "46.4.28.80" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1328\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1428FIND /C /I "46.4.62.150" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1516FIND /C /I "46.4.58.71" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1644"C:\Users\admin\Desktop\Activator\Antivirus Activation Assistant.exe" C:\Users\admin\Desktop\Activator\Antivirus Activation Assistant.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Antivirus Activation Assistant
Exit code:
0
Version:
2.1.0.0
Modules
Images
c:\users\admin\desktop\activator\antivirus activation assistant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1716FIND /C /I "46.4.28.80" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1780FIND /C /I "46.4.62.150" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
1992FIND /C /I "www.pns.avast.com" C:\WINDOWS\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
2116"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Activator.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
36 289
Read events
29 196
Write events
7 074
Delete events
19

Modification events

(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Activator.zip
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(5488) avast_premium_security_setup_online.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\WINDOWS\Temp\asw.9f8c54cb9ab51ac1
Executable files
420
Suspicious files
674
Text files
1 495
Unknown types
2

Dropped files

PID
Process
Filename
Type
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\Avast Security Premium\2029\license.avastlictext
MD5:6E889FAC8D38A9B467543331DD8DF4C6
SHA256:9D6F2562B3BC97312D8E4116D2EF6C49122A37A194BCD69FB3B263EB3DC3C62A
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\Avast Security Premium\2050\license.avastlictext
MD5:F55DEF2E4F0B1A5996C48D07F6BF73E8
SHA256:EE111BBC35AD0B3644325FB7989658A6EA4B7880D87577D76D7E416324E3D1A5
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Premium_Security\11-2024\license.avastlictext
MD5:A10FE0164ABEA9AAEBA4A96024635F06
SHA256:8E70299409561B2EEE76D69EC5F25D9996ABF6091FA10195F2244D6D97B6336E
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Ultimate\11-2026\license.avastlictext
MD5:76E8369A53F4A176867EB6836257BF8D
SHA256:5C1A3AF3CC5BE5E921505885A2EC6E2172F9DAE7BE4777556C3A7D9F7573FD2B
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\Ultimate\Ultimate-mainPage\2025-1\license.avastlictext
MD5:E1B05C88287EDC1CDD117CAD8F051779
SHA256:FC78B7B1A1B2ECFB7E8D4C079ACADD7411B61531DD9F2CA4C82CE84B8CC75DB7
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Ultimate\8-2025\license.avastlictext
MD5:1F8DAECFB92EB36444F62EEF5BE73F5A
SHA256:29AF8F2D93A78FCE91F7751A98DE6F795065D6F54D345D5E641336092459D24D
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Ultimate\6-2025\license.avastlictext
MD5:71075A04A69FFBC03B56D229484C4E89
SHA256:B0F32EE7C35404BC9BF49A77A5447F09453691B1771173D2F848BC239AAFC836
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\more_activations\Avast_Ultimate\7-2026\license.avastlictext
MD5:46A405B76699AD696BA2077099950873
SHA256:0DE7F1DCADD8351C01D80E33962B3CC2CA6C991AE8B2D415907DB93073258D74
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\Ultimate\Ultimate-mainPage\2026-1\license.avastlictext
MD5:BEA0AA157E931FE244057AC9248F31FE
SHA256:C6F23DDD81014DC5D725BE9423EF6667D8A3A7FD4D48B24F1C6823B492A14B8F
2116WinRAR.exeC:\Users\admin\Desktop\Activator\Activations\Ultimate\Ultimate-mainPage\2025-2\license.avastlictext
MD5:B27E81CEB514D122F69D3E0ABE0475B9
SHA256:E45B85EB617F5251745BC3FC406EE001CA5C6E7CBAF64B09050499F9520D4190
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
54
TCP/UDP connections
102
DNS requests
110
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3676
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5488
avast_premium_security_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
5488
avast_premium_security_setup_online.exe
POST
200
172.217.18.14:80
http://www.google-analytics.com/collect
unknown
unknown
5488
avast_premium_security_setup_online.exe
GET
200
2.19.126.143:80
http://iavs9x.u.avcdn.net/iavs9x/avast_premium_security_setup_online_x64.exe
unknown
whitelisted
5488
avast_premium_security_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
5488
avast_premium_security_setup_online.exe
POST
200
172.217.18.14:80
http://www.google-analytics.com/collect
unknown
unknown
3620
Instup.exe
GET
200
23.48.23.20:80
http://c3978047.iavs9x.u.avast.com/iavs9x/servers.def.vpx
unknown
whitelisted
4520
avast_premium_security_setup_online_x64.exe
GET
200
172.217.18.14:80
http://www.google-analytics.com/collect?aiid=mmm_prw_998_999_000_m&an=Premier&av=24.7.9311&cd=stub-extended&cd3=Online&cid=5bfe25cc-9691-403f-89ef-54b7eff91fa0&dt=Installation&t=screenview&tid=UA-58120669-3&v=1
unknown
whitelisted
3620
Instup.exe
GET
23.48.23.20:80
http://j0294597.iavs9x.u.avast.com/iavs9x/avbugreport_x64_ais-a45.vpx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
996
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6012
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2856
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
92.123.104.67:443
www.bing.com
Akamai International B.V.
DE
unknown
1516
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
5452
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
www.bing.com
  • 92.123.104.67
  • 92.123.104.4
  • 92.123.104.66
  • 92.123.104.10
  • 92.123.104.64
  • 92.123.104.8
  • 92.123.104.63
  • 92.123.104.62
  • 92.123.104.6
  • 92.123.104.23
  • 92.123.104.33
  • 92.123.104.31
  • 92.123.104.29
  • 92.123.104.32
  • 92.123.104.26
  • 92.123.104.30
  • 92.123.104.28
  • 92.123.104.34
whitelisted
google.com
  • 142.250.185.110
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.45
whitelisted
login.live.com
  • 20.190.159.68
  • 40.126.31.71
  • 40.126.31.73
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.67
  • 20.190.159.4
  • 20.190.159.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

PID
Process
Class
Message
5488
avast_premium_security_setup_online.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:55.923] [info ] [sfxinst ] [ 4520: 4028] [F8CC93: 395] Running SFX 'C:\WINDOWS\Temp\asw.9f8c54cb9ab51ac1\avast_premium_security_setup_online_x64.exe'
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:56.188] [info ] [sfxinst ] [ 4520: 4028] [F8CC93: 629] Moved extra data file 'ecoo.edat' to 'C:\WINDOWS\Temp\asw.7ef673c8a8f4fd47\cookie.bin'.
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:56.313] [notice ] [burger_rep ] [ 4520: 7040] [DC075C: 64] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:56.313] [info ] [sfxstats ] [ 4520: 3976] [9A143C: 149] Statistics sent successfully.
avast_premium_security_setup_online_x64.exe
[2024-07-28 20:41:57.063] [info ] [sfxinst ] [ 4520: 4028] [F8CC93: 919] Starting installer/updater executable 'C:\WINDOWS\Temp\asw.7ef673c8a8f4fd47\instup.exe'
Instup.exe
[2024-07-28 20:41:57.454] [info ] [instup ] [ 3620: 3840] [EE4A6B:2703] DISKs: C:\ - 218486MB free / 254GB total
Instup.exe
[2024-07-28 20:41:57.454] [info ] [instup ] [ 3620: 3840] [EE4A6B:2719] Running module version: instup.exe - '24.7.9311.0'
Instup.exe
[2024-07-28 20:41:57.454] [info ] [instup ] [ 3620: 3840] [EE4A6B:2734] Running module version: Instup.dll - '24.7.9311.0'
Instup.exe
[2024-07-28 20:41:57.454] [debug ] [repsup ] [ 3620: 3840] [84102E: 58] PfroMutant: \PendingRenameMutex mutant has been successfully opened.
Instup.exe
[2024-07-28 20:41:57.454] [info ] [instup ] [ 3620: 3840] [EE4A6B:2658] Command: '"C:\WINDOWS\Temp\asw.7ef673c8a8f4fd47\instup.exe" /sfx:lite /sfxstorage:C:\WINDOWS\Temp\asw.7ef673c8a8f4fd47 /edition:12 /prod:ais /stub_context:f4627aa5-7106-4ee4-8e2d-bb9f0f4456a6:9931888 /guid:5bfe25cc-9691-403f-89ef-54b7eff91fa0 /ga_clientid:01b081a0-7227-4224-a363-b551a383edd7 /cookie:mmm_prw_998_999_000_m /ga_clientid:01b081a0-7227-4224-a363-b551a383edd7 /edat_dir:C:\WINDOWS\Temp\asw.9f8c54cb9ab51ac1'