URL:

https://downloaderto.com/enoe/youtube-4k-downloader

Full analysis: https://app.any.run/tasks/1da88442-1ca0-47e4-a757-c1b82190b0cb
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 02, 2026, 17:18:06
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
phishing
stealer
opera
tool
antivm
Indicators:
MD5:

336A6EA3881AE810BA3F40C955682D1D

SHA1:

D1134D13D192009EC439CAA4C4D93C9463A4657D

SHA256:

A34122E43CAD2E6664DE66B20B3323639B9BE553F06DFCAD8C18F092A2C40FE2

SSDEEP:

3:N8SEuXRTTP2HtoI8Xn:2SHmHyIG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • PHISHING has been detected (SURICATA)

      • msedge.exe (PID: 6020)
    • Actions looks like stealing of personal data

      • installer.exe (PID: 8176)
      • AVGBrowserInstaller.exe (PID: 5900)
      • opera_crashreporter.exe (PID: 2996)
      • opera.exe (PID: 7240)
      • opera_crashreporter.exe (PID: 7860)
      • opera_crashreporter.exe (PID: 848)
      • opera_crashreporter.exe (PID: 3020)
      • opera.exe (PID: 1136)
      • browser_assistant.exe (PID: 6200)
      • opera_crashreporter.exe (PID: 8964)
      • opera_crashreporter.exe (PID: 9232)
      • browser_assistant.exe (PID: 8124)
      • opera.exe (PID: 9996)
      • opera.exe (PID: 10224)
      • opera_autoupdate.exe (PID: 9888)
      • opera_autoupdate.exe (PID: 9072)
      • AVGBrowser.exe (PID: 3232)
      • AVGBrowser.exe (PID: 7612)
    • Steals credentials from Web Browsers

      • installer.exe (PID: 8176)
      • installer.exe (PID: 9088)
      • assistant_installer.exe (PID: 1316)
      • assistant_installer.exe (PID: 6724)
      • installer.exe (PID: 7052)
      • installer.exe (PID: 2328)
      • installer.exe (PID: 8060)
      • installer.exe (PID: 8396)
      • assistant_installer.exe (PID: 5780)
      • assistant_installer.exe (PID: 6696)
      • assistant_installer.exe (PID: 4516)
      • opera.exe (PID: 7904)
      • opera_crashreporter.exe (PID: 7860)
      • opera_crashreporter.exe (PID: 2996)
      • opera.exe (PID: 7240)
      • opera_crashreporter.exe (PID: 848)
      • opera.exe (PID: 8580)
      • opera.exe (PID: 7204)
      • opera_crashreporter.exe (PID: 3020)
      • opera.exe (PID: 1136)
      • opera_crashreporter.exe (PID: 8964)
      • browser_assistant.exe (PID: 6200)
      • opera.exe (PID: 6696)
      • assistant_installer.exe (PID: 3040)
      • opera_crashreporter.exe (PID: 9232)
      • opera.exe (PID: 1656)
      • browser_assistant.exe (PID: 8124)
      • opera_crashreporter.exe (PID: 10024)
      • opera.exe (PID: 9996)
      • opera.exe (PID: 10224)
      • installer.exe (PID: 5592)
      • installer.exe (PID: 8972)
      • opera_autoupdate.exe (PID: 9756)
      • opera_autoupdate.exe (PID: 8404)
      • opera_autoupdate.exe (PID: 9888)
      • opera_autoupdate.exe (PID: 9072)
    • Changes the autorun value in the registry

      • AVGBrowserUpdate.exe (PID: 6804)
      • assistant_installer.exe (PID: 3040)
      • opera.exe (PID: 7240)
      • opera.exe (PID: 9996)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
    • Uses Task Scheduler to run other applications

      • AVGBrowserInstaller.exe (PID: 5900)
  • SUSPICIOUS

    • Application launched itself

      • installer.exe (PID: 8176)
      • assistant_installer.exe (PID: 1316)
      • installer.exe (PID: 2328)
      • installer.exe (PID: 8396)
      • assistant_installer.exe (PID: 3040)
      • assistant_installer.exe (PID: 4516)
      • browser_assistant.exe (PID: 8124)
      • opera.exe (PID: 7240)
      • setup.exe (PID: 9200)
      • opera.exe (PID: 9996)
      • installer.exe (PID: 8972)
      • opera_autoupdate.exe (PID: 9756)
      • opera_autoupdate.exe (PID: 9072)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 10964)
      • setup.exe (PID: 8796)
      • AVGBrowser.exe (PID: 7612)
      • AVGBrowser.exe (PID: 7512)
    • Starts itself from another location

      • installer.exe (PID: 8176)
      • AVGBrowserUpdate.exe (PID: 6804)
      • assistant_installer.exe (PID: 3040)
    • The process verifies whether the antivirus software is installed

      • AVGBrowserInstaller.exe (PID: 5900)
    • Creates/Modifies COM task schedule object

      • AVGBrowserUpdateComRegisterShell64.exe (PID: 9032)
      • AVGBrowserUpdate.exe (PID: 7448)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 3988)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 8576)
      • AVGBrowserUpdate.exe (PID: 6804)
    • There is functionality for VM detection antiVM strings (YARA)

      • AVGBrowserInstaller.exe (PID: 5900)
    • There is functionality for VM detection VirtualBox (YARA)

      • AVGBrowserInstaller.exe (PID: 5900)
    • There is functionality for VM detection VMWare (YARA)

      • AVGBrowserInstaller.exe (PID: 5900)
    • Reads the date of Windows installation

      • installer.exe (PID: 8396)
      • opera.exe (PID: 9996)
      • setup.exe (PID: 8796)
      • AVGBrowser.exe (PID: 11228)
      • AVGBrowser.exe (PID: 1000)
    • Searches for installed software

      • installer.exe (PID: 8396)
      • setup.exe (PID: 9200)
      • AVGBrowserInstaller.exe (PID: 5900)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 7612)
    • Possible stealing from browsers

      • opera_crashreporter.exe (PID: 2996)
      • opera.exe (PID: 7240)
      • opera_crashreporter.exe (PID: 7860)
      • opera_crashreporter.exe (PID: 848)
      • opera_crashreporter.exe (PID: 3020)
      • browser_assistant.exe (PID: 6200)
      • opera_crashreporter.exe (PID: 8964)
      • opera_crashreporter.exe (PID: 9232)
      • browser_assistant.exe (PID: 8124)
      • opera.exe (PID: 9996)
    • Reads Mozilla Firefox installation path

      • opera.exe (PID: 9996)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 7612)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 9756)
    • Reads the BIOS version

      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 7612)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 7284)
    • Drops script file

      • msedge.exe (PID: 7284)
      • msedge.exe (PID: 5516)
      • AVGBrowserInstaller.exe (PID: 5900)
      • installer.exe (PID: 2328)
      • installer.exe (PID: 8396)
      • opera.exe (PID: 7240)
      • opera.exe (PID: 9308)
      • opera.exe (PID: 9996)
      • opera.exe (PID: 9632)
      • opera.exe (PID: 8648)
      • opera.exe (PID: 9448)
      • AVGBrowser.exe (PID: 2328)
      • opera.exe (PID: 4212)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 10300)
      • AVGBrowser.exe (PID: 10288)
      • AVGBrowser.exe (PID: 10496)
      • AVGBrowser.exe (PID: 10416)
      • AVGBrowser.exe (PID: 10544)
      • AVGBrowser.exe (PID: 10856)
      • AVGBrowser.exe (PID: 11200)
      • AVGBrowser.exe (PID: 11208)
      • AVGBrowser.exe (PID: 11116)
      • AVGBrowser.exe (PID: 10988)
      • AVGBrowser.exe (PID: 7612)
    • Checks supported languages

      • identity_helper.exe (PID: 8780)
      • OperaSetup.exe (PID: 876)
      • installer.exe (PID: 8176)
      • installer.exe (PID: 9088)
      • installer.exe (PID: 6952)
      • Assistant_127.0.5778.14_Setup.exe_sfx.exe (PID: 5780)
      • assistant_installer.exe (PID: 6724)
      • avg_secure_browser_setup.exe (PID: 8916)
      • AVGBrowserInstaller.exe (PID: 5900)
      • installer.exe (PID: 2328)
      • installer.exe (PID: 7052)
      • AVGBrowserUpdateSetup.exe (PID: 3976)
      • AVGBrowserUpdate.exe (PID: 6804)
      • AVGBrowserUpdate.exe (PID: 7448)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 9032)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 3988)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 8576)
      • AVGBrowserUpdate.exe (PID: 7452)
      • AVGBrowserUpdate.exe (PID: 1092)
      • AVGBrowserUpdate.exe (PID: 4116)
      • installer.exe (PID: 8060)
      • installer.exe (PID: 8396)
      • assistant_installer.exe (PID: 3040)
      • assistant_installer.exe (PID: 4516)
      • assistant_installer.exe (PID: 6696)
      • opera.exe (PID: 7240)
      • browser_assistant.exe (PID: 8124)
      • opera.exe (PID: 7904)
      • AVGBrowserInstaller.exe (PID: 4816)
      • opera_crashreporter.exe (PID: 2996)
      • opera_crashreporter.exe (PID: 7860)
      • browser_assistant.exe (PID: 6200)
      • opera.exe (PID: 8580)
      • assistant_installer.exe (PID: 1316)
      • opera_crashreporter.exe (PID: 848)
      • opera.exe (PID: 7204)
      • opera.exe (PID: 7452)
      • opera_crashreporter.exe (PID: 3020)
      • opera.exe (PID: 1136)
      • opera.exe (PID: 6444)
      • opera.exe (PID: 6696)
      • opera.exe (PID: 4940)
      • opera.exe (PID: 5108)
      • opera.exe (PID: 6212)
      • setup.exe (PID: 9200)
      • opera_crashreporter.exe (PID: 8964)
      • opera.exe (PID: 1656)
      • setup.exe (PID: 224)
      • opera_crashreporter.exe (PID: 9232)
      • assistant_installer.exe (PID: 5780)
      • opera.exe (PID: 9264)
      • opera.exe (PID: 9308)
      • opera.exe (PID: 9848)
      • opera.exe (PID: 9860)
      • opera_crashreporter.exe (PID: 10024)
      • opera.exe (PID: 9996)
      • opera.exe (PID: 10224)
      • opera.exe (PID: 10212)
      • opera.exe (PID: 9348)
      • opera.exe (PID: 2976)
      • opera.exe (PID: 9608)
      • opera.exe (PID: 9596)
      • opera.exe (PID: 9420)
      • opera.exe (PID: 5872)
      • opera.exe (PID: 9588)
      • opera.exe (PID: 9632)
      • opera.exe (PID: 9624)
      • opera.exe (PID: 3120)
      • opera_gx_splash.exe (PID: 2684)
      • opera.exe (PID: 9372)
      • opera.exe (PID: 9384)
      • opera.exe (PID: 9032)
      • opera.exe (PID: 9980)
      • opera.exe (PID: 8720)
      • opera.exe (PID: 6332)
      • opera.exe (PID: 8580)
      • opera.exe (PID: 10136)
      • opera.exe (PID: 5796)
      • opera.exe (PID: 7036)
      • opera.exe (PID: 6440)
      • opera.exe (PID: 4044)
      • opera.exe (PID: 9072)
      • opera.exe (PID: 7232)
      • opera.exe (PID: 7628)
      • opera.exe (PID: 3192)
      • opera.exe (PID: 796)
      • opera.exe (PID: 8408)
      • opera.exe (PID: 8064)
      • opera.exe (PID: 7584)
      • opera.exe (PID: 7236)
      • opera.exe (PID: 4352)
      • opera.exe (PID: 4280)
      • opera.exe (PID: 5080)
      • opera.exe (PID: 6396)
      • opera.exe (PID: 8944)
      • opera.exe (PID: 9040)
      • opera.exe (PID: 1760)
      • opera.exe (PID: 4796)
      • opera.exe (PID: 4364)
      • installer.exe (PID: 8972)
      • opera.exe (PID: 9368)
      • opera.exe (PID: 3092)
      • installer.exe (PID: 5592)
      • opera_autoupdate.exe (PID: 9756)
      • opera_autoupdate.exe (PID: 8404)
      • opera_autoupdate.exe (PID: 9072)
      • opera_autoupdate.exe (PID: 9888)
      • opera.exe (PID: 9448)
      • opera.exe (PID: 2748)
      • opera.exe (PID: 9744)
      • opera.exe (PID: 9732)
      • opera.exe (PID: 4044)
      • opera.exe (PID: 9804)
      • opera.exe (PID: 7004)
      • AVGBrowserCrashHandler.exe (PID: 8016)
      • AVGBrowserCrashHandler64.exe (PID: 7672)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 9896)
      • opera.exe (PID: 9632)
      • opera.exe (PID: 8320)
      • opera.exe (PID: 7220)
      • opera.exe (PID: 3120)
      • opera.exe (PID: 9588)
      • opera.exe (PID: 6056)
      • opera.exe (PID: 8648)
      • opera.exe (PID: 9448)
      • opera.exe (PID: 4212)
      • opera.exe (PID: 9244)
      • opera.exe (PID: 6584)
      • opera.exe (PID: 5868)
      • opera.exe (PID: 9368)
      • opera.exe (PID: 6232)
      • AVGBrowser.exe (PID: 5732)
      • AVGBrowser.exe (PID: 5872)
      • opera.exe (PID: 7672)
      • AVGBrowser.exe (PID: 5716)
      • AVGBrowser.exe (PID: 3232)
      • AVGBrowser.exe (PID: 9252)
      • AVGBrowser.exe (PID: 6628)
      • AVGBrowser.exe (PID: 2348)
      • AVGBrowser.exe (PID: 5732)
      • AVGBrowser.exe (PID: 9440)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 7208)
      • AVGBrowser.exe (PID: 3232)
      • AVGBrowser.exe (PID: 7288)
      • AVGBrowser.exe (PID: 10280)
      • AVGBrowser.exe (PID: 7288)
      • AVGBrowser.exe (PID: 9256)
      • AVGBrowser.exe (PID: 3120)
      • AVGBrowser.exe (PID: 10288)
      • AVGBrowser.exe (PID: 10408)
      • AVGBrowser.exe (PID: 10300)
      • AVGBrowser.exe (PID: 10416)
      • AVGBrowser.exe (PID: 10496)
      • AVGBrowser.exe (PID: 752)
      • AVGBrowser.exe (PID: 10552)
      • AVGBrowser.exe (PID: 10544)
      • installer.exe (PID: 10560)
      • AVGBrowser.exe (PID: 10628)
      • AVGBrowser.exe (PID: 10848)
      • AVGBrowser.exe (PID: 10768)
      • AVGBrowser.exe (PID: 10804)
      • AVGBrowser.exe (PID: 10856)
      • AVGBrowser.exe (PID: 10904)
      • AVGBrowser.exe (PID: 10652)
      • AVGBrowser.exe (PID: 11028)
      • AVGBrowser.exe (PID: 11036)
      • AVGBrowser.exe (PID: 11200)
      • AVGBrowser.exe (PID: 11124)
      • AVGBrowser.exe (PID: 11208)
      • AVGBrowser.exe (PID: 10260)
      • AVGBrowser.exe (PID: 10400)
      • AVGBrowser.exe (PID: 10988)
      • AVGBrowser.exe (PID: 11116)
      • AVGBrowser.exe (PID: 10556)
      • AVGBrowser.exe (PID: 10804)
      • AVGBrowser.exe (PID: 10780)
      • AVGBrowser.exe (PID: 10948)
      • AVGBrowser.exe (PID: 10312)
      • AVGBrowser.exe (PID: 10472)
      • AVGBrowser.exe (PID: 9200)
      • AVGBrowser.exe (PID: 11120)
      • AVGBrowser.exe (PID: 9780)
      • AVGBrowser.exe (PID: 10976)
      • AVGBrowser.exe (PID: 10892)
      • AVGBrowser.exe (PID: 11064)
      • AVGBrowser.exe (PID: 10956)
      • AVGBrowser.exe (PID: 10964)
      • AVGBrowser.exe (PID: 8580)
      • setup.exe (PID: 8796)
      • setup.exe (PID: 10388)
      • AVGBrowserProtect.exe (PID: 10288)
      • AVGBrowser.exe (PID: 9776)
      • AVGBrowser.exe (PID: 7612)
      • AVGBrowser.exe (PID: 11228)
      • AVGBrowser.exe (PID: 10868)
      • AVGBrowser.exe (PID: 10668)
      • AVGBrowser.exe (PID: 10700)
      • AVGBrowser.exe (PID: 10528)
      • AVGBrowser.exe (PID: 10496)
      • AVGBrowser.exe (PID: 10504)
      • AVGBrowser.exe (PID: 10264)
      • AVGBrowser.exe (PID: 11132)
      • AVGBrowser.exe (PID: 11064)
      • AVGBrowser.exe (PID: 11168)
      • AVGBrowser.exe (PID: 11160)
      • AVGBrowser.exe (PID: 10692)
      • AVGBrowser.exe (PID: 11136)
      • AVGBrowser.exe (PID: 2796)
      • AVGBrowser.exe (PID: 9636)
      • AVGBrowser.exe (PID: 1000)
      • AVGBrowser.exe (PID: 7076)
      • AVGBrowser.exe (PID: 10892)
      • AVGBrowser.exe (PID: 12248)
      • AVGBrowser.exe (PID: 11576)
      • AVGBrowser.exe (PID: 9836)
      • AVGBrowser.exe (PID: 7512)
      • AVGBrowser.exe (PID: 9636)
      • AVGBrowser.exe (PID: 11468)
      • AVGBrowser.exe (PID: 12276)
      • AVGBrowser.exe (PID: 12256)
    • Reads Environment values

      • identity_helper.exe (PID: 8780)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 7612)
    • Reads the computer name

      • identity_helper.exe (PID: 8780)
      • installer.exe (PID: 8176)
      • assistant_installer.exe (PID: 1316)
      • installer.exe (PID: 2328)
      • AVGBrowserInstaller.exe (PID: 5900)
      • AVGBrowserUpdate.exe (PID: 6804)
      • AVGBrowserUpdate.exe (PID: 7448)
      • AVGBrowserUpdate.exe (PID: 1092)
      • AVGBrowserUpdate.exe (PID: 7452)
      • AVGBrowserUpdate.exe (PID: 4116)
      • installer.exe (PID: 8396)
      • assistant_installer.exe (PID: 3040)
      • assistant_installer.exe (PID: 4516)
      • opera.exe (PID: 7904)
      • opera.exe (PID: 7240)
      • AVGBrowserInstaller.exe (PID: 4816)
      • browser_assistant.exe (PID: 8124)
      • opera.exe (PID: 8580)
      • opera.exe (PID: 7204)
      • opera.exe (PID: 7452)
      • opera.exe (PID: 1136)
      • opera.exe (PID: 6696)
      • setup.exe (PID: 9200)
      • opera.exe (PID: 1656)
      • opera.exe (PID: 9264)
      • opera.exe (PID: 9996)
      • opera.exe (PID: 10212)
      • opera.exe (PID: 10224)
      • opera_gx_splash.exe (PID: 2684)
      • opera.exe (PID: 6332)
      • installer.exe (PID: 8972)
      • opera_autoupdate.exe (PID: 9756)
      • opera_autoupdate.exe (PID: 9072)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 9780)
      • AVGBrowser.exe (PID: 5732)
      • AVGBrowser.exe (PID: 3232)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 9440)
      • AVGBrowser.exe (PID: 752)
      • AVGBrowser.exe (PID: 10964)
      • setup.exe (PID: 8796)
      • AVGBrowser.exe (PID: 11228)
      • AVGBrowserProtect.exe (PID: 10288)
      • AVGBrowser.exe (PID: 9776)
      • AVGBrowser.exe (PID: 7612)
      • AVGBrowser.exe (PID: 10868)
      • AVGBrowser.exe (PID: 10504)
      • AVGBrowser.exe (PID: 1000)
      • AVGBrowser.exe (PID: 9836)
      • AVGBrowser.exe (PID: 7512)
      • AVGBrowser.exe (PID: 12256)
      • AVGBrowser.exe (PID: 12248)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 7284)
    • Create files in a temporary directory

      • OperaSetup.exe (PID: 876)
      • installer.exe (PID: 8176)
      • Assistant_127.0.5778.14_Setup.exe_sfx.exe (PID: 5780)
      • avg_secure_browser_setup.exe (PID: 8916)
      • AVGBrowserInstaller.exe (PID: 5900)
      • AVGBrowserUpdateSetup.exe (PID: 3976)
      • AVGBrowserUpdate.exe (PID: 4116)
      • installer.exe (PID: 8396)
      • installer.exe (PID: 8060)
      • opera.exe (PID: 7240)
      • opera.exe (PID: 9996)
      • installer.exe (PID: 8972)
      • installer.exe (PID: 5592)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
      • opera_autoupdate.exe (PID: 9756)
      • installer.exe (PID: 10560)
      • AVGBrowser.exe (PID: 7612)
    • Creates files or folders in the user directory

      • installer.exe (PID: 9088)
      • installer.exe (PID: 8176)
      • installer.exe (PID: 2328)
      • AVGBrowserUpdate.exe (PID: 6804)
      • AVGBrowserUpdate.exe (PID: 4116)
      • installer.exe (PID: 8396)
      • AVGBrowserInstaller.exe (PID: 4816)
      • opera.exe (PID: 7240)
      • opera.exe (PID: 1136)
      • assistant_installer.exe (PID: 3040)
      • setup.exe (PID: 224)
      • setup.exe (PID: 9200)
      • browser_assistant.exe (PID: 8124)
      • opera.exe (PID: 9996)
      • opera.exe (PID: 10224)
      • opera_autoupdate.exe (PID: 9072)
      • opera_autoupdate.exe (PID: 9888)
      • AVGBrowserInstaller.exe (PID: 5900)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 5732)
      • AVGBrowser.exe (PID: 3232)
      • AVGBrowser.exe (PID: 9440)
      • AVGBrowser.exe (PID: 3628)
      • opera_autoupdate.exe (PID: 9756)
      • AVGBrowser.exe (PID: 11120)
      • AVGBrowser.exe (PID: 10964)
      • AVGBrowser.exe (PID: 9776)
      • setup.exe (PID: 8796)
      • AVGBrowser.exe (PID: 7612)
      • AVGBrowser.exe (PID: 10504)
      • AVGBrowser.exe (PID: 7512)
    • Checks proxy server information

      • installer.exe (PID: 8176)
      • AVGBrowserInstaller.exe (PID: 5900)
      • AVGBrowserUpdate.exe (PID: 7452)
      • AVGBrowserUpdate.exe (PID: 4116)
      • opera.exe (PID: 7240)
      • opera.exe (PID: 9996)
      • browser_assistant.exe (PID: 8124)
      • slui.exe (PID: 9080)
      • opera_autoupdate.exe (PID: 9072)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
      • opera_autoupdate.exe (PID: 9756)
      • AVGBrowserProtect.exe (PID: 10288)
      • AVGBrowser.exe (PID: 7612)
    • Reads security settings of Internet Explorer

      • installer.exe (PID: 8176)
      • AVGBrowserInstaller.exe (PID: 5900)
      • AVGBrowserUpdate.exe (PID: 6804)
      • installer.exe (PID: 8396)
      • browser_assistant.exe (PID: 8124)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowserProtect.exe (PID: 10288)
      • setup.exe (PID: 8796)
      • AVGBrowser.exe (PID: 11228)
      • AVGBrowser.exe (PID: 7612)
    • There is functionality for taking screenshot (YARA)

      • installer.exe (PID: 8176)
      • installer.exe (PID: 9088)
      • avg_secure_browser_setup.exe (PID: 8916)
      • AVGBrowserInstaller.exe (PID: 5900)
    • Reads the machine GUID from the registry

      • installer.exe (PID: 8176)
      • AVGBrowserInstaller.exe (PID: 5900)
      • AVGBrowserUpdate.exe (PID: 6804)
      • AVGBrowserUpdate.exe (PID: 4116)
      • installer.exe (PID: 8396)
      • opera.exe (PID: 7240)
      • browser_assistant.exe (PID: 8124)
      • opera.exe (PID: 9996)
      • opera_autoupdate.exe (PID: 9756)
      • opera_autoupdate.exe (PID: 8404)
      • opera_autoupdate.exe (PID: 9072)
      • opera_autoupdate.exe (PID: 9888)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 7612)
    • Process checks computer location settings

      • AVGBrowserInstaller.exe (PID: 5900)
      • AVGBrowserUpdate.exe (PID: 6804)
      • opera.exe (PID: 7240)
      • opera.exe (PID: 4940)
      • opera.exe (PID: 5108)
      • opera.exe (PID: 9348)
      • opera.exe (PID: 9848)
      • opera.exe (PID: 9996)
      • opera.exe (PID: 3120)
      • opera.exe (PID: 9372)
      • opera.exe (PID: 9384)
      • opera.exe (PID: 9032)
      • opera.exe (PID: 8720)
      • opera.exe (PID: 9980)
      • opera.exe (PID: 8944)
      • opera.exe (PID: 5080)
      • opera.exe (PID: 1760)
      • opera.exe (PID: 4364)
      • opera.exe (PID: 7004)
      • opera.exe (PID: 9244)
      • opera.exe (PID: 7672)
      • opera.exe (PID: 9368)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 5716)
      • AVGBrowser.exe (PID: 6628)
      • AVGBrowser.exe (PID: 9252)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 7208)
      • AVGBrowser.exe (PID: 10652)
      • AVGBrowser.exe (PID: 10628)
      • AVGBrowser.exe (PID: 10260)
      • AVGBrowser.exe (PID: 10556)
      • AVGBrowser.exe (PID: 10780)
      • AVGBrowser.exe (PID: 10804)
      • AVGBrowser.exe (PID: 10948)
      • AVGBrowser.exe (PID: 10400)
      • AVGBrowser.exe (PID: 11064)
      • AVGBrowser.exe (PID: 10976)
      • AVGBrowser.exe (PID: 10956)
      • AVGBrowser.exe (PID: 7612)
      • AVGBrowser.exe (PID: 11228)
      • AVGBrowser.exe (PID: 10700)
      • AVGBrowser.exe (PID: 10668)
      • AVGBrowser.exe (PID: 11168)
      • AVGBrowser.exe (PID: 10692)
      • AVGBrowser.exe (PID: 10528)
      • AVGBrowser.exe (PID: 11132)
      • AVGBrowser.exe (PID: 11160)
      • AVGBrowser.exe (PID: 10496)
      • AVGBrowser.exe (PID: 11136)
      • AVGBrowser.exe (PID: 2796)
      • AVGBrowser.exe (PID: 1000)
      • AVGBrowser.exe (PID: 11064)
      • AVGBrowser.exe (PID: 7076)
      • AVGBrowser.exe (PID: 10892)
    • Process checks whether UAC notifications are on

      • AVGBrowserInstaller.exe (PID: 5900)
    • Launching a file from a Registry key

      • AVGBrowserUpdate.exe (PID: 6804)
      • assistant_installer.exe (PID: 3040)
      • opera.exe (PID: 7240)
      • opera.exe (PID: 9996)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 2328)
    • Creates a software uninstall entry

      • installer.exe (PID: 8396)
      • setup.exe (PID: 9200)
      • AVGBrowserInstaller.exe (PID: 5900)
      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 7612)
    • OPERA mutex has been found

      • opera.exe (PID: 7240)
      • browser_assistant.exe (PID: 8124)
      • opera.exe (PID: 9996)
      • opera_autoupdate.exe (PID: 9072)
      • opera_autoupdate.exe (PID: 9756)
    • Reads CPU info

      • AVGBrowser.exe (PID: 2328)
      • AVGBrowser.exe (PID: 3628)
      • AVGBrowser.exe (PID: 7612)
    • Launching a file from Task Scheduler

      • AVGBrowserInstaller.exe (PID: 5900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
452
Monitored processes
296
Malicious processes
35
Suspicious processes
14

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs #PHISHING msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs operasetup.exe no specs installer.exe installer.exe installer.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs assistant_127.0.5778.14_setup.exe_sfx.exe no specs assistant_installer.exe assistant_installer.exe slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs avg_secure_browser_setup.exe no specs avgbrowserinstaller.exe installer.exe installer.exe avgbrowserupdatesetup.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe msedge.exe no specs installer.exe installer.exe UIAutomationCrossBitnessHook32 Class no specs assistant_installer.exe assistant_installer.exe assistant_installer.exe assistant_installer.exe browser_assistant.exe opera.exe opera.exe avgbrowserinstaller.exe no specs opera_crashreporter.exe opera_crashreporter.exe browser_assistant.exe opera.exe msedge.exe no specs opera_crashreporter.exe opera.exe opera.exe no specs opera.exe opera_crashreporter.exe opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs setup.exe no specs opera_crashreporter.exe opera.exe setup.exe no specs opera_crashreporter.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe opera_crashreporter.exe opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_gx_splash.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs installer.exe opera.exe no specs opera.exe no specs installer.exe opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs avgbrowsercrashhandler.exe no specs avgbrowsercrashhandler64.exe no specs avgbrowser.exe avgbrowser.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs msedge.exe no specs msedge.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs msedge.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs installer.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs msedge.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowserprotect.exe setup.exe no specs setup.exe no specs avgbrowser.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs avgbrowser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
224C:\Users\admin\AppData\Local\AVG\Browser\Update\Install\{0F378ABD-3109-4172-A117-A0681389213C}\CR_61932.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\AVG\Browser\User Data\Crashpad" --url=fake_url --annotation=plat=Win64 --annotation=prod=AVG --annotation=ver=144.0.33853.133 --attachment=C:\Users\admin\AppData\Local\Temp\AVGBrowser_installer.log --initial-client-data=0x27c,0x280,0x284,0x258,0x288,0x7ff7fca1d958,0x7ff7fca1d964,0x7ff7fca1d970C:\Users\admin\AppData\Local\AVG\Browser\Update\Install\{0F378ABD-3109-4172-A117-A0681389213C}\CR_61932.tmp\setup.exesetup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Secure Browser Installer
Exit code:
0
Version:
144.0.33853.133
Modules
Images
c:\users\admin\appdata\local\avg\browser\update\install\{0f378abd-3109-4172-a117-a0681389213c}\cr_61932.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
492"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=44 --always-read-main-dll --field-trial-handle=9132,i,7310179478514384812,17411150116666942294,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7636 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
684"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=18 --always-read-main-dll --field-trial-handle=5420,i,7310179478514384812,17411150116666942294,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6368 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
684"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6212,i,7310179478514384812,17411150116666942294,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=8996 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
752"C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exe" --type=gpu-process --force-high-res-timeticks=disabled --gpu-preferences=SAAAAAAAAADgAAAEAAAAAAAAAAAAAGAAAQAAAAAAAAAAAAAAAAAAAAIAAAAAAAAAAAAAAAAAAAAQAAAAAAAAABAAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --metrics-shmem-handle=1988,i,1518425205680299924,58233169734054467,262144 --field-trial-handle=2096,i,9010192008847560136,2451452575593756180,262144 --variations-seed-version --trace-process-track-uuid=3190708988185955192 --mojo-platform-channel-handle=2092 /prefetch:2C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
AVG Secure Browser
Exit code:
0
Version:
144.0.33853.133
Modules
Images
c:\users\admin\appdata\local\avg\browser\application\avgbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\avg\browser\application\144.0.33853.133\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
796"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-dropdown-keyword-ads=on --with-feature:address-bar-intent=on --with-feature:address-bar-intent-competitors=on --with-feature:address-bar-intent-internal-matching=on --with-feature:address-bar-intent-server-switch=on --with-feature:ai-tab-management=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amp-requests-stats=on --with-feature:audio-analysis=on --with-feature:bluesky-in-sidebar=on --with-feature:cashback-assistant=on --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:discord-in-sidebar=on --with-feature:domain-suggestions-with-misspells=on --with-feature:early-bird=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:native-crypto-wallet=on --with-feature:opera-one-unskippable-introduction=on --with-feature:opera-startpage-special-2=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=off --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:slack-in-sidebar=on --with-feature:specific-keywords=on --with-feature:startpage-content=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner=on --with-feature:translator=on --with-feature:vpn-pro-v4-support=on --metrics-shmem-handle=8320,i,8117681903458100261,6563320182471556125,524288 --field-trial-handle=1576,i,12185686412329042090,2655181712989065780,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709017234252511 --mojo-platform-channel-handle=8380 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
127.0.5778.76
Modules
Images
c:\users\admin\appdata\local\programs\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera\127.0.5778.76\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
848C:\Users\admin\AppData\Local\Programs\Opera\127.0.5778.76\opera_crashreporter.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=127.0.5778.76 --initial-client-data=0x298,0x29c,0x2a0,0x294,0x2a4,0x7ffd475f8490,0x7ffd475f84a0,0x7ffd475f84b0C:\Users\admin\AppData\Local\Programs\Opera\127.0.5778.76\opera_crashreporter.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera crash-reporter
Exit code:
0
Version:
127.0.5778.76
Modules
Images
c:\users\admin\appdata\local\programs\opera\127.0.5778.76\opera_crashreporter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
876"C:\Users\admin\Downloads\OperaSetup.exe" C:\Users\admin\Downloads\OperaSetup.exemsedge.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Opera installer SFX
Exit code:
0
Version:
128.0.5807.25
Modules
Images
c:\users\admin\downloads\operasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
936"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=20 --always-read-main-dll --field-trial-handle=6836,i,7310179478514384812,17411150116666942294,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5480 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1000"C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exe" --type=shortcut-pin-helper /prefetch:8 has-startpin "C:\Users\admin\Desktop\AVG Secure Browser.lnk"C:\Users\admin\AppData\Local\AVG\Browser\Application\AVGBrowser.exeAVGBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
AVG Secure Browser
Exit code:
0
Version:
144.0.33853.133
Modules
Images
c:\users\admin\appdata\local\avg\browser\application\avgbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\avg\browser\application\144.0.33853.133\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
50 265
Read events
48 486
Write events
1 693
Delete events
86

Modification events

(PID) Process:(8176) installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8176) installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8176) installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5900) AVGBrowserInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\AVG\Browser
Operation:writeName:user_id
Value:
ae303bae9b4b41aa8144b6c84a100d63
(PID) Process:(5900) AVGBrowserInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5900) AVGBrowserInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5900) AVGBrowserInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5900) AVGBrowserInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\AVG\Browser
Operation:writeName:user_timestamp
Value:
1772471977
(PID) Process:(2328) installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera\
(PID) Process:(5900) AVGBrowserInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\AVG\Browser
Operation:writeName:BankMode
Value:
1
Executable files
0
Suspicious files
73
Text files
327
Unknown types
4 213

Dropped files

PID
Process
Filename
Type
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1e5477.TMP
MD5:
SHA256:
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1e5486.TMP
MD5:
SHA256:
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1e5486.TMP
MD5:
SHA256:
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1e5496.TMP
MD5:
SHA256:
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1e5496.TMP
MD5:
SHA256:
7284msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
392
TCP/UDP connections
313
DNS requests
337
Threats
26

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6020
msedge.exe
OPTIONS
200
35.190.80.1:443
https://a.nel.cloudflare.com/report/v4?s=ltYJfa8gEnuI%2FBxRCo5FT5dpE7CnPTKrSm%2FQrla75wcTHUUrjMmaQu10XHEP9nJcNq%2Fp6CVx97G9ce%2FW43NxxguV%2B%2FK%2BqAAYxT9quMOdaR8%3D
unknown
unknown
6020
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
unknown
binary
4.47 Kb
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
unknown
whitelisted
6020
msedge.exe
GET
200
104.18.22.222:443
https://copilot.microsoft.com/c/api/user/eligibility
unknown
text
25 b
whitelisted
6020
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
unknown
binary
446 b
whitelisted
6020
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:UtL7i2ndJzXEJcqQpW1NH3FI_s6TnUTZUt4F9n3lmNs&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
6020
msedge.exe
GET
200
104.21.43.103:443
https://downloaderto.com/enoe/youtube-4k-downloader
unknown
binary
368 Kb
unknown
6020
msedge.exe
GET
200
104.21.43.103:443
https://downloaderto.com/cdn-cgi/trace
unknown
332 b
unknown
6020
msedge.exe
GET
404
104.21.43.103:443
https://downloaderto.com/ads.js
unknown
6.45 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7428
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
2.16.204.135:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7004
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
6020
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.16.204.135
  • 2.16.204.146
  • 2.16.204.160
  • 2.16.204.141
  • 2.16.204.136
  • 2.16.204.152
  • 2.16.204.138
  • 2.16.204.151
  • 2.16.204.155
  • 2.16.204.150
  • 2.16.204.148
  • 2.16.204.145
  • 2.16.204.149
  • 2.16.204.134
  • 2.16.204.143
  • 2.16.204.161
  • 2.16.204.153
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 142.250.187.238
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
downloaderto.com
  • 104.21.43.103
  • 172.67.178.33
unknown
api.edgeoffer.microsoft.com
  • 13.107.246.45
  • 13.107.213.45
whitelisted
copilot.microsoft.com
  • 104.18.22.222
  • 104.18.23.222
whitelisted

Threats

PID
Process
Class
Message
6020
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
6020
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
6020
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6020
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6020
msedge.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Suspected Phishing Domain (ey43 .com)
6020
msedge.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Suspected Phishing Domain (ey43 .com)
6020
msedge.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Suspected Phishing Domain (ey43 .com)
6020
msedge.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Suspected Phishing Domain (ey43 .com)
6020
msedge.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
6020
msedge.exe
Misc activity
ET INFO EXE - Served Attached HTTP
Process
Message
installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
assistant_installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
assistant_installer.exe
[0302/121857.217:INFO:opera\desktop\windows\assistant\installer\assistant_installer_main.cc:170] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\dad013f4-f925-4410-918d-72a1fe276888 Opera Installer Temp\opera_package_202603021218431\assistant\assistant_installer.exe" --version
AVGBrowserInstaller.exe
2026-03-02T12:19:35 [installer] {0000170c:000021b4} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:169) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AVGBrowserInstaller.exe
2026-03-02T12:19:35 [installer] {0000170c:000021b4} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:171) build date: Jan 31 2026 build number: 1750 build time: 23:10:14 build timestamp: Jan 31 2026 23:10:14 company: Gen Digital Inc. copyright: (C) 2017-2026 Gen Digital Inc. description: Secure Browser Installer file name: AVGBrowserInstaller.exe file version: 9.3.3.1750 git commit: 63f56e383138a02d9c3807eb40da8f48b5e98ad1 internal name: jinx-installer product name: Secure Browser Installer product version: 9.3.3.1750 target system: windows
AVGBrowserInstaller.exe
2026-03-02T12:19:35 [installer] {0000170c:000021b4} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:167) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AVGBrowserInstaller.exe
2026-03-02T12:19:35 [installer] {0000170c:000021b4} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:168) Jinx logging started
AVGBrowserInstaller.exe
2026-03-02T12:19:35 [installer] {0000170c:000021b4} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:181) Operating system: Windows Enterprise x64 10.0.19045.4046 SP0
AVGBrowserInstaller.exe
2026-03-02T12:19:35 [installer] {0000170c:000021b4} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:184) Process is not elevated.
AVGBrowserInstaller.exe
2026-03-02T12:19:35 [installer] {0000170c:000021b4} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:190) Process owner: DESKTOP-JGLLJLD\admin (logon=true, admin=true)