| File name: | avg_tuneup_online_setup.exe |
| Full analysis: | https://app.any.run/tasks/cf4704c4-02dd-49e3-a6e1-e5b30f16ad81 |
| Verdict: | Malicious activity |
| Analysis date: | November 06, 2023, 14:33:49 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BC164BD9F8E381FC74112B3C5FCABE17 |
| SHA1: | 8857A252964EC5A1E67644A7127FA8A3AAB470BD |
| SHA256: | B1D3A6F89D9BF1694148AA84ECCE4904F6EF8247963CA3FCB58D043B56C8F3D8 |
| SSDEEP: | 49152:ljhWnDfYCqVT3y/0N1prjCmNXrF6ETisbaNJ0FOzohYX2DISkzNvCkt:lEfYCGT3y/0NH5N7FfFbaNJ0FECIS |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:10:20 09:41:05+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit, Removable run from swap, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 14.36 |
| CodeSize: | 917504 |
| InitializedDataSize: | 485888 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4e070 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 23.7.6305.0 |
| ProductVersionNumber: | 23.3.15198.8344 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | AVG Technologies |
| FileDescription: | AVG Self-Extract Package |
| FileVersion: | 23.7.6305.0 |
| InternalName: | icarus_sfx |
| LegalCopyright: | Copyright © 2023 AVG Technologies |
| MainProductId: | avg-tu |
| OriginalFileName: | icarus_sfx.exe |
| ProductId: | avg-icarus |
| ProductName: | AVG Installer |
| ProductVersion: | 23.3.15198.8344 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3428 | "C:\Users\admin\AppData\Local\Temp\avg_tuneup_online_setup.exe" | C:\Users\admin\AppData\Local\Temp\avg_tuneup_online_setup.exe | — | explorer.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: MEDIUM Description: AVG Self-Extract Package Exit code: 3221226540 Version: 23.7.6305.0 Modules
| |||||||||||||||
| 3504 | "C:\Users\admin\AppData\Local\Temp\avg_tuneup_online_setup.exe" | C:\Users\admin\AppData\Local\Temp\avg_tuneup_online_setup.exe | explorer.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Self-Extract Package Exit code: 0 Version: 23.7.6305.0 Modules
| |||||||||||||||
| 3528 | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\icarus.exe /icarus-info-path:C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\icarus-info.xml /install /sssid:3504 | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\icarus.exe | avg_tuneup_online_setup.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.7.6305.0 Modules
| |||||||||||||||
| 3576 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3724 | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\avg-tu\icarus.exe /sssid:3504 /er_master:master_ep_8390e4cd-e4db-41d4-bea0-42c522672816 /er_ui:ui_ep_30920f92-ff02-4da3-8d71-4ff4fb1bbf3a /er_slave:avg-tu_slave_ep_39e330f3-8277-428f-8894-0fb2109e206d /slave:avg-tu | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\avg-tu\icarus.exe | icarus.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.7.6305.0 Modules
| |||||||||||||||
| 3756 | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\icarus_ui.exe /sssid:3504 /er_master:master_ep_8390e4cd-e4db-41d4-bea0-42c522672816 /er_ui:ui_ep_30920f92-ff02-4da3-8d71-4ff4fb1bbf3a | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\icarus_ui.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG UI Exit code: 0 Version: 23.7.6305.0 Modules
| |||||||||||||||
| (PID) Process: | (3504) avg_tuneup_online_setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3576) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{90D713E4-8FBB-4433-A838-EC00DF3EF1F2}\{05DCF10E-8BCB-419B-8EF0-F8AFEDEB8911} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3576) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{90D713E4-8FBB-4433-A838-EC00DF3EF1F2} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3576) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{60BAD3A4-18E3-4F55-BE83-12D9DF2F157A} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3724) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 144807F0-DE37-4C62-9C05-EB4CC64A7A2F |
Value: 12927a33-4426-43b8-aef4-5afbb5afc126 | |||
| (PID) Process: | (3724) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 56C7A9DA-4B11-406A-8B1A-EFF157C294D6 |
Value: 12927a33-4426-43b8-aef4-5afbb5afc126 | |||
| (PID) Process: | (3724) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 5FD38555-4B16-40AE-9A09-E2C969CB74AF |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
| (PID) Process: | (3724) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 7CCD586D-2ABC-42FF-A23B-3731F4F183D9 |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
| (PID) Process: | (3724) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | BootExecute |
Value: autocheck autochk * | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3504 | avg_tuneup_online_setup.exe | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\product-info.xml | xml | |
MD5:F4E747C3C570C2F2B505023AE7E83400 | SHA256:6E3DE9DC40FC3D5EBB909712BF61753D90ACCC1C1FF25057F1BCCC71FC58A36B | |||
| 3504 | avg_tuneup_online_setup.exe | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\5eac38bb-970e-46e2-bc62-0065d8a00ee2 | binary | |
MD5:756ADEADCE97C753037B6ED5F7F9AADD | SHA256:F7501070E9F867C9FE00CF852653FD520A37F4F80965313751774A4B2B788494 | |||
| 3504 | avg_tuneup_online_setup.exe | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\icarus.exe | executable | |
MD5:7150D43D236409877A0CB2E5C0965428 | SHA256:A1FB1BF840D417E6BAEAF525CE6F4C4C6ED5E6C669D7F5F35F5832C88C0FF431 | |||
| 3504 | avg_tuneup_online_setup.exe | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\0d26bb67-a942-488a-97a6-e4049c9d6654 | binary | |
MD5:A8FC819D883075896A8F4D9E62E5850F | SHA256:E0C612E0E76085A6865A6BCDE153944C1A41383006D8B782592E55C1597ABD7B | |||
| 3528 | icarus.exe | C:\ProgramData\AVG\Icarus\Logs\report.log | — | |
MD5:— | SHA256:— | |||
| 3504 | avg_tuneup_online_setup.exe | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\dump_process.exe | executable | |
MD5:4FF7C4B4DE78FA1E124F7B66050DE88B | SHA256:56E141BF1B0B391407FACDE06F52FF0D4C1CD80A803C4FCB5CB6B9CCB48C2985 | |||
| 3504 | avg_tuneup_online_setup.exe | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\icarus_ui.exe | executable | |
MD5:D0AB6C3CADE5D2E3864DF63DF5EFEF0D | SHA256:385F5DFB811CF2D91535B666A91682E0F6ED9115D730D541E5FA192074E46663 | |||
| 3504 | avg_tuneup_online_setup.exe | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\7072cc76-50fa-4df0-8264-0ad2e95b0999 | binary | |
MD5:05062FBF79AE0510033E9A6532451890 | SHA256:BC94701617CFE950ACF49C09B8CAA9F239403B148689DFFC2AE99059C7ED79F4 | |||
| 3504 | avg_tuneup_online_setup.exe | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\1739e2d9-b53b-4dc2-b7c3-4f564ef9e65d | binary | |
MD5:C4C6AC7D50303726DA416CBFE4E26448 | SHA256:E35285C9B583098CA4172AE03D9E3778562515D57EDF7D596DFDE2A858172E14 | |||
| 3504 | avg_tuneup_online_setup.exe | C:\Windows\Temp\asw-24a24b4e-fbe7-4a65-818e-a34a7f8db33e\common\bug_report.exe | executable | |
MD5:45DCB7F4548F14A67FC7679A434E7E85 | SHA256:D16D9AF6744EE37520157E8EFD31C93DF319A055E969EA3D357EF8CB11DDD226 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3504 | avg_tuneup_online_setup.exe | 34.117.223.223:443 | analytics.avcdn.net | GOOGLE-CLOUD-PLATFORM | US | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3504 | avg_tuneup_online_setup.exe | 2.18.161.23:443 | honzik.avcdn.net | AKAMAI-AS | DE | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3528 | icarus.exe | 34.117.223.223:443 | analytics.avcdn.net | GOOGLE-CLOUD-PLATFORM | US | unknown |
3528 | icarus.exe | 34.160.176.28:443 | shepherd.ff.avast.com | GOOGLE | US | unknown |
3528 | icarus.exe | 2.18.161.23:443 | honzik.avcdn.net | AKAMAI-AS | DE | unknown |
3724 | icarus.exe | 2.18.161.23:443 | honzik.avcdn.net | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
analytics.avcdn.net |
| unknown |
honzik.avcdn.net |
| unknown |
shepherd.ff.avast.com |
| whitelisted |