| File name: | Microstub.exe |
| Full analysis: | https://app.any.run/tasks/c14a93a0-2d77-4ea3-8eeb-c71e80b6876e |
| Verdict: | Malicious activity |
| Analysis date: | December 20, 2023, 11:58:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 0CCDF8EDAF3A0FB11856FEE1690E2957 |
| SHA1: | ECCB8847CA5B42E9EA85B3EB96141899D47856E8 |
| SHA256: | A90757A87FFA192188C71D2AAEB7CC2D7758E7BAAEE7E1344D33A6C257884F10 |
| SSDEEP: | 3072:MhrEcYTuZF3sDmYFDL56DLiSNMWm5RC3Oy1jjHfJWcCAnzuVmoP7wxi6yd+gf8+A:UYTuZFuB66SBRHJWcPz8/JrL9+9 |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:04:12 10:36:29+02:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 137216 |
| InitializedDataSize: | 89088 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1020 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.1.99.0 |
| ProductVersionNumber: | 2.1.99.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | AVG Technologies CZ, s.r.o. |
| Edition: | 15 |
| FileDescription: | AVG Installer |
| FileVersion: | 2.1.99.0 |
| InternalName: | microstub |
| LegalCopyright: | Copyright (C) 2023 AVG Technologies CZ, s.r.o. |
| OriginalFileName: | microstub.exe |
| ProductName: | AVG |
| ProductVersion: | 2.1.99.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\Microstub.exe" | C:\Users\admin\AppData\Local\Temp\Microstub.exe | — | explorer.exe | |||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: MEDIUM Description: AVG Installer Exit code: 3221226540 Version: 2.1.99.0 Modules
| |||||||||||||||
| 1044 | "C:\Windows\Temp\asw.e3622f9737cc4f66\avg_antivirus_free_online_setup.exe" /ga_clientid:236e9bfa-818a-48f5-a012-b4727845d2e2 /edat_dir:C:\Windows\Temp\asw.e3622f9737cc4f66 | C:\Windows\Temp\asw.e3622f9737cc4f66\avg_antivirus_free_online_setup.exe | Microstub.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Self-Extract Package Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1748 | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\avg-av-vps\icarus.exe /track-guid:236e9bfa-818a-48f5-a012-b4727845d2e2 /edat_dir:C:\Windows\Temp\asw.e3622f9737cc4f66 /sssid:1044 /er_master:master_ep_9baada18-4d08-4054-b5fc-4813aec99912 /er_ui:ui_ep_bae00da9-05aa-4eb7-a9aa-bddf2a93a577 /er_slave:avg-av-vps_slave_ep_a2361223-798d-4172-a3c4-5bdc2b9d0ded /slave:avg-av-vps | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\avg-av-vps\icarus.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1840 | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\icarus.exe /icarus-info-path:C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\icarus-info.xml /install /track-guid:236e9bfa-818a-48f5-a012-b4727845d2e2 /edat_dir:C:\Windows\Temp\asw.e3622f9737cc4f66 /sssid:1044 | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\icarus.exe | avg_antivirus_free_online_setup.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1904 | "C:\Users\Public\Documents\aswOfferTool.exe" -checkChromeReactivation -bc=AWFA | C:\Users\Public\Documents\aswOfferTool.exe | — | aswOfferTool.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: MEDIUM Description: AVG Offer Installation Tool Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1936 | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\icarus_ui.exe /track-guid:236e9bfa-818a-48f5-a012-b4727845d2e2 /edat_dir:C:\Windows\Temp\asw.e3622f9737cc4f66 /sssid:1044 /er_master:master_ep_9baada18-4d08-4054-b5fc-4813aec99912 /er_ui:ui_ep_bae00da9-05aa-4eb7-a9aa-bddf2a93a577 | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\icarus_ui.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG UI Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 2096 | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\avg-av\icarus.exe /track-guid:236e9bfa-818a-48f5-a012-b4727845d2e2 /edat_dir:C:\Windows\Temp\asw.e3622f9737cc4f66 /sssid:1044 /er_master:master_ep_9baada18-4d08-4054-b5fc-4813aec99912 /er_ui:ui_ep_bae00da9-05aa-4eb7-a9aa-bddf2a93a577 /er_slave:avg-av_slave_ep_093b8b51-4796-492a-ac8b-da30f56e51f3 /slave:avg-av | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\avg-av\icarus.exe | icarus.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 2420 | "C:\Users\admin\AppData\Local\Temp\Microstub.exe" | C:\Users\admin\AppData\Local\Temp\Microstub.exe | explorer.exe | ||||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 2.1.99.0 Modules
| |||||||||||||||
| 2580 | "C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\avg-av\aswOfferTool.exe" -checkChromeReactivation -elevated -bc=AWFA | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\avg-av\aswOfferTool.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Offer Installation Tool Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| (PID) Process: | (2420) Microstub.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Windows\Temp\asw.e3622f9737cc4f66 | |||
| (PID) Process: | (2420) Microstub.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1044) avg_antivirus_free_online_setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2096) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 144807F0-DE37-4C62-9C05-EB4CC64A7A2F |
Value: 29cbdeb3-95b4-4827-b366-31f436c7f583 | |||
| (PID) Process: | (2096) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 56C7A9DA-4B11-406A-8B1A-EFF157C294D6 |
Value: 29cbdeb3-95b4-4827-b366-31f436c7f583 | |||
| (PID) Process: | (1748) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 144807F0-DE37-4C62-9C05-EB4CC64A7A2F |
Value: 29cbdeb3-95b4-4827-b366-31f436c7f583 | |||
| (PID) Process: | (1748) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 56C7A9DA-4B11-406A-8B1A-EFF157C294D6 |
Value: 29cbdeb3-95b4-4827-b366-31f436c7f583 | |||
| (PID) Process: | (1748) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 5FD38555-4B16-40AE-9A09-E2C969CB74AF |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
| (PID) Process: | (1748) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 7CCD586D-2ABC-42FF-A23B-3731F4F183D9 |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
| (PID) Process: | (2096) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 5FD38555-4B16-40AE-9A09-E2C969CB74AF |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1044 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\7e6205e1-8a8c-40ce-ba79-f9a3ae68b092 | binary | |
MD5:D354234E9230850AC1018529099B5C9C | SHA256:EFA35BE97D4C194659B5B1CE120E69F431D5B67B83F81B4140ABC14D8FDDAE3E | |||
| 1044 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\bug_report.exe | executable | |
MD5:9672D59B4F4FD4083FACDB53DDC4A83E | SHA256:A1A69486E716550834B0D28E07ED55412157B671B90AEE545EA57649F90AFBDA | |||
| 1044 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\icarus_mod.dll | executable | |
MD5:D82C7E7541B0FB4BCC07230A464110F3 | SHA256:787F09B46F996C1835532A9A0BD03D3D02BA200655F59D09067AEA164E581FF7 | |||
| 1044 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\product-info.xml | xml | |
MD5:65778E16CBB222FB0400EEA279677D6F | SHA256:BC682E7D273A49660BCCF8612807135D7AAD1E6B0682089E792287BB1795F273 | |||
| 1044 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\icarus_ui.exe | executable | |
MD5:FEF5E959190FDBA9365B3672B117D00F | SHA256:85A35C7B03857C3482526938DA2C912AF6092C251DDD7359973B373153EE6B65 | |||
| 1044 | avg_antivirus_free_online_setup.exe | C:\ProgramData\AVG\Icarus\Logs\sfx.log | text | |
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA | SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5 | |||
| 1044 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\6c5e95e1-c7a8-4980-8894-e77cce991670 | binary | |
MD5:5751F90923D39573F3847A28A6EE4EEE | SHA256:67C3B970F86558F3C769BCB301A89102616E19549DAFDA74E0EF201F023792BF | |||
| 1044 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\dump_process.exe | executable | |
MD5:8CC5F31FA26AD66EADCE8800FB44DD93 | SHA256:9CAA072C6DC0F31E5731FA8800BD8327CFBBF83373E6211583D21395C8AE842D | |||
| 1840 | icarus.exe | C:\ProgramData\AVG\Icarus\Logs\report.log | — | |
MD5:— | SHA256:— | |||
| 1044 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-d08e84d0-bc78-4575-b073-0dc7d76667a2\common\icarus.exe | executable | |
MD5:74304FACCD7A95FFF290B0A8AD15EE88 | SHA256:8639967DFE4310D2C942052A45E0C47D7AB4EF6A0EC245AA67DF3A01E81E07A9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2420 | Microstub.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | unknown |
2420 | Microstub.exe | POST | 200 | 216.239.38.178:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | unknown |
2420 | Microstub.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | unknown |
2420 | Microstub.exe | POST | 200 | 216.239.38.178:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2420 | Microstub.exe | 34.117.223.223:80 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2420 | Microstub.exe | 216.239.38.178:80 | www.google-analytics.com | GOOGLE | US | unknown |
2420 | Microstub.exe | 2.18.161.23:443 | honzik.avcdn.net | AKAMAI-AS | DE | unknown |
1044 | avg_antivirus_free_online_setup.exe | 34.117.223.223:443 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1044 | avg_antivirus_free_online_setup.exe | 2.18.161.23:443 | honzik.avcdn.net | AKAMAI-AS | DE | unknown |
1840 | icarus.exe | 34.117.223.223:443 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1840 | icarus.exe | 34.160.176.28:443 | shepherd.avcdn.net | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.google-analytics.com |
| whitelisted |
honzik.avcdn.net |
| unknown |
v7event.stats.avast.com |
| whitelisted |
analytics.avcdn.net |
| unknown |
shepherd.avcdn.net |
| whitelisted |