URL:

https://package.avira.com/download/spotlight-windows-bootstrapper/avira_en_sptl1_598368817-1596472522__pavwws-spotlight-release.exe

Full analysis: https://app.any.run/tasks/b8845e7d-2159-4896-b9c7-92b017a4ab5e
Verdict: Malicious activity
Analysis date: August 13, 2020, 08:28:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

C69ED37288ACC0432E78A518F9CEBD9E

SHA1:

FD937BD2584EF7DD010BE62E0085C2B65229C267

SHA256:

5730CCCF5155AB5C9CB168CB767E0A780C6CFD8A9CAEC4AFC670D0C17EF249D0

SSDEEP:

3:N8AZEXXiKK8LZU/3CNxExxSvU7jf8UQcTuQXq+7gRJMCUCrAC:2AZSXiKO3CNxEeMNQiS0gRJMlC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • avira_en_sptl1_598368817-1596472522__pavwws-spotlight-release.exe (PID: 2864)
      • avira_en_sptl1_598368817-1596472522__pavwws-spotlight-release.exe (PID: 852)
      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 2832)
      • Avira.OE.Setup.Bundle.exe (PID: 2452)
      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 4032)
      • Avira.OE.Setup.Prerequisites.exe (PID: 948)
      • Avira.ServiceHost.exe (PID: 2292)
      • Avira.Systray.exe (PID: 2232)
      • Avira.Systray.exe (PID: 2432)
      • Avira.OE.Setup.Prerequisites.exe (PID: 3616)
      • avira_system_speedup.exe (PID: 4044)
    • Changes settings of System certificates

      • Avira.Spotlight.Bootstrapper.exe (PID: 2980)
      • Avira.ServiceHost.exe (PID: 2292)
    • Changes the autorun value in the registry

      • Avira.OE.Setup.Bundle.exe (PID: 2452)
    • Loads dropped or rewritten executable

      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 4032)
      • rundll32.exe (PID: 2516)
      • rundll32.exe (PID: 3628)
      • rundll32.exe (PID: 1748)
      • rundll32.exe (PID: 1256)
      • rundll32.exe (PID: 2556)
      • rundll32.exe (PID: 3916)
      • rundll32.exe (PID: 2876)
      • rundll32.exe (PID: 2324)
      • rundll32.exe (PID: 3092)
      • rundll32.exe (PID: 720)
      • rundll32.exe (PID: 3964)
      • rundll32.exe (PID: 2340)
      • rundll32.exe (PID: 3780)
      • rundll32.exe (PID: 3788)
      • rundll32.exe (PID: 3092)
      • Avira.Systray.exe (PID: 2232)
      • Avira.Systray.exe (PID: 2432)
      • rundll32.exe (PID: 2548)
      • rundll32.exe (PID: 3544)
      • Avira.ServiceHost.exe (PID: 2292)
    • Uses Task Scheduler to run other applications

      • MsiExec.exe (PID: 3000)
    • Actions looks like stealing of personal data

      • Avira.ServiceHost.exe (PID: 2292)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2696)
      • iexplore.exe (PID: 2188)
      • Avira.Spotlight.Bootstrapper.exe (PID: 2980)
      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 4032)
      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 2832)
      • Avira.OE.Setup.Bundle.exe (PID: 2452)
      • rundll32.exe (PID: 1748)
      • rundll32.exe (PID: 2324)
      • msiexec.exe (PID: 3124)
      • rundll32.exe (PID: 3092)
      • rundll32.exe (PID: 2340)
      • rundll32.exe (PID: 3788)
      • rundll32.exe (PID: 3092)
      • rundll32.exe (PID: 2548)
      • rundll32.exe (PID: 3544)
      • avira_system_speedup.exe (PID: 4044)
      • avira_system_speedup.tmp (PID: 2932)
    • Searches for installed software

      • Avira.Spotlight.Bootstrapper.exe (PID: 2980)
      • Avira.ServiceHost.exe (PID: 2292)
    • Adds / modifies Windows certificates

      • Avira.Spotlight.Bootstrapper.exe (PID: 2980)
      • Avira.ServiceHost.exe (PID: 2292)
    • Reads Environment values

      • Avira.Spotlight.Bootstrapper.exe (PID: 2980)
      • Avira.ServiceHost.exe (PID: 2292)
      • avira_system_speedup.tmp (PID: 2932)
    • Creates files in the Windows directory

      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 2832)
      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 4032)
      • Avira.ServiceHost.exe (PID: 2292)
    • Starts itself from another location

      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 4032)
    • Creates a software uninstall entry

      • Avira.OE.Setup.Bundle.exe (PID: 2452)
      • rundll32.exe (PID: 3916)
    • Reads internet explorer settings

      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 4032)
    • Reads Internet Cache Settings

      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 4032)
      • avira_system_speedup.tmp (PID: 2932)
    • Changes IE settings (feature browser emulation)

      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 4032)
      • Avira.Systray.exe (PID: 2232)
      • Avira.Systray.exe (PID: 2432)
    • Creates files in the program directory

      • Avira.OE.Setup.Bundle.exe (PID: 2452)
      • rundll32.exe (PID: 2876)
      • rundll32.exe (PID: 3092)
      • rundll32.exe (PID: 3092)
      • Avira.ServiceHost.exe (PID: 2292)
      • Avira.Systray.exe (PID: 2432)
    • Removes files from Windows directory

      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 4032)
      • Avira.ServiceHost.exe (PID: 2292)
      • avira_en__598368817-1596472522__pavwws-spotlight-release.exe (PID: 2832)
    • Uses RUNDLL32.EXE to load library

      • MsiExec.exe (PID: 3000)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 3124)
    • Executed as Windows Service

      • Avira.ServiceHost.exe (PID: 2292)
    • Reads the cookies of Google Chrome

      • Avira.ServiceHost.exe (PID: 2292)
    • Creates files in the user directory

      • Avira.ServiceHost.exe (PID: 2292)
    • Reads the cookies of Mozilla Firefox

      • Avira.ServiceHost.exe (PID: 2292)
    • Reads the Windows organization settings

      • avira_system_speedup.tmp (PID: 2932)
    • Reads Windows owner or organization settings

      • avira_system_speedup.tmp (PID: 2932)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2696)
      • iexplore.exe (PID: 2188)
    • Application launched itself

      • iexplore.exe (PID: 2696)
      • msiexec.exe (PID: 3124)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2188)
      • Avira.Spotlight.Bootstrapper.exe (PID: 2980)
      • rundll32.exe (PID: 1748)
      • Avira.ServiceHost.exe (PID: 2292)
      • iexplore.exe (PID: 2696)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2696)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2696)
    • Changes internet zones settings

      • iexplore.exe (PID: 2696)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2696)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3000)
      • msiexec.exe (PID: 3124)
      • MsiExec.exe (PID: 2176)
      • avira_system_speedup.tmp (PID: 2932)
    • Dropped object may contain Bitcoin addresses

      • msiexec.exe (PID: 3124)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3124)
    • Creates files in the program directory

      • msiexec.exe (PID: 3124)
    • Application was dropped or rewritten from another process

      • avira_system_speedup.tmp (PID: 2932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
35
Malicious processes
26
Suspicious processes
6

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe avira_en_sptl1_598368817-1596472522__pavwws-spotlight-release.exe no specs avira_en_sptl1_598368817-1596472522__pavwws-spotlight-release.exe avira.spotlight.bootstrapper.exe avira_en__598368817-1596472522__pavwws-spotlight-release.exe avira_en__598368817-1596472522__pavwws-spotlight-release.exe avira.oe.setup.bundle.exe avira.oe.setup.prerequisites.exe no specs avira.oe.setup.prerequisites.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs msiexec.exe no specs rundll32.exe rundll32.exe no specs rundll32.exe rundll32.exe no specs rundll32.exe no specs rundll32.exe msiexec.exe rundll32.exe no specs rundll32.exe msiexec.exe no specs rundll32.exe no specs avira.servicehost.exe rundll32.exe rundll32.exe avira.systray.exe no specs avira.systray.exe rundll32.exe rundll32.exe avira_system_speedup.exe avira_system_speedup.tmp

Process information

PID
CMD
Path
Indicators
Parent process
720rundll32.exe "C:\Windows\Installer\MSI31E5.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_930265 140 Avira.OE.Setup.CustomActions!Avira.OE.Setup.CustomActions.HtmlUiCustomActions.FixCssClassContentTypeC:\Windows\system32\rundll32.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imagehlp.dll
852"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\avira_en_sptl1_598368817-1596472522__pavwws-spotlight-release.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\avira_en_sptl1_598368817-1596472522__pavwws-spotlight-release.exe
iexplore.exe
User:
admin
Company:
Avira Operations GmbH & Co. KG
Integrity Level:
HIGH
Description:
Avira Security
Exit code:
0
Version:
1.0.8.853
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\avira_en_sptl1_598368817-1596472522__pavwws-spotlight-release.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
948"C:\ProgramData\Package Cache\6BCB4FE3D778D299F09EDB594B11CC6878F635AB\Avira.OE.Setup.Prerequisites.exe" /writeCrossDetectionKeyC:\ProgramData\Package Cache\6BCB4FE3D778D299F09EDB594B11CC6878F635AB\Avira.OE.Setup.Prerequisites.exeAvira.OE.Setup.Bundle.exe
User:
admin
Company:
Avira Operations GmbH & Co. KG
Integrity Level:
HIGH
Description:
Avira.OE.Setup.Prerequisites
Exit code:
0
Version:
1.2.148.24463
Modules
Images
c:\programdata\package cache\6bcb4fe3d778d299f09edb594b11cc6878f635ab\avira.oe.setup.prerequisites.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1256rundll32.exe "C:\Windows\Installer\MSI22ED.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_926421 119 Avira.OE.Setup.CustomActions!Avira.OE.Setup.CustomActions.ServiceRegistration.EnsureServiceIsNotMarkedForDelitionC:\Windows\system32\rundll32.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1748rundll32.exe "C:\Windows\Installer\MSI2137.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_926000 110 Avira.OE.Setup.CustomActions!Avira.OE.Setup.CustomActions.CertificateInstaller.EnsureRootCertificatesAreInstalledC:\Windows\system32\rundll32.exe
MsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2176C:\Windows\system32\MsiExec.exe -Embedding 0027F571865E5E5C85DDA527D0C269B2 M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2188"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2696 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2232"C:\Program Files\Avira\Launcher\Avira.Systray.exe"C:\Program Files\Avira\Launcher\Avira.Systray.exemsiexec.exe
User:
admin
Company:
Avira Operations GmbH & Co. KG
Integrity Level:
HIGH
Description:
Avira
Exit code:
1
Version:
1.2.148.24463
Modules
Images
c:\program files\avira\launcher\avira.systray.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2292"C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe"C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
services.exe
User:
SYSTEM
Company:
Avira Operations GmbH & Co. KG
Integrity Level:
SYSTEM
Description:
Avira Service Host
Exit code:
0
Version:
1.2.148.24463
Modules
Images
c:\program files\avira\launcher\avira.servicehost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2324rundll32.exe "C:\Windows\Installer\MSI23D9.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_926671 126 Avira.OE.Setup.CustomActions!Avira.OE.Setup.CustomActions.Configuration.SetTrackingIdC:\Windows\system32\rundll32.exe
MsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
3 795
Read events
3 164
Write events
608
Delete events
23

Modification events

(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
3435714542
(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30830923
(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A3000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2696) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
157
Suspicious files
43
Text files
505
Unknown types
26

Dropped files

PID
Process
Filename
Type
2188iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\CabBB71.tmp
MD5:
SHA256:
2188iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\TarBB72.tmp
MD5:
SHA256:
2696iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF79EE6F1ADBFEADEA.TMP
MD5:
SHA256:
2696iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\avira_en_sptl1_598368817-1596472522__pavwws-spotlight-release.exe.7f5rfxh.partial:Zone.Identifier
MD5:
SHA256:
2696iexplore.exeC:\Users\admin\AppData\Local\Temp\CabCD82.tmp
MD5:
SHA256:
2696iexplore.exeC:\Users\admin\AppData\Local\Temp\TarCD83.tmp
MD5:
SHA256:
2696iexplore.exeC:\Users\admin\AppData\Local\Temp\CabCD93.tmp
MD5:
SHA256:
2696iexplore.exeC:\Users\admin\AppData\Local\Temp\TarCD94.tmp
MD5:
SHA256:
2696iexplore.exeC:\Users\admin\AppData\Local\Temp\CabCE12.tmp
MD5:
SHA256:
2696iexplore.exeC:\Users\admin\AppData\Local\Temp\TarCE13.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
21
DNS requests
11
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2696
iexplore.exe
GET
200
205.185.216.10:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
56.7 Kb
whitelisted
2696
iexplore.exe
GET
304
205.185.216.10:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
56.7 Kb
whitelisted
2188
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertGlobalRootCA.crl
US
der
631 b
whitelisted
4032
avira_en__598368817-1596472522__pavwws-spotlight-release.exe
GET
200
93.184.220.29:80
http://status.geotrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR3enuod9bxDxzpICGW%2B2sabjf17QQUkFj%2FsJx1qFFUd7Ht8qNDFjiebMUCEAhpwjriHwb%2BBA3oHNrcctU%3D
US
der
471 b
whitelisted
2696
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2188
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D
US
der
471 b
whitelisted
2696
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2696
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2292
Avira.ServiceHost.exe
GET
200
2.16.186.26:80
http://www.msftncsi.com/ncsi.txt
unknown
text
14 b
whitelisted
2292
Avira.ServiceHost.exe
GET
200
2.16.186.26:80
http://www.msftncsi.com/ncsi.txt
unknown
text
14 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2188
iexplore.exe
92.122.253.212:443
package.avira.com
GTT Communications Inc.
suspicious
2188
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2696
iexplore.exe
205.185.216.10:80
www.download.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
4032
avira_en__598368817-1596472522__pavwws-spotlight-release.exe
35.190.25.25:443
api.mixpanel.com
Google Inc.
US
whitelisted
2696
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2696
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2292
Avira.ServiceHost.exe
2.16.186.26:80
www.msftncsi.com
Akamai International B.V.
whitelisted
2292
Avira.ServiceHost.exe
35.190.25.25:443
api.mixpanel.com
Google Inc.
US
whitelisted
2932
avira_system_speedup.tmp
35.190.25.25:443
api.mixpanel.com
Google Inc.
US
whitelisted
2292
Avira.ServiceHost.exe
18.194.159.112:443
ssldev.oes.avira.com
Amazon.com, Inc.
DE
unknown

DNS requests

Domain
IP
Reputation
package.avira.com
  • 92.122.253.212
suspicious
ocsp.digicert.com
  • 93.184.220.29
whitelisted
www.download.windowsupdate.com
  • 205.185.216.10
  • 205.185.216.42
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
api.mixpanel.com
  • 35.190.25.25
  • 130.211.34.183
  • 35.186.241.51
  • 107.178.240.159
whitelisted
status.geotrust.com
  • 93.184.220.29
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ssldev.oes.avira.com
  • 18.194.159.112
  • 52.57.226.120
  • 52.58.108.221
  • 3.124.92.169
unknown
www.msftncsi.com
  • 2.16.186.26
  • 2.16.186.17
whitelisted

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
Process
Message
avira_en__598368817-1596472522__pavwws-spotlight-release.exe
Launcher Install Start
avira_en__598368817-1596472522__pavwws-spotlight-release.exe
Launcher Install Start
avira_en__598368817-1596472522__pavwws-spotlight-release.exe
Launcher Install End
avira_en__598368817-1596472522__pavwws-spotlight-release.exe
~WebBrowser: Finished
avira_en__598368817-1596472522__pavwws-spotlight-release.exe
~WebBrowser: Finished
avira_system_speedup.tmp
*** Initialize