File name:

avast_secure_browser_setup.exe

Full analysis: https://app.any.run/tasks/5b63bc56-89b4-4cf3-b191-da77f90b666a
Verdict: Malicious activity
Analysis date: January 17, 2024, 10:21:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

DA92FDAD745EFE50E487EAA91B761E7A

SHA1:

9F5C98F85E02A1046C11ADA17BB91D259219F661

SHA256:

7F206EEA185B0F21CCF784635E8E7B01A081DAD0F73CA525CEC6E02556024AC3

SSDEEP:

98304:MjMzSEAuMNS6jnOQdZxi+wcABFNjkIjrmNTT9stBkLdVxCvI0D6wxNvfP2zdeNaB:UCRKx7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdateSetup.exe (PID: 1804)
      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Steals credentials from Web Browsers

      • ajEC4.exe (PID: 2084)
    • Actions looks like stealing of personal data

      • ajEC4.exe (PID: 2084)
  • SUSPICIOUS

    • Searches for installed software

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
    • Executable content was dropped or overwritten

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdateSetup.exe (PID: 1804)
      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1900)
    • The process verifies whether the antivirus software is installed

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
    • Reads the Internet Settings

      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdate.exe (PID: 1536)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Checks Windows Trust Settings

      • ajEC4.exe (PID: 2084)
    • Reads settings of System Certificates

      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdate.exe (PID: 1536)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Reads security settings of Internet Explorer

      • ajEC4.exe (PID: 2084)
    • Creates/Modifies COM task schedule object

      • AvastBrowserUpdate.exe (PID: 1732)
    • Starts itself from another location

      • AvastBrowserUpdate.exe (PID: 712)
    • Process requests binary or script from the Internet

      • AvastBrowserUpdate.exe (PID: 1900)
  • INFO

    • Create files in a temporary directory

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdateSetup.exe (PID: 1804)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Process checks computer location settings

      • ajEC4.exe (PID: 2084)
      • avast_secure_browser_setup.exe (PID: 2036)
    • Reads the machine GUID from the registry

      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1900)
      • AvastBrowserUpdate.exe (PID: 1636)
      • AvastBrowserUpdate.exe (PID: 1536)
    • Reads the computer name

      • ajEC4.exe (PID: 2084)
      • avast_secure_browser_setup.exe (PID: 2036)
      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1536)
      • AvastBrowserUpdate.exe (PID: 1732)
      • AvastBrowserUpdate.exe (PID: 1900)
      • AvastBrowserUpdate.exe (PID: 1636)
    • Checks supported languages

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
      • AvastBrowserUpdateSetup.exe (PID: 1804)
      • AvastBrowserUpdate.exe (PID: 712)
      • AvastBrowserUpdate.exe (PID: 1536)
      • AvastBrowserUpdate.exe (PID: 1636)
      • AvastBrowserUpdate.exe (PID: 1732)
      • AvastBrowserUpdate.exe (PID: 1900)
    • Reads Environment values

      • avast_secure_browser_setup.exe (PID: 2036)
      • ajEC4.exe (PID: 2084)
    • Checks proxy server information

      • ajEC4.exe (PID: 2084)
    • Creates files or folders in the user directory

      • AvastBrowserUpdate.exe (PID: 712)
      • ajEC4.exe (PID: 2084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:12:16 01:50:53+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x350d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 8.11.5.7269
ProductVersionNumber: 8.11.5.7269
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Arabic
CharacterSet: Windows, Arabic
BuildDate: 19700120T163136
BuildTimestamp: 1701096510
BuildVersion: 8.11.5.7269
FileDescription: إعداد Avast Secure Browser
FileVersion: 8.11.5.7269
InstallerCommit: 9f7fdfd50145d84250cbfc8b264b821d4fd70781
InstallerEdition: web
InstallerKeyword: avast-securebrowser
InternalName: Avast Secure Browser
JsisCommit: 9493fd2f0fa70e8e33fa09133b99cb45ce6442ca
LegalCopyright: حقوق الطبع والنشر (c) لعام 2023 محفوظة لشركة AVAST Software
OmahaVersion: 1.8.1653.5
ProductName: إعداد Avast Secure Browser
ProductVersion: 8.11.5.7269
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
8
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start avast_secure_browser_setup.exe ajec4.exe avastbrowserupdatesetup.exe avastbrowserupdate.exe avastbrowserupdate.exe no specs avastbrowserupdate.exe avastbrowserupdate.exe no specs avastbrowserupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
712C:\Users\admin\AppData\Local\Temp\GUM59EE.tmp\AvastBrowserUpdate.exe /silent /install "bundlename=Avast Secure Browser&appguid={A8504530-742B-42BC-895D-2BAD6406F698}&appname=Avast Secure Browser&needsadmin=false&lang=en-US&brand=6155&installargs=--no-create-user-shortcuts --reset-default-win10 --auto-import-data%3Dmsedge --import-cookies --auto-launch-chrome"C:\Users\admin\AppData\Local\Temp\GUM59EE.tmp\AvastBrowserUpdate.exe
AvastBrowserUpdateSetup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\temp\gum59ee.tmp\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1536"C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgb21haGFpZD0iezZEMzdDNzYwLThGRUQtNDhBNS1BNEE0LUNFQzA5NUIyRDhERH0iIHVwZGF0ZXJ2ZXJzaW9uPSIxLjguMTY1My41IiBzaGVsbF92ZXJzaW9uPSIxLjguMTY1My41IiBpc21hY2hpbmU9IjAiIGlzX29tYWhhNjRiaXQ9IjAiIGlzX29zNjRiaXQ9IjAiIHNlc3Npb25pZD0ie0M0Qzk5NDQyLThFNEUtNDQxMC05Rjk5LTlGODI5OTA5RDcyQn0iIGNlcnRfZXhwX2RhdGU9IjIwMjUwOTE3IiB1c2VyaWQ9IntEMThBNUVDOS1CMzA5LTQzRTEtQUMzRi01MUMyRjYzOTUzRjJ9IiB1c2VyaWRfZGF0ZT0iMjAyNDAxMTciIG1hY2hpbmVpZD0iezAwMDA0NEMzLUZEMkMtRDk1NC0wRkY0LUJBRjVEODhFRTkzRX0iIG1hY2hpbmVpZF9kYXRlPSIyMDI0MDExNyIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiB0ZXN0c291cmNlPSJhdXRvIiByZXF1ZXN0aWQ9Ins0RUNGNzk3MS1FMDdELTRCNjEtQjdBQi01OEQ5OUZGMDY5Q0Z9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IHBoeXNtZW1vcnk9IjMiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjI0NTQ2IiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing4NiIvPjxhcHAgYXBwaWQ9Ins2RDM3Qzc2MC04RkVELTQ4QTUtQTRBNC1DRUMwOTVCMkQ4RER9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxLjguMTY1My41IiBsYW5nPSJlbi1VUyIgYnJhbmQ9IjYxNTUiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjUxNiIvPjwvYXBwPjwvcmVxdWVzdD4C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
AvastBrowserUpdate.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1636"C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /handoff "bundlename=Avast Secure Browser&appguid={A8504530-742B-42BC-895D-2BAD6406F698}&appname=Avast Secure Browser&needsadmin=false&lang=en-US&brand=6155&installargs=--no-create-user-shortcuts --reset-default-win10 --auto-import-data%3Dmsedge --import-cookies --auto-launch-chrome" /installsource otherinstallcmd /sessionid "{C4C99442-8E4E-4410-9F99-9F829909D72B}" /silentC:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exeAvastBrowserUpdate.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1732"C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /regserverC:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exeAvastBrowserUpdate.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1804AvastBrowserUpdateSetup.exe /silent /install "bundlename=Avast Secure Browser&appguid={A8504530-742B-42BC-895D-2BAD6406F698}&appname=Avast Secure Browser&needsadmin=false&lang=en-US&brand=6155&installargs=--no-create-user-shortcuts --reset-default-win10 --auto-import-data%3Dmsedge --import-cookies --auto-launch-chrome"C:\Users\admin\AppData\Local\Temp\nsx1049.tmp\AvastBrowserUpdateSetup.exe
ajEC4.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser Setup
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\temp\nsx1049.tmp\avastbrowserupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1900"C:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
svchost.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Browser
Exit code:
0
Version:
1.8.1653.5
Modules
Images
c:\users\admin\appdata\local\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2036"C:\Users\admin\Desktop\avast_secure_browser_setup.exe" C:\Users\admin\Desktop\avast_secure_browser_setup.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Avast Secure Browser Setup
Exit code:
0
Version:
8.11.5.7269
Modules
Images
c:\users\admin\desktop\avast_secure_browser_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2084"C:\Users\admin\AppData\Local\Temp\ajEC4.exe" /relaunch=8 /was_elevated=0 /tagdata C:\Users\admin\AppData\Local\Temp\ajEC4.exe
avast_secure_browser_setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Avast Secure Browser Setup
Exit code:
0
Version:
8.11.5.7269
Modules
Images
c:\users\admin\appdata\local\temp\ajec4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
16 196
Read events
12 384
Write events
3 802
Delete events
10

Modification events

(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2084) ajEC4.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2084) ajEC4.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1732) AvastBrowserUpdate.exeKey:HKEY_CLASSES_ROOT\CLSID\{167FD956-39C3-374C-927A-1D3C47CB6663}\InprocServer32
Operation:delete keyName:(default)
Value:
Executable files
173
Suspicious files
10
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\StdUtils.dllexecutable
MD5:CFFAB93125679136C065649F7196047C
SHA256:0870AAE45A6B0417DDDCD536207C6A4DF0B3D861180F60A44C4E5F8784C0AE58
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\inetc.dllexecutable
MD5:23E0A7D53E3DF83685B70EA8CE33DC37
SHA256:96A871F048202C26B85487E24593080D6A95C271ACAF5CD676BD2E2D96DE57DB
2084ajEC4.exeC:\Users\admin\AppData\Local\Temp\nsx1049.tmp\Midex.dllexecutable
MD5:E4EB6EE3CC523D52DDDD018497DE64C5
SHA256:75BF6CCE57CE3089F662E0E0700FCD28903FD0DAB06ECF47714F75A411A68305
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\avast-securebrowser-web-tagsbinary
MD5:0CA0BCC7D884C71DB3BEA29B3A0DB8D8
SHA256:6CAC619A8A2B092C6BF96AE131F18207F32690F30412F2B14EC43A71F047F286
2084ajEC4.exeC:\Users\admin\AppData\Local\Temp\nsx1049.tmp\thirdparty.dllexecutable
MD5:C855765DD1290045D985FFA2CA6D4882
SHA256:8C0222A57A491960CB86E167BC17188D581BE9B64CAE8BA3A6EC1A56B9091931
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\reboot.dllexecutable
MD5:2A6A9C73EA41A4634413F626087EA4B4
SHA256:1F9FC5B90F75AEA4BAE67F2B88791EE488DE61FB959BE7A8795ADC47FA45C3DE
2084ajEC4.exeC:\Users\admin\AppData\Local\Temp\nsx1049.tmp\FF.places.tmp
MD5:
SHA256:
2084ajEC4.exeC:\Users\admin\AppData\Local\Temp\nsx1049.tmp\inetc.dllexecutable
MD5:23E0A7D53E3DF83685B70EA8CE33DC37
SHA256:96A871F048202C26B85487E24593080D6A95C271ACAF5CD676BD2E2D96DE57DB
2036avast_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nsn2BD.tmp\AccessControl.dllexecutable
MD5:A1B76C4386328C2A243FC4D2B35328AF
SHA256:BAC3B3A526EB67AE375A9FE29CAB6268536E44C2ECE1239B65BD1827D055157A
2084ajEC4.exeC:\Users\admin\AppData\Local\Temp\nsx1049.tmp\StdUtils.dllexecutable
MD5:CFFAB93125679136C065649F7196047C
SHA256:0870AAE45A6B0417DDDCD536207C6A4DF0B3D861180F60A44C4E5F8784C0AE58
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
17
DNS requests
5
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?85d4b5be3d25b038
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
1900
AvastBrowserUpdate.exe
GET
2.16.164.99:80
http://browser-update.avast.com/browser/win/x86/109.0.19981.120/AvastBrowserInstaller.exe
unknown
unknown
2084
ajEC4.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5c9575644cc14e32
unknown
compressed
4.66 Kb
unknown
2084
ajEC4.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2084
ajEC4.exe
104.20.159.62:443
stats.securebrowser.com
CLOUDFLARENET
unknown
2084
ajEC4.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2084
ajEC4.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1536
AvastBrowserUpdate.exe
172.67.15.96:443
update.avastbrowser.com
CLOUDFLARENET
US
unknown
1900
AvastBrowserUpdate.exe
172.67.15.96:443
update.avastbrowser.com
CLOUDFLARENET
US
unknown
1900
AvastBrowserUpdate.exe
2.16.164.99:80
browser-update.avast.com
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
stats.securebrowser.com
  • 104.20.159.62
  • 104.20.158.62
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
update.avastbrowser.com
  • 172.67.15.96
  • 104.22.78.87
  • 104.22.79.87
unknown
browser-update.avast.com
  • 2.16.164.99
  • 2.16.164.122
unknown

Threats

PID
Process
Class
Message
1900
AvastBrowserUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1900
AvastBrowserUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1900
AvastBrowserUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1900
AvastBrowserUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
avast_secure_browser_setup.exe
2024-01-17T10:21:32 [libnsis] {000007f4:000006f0} <2:Info> (893f00f663353e48\src\jsis-plugins\plugins\Plugin.cpp:82) JSIS Plugin logging enabled
avast_secure_browser_setup.exe
2024-01-17T10:21:32 [libnsis] {000007f4:000006f0} <4:Error> (893f00f663353e48\src\jsis-plugins\plugins\UtilitiesPlugin\TagData.cpp:85) 0x00000400000715 91aa05bf654a77ad\src\sbplugins\windows\RCData.cpp:62
avast_secure_browser_setup.exe
2024-01-17T10:21:32 [libnsis] {000007f4:000006f0} <1:Debug> (91aa05bf654a77ad\src\sbplugins\windows\RCData.cpp:62) Throwing exception 0x00000400000715
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <2:Info> (893f00f663353e48\src\jsis-plugins\plugins\Plugin.cpp:82) JSIS Plugin logging enabled
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT ((visits.visit_time/1000000)-11644473600) /60 /60 / 24 AS vtime FROM 'visits' WHERE vtime >= 19709 AND vtime <= 19740 GROUP BY vtime
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nsx1049.tmp\CR.History.tmp
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT ((visits.visit_time/1000000)-11644473600) /60 /60 / 24 AS vtime FROM 'visits' WHERE vtime >= 19709 AND vtime <= 19740 GROUP BY vtime
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nsx1049.tmp\CR.History.tmp
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nsx1049.tmp\FF.places.tmp
ajEC4.exe
2024-01-17T10:21:34 [libnsis] {00000824:00000810} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT last_visit_date / 1000000 /60 /60 / 24 AS vtime FROM 'moz_places' WHERE vtime >= 19709 AND vtime <= 19740 GROUP BY vtime