File name:

avast_free_antivirus_setup_online.exe

Full analysis: https://app.any.run/tasks/60496f1c-30d1-4b2b-8d71-e4434ffada6f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 11, 2024, 22:39:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
evasion
pikabot
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D6325D8DC8A82A8ACF6A86991186FE44

SHA1:

38A3EF7121CCFFA4F5F8EEB857910A35B7E9FB8A

SHA256:

9C66F71830596C29E3293EC1378328D1B63647CC756AA0209D662D7925626BA1

SSDEEP:

3072:chrEcYTuZF3sDmYFDL56DLiSNMWm5RC3Oy1jjHfJWcCAnzuVmoP7wxi6yd+gf8ns:EYTuZFuB66SBRHJWcPz8/JrLASuTT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 1576)
      • aswOfferTool.exe (PID: 1808)
      • aswOfferTool.exe (PID: 2728)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 128)
      • SetupInf.exe (PID: 3140)
      • drvinst.exe (PID: 2024)
      • engsup.exe (PID: 1288)
      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 2096)
      • aswOfferTool.exe (PID: 3036)
    • Changes the autorun value in the registry

      • instup.exe (PID: 2256)
      • instup.exe (PID: 2096)
    • Creates a writable file in the system directory

      • instup.exe (PID: 2256)
      • drvinst.exe (PID: 2024)
      • SetupInf.exe (PID: 3140)
      • AvastSvc.exe (PID: 3640)
    • Actions looks like stealing of personal data

      • engsup.exe (PID: 3672)
      • aswToolsSvc.exe (PID: 4012)
      • AvastSvc.exe (PID: 3640)
      • AvastUI.exe (PID: 2960)
    • Steals credentials from Web Browsers

      • engsup.exe (PID: 3672)
      • AvastSvc.exe (PID: 3640)
    • Antivirus name has been found in the command line (generic signature)

      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 2480)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 3824)
    • Disables Windows Defender

      • wsc_proxy.exe (PID: 2136)
    • PIKABOT has been detected (YARA)

      • AvastUI.exe (PID: 2960)
  • SUSPICIOUS

    • Process requests binary or script from the Internet

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • AvEmUpdate.exe (PID: 128)
      • AvastSvc.exe (PID: 3640)
    • Reads settings of System Certificates

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • instup.exe (PID: 2096)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
    • Executable content was dropped or overwritten

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 1808)
      • aswOfferTool.exe (PID: 1576)
      • aswOfferTool.exe (PID: 2728)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 128)
      • SetupInf.exe (PID: 3140)
      • drvinst.exe (PID: 2024)
      • engsup.exe (PID: 1288)
      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 2096)
      • aswOfferTool.exe (PID: 3036)
    • Reads the Internet Settings

      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvastUI.exe (PID: 2960)
    • Starts itself from another location

      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 1808)
    • Likely accesses (executes) a file from the Public directory

      • aswOfferTool.exe (PID: 2728)
    • The process drops C-runtime libraries

      • instup.exe (PID: 2256)
      • engsup.exe (PID: 1288)
    • Process drops legitimate windows executable

      • instup.exe (PID: 2256)
      • engsup.exe (PID: 1288)
      • instup.exe (PID: 2096)
    • Creates files in the driver directory

      • instup.exe (PID: 2256)
      • drvinst.exe (PID: 2024)
      • SetupInf.exe (PID: 3140)
    • Creates or modifies Windows services

      • instup.exe (PID: 2256)
    • Creates/Modifies COM task schedule object

      • instup.exe (PID: 2256)
      • RegSvr.exe (PID: 1604)
      • RegSvr.exe (PID: 3472)
    • Drops a system driver (possible attempt to evade defenses)

      • instup.exe (PID: 2256)
      • SetupInf.exe (PID: 3140)
      • drvinst.exe (PID: 2024)
    • The process verifies whether the antivirus software is installed

      • SetupInf.exe (PID: 712)
      • SetupInf.exe (PID: 2632)
      • SetupInf.exe (PID: 844)
      • SetupInf.exe (PID: 2468)
      • AvEmUpdate.exe (PID: 2760)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 2516)
      • SetupInf.exe (PID: 2616)
      • SetupInf.exe (PID: 3140)
      • RegSvr.exe (PID: 1604)
      • RegSvr.exe (PID: 3472)
      • AvastNM.exe (PID: 1408)
      • overseer.exe (PID: 2032)
      • engsup.exe (PID: 1288)
      • wsc_proxy.exe (PID: 1932)
      • wsc_proxy.exe (PID: 2136)
      • engsup.exe (PID: 3672)
      • aswToolsSvc.exe (PID: 4012)
      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2256)
      • instup.exe (PID: 984)
      • AvEmUpdate.exe (PID: 3632)
      • aswOfferTool.exe (PID: 3036)
      • aswOfferTool.exe (PID: 2044)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 2480)
      • instup.exe (PID: 2096)
    • Creates a software uninstall entry

      • instup.exe (PID: 2256)
    • Application launched itself

      • AvEmUpdate.exe (PID: 128)
      • AvastUI.exe (PID: 2960)
    • Adds/modifies Windows certificates

      • SetupInf.exe (PID: 3140)
      • AvastSvc.exe (PID: 3640)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 2024)
      • AvastSvc.exe (PID: 3640)
    • Searches for installed software

      • overseer.exe (PID: 2032)
      • aswToolsSvc.exe (PID: 4012)
    • Executes as Windows Service

      • wsc_proxy.exe (PID: 2136)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
    • Reads browser cookies

      • engsup.exe (PID: 3672)
    • Reads security settings of Internet Explorer

      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 2256)
    • Reads the date of Windows installation

      • instup.exe (PID: 2256)
      • AvastSvc.exe (PID: 3640)
    • Checks for Java to be installed

      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
    • Checks for external IP

      • AvastUI.exe (PID: 2960)
  • INFO

    • Reads the computer name

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • aswOfferTool.exe (PID: 1808)
      • SetupInf.exe (PID: 712)
      • SetupInf.exe (PID: 2632)
      • SetupInf.exe (PID: 844)
      • SetupInf.exe (PID: 2468)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • SetupInf.exe (PID: 2616)
      • SetupInf.exe (PID: 3140)
      • AvEmUpdate.exe (PID: 2760)
      • drvinst.exe (PID: 2024)
      • RegSvr.exe (PID: 1604)
      • RegSvr.exe (PID: 3472)
      • overseer.exe (PID: 2032)
      • wsc_proxy.exe (PID: 1932)
      • wsc_proxy.exe (PID: 2136)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • engsup.exe (PID: 3672)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • AvEmUpdate.exe (PID: 3632)
      • instup.exe (PID: 984)
      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 2480)
    • Checks supported languages

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • aswOfferTool.exe (PID: 2432)
      • aswOfferTool.exe (PID: 2564)
      • aswOfferTool.exe (PID: 1576)
      • aswOfferTool.exe (PID: 1808)
      • aswOfferTool.exe (PID: 2728)
      • sbr.exe (PID: 2388)
      • SetupInf.exe (PID: 712)
      • SetupInf.exe (PID: 2632)
      • SetupInf.exe (PID: 844)
      • SetupInf.exe (PID: 2468)
      • AvEmUpdate.exe (PID: 2760)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • SetupInf.exe (PID: 2616)
      • drvinst.exe (PID: 2024)
      • SetupInf.exe (PID: 3140)
      • RegSvr.exe (PID: 1604)
      • RegSvr.exe (PID: 3472)
      • AvastNM.exe (PID: 1408)
      • overseer.exe (PID: 2032)
      • engsup.exe (PID: 1288)
      • wsc_proxy.exe (PID: 1932)
      • wsc_proxy.exe (PID: 2136)
      • AvastSvc.exe (PID: 3640)
      • engsup.exe (PID: 3672)
      • aswToolsSvc.exe (PID: 4012)
      • instup.exe (PID: 2096)
      • keytool.exe (PID: 2052)
      • instup.exe (PID: 984)
      • keytool.exe (PID: 3528)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
      • aswOfferTool.exe (PID: 3036)
      • aswOfferTool.exe (PID: 2044)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 1600)
      • instup.exe (PID: 1376)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 2480)
      • AvastUI.exe (PID: 4060)
    • Reads the machine GUID from the registry

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • SetupInf.exe (PID: 712)
      • SetupInf.exe (PID: 2632)
      • SetupInf.exe (PID: 844)
      • SetupInf.exe (PID: 2468)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • SetupInf.exe (PID: 2616)
      • SetupInf.exe (PID: 3140)
      • drvinst.exe (PID: 2024)
      • RegSvr.exe (PID: 1604)
      • RegSvr.exe (PID: 3472)
      • overseer.exe (PID: 2032)
      • wsc_proxy.exe (PID: 1932)
      • wsc_proxy.exe (PID: 2136)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • instup.exe (PID: 2096)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 984)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 4060)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 2480)
    • Reads the software policy settings

      • avast_free_antivirus_setup_online.exe (PID: 3772)
      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • drvinst.exe (PID: 2024)
      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
    • Reads CPU info

      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • SetupInf.exe (PID: 712)
      • SetupInf.exe (PID: 2632)
      • SetupInf.exe (PID: 2468)
      • SetupInf.exe (PID: 844)
      • AvEmUpdate.exe (PID: 2760)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • SetupInf.exe (PID: 2616)
      • SetupInf.exe (PID: 3140)
      • RegSvr.exe (PID: 1604)
      • AvastNM.exe (PID: 1408)
      • RegSvr.exe (PID: 3472)
      • engsup.exe (PID: 1288)
      • wsc_proxy.exe (PID: 1932)
      • wsc_proxy.exe (PID: 2136)
      • aswToolsSvc.exe (PID: 4012)
      • engsup.exe (PID: 3672)
      • AvastSvc.exe (PID: 3640)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • instup.exe (PID: 984)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 3824)
      • AvastUI.exe (PID: 1600)
      • AvastUI.exe (PID: 2580)
      • AvastUI.exe (PID: 2480)
      • AvastUI.exe (PID: 4060)
    • Creates files in the program directory

      • avast_free_antivirus_setup_online.exe (PID: 2304)
      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 2760)
      • AvastNM.exe (PID: 1408)
      • engsup.exe (PID: 1288)
      • wsc_proxy.exe (PID: 1932)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • engsup.exe (PID: 3672)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 2096)
      • keytool.exe (PID: 2052)
      • AvastUI.exe (PID: 2960)
      • aswOfferTool.exe (PID: 3036)
    • Reads Environment values

      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
      • AvEmUpdate.exe (PID: 128)
      • AvEmUpdate.exe (PID: 1936)
      • AvEmUpdate.exe (PID: 2516)
      • AvEmUpdate.exe (PID: 2760)
      • AvastSvc.exe (PID: 3640)
      • aswToolsSvc.exe (PID: 4012)
      • instup.exe (PID: 2096)
      • instup.exe (PID: 1376)
      • instup.exe (PID: 984)
      • AvEmUpdate.exe (PID: 3632)
      • AvastUI.exe (PID: 2960)
    • Checks proxy server information

      • Instup.exe (PID: 3964)
      • instup.exe (PID: 2256)
    • Dropped object may contain TOR URL's

      • Instup.exe (PID: 3964)
      • aswOfferTool.exe (PID: 1808)
      • instup.exe (PID: 2256)
    • Create files in a temporary directory

      • SetupInf.exe (PID: 3140)
      • engsup.exe (PID: 3672)
      • AvastUI.exe (PID: 2960)
    • Reads Microsoft Office registry keys

      • aswToolsSvc.exe (PID: 4012)
    • Manual execution by a user

      • AvastUI.exe (PID: 2960)
    • Process checks computer location settings

      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 2480)
      • AvastUI.exe (PID: 3824)
    • Creates files or folders in the user directory

      • AvastUI.exe (PID: 2960)
      • AvastUI.exe (PID: 4060)
    • Process checks whether UAC notifications are on

      • AvastSvc.exe (PID: 3640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:04:12 08:36:05+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 137216
InitializedDataSize: 117760
UninitializedDataSize: -
EntryPoint: 0x1020
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.1.99.0
ProductVersionNumber: 2.1.99.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: AVAST Software
Edition: 1
FileDescription: Avast Installer
FileVersion: 2.1.99.0
InternalName: microstub
LegalCopyright: Copyright (c) 2023 AVAST Software
OriginalFileName: microstub.exe
ProductName: Avast
ProductVersion: 2.1.99.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
92
Monitored processes
47
Malicious processes
37
Suspicious processes
1

Behavior graph

Click at the process to see the details
start avast_free_antivirus_setup_online.exe avast_free_antivirus_setup_online.exe instup.exe instup.exe aswoffertool.exe no specs aswoffertool.exe no specs aswoffertool.exe aswoffertool.exe aswoffertool.exe sbr.exe no specs setupinf.exe no specs setupinf.exe no specs setupinf.exe no specs setupinf.exe no specs avemupdate.exe no specs avemupdate.exe avemupdate.exe avemupdate.exe setupinf.exe no specs setupinf.exe drvinst.exe regsvr.exe no specs regsvr.exe no specs avastnm.exe no specs overseer.exe engsup.exe wsc_proxy.exe no specs wsc_proxy.exe no specs avastsvc.exe aswtoolssvc.exe engsup.exe instup.exe instup.exe keytool.exe no specs instup.exe icacls.exe no specs keytool.exe no specs avemupdate.exe #PIKABOT avastui.exe aswoffertool.exe aswoffertool.exe no specs avastui.exe no specs avastui.exe no specs avastui.exe avastui.exe no specs avastui.exe no specs avast_free_antivirus_setup_online.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\Avast Software\Avast\AvEmUpdate.exe" /installer1C:\Program Files\Avast Software\Avast\AvEmUpdate.exe
instup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Emergency Update
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\avemupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
712"C:\Program Files\Avast Software\Avast\SetupInf.exe" /uninstall /catalog:aswRdr2.catC:\Program Files\Avast Software\Avast\SetupInf.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\setupinf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
844"C:\Program Files\Avast Software\Avast\SetupInf.exe" /uninstall /catalog:aswVmm.catC:\Program Files\Avast Software\Avast\SetupInf.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\setupinf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
984"C:\Program Files\Avast Software\Avast\setup\instup.exe" /wait /instop:update_configdefC:\Program Files\Avast Software\Avast\setup\instup.exe
AvastSvc.exe
User:
SYSTEM
Company:
AVAST Software
Integrity Level:
SYSTEM
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\setup\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1288"C:\Program Files\Avast Software\Avast\defs\24021099\engsup.exe" /prepare_definitions_folderC:\Program Files\Avast Software\Avast\defs\24021099\engsup.exe
instup.exe
User:
admin
Company:
Avast Software
Integrity Level:
HIGH
Description:
Avast Antivirus vps tool
Exit code:
0
Version:
18.0.1833.0
Modules
Images
c:\program files\avast software\avast\defs\24021099\engsup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1376"C:\Program Files\Avast Software\Avast\setup\instup.exe" /wait /instop:update_configdefC:\Program Files\Avast Software\Avast\setup\instup.exe
AvastSvc.exe
User:
SYSTEM
Company:
AVAST Software
Integrity Level:
SYSTEM
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\setup\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1408"C:\Program Files\Avast Software\Avast\AvastNM.exe" /installC:\Program Files\Avast Software\Avast\AvastNM.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\avastnm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1576"C:\Windows\Temp\asw.4a28b6ad67c31182\New_180117d3\aswOfferTool.exe" -checkChrome -elevatedC:\Windows\Temp\asw.4a28b6ad67c31182\New_180117d3\aswOfferTool.exe
instup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Offer Installation Tool
Exit code:
2
Version:
24.1.8821.0
Modules
Images
c:\windows\temp\asw.4a28b6ad67c31182\new_180117d3\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shell32.dll
1600"C:\Program Files\Avast Software\Avast\AvastUI.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=7776,10718441850611719887,9835331506675776271,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,ForcedColors,SameSiteByDefaultCookies,SameSiteDefaultChecksMethodRigorously --lang=en-US --service-sandbox-type=utility --no-sandbox --force-wave-audio --log-file="C:\Users\admin\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --log-severity=disable --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.3.3626.1895 Safari/537.36 Avastium (0.0.0) (Windows 6.1)" --lang=en-US --proxy-auto-detect --disable-webaudio --force-wave-audio --disable-software-rasterizer --no-sandbox --blacklist-accelerated-compositing --disable-accelerated-2d-canvas --disable-accelerated-compositing --disable-accelerated-layers --disable-accelerated-video-decode --blacklist-webgl --disable-bundled-ppapi-flash --disable-flash-3d --enable-aggressive-domstorage-flushing --enable-media-stream --disable-gpu --disable-webgl --disable-gpu-compositing --allow-file-access-from-files=1 --pack_loading_disabled=1 --log-file="C:\Users\admin\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --mojo-platform-channel-handle=5440 /prefetch:8C:\Program Files\Avast Software\Avast\AvastUI.exeAvastUI.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Antivirus
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\avastui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avast software\avast\aavmrpch.dll
c:\windows\system32\rpcrt4.dll
c:\program files\avast software\avast\aswcmnbs.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1604"C:\Program Files\Avast Software\Avast\RegSvr.exe" "C:\Program Files\Avast Software\Avast\aswAMSI.dll"C:\Program Files\Avast Software\Avast\RegSvr.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
24.1.8821.0
Modules
Images
c:\program files\avast software\avast\regsvr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
119 936
Read events
110 879
Write events
8 962
Delete events
95

Modification events

(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Windows\Temp\asw.b759c86e0f3e647e
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(3772) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
190000000100000010000000BCC80DAA2F98A4692805BFF4CBB372EB0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB61400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D7200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2304) avast_free_antivirus_setup_online.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2304) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
0
(PID) Process:(2304) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
7
(PID) Process:(2304) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
14
Executable files
589
Suspicious files
424
Text files
470
Unknown types
300

Dropped files

PID
Process
Filename
Type
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\prod-pgm.vpxbinary
MD5:48CADB7D59DAF8E3B51175F48554E58D
SHA256:FA9CDCDDE4F1FB32E7F7BFF8CD5DF48EF4B3ECC29CEC6803E7DD3F7BB63A35A3
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\part-vps_windows-24020600.vpxbinary
MD5:526AD86C7563D8E89C79034C6F50AD4B
SHA256:EDEDF623E34555BAFD092BABA995CCBD410E44E81663F8AD5DDFD3393765958B
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\part-prg_ais-180117d3.vpxbinary
MD5:C9AB86327CC6D1B698906C6B42364040
SHA256:918DFC9B513535FDA13A3A1F1BB3741728936BD9B355958288A395F68090B81F
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\uata64.vpxbinary
MD5:5EFA1250A1D1E9541E46BAABC128D87F
SHA256:CC42D6B9D209C6A3A87733C5A383CF56B5F5A019D5395725526A1DED711F8A04
3964Instup.exeC:\Windows\Temp\asw.4a28b6ad67c31182\asw2747d7741d08bd09.tmp.newtext
MD5:B0054539C30F949798430B3D415CCA16
SHA256:3AA245096A1C8CF9903576DD86AA493C498AD634D53801EBCC39C427FA776151
3964Instup.exeC:\Windows\Temp\asw.4a28b6ad67c31182\config.defini
MD5:B0054539C30F949798430B3D415CCA16
SHA256:3AA245096A1C8CF9903576DD86AA493C498AD634D53801EBCC39C427FA776151
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\prod-vps.vpxbinary
MD5:7366BD32AA01DC9CA58F78F895D87EB4
SHA256:CD07142FB15B5537BA82395C1420089D1A844D8F62F199FEE1D4FEBFA45270DC
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\part-setup_ais-180117d3.vpxbinary
MD5:72FEEE470E611C17FCB9494E9BF08B7D
SHA256:DED1EDCAD352CB5236D924F34FEEDEE238DA2B510B36701DE35F1C001D3A5697
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\servers.def.vpxbinary
MD5:853F70DE2BD1D39E2B6D5AF57647974B
SHA256:2A0CA28C5F7AD60154D5A99B32CE14F9B77A8C5FF217627171CFCA20C5AC9CA2
2304avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.4a28b6ad67c31182\uat64.vpxbinary
MD5:33B91876562EAB512A99946D2AB1B250
SHA256:5B17357093F667242CAE0A263A6232C61BDA86E7B91034C566BD730C64633198
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
224
TCP/UDP connections
171
DNS requests
158
Threats
21

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3772
avast_free_antivirus_setup_online.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2304
avast_free_antivirus_setup_online.exe
GET
200
142.250.185.110:80
http://www.google-analytics.com/collect?aiid=mmm_cnt_dlp_007_880_m&an=Free&av=24.1.8821&cd=stub-extended&cd3=Online&cid=c52ff99e-1d9c-427b-9688-f7260a65909a&dt=Installation&t=screenview&tid=UA-58120669-3&v=1
unknown
image
35 b
unknown
3964
Instup.exe
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
unknown
binary
573 b
unknown
3964
Instup.exe
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/avbugreport_ais-a2c.vpx
unknown
binary
1.25 Mb
unknown
3964
Instup.exe
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/instcont_ais-a2c.vpx
unknown
binary
921 Kb
unknown
3964
Instup.exe
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/avdump_x86_ais-a2c.vpx
unknown
binary
371 Kb
unknown
3964
Instup.exe
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/instup_ais-a2c.vpx
unknown
binary
5.55 Mb
unknown
3964
Instup.exe
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/sbr_x86_ais-a2c.vpx
unknown
binary
11.0 Kb
unknown
GET
200
23.213.161.24:80
http://p1043812.iavs9x.u.avast.com/iavs9x/offertool_ais-a2c.vpx
unknown
binary
885 Kb
unknown
2256
instup.exe
GET
200
23.213.161.8:80
http://l4691727.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
unknown
binary
573 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3772
avast_free_antivirus_setup_online.exe
142.250.185.110:80
www.google-analytics.com
GOOGLE
US
whitelisted
3772
avast_free_antivirus_setup_online.exe
34.117.223.223:80
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3772
avast_free_antivirus_setup_online.exe
104.124.11.24:443
iavs9x.u.avcdn.net
Akamai International B.V.
DE
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3772
avast_free_antivirus_setup_online.exe
104.124.11.24:80
iavs9x.u.avcdn.net
Akamai International B.V.
DE
unknown
2304
avast_free_antivirus_setup_online.exe
34.117.223.223:443
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2304
avast_free_antivirus_setup_online.exe
142.250.185.110:80
www.google-analytics.com
GOOGLE
US
whitelisted
3964
Instup.exe
34.160.176.28:443
shepherd.ff.avast.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 142.250.185.110
whitelisted
iavs9x.u.avcdn.net
  • 104.124.11.24
  • 104.124.11.40
unknown
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
analytics.avcdn.net
  • 34.117.223.223
unknown
shepherd.ff.avast.com
  • 34.160.176.28
whitelisted
l4691727.iavs9x.u.avast.com
  • 23.213.161.24
  • 23.213.161.8
  • 2a02:26f0:3500:11::215:14c6
  • 2a02:26f0:3500:11::215:14cc
whitelisted
m0658849.iavs9x.u.avast.com
  • 23.213.161.24
  • 23.213.161.8
  • 2a02:26f0:3500:11::215:14cc
  • 2a02:26f0:3500:11::215:14c6
whitelisted
p1043812.iavs9x.u.avast.com
  • 23.213.161.24
  • 23.213.161.8
  • 2a02:26f0:3500:11::215:14cc
  • 2a02:26f0:3500:11::215:14c6
unknown
s-iavs9x.avcdn.net
  • 23.35.229.27
  • 2a02:26f0:3500:595::240d
  • 2a02:26f0:3500:59a::240d
  • 184.30.25.22
whitelisted
w5805295.iavs9x.u.avast.com
  • 23.213.161.24
  • 23.213.161.8
  • 2a02:26f0:3500:11::215:14c6
  • 2a02:26f0:3500:11::215:14cc
whitelisted

Threats

PID
Process
Class
Message
3772
avast_free_antivirus_setup_online.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
128
AvEmUpdate.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
128
AvEmUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
1936
AvEmUpdate.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Process
Message
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:57.280] [info ] [sfxinst ] [ 2304: 1040] [7361C5: 370] Running SFX 'C:\Windows\Temp\asw.b759c86e0f3e647e\avast_free_antivirus_setup_online.exe'
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:57.561] [info ] [sfxinst ] [ 2304: 1040] [7361C5: 592] Moved extra data file 'ecoo.edat' to 'C:\Windows\Temp\asw.4a28b6ad67c31182\cookie.bin'.
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:57.748] [notice ] [burger_rep ] [ 2304: 3428] [64A1D8: 66] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:57.764] [info ] [sfxstats ] [ 2304: 864] [03AC9E: 149] Statistics sent successfully.
avast_free_antivirus_setup_online.exe
[2024-02-11 22:39:58.733] [info ] [sfxinst ] [ 2304: 1040] [7361C5: 881] Starting installer/updater executable 'C:\Windows\Temp\asw.4a28b6ad67c31182\instup.exe'
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2658] Command: '"C:\Windows\Temp\asw.4a28b6ad67c31182\instup.exe" /sfx:lite /sfxstorage:C:\Windows\Temp\asw.4a28b6ad67c31182 /edition:1 /prod:ais /stub_mapping_guid:cf860b81-13bd-4841-8f00-32978b6c86da:9635040 /guid:c52ff99e-1d9c-427b-9688-f7260a65909a /ga_clientid:08c6ea17-9d84-4205-923c-22e859bb7bb5 /cookie:mmm_cnt_dlp_007_880_m /ga_clientid:08c6ea17-9d84-4205-923c-22e859bb7bb5 /edat_dir:C:\Windows\Temp\asw.b759c86e0f3e647e'
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2664] CPU: Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz,4
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2669] OS: Windows 7 SP1 x86
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2672] setup: x86
Instup.exe
[2024-02-11 22:39:59.155] [info ] [instup ] [ 3964: 4000] [87A008:2686] Memory: 22% load. Phys:2453240/3145208K free, Page:4194303/4194303K free, Virt:1990360/2097024K free