File name:

Avast free antivirus.exe

Full analysis: https://app.any.run/tasks/f4511b14-3eee-4144-bfb5-21703f004f56
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 14, 2024, 08:48:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

85C737BA3F50432973315EAFC06E2AD8

SHA1:

5603A13D7914A62DCDA5F8C0FF1FA0039BDCD223

SHA256:

846B89D5D34EAF50E24B2E47D9926C26BC18D8392740F0A5935DB5CB536AC5ED

SSDEEP:

96:0PP6oxgXUxqN2Qq6LR/QtMb3KU2PD/6Sd+X/IKDMhVKX1zZVN3lZXxXTzNt:0H5gXUxqN3q6VFAhVOlZVN3LXxX1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Runs injected code in another process

      • Avast free antivirus.exe (PID: 6024)
    • Application was injected by another process

      • explorer.exe (PID: 4616)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Avast free antivirus.exe (PID: 6024)
    • Executes application which crashes

      • explorer.exe (PID: 4616)
    • Potential Corporate Privacy Violation

      • Avast free antivirus.exe (PID: 6024)
  • INFO

    • Reads the computer name

      • Avast free antivirus.exe (PID: 6024)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4616)
    • The process uses the downloaded file

      • explorer.exe (PID: 4616)
    • Checks supported languages

      • Avast free antivirus.exe (PID: 6024)
    • Disables trace logs

      • Avast free antivirus.exe (PID: 6024)
    • Checks proxy server information

      • Avast free antivirus.exe (PID: 6024)
    • Reads Environment values

      • Avast free antivirus.exe (PID: 6024)
    • Reads the machine GUID from the registry

      • Avast free antivirus.exe (PID: 6024)
    • Manual execution by a user

      • WerFault.exe (PID: 3772)
      • Taskmgr.exe (PID: 5336)
      • Taskmgr.exe (PID: 3788)
    • Sends debugging messages

      • StartMenuExperienceHost.exe (PID: 6692)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2051:10:08 18:16:39+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 4608
InitializedDataSize: 2560
UninitializedDataSize: -
EntryPoint: 0x30c6
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Avast free antivirus
FileVersion: 1.0.0.0
InternalName: Avast free antivirus.exe
LegalCopyright: Copyright © 2024
LegalTrademarks: -
OriginalFileName: Avast free antivirus.exe
ProductName: Avast free antivirus
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
12
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start avast free antivirus.exe werfault.exe no specs textinputhost.exe no specs startmenuexperiencehost.exe no specs tiworker.exe no specs searchapp.exe mobsync.exe no specs taskmgr.exe no specs taskmgr.exe sppextcomobj.exe no specs slui.exe no specs explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
3728"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
3772C:\WINDOWS\system32\WerFault.exe -u -p 4616 -s 8624C:\Windows\System32\WerFault.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
3788"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Manager
Exit code:
3221226540
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
4004C:\WINDOWS\System32\mobsync.exe -EmbeddingC:\Windows\System32\mobsync.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Sync Center
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mobsync.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4616C:\WINDOWS\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1467
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dlnashext.dll
c:\windows\system32\wpdshext.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5008C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -EmbeddingC:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Modules Installer Worker
Version:
10.0.19041.3989 (WinBuild.160101.0800)
Modules
Images
c:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\tiworker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
5336"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
6024"C:\Users\admin\AppData\Local\Temp\Avast free antivirus.exe" C:\Users\admin\AppData\Local\Temp\Avast free antivirus.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Avast free antivirus
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\avast free antivirus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6168"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wincorlib.dll
c:\windows\system32\combase.dll
6692"C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mcaC:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\windows\systemapps\microsoft.windows.startmenuexperiencehost_cw5n1h2txyewy\startmenuexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wincorlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
21 681
Read events
21 539
Write events
132
Delete events
10

Modification events

(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6024) Avast free antivirus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avast free antivirus_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
118
Text files
160
Unknown types
7

Dropped files

PID
Process
Filename
Type
3772WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_8e94a9231f24e126d6a01eaa10342d23219_a6883b46_ee49146f-18e0-438e-9734-35f3b6cfe897\Report.wer
MD5:
SHA256:
3772WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\explorer.exe.4616.dmp
MD5:
SHA256:
6168SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133760477318390519.txt~RF9281d.TMP
MD5:
SHA256:
3772WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WEREA59.tmp.dmpbinary
MD5:8D3BDD7B9C460AF714D5465BF7FD2868
SHA256:58036176C593591F122EDAEDEA111A474F03DF2060669D0504C7941D3A971200
6168SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\NLQCMX2T\-UAIppANYxiGpRWJy2NDph4qOEw.gz[1].jss
MD5:9E527B91C2D8B31B0017B76049B5E4E3
SHA256:38EDF0F961C1CCB287880B88F12F370775FC65B2E28227EEE215E849CDBE9BBC
6168SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5Y734AMR\63\6aa-EF2IAVwnTTOiwAbhwI_VmCw[1].jss
MD5:B2C3CBF8A1D940D6C83D59A67486675C
SHA256:08EA9109346E9018ED50567503D2C141F7A84CFDE80EB25E97FDDCFE270BAA67
5008TiWorker.exeC:\Windows\Logs\CBS\CBS.logtext
MD5:BE844F121661FBC8C3BE192CE202D9A1
SHA256:D4E6645C4002C53A0BCCD43A7DAF533208BCEBCB016378CBA96B5605F68352AB
6168SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133760477318390519.txt.~tmpini
MD5:EBA9D627AEFA0148EA256382E454768F
SHA256:85F02886D53B7427792E54BCEE97D366AD46F78CF90AA25DCC3FAE29ED7FA7F8
6168SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\fbaf94e759052658216786bfbabcdced1b67a5c2.tbresbinary
MD5:C23B6C812FBC54024FA3E9FC8F25E584
SHA256:BAD5A59079E77C00A827B834D6B3B8A83ED9C44234276C69D044E870E05AC7C9
3772WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER5B2.tmp.WERInternalMetadata.xmlxml
MD5:C1CD11988AD5F8511A9D59AA9A27DEB8
SHA256:9CB705BEB34F6A0DF4A200AB6E50327A402FEF958FFB8E81BF35AD4796F691AE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
52
DNS requests
20
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
948
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4956
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6024
Avast free antivirus.exe
GET
200
141.8.192.217:80
http://a1051707.xsph.ru/conhosts.exe
unknown
whitelisted
4956
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2576
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
104.126.37.137:443
th.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
948
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
948
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6024
Avast free antivirus.exe
141.8.192.217:80
a1051707.xsph.ru
Sprinthost.ru LLC
RU
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.78
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.75
  • 40.126.31.73
  • 20.190.159.4
  • 40.126.31.67
  • 20.190.159.68
  • 20.190.159.64
  • 20.190.159.2
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
a1051707.xsph.ru
  • 141.8.192.217
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
th.bing.com
  • 104.126.37.160
  • 104.126.37.131
  • 104.126.37.130
  • 104.126.37.139
  • 104.126.37.152
  • 104.126.37.155
  • 104.126.37.137
  • 104.126.37.153
  • 104.126.37.161
whitelisted
r.bing.com
  • 104.126.37.137
  • 104.126.37.163
  • 104.126.37.139
  • 104.126.37.155
  • 104.126.37.153
  • 104.126.37.161
  • 104.126.37.162
  • 104.126.37.171
  • 104.126.37.160
whitelisted

Threats

PID
Process
Class
Message
2172
svchost.exe
Misc activity
ET INFO Observed DNS Query to xsph .ru Domain
6024
Avast free antivirus.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
6024
Avast free antivirus.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info