URL:

https://wearedevs.net/d/jjsploit

Full analysis: https://app.any.run/tasks/51698f2c-3b33-4fd1-af3a-d30ff235dbd6
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 14, 2024, 14:44:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

C3ED6403FEA9F2F9DC8E86C412CB3334

SHA1:

A3CB61C057D39E1CC76B888C3CADAB5E275C065C

SHA256:

59C4ED340EE1B0F9A7136E9680FF6DD4512E5EE4324112DB9BC744ADAF24A069

SSDEEP:

3:N8R/BApK8K:25BuBK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • avast_free_antivirus_online-installation.exe (PID: 2268)
      • avast_free_antivirus_setup_online.exe (PID: 3968)
      • Instup.exe (PID: 3568)
      • powershell.exe (PID: 4436)
      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • aswOfferTool.exe (PID: 5228)
      • aswOfferTool.exe (PID: 5240)
      • aswOfferTool.exe (PID: 5288)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 5812)
      • setup.exe (PID: 5828)
      • instup.exe (PID: 4600)
      • AvEmUpdate.exe (PID: 2312)
      • SetupInf.exe (PID: 5760)
      • drvinst.exe (PID: 3712)
      • AvastSvc.exe (PID: 5984)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 4436)
    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • instup.exe (PID: 4600)
    • Creates a writable file in the system directory

      • instup.exe (PID: 4600)
      • drvinst.exe (PID: 3712)
      • SetupInf.exe (PID: 5760)
      • AvastSvc.exe (PID: 5984)
    • The DLL Hijacking

      • msedgewebview2.exe (PID: 896)
      • msedgewebview2.exe (PID: 2024)
    • Scans artifacts that could help determine the target

      • msedgewebview2.exe (PID: 4388)
    • Actions looks like stealing of personal data

      • engsup.exe (PID: 6036)
    • Steals credentials from Web Browsers

      • engsup.exe (PID: 6036)
    • Disables Windows Defender

      • wsc_proxy.exe (PID: 4444)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • avast_free_antivirus_online-installation.exe (PID: 2268)
      • avast_free_antivirus_setup_online.exe (PID: 3968)
      • Instup.exe (PID: 3568)
      • instup.exe (PID: 4600)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • msedgewebview2.exe (PID: 4388)
      • AvEmUpdate.exe (PID: 2312)
      • AvEmUpdate.exe (PID: 3004)
      • AvEmUpdate.exe (PID: 5596)
      • instup.exe (PID: 956)
    • Process requests binary or script from the Internet

      • avast_free_antivirus_online-installation.exe (PID: 2268)
      • AvEmUpdate.exe (PID: 2312)
    • Executable content was dropped or overwritten

      • avast_free_antivirus_online-installation.exe (PID: 2268)
      • avast_free_antivirus_setup_online.exe (PID: 3968)
      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • Instup.exe (PID: 3568)
      • aswOfferTool.exe (PID: 5228)
      • aswOfferTool.exe (PID: 5240)
      • aswOfferTool.exe (PID: 5288)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 5812)
      • instup.exe (PID: 4600)
      • setup.exe (PID: 5828)
      • AvEmUpdate.exe (PID: 2312)
      • SetupInf.exe (PID: 5760)
      • drvinst.exe (PID: 3712)
      • AvastSvc.exe (PID: 5984)
    • Reads the Internet Settings

      • Instup.exe (PID: 3568)
      • powershell.exe (PID: 4436)
      • instup.exe (PID: 4600)
      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • cmd.exe (PID: 3492)
      • cmd.exe (PID: 1992)
      • msedgewebview2.exe (PID: 4388)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 4584)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 4436)
    • Process drops legitimate windows executable

      • powershell.exe (PID: 4436)
      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 5812)
      • instup.exe (PID: 4600)
      • setup.exe (PID: 5828)
    • Starts itself from another location

      • Instup.exe (PID: 3568)
      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • aswOfferTool.exe (PID: 5240)
    • Executes as Windows Service

      • VSSVC.exe (PID: 4144)
      • AvastSvc.exe (PID: 5984)
      • wsc_proxy.exe (PID: 4444)
      • aswToolsSvc.exe (PID: 4840)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 4728)
      • instup.exe (PID: 4600)
      • RegSvr.exe (PID: 5824)
      • RegSvr.exe (PID: 4824)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • instup.exe (PID: 4600)
      • AvastSvc.exe (PID: 5984)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • drvinst.exe (PID: 3712)
      • AvastSvc.exe (PID: 5984)
    • Likely accesses (executes) a file from the Public directory

      • aswOfferTool.exe (PID: 5288)
    • Unusual connection from system programs

      • powershell.exe (PID: 4436)
    • The Powershell connects to the Internet

      • powershell.exe (PID: 4436)
    • The process drops C-runtime libraries

      • instup.exe (PID: 4600)
    • Creates files in the driver directory

      • instup.exe (PID: 4600)
      • drvinst.exe (PID: 3712)
      • SetupInf.exe (PID: 5760)
    • Application launched itself

      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • msedgewebview2.exe (PID: 4388)
      • AvEmUpdate.exe (PID: 2312)
    • Creates a software uninstall entry

      • setup.exe (PID: 5828)
      • instup.exe (PID: 4600)
    • Searches for installed software

      • setup.exe (PID: 5828)
      • overseer.exe (PID: 4588)
      • aswToolsSvc.exe (PID: 4840)
    • Drops a system driver (possible attempt to evade defenses)

      • instup.exe (PID: 4600)
      • SetupInf.exe (PID: 5760)
      • drvinst.exe (PID: 3712)
    • Creates or modifies Windows services

      • instup.exe (PID: 4600)
    • The process verifies whether the antivirus software is installed

      • SetupInf.exe (PID: 2868)
      • SetupInf.exe (PID: 908)
      • SetupInf.exe (PID: 1880)
      • SetupInf.exe (PID: 5532)
      • AvEmUpdate.exe (PID: 4124)
      • AvEmUpdate.exe (PID: 5596)
      • AvEmUpdate.exe (PID: 2312)
      • SetupInf.exe (PID: 2864)
      • AvEmUpdate.exe (PID: 3004)
      • SetupInf.exe (PID: 5760)
      • RegSvr.exe (PID: 5824)
      • RegSvr.exe (PID: 4824)
      • overseer.exe (PID: 4588)
      • AvastNM.exe (PID: 4596)
      • wsc_proxy.exe (PID: 4444)
      • wsc_proxy.exe (PID: 4552)
      • engsup.exe (PID: 4544)
      • engsup.exe (PID: 6036)
      • instup.exe (PID: 1696)
      • aswToolsSvc.exe (PID: 4840)
      • instup.exe (PID: 956)
      • AvastSvc.exe (PID: 5984)
      • instup.exe (PID: 3004)
      • instup.exe (PID: 4600)
    • Adds/modifies Windows certificates

      • SetupInf.exe (PID: 5760)
      • AvastSvc.exe (PID: 5984)
    • Reads the date of Windows installation

      • instup.exe (PID: 4600)
    • Checks for Java to be installed

      • AvastSvc.exe (PID: 5984)
      • aswToolsSvc.exe (PID: 4840)
  • INFO

    • The process uses the downloaded file

      • firefox.exe (PID: 2120)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 2120)
      • msiexec.exe (PID: 3836)
    • Application launched itself

      • firefox.exe (PID: 3500)
      • firefox.exe (PID: 2120)
      • msedge.exe (PID: 4364)
      • msedge.exe (PID: 4192)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 2120)
      • msiexec.exe (PID: 3836)
    • Checks supported languages

      • avast_free_antivirus_online-installation.exe (PID: 2268)
      • avast_free_antivirus_setup_online.exe (PID: 3968)
      • Instup.exe (PID: 3568)
      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • instup.exe (PID: 4600)
      • MicrosoftEdgeUpdate.exe (PID: 4728)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 4812)
      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • aswOfferTool.exe (PID: 5204)
      • aswOfferTool.exe (PID: 5216)
      • aswOfferTool.exe (PID: 5228)
      • aswOfferTool.exe (PID: 5240)
      • aswOfferTool.exe (PID: 5288)
      • setup.exe (PID: 5828)
      • sbr.exe (PID: 5344)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 5812)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • msedgewebview2.exe (PID: 3744)
      • msedgewebview2.exe (PID: 4388)
      • msedgewebview2.exe (PID: 4048)
      • msedgewebview2.exe (PID: 896)
      • msedgewebview2.exe (PID: 3484)
      • msedgewebview2.exe (PID: 3780)
      • msedgewebview2.exe (PID: 2024)
      • SetupInf.exe (PID: 1880)
      • SetupInf.exe (PID: 2868)
      • SetupInf.exe (PID: 908)
      • SetupInf.exe (PID: 5532)
      • AvEmUpdate.exe (PID: 4124)
      • AvEmUpdate.exe (PID: 2312)
      • AvEmUpdate.exe (PID: 5596)
      • SetupInf.exe (PID: 2864)
      • AvEmUpdate.exe (PID: 3004)
      • drvinst.exe (PID: 3712)
      • SetupInf.exe (PID: 5760)
      • RegSvr.exe (PID: 5824)
      • RegSvr.exe (PID: 4824)
      • AvastNM.exe (PID: 4596)
      • overseer.exe (PID: 4588)
      • engsup.exe (PID: 4544)
      • wsc_proxy.exe (PID: 4444)
      • wsc_proxy.exe (PID: 4552)
      • AvastSvc.exe (PID: 5984)
      • aswToolsSvc.exe (PID: 4840)
      • engsup.exe (PID: 6036)
      • instup.exe (PID: 1696)
      • instup.exe (PID: 956)
      • keytool.exe (PID: 4784)
      • keytool.exe (PID: 2472)
      • instup.exe (PID: 3004)
    • Reads the machine GUID from the registry

      • avast_free_antivirus_online-installation.exe (PID: 2268)
      • avast_free_antivirus_setup_online.exe (PID: 3968)
      • Instup.exe (PID: 3568)
      • instup.exe (PID: 4600)
      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • MicrosoftEdgeUpdate.exe (PID: 4812)
      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • msedgewebview2.exe (PID: 4388)
      • SetupInf.exe (PID: 908)
      • SetupInf.exe (PID: 1880)
      • SetupInf.exe (PID: 2868)
      • SetupInf.exe (PID: 5532)
      • AvEmUpdate.exe (PID: 5596)
      • AvEmUpdate.exe (PID: 2312)
      • SetupInf.exe (PID: 2864)
      • AvEmUpdate.exe (PID: 3004)
      • SetupInf.exe (PID: 5760)
      • drvinst.exe (PID: 3712)
      • RegSvr.exe (PID: 5824)
      • RegSvr.exe (PID: 4824)
      • overseer.exe (PID: 4588)
      • wsc_proxy.exe (PID: 4552)
      • wsc_proxy.exe (PID: 4444)
      • AvastSvc.exe (PID: 5984)
      • aswToolsSvc.exe (PID: 4840)
      • instup.exe (PID: 956)
      • instup.exe (PID: 1696)
      • instup.exe (PID: 3004)
    • Manual execution by a user

      • avast_free_antivirus_online-installation.exe (PID: 2268)
      • avast_free_antivirus_online-installation.exe (PID: 4032)
      • msiexec.exe (PID: 3836)
    • Reads the computer name

      • avast_free_antivirus_online-installation.exe (PID: 2268)
      • avast_free_antivirus_setup_online.exe (PID: 3968)
      • Instup.exe (PID: 3568)
      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • instup.exe (PID: 4600)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 4728)
      • MicrosoftEdgeUpdate.exe (PID: 4812)
      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • aswOfferTool.exe (PID: 5240)
      • setup.exe (PID: 5828)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 5812)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • msedgewebview2.exe (PID: 3484)
      • msedgewebview2.exe (PID: 896)
      • msedgewebview2.exe (PID: 4388)
      • msedgewebview2.exe (PID: 2024)
      • SetupInf.exe (PID: 1880)
      • SetupInf.exe (PID: 2868)
      • SetupInf.exe (PID: 908)
      • AvEmUpdate.exe (PID: 2312)
      • SetupInf.exe (PID: 5532)
      • AvEmUpdate.exe (PID: 4124)
      • AvEmUpdate.exe (PID: 5596)
      • SetupInf.exe (PID: 2864)
      • AvEmUpdate.exe (PID: 3004)
      • drvinst.exe (PID: 3712)
      • SetupInf.exe (PID: 5760)
      • RegSvr.exe (PID: 5824)
      • overseer.exe (PID: 4588)
      • RegSvr.exe (PID: 4824)
      • wsc_proxy.exe (PID: 4552)
      • wsc_proxy.exe (PID: 4444)
      • AvastSvc.exe (PID: 5984)
      • aswToolsSvc.exe (PID: 4840)
      • engsup.exe (PID: 6036)
      • instup.exe (PID: 956)
      • instup.exe (PID: 1696)
      • instup.exe (PID: 3004)
    • Reads the software policy settings

      • avast_free_antivirus_online-installation.exe (PID: 2268)
      • avast_free_antivirus_setup_online.exe (PID: 3968)
      • Instup.exe (PID: 3568)
      • instup.exe (PID: 4600)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • msedgewebview2.exe (PID: 4388)
      • AvEmUpdate.exe (PID: 5596)
      • AvEmUpdate.exe (PID: 2312)
      • AvEmUpdate.exe (PID: 3004)
      • drvinst.exe (PID: 3712)
      • AvastSvc.exe (PID: 5984)
      • instup.exe (PID: 1696)
      • instup.exe (PID: 956)
    • Reads CPU info

      • avast_free_antivirus_setup_online.exe (PID: 3968)
      • Instup.exe (PID: 3568)
      • instup.exe (PID: 4600)
      • SetupInf.exe (PID: 908)
      • SetupInf.exe (PID: 1880)
      • SetupInf.exe (PID: 2868)
      • AvEmUpdate.exe (PID: 4124)
      • AvEmUpdate.exe (PID: 2312)
      • SetupInf.exe (PID: 5532)
      • AvEmUpdate.exe (PID: 5596)
      • AvEmUpdate.exe (PID: 3004)
      • SetupInf.exe (PID: 2864)
      • SetupInf.exe (PID: 5760)
      • RegSvr.exe (PID: 5824)
      • AvastNM.exe (PID: 4596)
      • RegSvr.exe (PID: 4824)
      • wsc_proxy.exe (PID: 4552)
      • wsc_proxy.exe (PID: 4444)
      • engsup.exe (PID: 4544)
      • AvastSvc.exe (PID: 5984)
      • aswToolsSvc.exe (PID: 4840)
      • engsup.exe (PID: 6036)
      • instup.exe (PID: 1696)
      • instup.exe (PID: 956)
      • instup.exe (PID: 3004)
    • Creates files in the program directory

      • Instup.exe (PID: 3568)
      • avast_free_antivirus_setup_online.exe (PID: 3968)
      • instup.exe (PID: 4600)
      • AvEmUpdate.exe (PID: 4124)
      • AvEmUpdate.exe (PID: 2312)
      • AvastNM.exe (PID: 4596)
      • engsup.exe (PID: 4544)
      • wsc_proxy.exe (PID: 4552)
      • AvastSvc.exe (PID: 5984)
      • aswToolsSvc.exe (PID: 4840)
      • engsup.exe (PID: 6036)
      • instup.exe (PID: 1696)
      • instup.exe (PID: 956)
      • keytool.exe (PID: 2472)
    • Reads Environment values

      • Instup.exe (PID: 3568)
      • instup.exe (PID: 4600)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • AvEmUpdate.exe (PID: 4124)
      • AvEmUpdate.exe (PID: 2312)
      • AvEmUpdate.exe (PID: 5596)
      • AvEmUpdate.exe (PID: 3004)
      • AvastSvc.exe (PID: 5984)
      • aswToolsSvc.exe (PID: 4840)
      • instup.exe (PID: 956)
      • instup.exe (PID: 1696)
      • instup.exe (PID: 3004)
    • Checks proxy server information

      • Instup.exe (PID: 3568)
      • instup.exe (PID: 4600)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 5812)
      • setup.exe (PID: 5828)
      • MicrosoftEdgeUpdate.exe (PID: 4836)
      • msedgewebview2.exe (PID: 4388)
      • msedgewebview2.exe (PID: 4048)
      • msedgewebview2.exe (PID: 3484)
    • Dropped object may contain TOR URL's

      • Instup.exe (PID: 3568)
      • aswOfferTool.exe (PID: 5240)
      • instup.exe (PID: 4600)
    • Create files in a temporary directory

      • MicrosoftEdgeUpdate.exe (PID: 4584)
      • MicrosoftEdgeUpdate.exe (PID: 4772)
      • MicrosoftEdgeUpdate.exe (PID: 5920)
      • msedgewebview2.exe (PID: 4388)
      • SetupInf.exe (PID: 5760)
      • engsup.exe (PID: 6036)
    • Process checks computer location settings

      • msedgewebview2.exe (PID: 4388)
      • msedgewebview2.exe (PID: 3780)
      • AvastSvc.exe (PID: 5984)
    • Reads Microsoft Office registry keys

      • aswToolsSvc.exe (PID: 4840)
    • Reads product name

      • AvastSvc.exe (PID: 5984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
101
Malicious processes
39
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs avast_free_antivirus_online-installation.exe no specs avast_free_antivirus_online-installation.exe avast_free_antivirus_setup_online.exe msiexec.exe instup.exe vssvc.exe no specs powershell.exe microsoftedgeupdate.exe instup.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe aswoffertool.exe no specs aswoffertool.exe no specs aswoffertool.exe aswoffertool.exe aswoffertool.exe sbr.exe no specs microsoftedge_x86_109.0.1518.140.exe setup.exe microsoftedgeupdate.exe cmd.exe no specs cmd.exe no specs msedge.exe msedge.exe no specs msedgewebview2.exe msedge.exe no specs msedgewebview2.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedge.exe no specs msedge.exe no specs msedgewebview2.exe no specs msedgewebview2.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setupinf.exe no specs setupinf.exe no specs setupinf.exe no specs setupinf.exe no specs avemupdate.exe no specs avemupdate.exe avemupdate.exe avemupdate.exe setupinf.exe no specs setupinf.exe drvinst.exe regsvr.exe no specs regsvr.exe no specs avastnm.exe no specs overseer.exe engsup.exe no specs wsc_proxy.exe no specs wsc_proxy.exe no specs avastsvc.exe aswtoolssvc.exe engsup.exe instup.exe instup.exe keytool.exe no specs icacls.exe no specs instup.exe keytool.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2120.5.1010761479\833022971" -childID 4 -isForBrowser -prefsHandle 3824 -prefMapHandle 3728 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 844 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {9fbe6ed2-ec07-4cf6-b0d4-a7237ce47e2b} 2120 "\\.\pipe\gecko-crash-server-pipe.2120" 3736 221ec3f0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
896"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\109.0.1518.140\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\net.wearedevs\EBWebView" --webview-exe-name=JJSploit.exe --webview-exe-version=7.3.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=1 --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1120 --field-trial-handle=1200,i,17465145957157684367,530926408444177023,131072 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI /prefetch:2C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\109.0.1518.140\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
109.0.1518.140
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\109.0.1518.140\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\109.0.1518.140\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
908"C:\Program Files\Avast Software\Avast\SetupInf.exe" /uninstall /catalog:aswHwid.catC:\Program Files\Avast Software\Avast\SetupInf.exeinstup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.3.8975.0
Modules
Images
c:\program files\avast software\avast\setupinf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
924"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2120.6.1278503427\910764110" -childID 5 -isForBrowser -prefsHandle 3916 -prefMapHandle 3656 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 844 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {03eea104-13a4-4a14-96de-74f2655d4a12} 2120 "\\.\pipe\gecko-crash-server-pipe.2120" 3932 221ec560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
956"C:\Program Files\Avast Software\Avast\setup\instup.exe" /wait /session_id:1 /edat_dir:C:\Windows\Temp\asw.a844c2e21dc62560 /finish_delayed_installationC:\Program Files\Avast Software\Avast\setup\instup.exe
AvastSvc.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Version:
24.3.8975.0
Modules
Images
c:\program files\avast software\avast\setup\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
980"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1200 --field-trial-handle=1376,i,4200606252293667827,11190373223352626390,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2120.13.261123716\838267734" -childID 12 -isForBrowser -prefsHandle 7764 -prefMapHandle 7768 -prefsLen 31243 -prefMapSize 244195 -jsInitHandle 844 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f222cefb-74ce-49d7-b158-4235728ea885} 2120 "\\.\pipe\gecko-crash-server-pipe.2120" 7976 1ef5ce00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1348"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2120.1.1171771633\1506723503" -parentBuildID 20230710165010 -prefsHandle 1404 -prefMapHandle 1400 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5ff22ad1-831c-4968-a47e-07236be23362} 2120 "\\.\pipe\gecko-crash-server-pipe.2120" 1416 17d1fc20 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1584"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2120.4.1144226879\1812577771" -childID 3 -isForBrowser -prefsHandle 3540 -prefMapHandle 3720 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 844 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {706b9cea-9a2e-40c9-8027-070fbd52372d} 2120 "\\.\pipe\gecko-crash-server-pipe.2120" 3736 1c55ec90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1588"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.PageScreenshotProcessor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=4056 --field-trial-handle=1304,i,15371554403171387015,14693647856315781947,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
159 118
Read events
146 799
Write events
12 031
Delete events
288

Modification events

(PID) Process:(3500) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
2ED5635101000000
(PID) Process:(2120) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
C4AE655101000000
(PID) Process:(2120) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(2120) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(2120) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(2120) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(2120) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(2120) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(2120) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(2120) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
Executable files
628
Suspicious files
536
Text files
394
Unknown types
206

Dropped files

PID
Process
Filename
Type
2120firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:
SHA256:
2120firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:
SHA256:
2120firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:
SHA256:
2120firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:
SHA256:
2120firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:
SHA256:
2120firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:
SHA256:
2120firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:
SHA256:
2120firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:
SHA256:
2120firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:
SHA256:
2120firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journalbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
141
TCP/UDP connections
404
DNS requests
666
Threats
15

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
firefox.exe
POST
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
2120
firefox.exe
POST
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
2120
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
unknown
2120
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
unknown
2120
firefox.exe
POST
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
2120
firefox.exe
POST
200
95.101.54.145:80
http://r3.o.lencr.org/
unknown
unknown
2120
firefox.exe
POST
200
95.101.54.145:80
http://r3.o.lencr.org/
unknown
unknown
2120
firefox.exe
POST
200
95.101.54.145:80
http://r3.o.lencr.org/
unknown
unknown
2120
firefox.exe
POST
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
2120
firefox.exe
POST
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2120
firefox.exe
172.67.71.2:443
wearedevs.net
unknown
2120
firefox.exe
172.217.18.10:443
safebrowsing.googleapis.com
whitelisted
2120
firefox.exe
34.117.188.166:443
spocs.getpocket.com
unknown
2120
firefox.exe
104.26.6.147:443
wearedevs.net
unknown
2120
firefox.exe
34.107.243.93:443
push.services.mozilla.com
unknown
2120
firefox.exe
142.250.186.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2120
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
wearedevs.net
  • 172.67.71.2
  • 104.26.7.147
  • 104.26.6.147
  • 2606:4700:20::681a:793
  • 2606:4700:20::ac43:4702
  • 2606:4700:20::681a:693
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
spocs.getpocket.com
  • 34.117.188.166
shared
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown
r3.o.lencr.org
  • 95.101.54.145
  • 95.101.54.203
  • 2.16.202.112
  • 95.101.54.130
  • 2.16.202.114
  • 95.101.54.200
  • 95.101.54.121
  • 2.16.202.120
  • 95.101.54.216
  • 2.16.202.115
  • 95.101.54.115
  • 95.101.54.112
  • 95.101.54.201
shared
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted

Threats

PID
Process
Class
Message
2268
avast_free_antivirus_online-installation.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
856
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
2312
AvEmUpdate.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
2312
AvEmUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
5596
AvEmUpdate.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Process
Message
avast_free_antivirus_setup_online.exe
[2024-04-14 14:45:25.041] [info ] [sfxinst ] [ 3968: 560] [F8DE33: 355] Running SFX 'C:\Windows\Temp\asw.a844c2e21dc62560\avast_free_antivirus_setup_online.exe'
avast_free_antivirus_setup_online.exe
[2024-04-14 14:45:25.236] [info ] [sfxinst ] [ 3968: 560] [F8DE33: 589] Moved extra data file 'ecoo.edat' to 'C:\Windows\Temp\asw.7bee0e5d8afde987\cookie.bin'.
avast_free_antivirus_setup_online.exe
[2024-04-14 14:45:25.240] [info ] [sfxinst ] [ 3968: 560] [F8DE33: 589] Moved extra data file 'eref.edat' to 'C:\Windows\Temp\asw.7bee0e5d8afde987\eref.edat'.
avast_free_antivirus_setup_online.exe
[2024-04-14 14:45:25.415] [info ] [sfxstats ] [ 3968: 1860] [A958A0: 149] Statistics sent successfully.
avast_free_antivirus_setup_online.exe
[2024-04-14 14:45:25.421] [notice ] [burger_rep ] [ 3968: 3788] [9940AC: 66] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
avast_free_antivirus_setup_online.exe
[2024-04-14 14:45:26.311] [info ] [sfxinst ] [ 3968: 560] [F8DE33: 876] Starting installer/updater executable 'C:\Windows\Temp\asw.7bee0e5d8afde987\instup.exe'
Instup.exe
[2024-04-14 14:45:26.663] [info ] [instup ] [ 3568: 3056] [120D43:2658] Command: '"C:\Windows\Temp\asw.7bee0e5d8afde987\instup.exe" /sfx:lite /sfxstorage:C:\Windows\Temp\asw.7bee0e5d8afde987 /edition:1 /prod:ais /stub_context:3968:228 /guid:864cc460-0073-400e-b3c0-99ed209f93a9 /ga_clientid:2900b754-ab4a-42d5-a32f-d91982debe7a /cookie:mmm_ava_012_999_e8d_m /ga_clientid:2900b754-ab4a-42d5-a32f-d91982debe7a /edat_dir:C:\Windows\Temp\asw.a844c2e21dc62560'
Instup.exe
[2024-04-14 14:45:26.664] [info ] [instup ] [ 3568: 3056] [120D43:2719] Running module version: instup.exe - '24.3.8975.0'
Instup.exe
[2024-04-14 14:45:26.664] [info ] [instup ] [ 3568: 3056] [120D43:2703] DISKs: C:\ - 222180MB free / 255GB total
Instup.exe
[2024-04-14 14:45:26.664] [info ] [instup ] [ 3568: 3056] [120D43:2664] CPU: Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz,4