File name:

avast_secure_browser_setup.exe

Full analysis: https://app.any.run/tasks/5b63bc56-89b4-4cf3-b191-da77f90b666a
Verdict: Malicious activity
Analysis date: January 17, 2024, 10:21:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

DA92FDAD745EFE50E487EAA91B761E7A

SHA1:

9F5C98F85E02A1046C11ADA17BB91D259219F661

SHA256:

7F206EEA185B0F21CCF784635E8E7B01A081DAD0F73CA525CEC6E02556024AC3

SSDEEP:

98304:MjMzSEAuMNS6jnOQdZxi+wcABFNjkIjrmNTT9stBkLdVxCvI0D6wxNvfP2zdeNaB:UCRKx7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdateSetup.exe (PID: 1804)
      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Steals credentials from Web Browsers

      • ajEC4.exe (PID: 2084)
    • Actions looks like stealing of personal data

      • ajEC4.exe (PID: 2084)
  • SUSPICIOUS

    • The process verifies whether the antivirus software is installed

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
    • Executable content was dropped or overwritten

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdateSetup.exe (PID: 1804)
      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Searches for installed software

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
    • Reads the Internet Settings

      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdate.exe (PID: 1536)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Checks Windows Trust Settings

      • ajEC4.exe (PID: 2084)
    • Reads security settings of Internet Explorer

      • ajEC4.exe (PID: 2084)
    • Reads settings of System Certificates

      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdate.exe (PID: 1536)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Creates/Modifies COM task schedule object

      • AvastBrowserUpdate.exe (PID: 1732)
    • Starts itself from another location

      • AvastBrowserUpdate.exe (PID: 712)
    • Process requests binary or script from the Internet

      • AvastBrowserUpdate.exe (PID: 1900)
  • INFO

    • Create files in a temporary directory

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdateSetup.exe (PID: 1804)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Reads the computer name

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1732)
      • AvastBrowserUpdate.exe (PID: 1536)
      • AvastBrowserUpdate.exe (PID: 1900)
      • AvastBrowserUpdate.exe (PID: 1636)
    • Checks supported languages

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdateSetup.exe (PID: 1804)
      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1732)
      • AvastBrowserUpdate.exe (PID: 1536)
      • AvastBrowserUpdate.exe (PID: 1636)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Process checks computer location settings

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
    • Reads Environment values

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
    • Checks proxy server information

      • ajEC4.exe (PID: 2084)
    • Creates files or folders in the user directory

      • AvastBrowserUpdate.exe (PID: 712)
      • ajEC4.exe (PID: 2084)
    • Reads the machine GUID from the registry

      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1636)
      • AvastBrowserUpdate.exe (PID: 1900)
      • AvastBrowserUpdate.exe (PID: 1536)
      • ajEC4.exe (PID: 2084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:12:16 01:50:53+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x350d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 8.11.5.7269
ProductVersionNumber: 8.11.5.7269
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Arabic
CharacterSet: Windows, Arabic
BuildDate: 19700120T163136
BuildTimestamp: 1701096510
BuildVersion: 8.11.5.7269
FileDescription: إعداد Avast Secure Browser
FileVersion: 8.11.5.7269
InstallerCommit: 9f7fdfd50145d84250cbfc8b264b821d4fd70781
InstallerEdition: web
InstallerKeyword: avast-securebrowser
InternalName: Avast Secure Browser
JsisCommit: 9493fd2f0fa70e8e33fa09133b99cb45ce6442ca
LegalCopyright: حقوق الطبع والنشر (c) لعام 2023 محفوظة لشركة AVAST Software
OmahaVersion: 1.8.1653.5
ProductName: إعداد Avast Secure Browser
ProductVersion: 8.11.5.7269
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
8
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start avast_secure_browser_setup.exe ajec4.exe avastbrowserupdatesetup.exe avastbrowserupdate.exe avastbrowserupdate.exe no specs avastbrowserupdate.exe avastbrowserupdate.exe no specs avastbrowserupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
712C:\Users\admin\AppData\Local\Temp\GUM59EE.tmp\AvastBrowserUpdate.exe /silent /install "bundlename=Avast Secure Browser&appguid={A8504530-742B-42BC-895D-2BAD6406F698}&appname=Avast Secure Browser&needsadmin=false&lang=en-US&brand=6155&installargs=--no-create-user-shortcuts --reset-default-win10 --auto-import-data%3Dmsedge --import-cookies --auto-launch-chrome"C:\Users\admin\AppData\Local\Temp\GUM59EE.tmp\AvastBrowserUpdate.exe
AvastBrowserUpdateSetup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\temp\gum59ee.tmp\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1536"C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgb21haGFpZD0iezZEMzdDNzYwLThGRUQtNDhBNS1BNEE0LUNFQzA5NUIyRDhERH0iIHVwZGF0ZXJ2ZXJzaW9uPSIxLjguMTY1My41IiBzaGVsbF92ZXJzaW9uPSIxLjguMTY1My41IiBpc21hY2hpbmU9IjAiIGlzX29tYWhhNjRiaXQ9IjAiIGlzX29zNjRiaXQ9IjAiIHNlc3Npb25pZD0ie0M0Qzk5NDQyLThFNEUtNDQxMC05Rjk5LTlGODI5OTA5RDcyQn0iIGNlcnRfZXhwX2RhdGU9IjIwMjUwOTE3IiB1c2VyaWQ9IntEMThBNUVDOS1CMzA5LTQzRTEtQUMzRi01MUMyRjYzOTUzRjJ9IiB1c2VyaWRfZGF0ZT0iMjAyNDAxMTciIG1hY2hpbmVpZD0iezAwMDA0NEMzLUZEMkMtRDk1NC0wRkY0LUJBRjVEODhFRTkzRX0iIG1hY2hpbmVpZF9kYXRlPSIyMDI0MDExNyIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiB0ZXN0c291cmNlPSJhdXRvIiByZXF1ZXN0aWQ9Ins0RUNGNzk3MS1FMDdELTRCNjEtQjdBQi01OEQ5OUZGMDY5Q0Z9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IHBoeXNtZW1vcnk9IjMiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjI0NTQ2IiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing4NiIvPjxhcHAgYXBwaWQ9Ins2RDM3Qzc2MC04RkVELTQ4QTUtQTRBNC1DRUMwOTVCMkQ4RER9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxLjguMTY1My41IiBsYW5nPSJlbi1VUyIgYnJhbmQ9IjYxNTUiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjUxNiIvPjwvYXBwPjwvcmVxdWVzdD4C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
AvastBrowserUpdate.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1636"C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /handoff "bundlename=Avast Secure Browser&appguid={A8504530-742B-42BC-895D-2BAD6406F698}&appname=Avast Secure Browser&needsadmin=false&lang=en-US&brand=6155&installargs=--no-create-user-shortcuts --reset-default-win10 --auto-import-data%3Dmsedge --import-cookies --auto-launch-chrome" /installsource otherinstallcmd /sessionid "{C4C99442-8E4E-4410-9F99-9F829909D72B}" /silentC:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exeAvastBrowserUpdate.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1732"C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /regserverC:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exeAvastBrowserUpdate.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1804AvastBrowserUpdateSetup.exe /silent /install "bundlename=Avast Secure Browser&appguid={A8504530-742B-42BC-895D-2BAD6406F698}&appname=Avast Secure Browser&needsadmin=false&lang=en-US&brand=6155&installargs=--no-create-user-shortcuts --reset-default-win10 --auto-import-data%3Dmsedge --import-cookies --auto-launch-chrome"C:\Users\admin\AppData\Local\Temp\nsx1049.tmp\AvastBrowserUpdateSetup.exe
ajEC4.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser Setup
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\temp\nsx1049.tmp\avastbrowserupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1900"C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
svchost.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2036"C:\Users\admin\Desktop\avast_secure_browser_setup.exe" C:\Users\admin\Desktop\avast_secure_browser_setup.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Avast Secure Browser Setup
Exit code:
0
Version:
8.11.5.7269
Modules
Images
c:\users\admin\desktop\avast_secure_browser_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2084"C:\Users\admin\AppData\Local\Temp\ajEC4.exe" /relaunch=8 /was_elevated=0 /tagdata C:\Users\admin\AppData\Local\Temp\ajEC4.exe
avast_secure_browser_setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Avast Secure Browser Setup
Exit code:
0
Version:
8.11.5.7269
Modules
Images
c:\users\admin\appdata\local\temp\ajec4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
16 196
Read events
12 384
Write events
3 802
Delete events
10

Modification events

(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2084) ajEC4.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1732) AvastBrowserUpdate.exeKey:HKEY_CLASSES_ROOT\CLSID\{167FD956-39C3-374C-927A-1D3C47CB6663}\InprocServer32
Operation:delete keyName:(default)
Value:
Executable files
173
Suspicious files
10
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\nsJSON.dllexecutable
MD5:A6866A31DE35CD31009FB535693A8612
SHA256:D3A1C0D5E3DB477595D3F3A41B2704405AD992D346397BEDD8DAF31F104F5300
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\Midex.dllexecutable
MD5:E4EB6EE3CC523D52DDDD018497DE64C5
SHA256:75BF6CCE57CE3089F662E0E0700FCD28903FD0DAB06ECF47714F75A411A68305
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\jsisdl.dllexecutable
MD5:77C51CA944AF4FCBAB10D7AE8207B21E
SHA256:D5144A098D50F09F9CF2DF12AD56D50AA172554779BB6128A429A055259E65C3
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\thirdparty.dllexecutable
MD5:C855765DD1290045D985FFA2CA6D4882
SHA256:8C0222A57A491960CB86E167BC17188D581BE9B64CAE8BA3A6EC1A56B9091931
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\AccessControl.dllexecutable
MD5:A1B76C4386328C2A243FC4D2B35328AF
SHA256:BAC3B3A526EB67AE375A9FE29CAB6268536E44C2ECE1239B65BD1827D055157A
2084ajEC4.exeC:\Users\admin\AppData\Local\Temp\nsx1049.tmp\jsis.dllexecutable
MD5:EEB9DC60D33C7F9479DD6F0A2DB6EC3C
SHA256:B3962B7EC5E21EA51BC4D9F42E293C77F3DA4632C711924619F2343AFF4D138A
2084ajEC4.exeC:\Users\admin\AppData\Local\Temp\nsx1049.tmp\FF.places.tmp
MD5:
SHA256:
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\sciterui.dllexecutable
MD5:ED9DBB0A767650D2AB5DEF91A0CE23C7
SHA256:3C1D228BA3513067C9408ED2ABA751291CBE667F60F050611A0309D26AAC6654
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\reboot.dllexecutable
MD5:2A6A9C73EA41A4634413F626087EA4B4
SHA256:1F9FC5B90F75AEA4BAE67F2B88791EE488DE61FB959BE7A8795ADC47FA45C3DE
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\ajEC4.exeexecutable
MD5:0D608A240A8733A1119763D28E2666FA
SHA256:D7A336F17DBB109832042F51E366FD725307CC41FE326F0685A2069FA73145C2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
17
DNS requests
5
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2084
ajEC4.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5c9575644cc14e32
unknown
compressed
4.66 Kb
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?85d4b5be3d25b038
unknown
unknown
2084
ajEC4.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2084
ajEC4.exe
104.20.159.62:443
stats.securebrowser.com
CLOUDFLARENET
unknown
2084
ajEC4.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2084
ajEC4.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1536
AvastBrowserUpdate.exe
172.67.15.96:443
update.avastbrowser.com
CLOUDFLARENET
US
unknown
1900
AvastBrowserUpdate.exe
172.67.15.96:443
update.avastbrowser.com
CLOUDFLARENET
US
unknown
1900
AvastBrowserUpdate.exe
2.16.164.99:80
browser-update.avast.com
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
stats.securebrowser.com
  • 104.20.159.62
  • 104.20.158.62
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
update.avastbrowser.com
  • 172.67.15.96
  • 104.22.78.87
  • 104.22.79.87
unknown
browser-update.avast.com
  • 2.16.164.99
  • 2.16.164.122
unknown

Threats

PID
Process
Class
Message
1900
AvastBrowserUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1900
AvastBrowserUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1900
AvastBrowserUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1900
AvastBrowserUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
avast_secure_browser_setup.exe
2024-01-17T10:21:32 [libnsis] {000007f4:000006f0} <2:Info> (893f00f663353e48\src\jsis-plugins\plugins\Plugin.cpp:82) JSIS Plugin logging enabled
avast_secure_browser_setup.exe
2024-01-17T10:21:32 [libnsis] {000007f4:000006f0} <4:Error> (893f00f663353e48\src\jsis-plugins\plugins\UtilitiesPlugin\TagData.cpp:85) 0x00000400000715 91aa05bf654a77ad\src\sbplugins\windows\RCData.cpp:62
avast_secure_browser_setup.exe
2024-01-17T10:21:32 [libnsis] {000007f4:000006f0} <1:Debug> (91aa05bf654a77ad\src\sbplugins\windows\RCData.cpp:62) Throwing exception 0x00000400000715
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <2:Info> (893f00f663353e48\src\jsis-plugins\plugins\Plugin.cpp:82) JSIS Plugin logging enabled
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT ((visits.visit_time/1000000)-11644473600) /60 /60 / 24 AS vtime FROM 'visits' WHERE vtime >= 19709 AND vtime <= 19740 GROUP BY vtime
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nsx1049.tmp\CR.History.tmp
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT ((visits.visit_time/1000000)-11644473600) /60 /60 / 24 AS vtime FROM 'visits' WHERE vtime >= 19709 AND vtime <= 19740 GROUP BY vtime
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nsx1049.tmp\CR.History.tmp
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nsx1049.tmp\FF.places.tmp
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT last_visit_date / 1000000 /60 /60 / 24 AS vtime FROM 'moz_places' WHERE vtime >= 19709 AND vtime <= 19740 GROUP BY vtime