File name:

avast_free_antivirus_setup_online.exe

Full analysis: https://app.any.run/tasks/60496f1c-30d1-4b2b-8d71-e4434ffada6f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 11, 2024, 22:39:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
evasion
pikabot
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D6325D8DC8A82A8ACF6A86991186FE44

SHA1:

38A3EF7121CCFFA4F5F8EEB857910A35B7E9FB8A

SHA256:

9C66F71830596C29E3293EC1378328D1B63647CC756AA0209D662D7925626BA1

SSDEEP:

3072:chrEcYTuZF3sDmYFDL56DLiSNMWm5RC3Oy1jjHfJWcCAnzuVmoP7wxi6yd+gf8ns:EYTuZFuB66SBRHJWcPz8/JrLASuTT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 1576)
      • aswOfferTool.exe (PID: 1808)
      • aswOfferTool.exe (PID: 2728)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 128)
      • SetupInf.exe (PID: 3140)
      • drvinst.exe (PID: 2024)
      • engsup.exe (PID: 1288)
      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 2096)
      • aswOfferTool.exe (PID: 3036)
    • Changes the autorun value in the registry

      • instup.exe (PID: 2256)
      • instup.exe (PID: 2096)
    • Creates a writable file in the system directory

      • instup.exe (PID: 2256)
      • drvinst.exe (PID: 2024)
      • SetupInf.exe (PID: 3140)
      • AvastSvc.exe (PID: 3640)
    • Steals credentials from Web Browsers

      • engsup.exe (PID: 3672)
      • AvastSvc.exe (PID: 3640)
    • Disables Windows Defender

      • wsc_proxy.exe (PID: 2136)
    • Actions looks like stealing of personal data

      • engsup.exe (PID: 3672)
      • aswToolsSvc.exe (PID: 4012)
      • AvastSvc.exe (PID: 3640)
      • AvastUI.exe (PID: 2960)
    • Antivirus name has been found in the command line (generic signature)

      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 2480)
      • AvastUI.exe (PID: 3824)
    • PIKABOT has been detected (YARA)

      • AvastUI.exe (PID: 2960)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • instup.exe (PID: 2096)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
    • Process requests binary or script from the Internet

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • AvEmUpdate.exe (PID: 128)
      • AvastSvc.exe (PID: 3640)
    • Executable content was dropped or overwritten

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 1576)
      • aswOfferTool.exe (PID: 2728)
      • instup.exe (PID: 2256)
      • aswOfferTool.exe (PID: 1808)
      • AvEmUpdate.exe (PID: 128)
      • SetupInf.exe (PID: 3140)
      • drvinst.exe (PID: 2024)
      • engsup.exe (PID: 1288)
      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 2096)
      • aswOfferTool.exe (PID: 3036)
    • Reads the Internet Settings

      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvastUI.exe (PID: 2960)
    • Starts itself from another location

      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 1808)
    • Likely accesses (executes) a file from the Public directory

      • aswOfferTool.exe (PID: 2728)
    • Process drops legitimate windows executable

      • instup.exe (PID: 2256)
      • engsup.exe (PID: 1288)
      • instup.exe (PID: 2096)
    • Creates or modifies Windows services

      • instup.exe (PID: 2256)
    • The process drops C-runtime libraries

      • instup.exe (PID: 2256)
      • engsup.exe (PID: 1288)
    • Drops a system driver (possible attempt to evade defenses)

      • instup.exe (PID: 2256)
      • SetupInf.exe (PID: 3140)
      • drvinst.exe (PID: 2024)
    • Creates files in the driver directory

      • instup.exe (PID: 2256)
      • drvinst.exe (PID: 2024)
      • SetupInf.exe (PID: 3140)
    • Creates a software uninstall entry

      • instup.exe (PID: 2256)
    • The process verifies whether the antivirus software is installed

      • SetupInf.exe (PID: 712)
      • SetupInf.exe (PID: 2468)
      • SetupInf.exe (PID: 2632)
      • AvEmUpdate.exe (PID: 2760)
      • SetupInf.exe (PID: 844)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • SetupInf.exe (PID: 2616)
      • SetupInf.exe (PID: 3140)
      • AvEmUpdate.exe (PID: 2516)
      • instup.exe (PID: 2256)
      • RegSvr.exe (PID: 1604)
      • RegSvr.exe (PID: 3472)
      • AvastNM.exe (PID: 1408)
      • overseer.exe (PID: 2032)
      • engsup.exe (PID: 1288)
      • wsc_proxy.exe (PID: 1932)
      • wsc_proxy.exe (PID: 2136)
      • engsup.exe (PID: 3672)
      • aswToolsSvc.exe (PID: 4012)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 984)
      • AvastSvc.exe (PID: 3640)
      • AvEmUpdate.exe (PID: 3632)
      • aswOfferTool.exe (PID: 3036)
      • AvastUI.exe (PID: 2960)
      • aswOfferTool.exe (PID: 2044)
      • instup.exe (PID: 2096)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 2480)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 2580)
    • Creates/Modifies COM task schedule object

      • instup.exe (PID: 2256)
      • RegSvr.exe (PID: 1604)
      • RegSvr.exe (PID: 3472)
    • Application launched itself

      • AvEmUpdate.exe (PID: 128)
      • AvastUI.exe (PID: 2960)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 2024)
      • AvastSvc.exe (PID: 3640)
    • Adds/modifies Windows certificates

      • SetupInf.exe (PID: 3140)
      • AvastSvc.exe (PID: 3640)
    • Executes as Windows Service

      • wsc_proxy.exe (PID: 2136)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
    • Searches for installed software

      • overseer.exe (PID: 2032)
      • aswToolsSvc.exe (PID: 4012)
    • Reads browser cookies

      • engsup.exe (PID: 3672)
    • Reads the date of Windows installation

      • instup.exe (PID: 2256)
      • AvastSvc.exe (PID: 3640)
    • Reads security settings of Internet Explorer

      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 2256)
    • Checks for Java to be installed

      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
    • Checks for external IP

      • AvastUI.exe (PID: 2960)
  • INFO

    • Reads the computer name

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 1808)
      • instup.exe (PID: 2256)
      • SetupInf.exe (PID: 712)
      • SetupInf.exe (PID: 844)
      • SetupInf.exe (PID: 2468)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 2760)
      • SetupInf.exe (PID: 2632)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • SetupInf.exe (PID: 2616)
      • drvinst.exe (PID: 2024)
      • SetupInf.exe (PID: 3140)
      • RegSvr.exe (PID: 3472)
      • overseer.exe (PID: 2032)
      • RegSvr.exe (PID: 1604)
      • wsc_proxy.exe (PID: 1932)
      • wsc_proxy.exe (PID: 2136)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • engsup.exe (PID: 3672)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • AvEmUpdate.exe (PID: 3632)
      • instup.exe (PID: 984)
      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 2480)
    • Checks supported languages

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • instup.exe (PID: 2256)
      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 2432)
      • aswOfferTool.exe (PID: 1576)
      • aswOfferTool.exe (PID: 2564)
      • aswOfferTool.exe (PID: 1808)
      • aswOfferTool.exe (PID: 2728)
      • sbr.exe (PID: 2388)
      • SetupInf.exe (PID: 2468)
      • SetupInf.exe (PID: 2632)
      • SetupInf.exe (PID: 712)
      • AvEmUpdate.exe (PID: 2760)
      • SetupInf.exe (PID: 844)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • SetupInf.exe (PID: 2616)
      • SetupInf.exe (PID: 3140)
      • AvEmUpdate.exe (PID: 2516)
      • drvinst.exe (PID: 2024)
      • RegSvr.exe (PID: 3472)
      • overseer.exe (PID: 2032)
      • AvastNM.exe (PID: 1408)
      • RegSvr.exe (PID: 1604)
      • engsup.exe (PID: 1288)
      • wsc_proxy.exe (PID: 2136)
      • wsc_proxy.exe (PID: 1932)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • engsup.exe (PID: 3672)
      • instup.exe (PID: 2096)
      • instup.exe (PID: 1376)
      • keytool.exe (PID: 2052)
      • instup.exe (PID: 984)
      • keytool.exe (PID: 3528)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
      • aswOfferTool.exe (PID: 3036)
      • aswOfferTool.exe (PID: 2044)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 2480)
    • Reads the software policy settings

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • drvinst.exe (PID: 2024)
      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
    • Reads the machine GUID from the registry

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • SetupInf.exe (PID: 712)
      • SetupInf.exe (PID: 2632)
      • SetupInf.exe (PID: 844)
      • SetupInf.exe (PID: 2468)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • SetupInf.exe (PID: 2616)
      • drvinst.exe (PID: 2024)
      • SetupInf.exe (PID: 3140)
      • RegSvr.exe (PID: 1604)
      • RegSvr.exe (PID: 3472)
      • overseer.exe (PID: 2032)
      • wsc_proxy.exe (PID: 1932)
      • wsc_proxy.exe (PID: 2136)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • instup.exe (PID: 984)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 2480)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 2580)
    • Reads CPU info

      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • SetupInf.exe (PID: 844)
      • SetupInf.exe (PID: 2632)
      • SetupInf.exe (PID: 712)
      • SetupInf.exe (PID: 2468)
      • AvEmUpdate.exe (PID: 2760)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • SetupInf.exe (PID: 2616)
      • SetupInf.exe (PID: 3140)
      • RegSvr.exe (PID: 1604)
      • RegSvr.exe (PID: 3472)
      • AvastNM.exe (PID: 1408)
      • engsup.exe (PID: 1288)
      • wsc_proxy.exe (PID: 1932)
      • wsc_proxy.exe (PID: 2136)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • engsup.exe (PID: 3672)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • instup.exe (PID: 984)
      • AvastUI.exe (PID: 2960)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 2480)
    • Creates files in the program directory

      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 2760)
      • AvEmUpdate.exe (PID: 128)
      • AvastNM.exe (PID: 1408)
      • engsup.exe (PID: 1288)
      • wsc_proxy.exe (PID: 1932)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • engsup.exe (PID: 3672)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • keytool.exe (PID: 2052)
      • AvastUI.exe (PID: 2960)
      • aswOfferTool.exe (PID: 3036)
    • Checks proxy server information

      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
    • Dropped object may contain TOR URL's

      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 1808)
      • instup.exe (PID: 2256)
    • Reads Environment values

      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 2760)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • instup.exe (PID: 984)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
    • Create files in a temporary directory

      • SetupInf.exe (PID: 3140)
      • engsup.exe (PID: 3672)
      • AvastUI.exe (PID: 2960)
    • Reads Microsoft Office registry keys

      • aswToolsSvc.exe (PID: 4012)
    • Manual execution by a user

      • AvastUI.exe (PID: 2960)
    • Process checks computer location settings

      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 2480)
      • AvastUI.exe (PID: 3824)
    • Creates files or folders in the user directory

      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 4060)
    • Process checks whether UAC notifications are on

      • AvastSvc.exe (PID: 3640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:04:12 08:36:05+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 137216
InitializedDataSize: 117760
UninitializedDataSize: -
EntryPoint: 0x1020
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.1.99.0
ProductVersionNumber: 2.1.99.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: AVAST Software
Edition: 1
FileDescription: Avast Installer
FileVersion: 2.1.99.0
InternalName: microstub
LegalCopyright: Copyright (c) 2023 AVAST Software
OriginalFileName: microstub.exe
ProductName: Avast
ProductVersion: 2.1.99.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
92
Monitored processes
47
Malicious processes
37
Suspicious processes
1

Behavior graph

Click at the process to see the details
start avast_free_antivirus_setup_online.exe avast_free_antivirus_setup_online.exe instup.exe instup.exe aswoffertool.exe no specs aswoffertool.exe no specs aswoffertool.exe aswoffertool.exe aswoffertool.exe sbr.exe no specs setupinf.exe no specs setupinf.exe no specs setupinf.exe no specs setupinf.exe no specs avemupdate.exe no specs avemupdate.exe avemupdate.exe avemupdate.exe setupinf.exe no specs setupinf.exe drvinst.exe regsvr.exe no specs regsvr.exe no specs avastnm.exe no specs overseer.exe engsup.exe wsc_proxy.exe no specs wsc_proxy.exe no specs avastsvc.exe aswtoolssvc.exe engsup.exe instup.exe instup.exe keytool.exe no specs instup.exe icacls.exe no specs keytool.exe no specs avemupdate.exe #PIKABOT avastui.exe aswoffertool.exe aswoffertool.exe no specs avastui.exe no specs avastui.exe no specs avastui.exe avastui.exe no specs avastui.exe no specs avast_free_antivirus_setup_online.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\Avast Software\Avast\AvEmUpdate.exe" /installer1C:\Program Files\Avast Software\Avast\AvEmUpdate.exe
instup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Emergency Update
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\avemupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
712"C:\Program Files\Avast Software\Avast\SetupInf.exe" /uninstall /catalog:aswRdr2.catC:\Program Files\Avast Software\Avast\SetupInf.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\setupinf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
844"C:\Program Files\Avast Software\Avast\SetupInf.exe" /uninstall /catalog:aswVmm.catC:\Program Files\Avast Software\Avast\SetupInf.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\setupinf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
984"C:\Program Files\Avast Software\Avast\setup\instup.exe" /wait /instop:update_configdefC:\Program Files\Avast Software\Avast\setup\instup.exe
AvastSvc.exe
User:
SYSTEM
Company:
AVAST Software
Integrity Level:
SYSTEM
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\setup\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1288"C:\Program Files\Avast Software\Avast\defs\24021099\engsup.exe" /prepare_definitions_folderC:\Program Files\Avast Software\Avast\defs\24021099\engsup.exe
instup.exe
User:
admin
Company:
Avast Software
Integrity Level:
HIGH
Description:
Avast Antivirus vps tool
Exit code:
0
Version:
18.0.1833.0
Modules
Images
c:\program files\avast software\avast\defs\24021099\engsup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1376"C:\Program Files\Avast Software\Avast\setup\instup.exe" /wait /instop:update_configdefC:\Program Files\Avast Software\Avast\setup\instup.exe
AvastSvc.exe
User:
SYSTEM
Company:
AVAST Software
Integrity Level:
SYSTEM
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\setup\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1408"C:\Program Files\Avast Software\Avast\AvastNM.exe" /installC:\Program Files\Avast Software\Avast\AvastNM.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\avastnm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1576"C:\Windows\Temp\asw.4a28b6ad67c31182\New_180117d3\aswOfferTool.exe" -checkChrome -elevatedC:\Windows\Temp\asw.4a28b6ad67c31182\New_180117d3\aswOfferTool.exe
instup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Offer Installation Tool
Exit code:
2
Version:
24.1.8821.0
Modules
Images
c:\windows\temp\asw.4a28b6ad67c31182\new_180117d3\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shell32.dll
1600"C:\Program Files\Avast Software\Avast\AvastUI.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=7776,10718441850611719887,9835331506675776271,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,ForcedColors,SameSiteByDefaultCookies,SameSiteDefaultChecksMethodRigorously --lang=en-US --service-sandbox-type=utility --no-sandbox --force-wave-audio --log-file="C:\Users\admin\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --log-severity=disable --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.3.3626.1895 Safari/537.36 Avastium (0.0.0) (Windows 6.1)" --lang=en-US --proxy-auto-detect --disable-webaudio --force-wave-audio --disable-software-rasterizer --no-sandbox --blacklist-accelerated-compositing --disable-accelerated-2d-canvas --disable-accelerated-compositing --disable-accelerated-layers --disable-accelerated-video-decode --blacklist-webgl --disable-bundled-ppapi-flash --disable-flash-3d --enable-aggressive-domstorage-flushing --enable-media-stream --disable-gpu --disable-webgl --disable-gpu-compositing --allow-file-access-from-files=1 --pack_loading_disabled=1 --log-file="C:\Users\admin\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --mojo-platform-channel-handle=5440 /prefetch:8C:\Program Files\Avast Software\Avast\AvastUI.exeAvastUI.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Antivirus
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\avastui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avast software\avast\aavmrpch.dll
c:\windows\system32\rpcrt4.dll
c:\program files\avast software\avast\aswcmnbs.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1604"C:\Program Files\Avast Software\Avast\RegSvr.exe" "C:\Program Files\Avast Software\Avast\aswAMSI.dll"C:\Program Files\Avast Software\Avast\RegSvr.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\regsvr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
119 936
Read events
110 879
Write events
8 962
Delete events
95

Modification events

(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Windows\Temp\asw.b759c86e0f3e647e
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
190000000100000010000000BCC80DAA2F98A4692805BFF4CBB372EB0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB61400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D7200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2304) avast_free_antivirus_setup_online.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2304) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
0
(PID) Process:(2304) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
7
(PID) Process:(2304) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
14
Executable files
589
Suspicious files
424
Text files
470
Unknown types
300

Dropped files

PID
Process
Filename
Type
3772avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.b759c86e0f3e647e\avast_free_antivirus_setup_online.exeexecutable
MD5:8B6BEC90BE60B31706C57CD4FA73D208
SHA256:5363E552CDDD0E6D9F66910D6835E811FBB9220E20F851E6A9BCA6F39F48016C
2304avast_free_antivirus_setup_online.exeC:\ProgramData\Avast Software\Persistent Data\Avast\Logs\Setup.logtext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\part-prg_ais-180117d3.vpxbinary
MD5:C9AB86327CC6D1B698906C6B42364040
SHA256:918DFC9B513535FDA13A3A1F1BB3741728936BD9B355958288A395F68090B81F
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\part-jrog2-132c.vpxbinary
MD5:F757934C2D28D322FCA999FFAFDB4584
SHA256:09C79062FED78B3BB7BB1DA546014D812FE77904A3F161B4908DC5724FF86A12
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\config.defini
MD5:12774C43E92F60CC72545917CA226AA1
SHA256:DDD77710A67F3B37298429B1A4A0D9B952084AF42FF96454DF364F42F9B7DA60
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\cookie.bintext
MD5:69BD03FCD5429BBFC9A23CCE407C999E
SHA256:5125664CD8B9B89D5D00B1C749C3A4BB8149FE456DFD0DE50272AAD783C15053
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\config.def.vpxbinary
MD5:65A94D643E10FFC9156EE8F1BAE43C25
SHA256:2C9559A99BB1859206D554D1C3984787E5B4F347C5C55E8C05D3C6350EBFB760
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\servers.deftext
MD5:328DF5A6F079158F02FA851462750ACC
SHA256:89F57671B7CC33D68B04D22791ED81EB5AF888C22F54E0F0D2E933E62B2931B0
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\part-setup_ais-180117d3.vpxbinary
MD5:72FEEE470E611C17FCB9494E9BF08B7D
SHA256:DED1EDCAD352CB5236D924F34FEEDEE238DA2B510B36701DE35F1C001D3A5697
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\part-vps_windows-24020600.vpxbinary
MD5:526AD86C7563D8E89C79034C6F50AD4B
SHA256:EDEDF623E34555BAFD092BABA995CCBD410E44E81663F8AD5DDFD3393765958B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
224
TCP/UDP connections
171
DNS requests
158
Threats
21

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3772
avast_free_antivirus_setup_online.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
3772
avast_free_antivirus_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
3772
avast_free_antivirus_setup_online.exe
GET
200
104.124.11.24:80
http://iavs9x.u.avcdn.net/iavs9x/avast_free_antivirus_setup_online.exe
unknown
executable
9.19 Mb
unknown
3772
avast_free_antivirus_setup_online.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
3772
avast_free_antivirus_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
2304
avast_free_antivirus_setup_online.exe
GET
200
142.250.185.110:80
http://www.google-analytics.com/collect?aiid=mmm_cnt_dlp_007_880_m&an=Free&av=24.1.8821&cd=stub-extended&cd3=Online&cid=c52ff99e-1d9c-427b-9688-f7260a65909a&dt=Installation&t=screenview&tid=UA-58120669-3&v=1
unknown
image
35 b
unknown
3964
Instup.exe
GET
200
23.213.161.8:80
http://y9830512.iavs9x.u.avast.com/iavs9x/servers.def.vpx
unknown
binary
2.40 Kb
unknown
3964
Instup.exe
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
unknown
binary
573 b
unknown
3964
Instup.exe
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/avbugreport_ais-a2c.vpx
unknown
binary
1.25 Mb
unknown
3964
Instup.exe
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/avdump_x86_ais-a2c.vpx
unknown
binary
371 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3772
avast_free_antivirus_setup_online.exe
142.250.185.110:80
www.google-analytics.com
GOOGLE
US
whitelisted
3772
avast_free_antivirus_setup_online.exe
34.117.223.223:80
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3772
avast_free_antivirus_setup_online.exe
104.124.11.24:443
iavs9x.u.avcdn.net
Akamai International B.V.
DE
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3772
avast_free_antivirus_setup_online.exe
104.124.11.24:80
iavs9x.u.avcdn.net
Akamai International B.V.
DE
unknown
2304
avast_free_antivirus_setup_online.exe
34.117.223.223:443
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2304
avast_free_antivirus_setup_online.exe
142.250.185.110:80
www.google-analytics.com
GOOGLE
US
whitelisted
3964
Instup.exe
34.160.176.28:443
shepherd.ff.avast.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 142.250.185.110
whitelisted
iavs9x.u.avcdn.net
  • 104.124.11.24
  • 104.124.11.40
unknown
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
analytics.avcdn.net
  • 34.117.223.223
unknown
shepherd.ff.avast.com
  • 34.160.176.28
whitelisted
l4691727.iavs9x.u.avast.com
  • 23.213.161.24
  • 23.213.161.8
  • 2a02:26f0:3500:11::215:14c6
  • 2a02:26f0:3500:11::215:14cc
whitelisted
m0658849.iavs9x.u.avast.com
  • 23.213.161.24
  • 23.213.161.8
  • 2a02:26f0:3500:11::215:14cc
  • 2a02:26f0:3500:11::215:14c6
whitelisted
p1043812.iavs9x.u.avast.com
  • 23.213.161.24
  • 23.213.161.8
  • 2a02:26f0:3500:11::215:14cc
  • 2a02:26f0:3500:11::215:14c6
unknown
s-iavs9x.avcdn.net
  • 23.35.229.27
  • 2a02:26f0:3500:595::240d
  • 2a02:26f0:3500:59a::240d
  • 184.30.25.22
whitelisted
w5805295.iavs9x.u.avast.com
  • 23.213.161.24
  • 23.213.161.8
  • 2a02:26f0:3500:11::215:14c6
  • 2a02:26f0:3500:11::215:14cc
whitelisted

Threats

PID
Process
Class
Message
3772
avast_free_antivirus_setup_online.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
128
AvEmUpdate.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
128
AvEmUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1936
AvEmUpdate.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Process
Message
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:57.280] [info ] [sfxinst ] [ 2304: 1040] [7361C5: 370] Running SFX 'C:\Windows\Temp\asw.b759c86e0f3e647e\avast_free_antivirus_setup_online.exe'
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:57.561] [info ] [sfxinst ] [ 2304: 1040] [7361C5: 592] Moved extra data file 'ecoo.edat' to 'C:\Windows\Temp\asw.4a28b6ad67c31182\cookie.bin'.
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:57.748] [notice ] [burger_rep ] [ 2304: 3428] [64A1D8: 66] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:57.764] [info ] [sfxstats ] [ 2304: 864] [03AC9E: 149] Statistics sent successfully.
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:58.733] [info ] [sfxinst ] [ 2304: 1040] [7361C5: 881] Starting installer/updater executable 'C:\Windows\Temp\asw.4a28b6ad67c31182\instup.exe'
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2658] Command: '"C:\Windows\Temp\asw.4a28b6ad67c31182\instup.exe" /sfx:lite /sfxstorage:C:\Windows\Temp\asw.4a28b6ad67c31182 /edition:1 /prod:ais /stub_mapping_guid:cf860b81-13bd-4841-8f00-32978b6c86da:9635040 /guid:c52ff99e-1d9c-427b-9688-f7260a65909a /ga_clientid:08c6ea17-9d84-4205-923c-22e859bb7bb5 /cookie:mmm_cnt_dlp_007_880_m /ga_clientid:08c6ea17-9d84-4205-923c-22e859bb7bb5 /edat_dir:C:\Windows\Temp\asw.b759c86e0f3e647e'
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2664] CPU: Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz,4
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2669] OS: Windows 7 SP1 x86
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2672] setup: x86
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2686] Memory: 22% load. Phys:2453240/3145208K free, Page:4194303/4194303K free, Virt:1990360/2097024K free