URL:

https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient

Full analysis: https://app.any.run/tasks/c600ed20-1e84-48f1-9aa5-bc70c067ab98
Verdict: Malicious activity
Analysis date: May 19, 2025, 17:05:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
evasion
arch-scr
Indicators:
MD5:

95BF76059B984ACBF43EB9048431D4AC

SHA1:

C6A12B0FADC97A9AF7E72C6B58B7A68139581FBE

SHA256:

B23408030748EC5BB14329D9CAE42C20F535659F5ADC6F469363AAE120D94E0A

SSDEEP:

3:N8DSL/K7C/I1dBRIYrJD6QWmOLEom//I+lAL+2MJGDLR:2OLCVsQfWmMmYddMJGXR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks for external IP

      • avast_free_antivirus_online-installation.exe (PID: 8188)
    • Executable content was dropped or overwritten

      • avast_free_antivirus_online-installation.exe (PID: 8188)
      • avast_free_antivirus_online_setup.exe (PID: 8164)
      • icarus.exe (PID: 6512)
      • icarus.exe (PID: 5588)
      • icarus.exe (PID: 5380)
    • Starts itself from another location

      • icarus.exe (PID: 6512)
    • Reads security settings of Internet Explorer

      • icarus_ui.exe (PID: 5400)
    • Process drops legitimate windows executable

      • icarus.exe (PID: 5588)
    • Drops a system driver (possible attempt to evade defenses)

      • icarus.exe (PID: 5588)
    • The process creates files with name similar to system file names

      • icarus.exe (PID: 5588)
    • The process drops C-runtime libraries

      • icarus.exe (PID: 5588)
    • The process verifies whether the antivirus software is installed

      • icarus.exe (PID: 5588)
      • icarus.exe (PID: 5380)
  • INFO

    • Checks supported languages

      • avast_free_antivirus_online-installation.exe (PID: 8188)
      • avast_free_antivirus_online_setup.exe (PID: 8164)
      • icarus.exe (PID: 6512)
      • icarus_ui.exe (PID: 5400)
      • icarus.exe (PID: 5380)
      • icarus.exe (PID: 5588)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 1276)
    • Reads the computer name

      • avast_free_antivirus_online-installation.exe (PID: 8188)
      • avast_free_antivirus_online_setup.exe (PID: 8164)
      • icarus.exe (PID: 6512)
      • icarus_ui.exe (PID: 5400)
      • icarus.exe (PID: 5588)
      • icarus.exe (PID: 5380)
    • Reads the machine GUID from the registry

      • avast_free_antivirus_online-installation.exe (PID: 8188)
      • avast_free_antivirus_online_setup.exe (PID: 8164)
      • icarus_ui.exe (PID: 5400)
      • icarus.exe (PID: 6512)
      • icarus.exe (PID: 5588)
      • icarus.exe (PID: 5380)
    • The sample compiled with english language support

      • avast_free_antivirus_online-installation.exe (PID: 8188)
      • avast_free_antivirus_online_setup.exe (PID: 8164)
      • icarus.exe (PID: 6512)
      • icarus.exe (PID: 5588)
      • icarus.exe (PID: 5380)
    • Application launched itself

      • chrome.exe (PID: 1276)
    • Reads the software policy settings

      • avast_free_antivirus_online-installation.exe (PID: 8188)
      • avast_free_antivirus_online_setup.exe (PID: 8164)
      • icarus_ui.exe (PID: 5400)
      • slui.exe (PID: 7896)
    • Creates files in the program directory

      • avast_free_antivirus_online_setup.exe (PID: 8164)
      • icarus.exe (PID: 6512)
      • icarus_ui.exe (PID: 5400)
      • icarus.exe (PID: 5588)
      • icarus.exe (PID: 5380)
    • Create files in a temporary directory

      • avast_free_antivirus_online_setup.exe (PID: 8164)
    • Checks proxy server information

      • avast_free_antivirus_online_setup.exe (PID: 8164)
      • icarus_ui.exe (PID: 5400)
    • Reads CPU info

      • icarus.exe (PID: 6512)
      • icarus_ui.exe (PID: 5400)
      • icarus.exe (PID: 5380)
      • icarus.exe (PID: 5588)
    • Reads Environment values

      • icarus.exe (PID: 5588)
    • Creates files or folders in the user directory

      • icarus_ui.exe (PID: 5400)
    • The sample compiled with czech language support

      • icarus.exe (PID: 5588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
162
Monitored processes
26
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs sppextcomobj.exe no specs slui.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs avast_free_antivirus_online-installation.exe no specs avast_free_antivirus_online-installation.exe avast_free_antivirus_online_setup.exe icarus.exe icarus_ui.exe icarus.exe icarus.exe slui.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
660"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5492 --field-trial-handle=1868,i,9555279895445847641,5976056700841428405,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
864"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6040 --field-trial-handle=1868,i,9555279895445847641,5976056700841428405,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1276"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4120"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=5920 --field-trial-handle=1868,i,9555279895445847641,5976056700841428405,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4300"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4436 --field-trial-handle=1868,i,9555279895445847641,5976056700841428405,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5064"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5704 --field-trial-handle=1868,i,9555279895445847641,5976056700841428405,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5380C:\WINDOWS\Temp\asw-7231d2da-86b6-49bc-94c0-635bf72f4e18\avast-av-vps\icarus.exe /cookie:mmm_ava_esg_000_361_m /edat_dir:C:\WINDOWS\Temp\asw.ecb66818144db3ad /geo:US /track-guid:b0541534-e232-406a-9156-24bff8f995eb /sssid:8164 /er_master:master_ep_c179e35c-2918-4167-928e-2fc3c0529c7a /er_ui:ui_ep_c006a6a1-1633-4d0c-9a0e-63dfa5ae1a59 /er_slave:avast-av-vps_slave_ep_5c4d8f4b-760f-4a67-8a33-37a2e246d434 /slave:avast-av-vpsC:\Windows\Temp\asw-7231d2da-86b6-49bc-94c0-635bf72f4e18\avast-av-vps\icarus.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Installer
Version:
25.4.9091.0
Modules
Images
c:\windows\temp\asw-7231d2da-86b6-49bc-94c0-635bf72f4e18\avast-av-vps\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\winhttp.dll
5400C:\WINDOWS\Temp\asw-7231d2da-86b6-49bc-94c0-635bf72f4e18\common\icarus_ui.exe /cookie:mmm_ava_esg_000_361_m /edat_dir:C:\WINDOWS\Temp\asw.ecb66818144db3ad /geo:US /track-guid:b0541534-e232-406a-9156-24bff8f995eb /sssid:8164 /er_master:master_ep_c179e35c-2918-4167-928e-2fc3c0529c7a /er_ui:ui_ep_c006a6a1-1633-4d0c-9a0e-63dfa5ae1a59C:\Windows\Temp\asw-7231d2da-86b6-49bc-94c0-635bf72f4e18\common\icarus_ui.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast UI
Version:
25.4.9091.0
Modules
Images
c:\windows\temp\asw-7231d2da-86b6-49bc-94c0-635bf72f4e18\common\icarus_ui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
5588C:\WINDOWS\Temp\asw-7231d2da-86b6-49bc-94c0-635bf72f4e18\avast-av\icarus.exe /cookie:mmm_ava_esg_000_361_m /edat_dir:C:\WINDOWS\Temp\asw.ecb66818144db3ad /geo:US /track-guid:b0541534-e232-406a-9156-24bff8f995eb /sssid:8164 /er_master:master_ep_c179e35c-2918-4167-928e-2fc3c0529c7a /er_ui:ui_ep_c006a6a1-1633-4d0c-9a0e-63dfa5ae1a59 /er_slave:avast-av_slave_ep_ce22e062-5487-44dd-9ea9-bd5b70d82a45 /slave:avast-avC:\Windows\Temp\asw-7231d2da-86b6-49bc-94c0-635bf72f4e18\avast-av\icarus.exe
icarus.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Installer
Version:
25.4.9091.0
Modules
Images
c:\windows\temp\asw-7231d2da-86b6-49bc-94c0-635bf72f4e18\avast-av\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
5728"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4780 --field-trial-handle=1868,i,9555279895445847641,5976056700841428405,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
11 965
Read events
11 739
Write events
215
Delete events
11

Modification events

(PID) Process:(1276) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1276) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1276) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1276) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(1276) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(5728) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
0100000000000000FB514153E0C8DB01
(PID) Process:(8164) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:8C5CFDF4-AB05-4EB0-8EF6-7B4620DC2CF3
Value:
AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAkNaojg36rkScv3lvn29WBwQAAAACAAAAAAAQZgAAAAEAACAAAAAumlV4Dd5nUrxH2NLznnIhjZSFV3VXai/w072J06reJwAAAAAOgAAAAAIAACAAAABanQVx3Qye4BkSXCQo0Cw+oSVMreqJ9w9/FNWBO7MM71AAAACmho1QQ3FyLDnXhKr39SeGnp3wSWGCbGxdpMvh8WGdNPb+miQdShaTInurKW12UlO/jFYnPGEbI6nQB7uNoUq8HOd4yySwjD/+gH0TO5T9lUAAAADHUDrjAZVQjq185Fg43gVRztgqXqGvn33TiwWtd4AZ4z5UZaQmhb2HSb960d8RiYLAob0gJ9FxF+OvAQEGGiOi
(PID) Process:(8164) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F
Operation:writeName:5E1D6A55-0134-486E-A166-38C2E4919BB1
Value:
AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAkNaojg36rkScv3lvn29WBwQAAAACAAAAAAAQZgAAAAEAACAAAAAumlV4Dd5nUrxH2NLznnIhjZSFV3VXai/w072J06reJwAAAAAOgAAAAAIAACAAAABanQVx3Qye4BkSXCQo0Cw+oSVMreqJ9w9/FNWBO7MM71AAAACmho1QQ3FyLDnXhKr39SeGnp3wSWGCbGxdpMvh8WGdNPb+miQdShaTInurKW12UlO/jFYnPGEbI6nQB7uNoUq8HOd4yySwjD/+gH0TO5T9lUAAAADHUDrjAZVQjq185Fg43gVRztgqXqGvn33TiwWtd4AZ4z5UZaQmhb2HSb960d8RiYLAob0gJ9FxF+OvAQEGGiOi
(PID) Process:(8164) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
Operation:writeName:144807F0-DE37-4C62-9C05-EB4CC64A7A2F
Value:
800320cf-c93d-4f2a-a002-d684e2d442f6
(PID) Process:(8164) avast_free_antivirus_online_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F
Operation:writeName:56C7A9DA-4B11-406A-8B1A-EFF157C294D6
Value:
800320cf-c93d-4f2a-a002-d684e2d442f6
Executable files
612
Suspicious files
1 044
Text files
266
Unknown types
0

Dropped files

PID
Process
Filename
Type
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF10c9ca.TMP
MD5:
SHA256:
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF10c9ca.TMP
MD5:
SHA256:
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF10c9e9.TMP
MD5:
SHA256:
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF10c9ca.TMP
MD5:
SHA256:
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF10c9f9.TMP
MD5:
SHA256:
1276chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF10c9e9.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
156
DNS requests
160
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.35:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8188
avast_free_antivirus_online-installation.exe
POST
200
142.250.185.78:80
http://www.google-analytics.com/collect
unknown
whitelisted
8188
avast_free_antivirus_online-installation.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
whitelisted
8188
avast_free_antivirus_online-installation.exe
POST
200
142.250.185.78:80
http://www.google-analytics.com/collect
unknown
whitelisted
8188
avast_free_antivirus_online-installation.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
whitelisted
8020
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8020
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5400
icarus_ui.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.35:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1276
chrome.exe
239.255.255.250:1900
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
23.206.210.36:443
www.avast.com
AKAMAI-AS
DE
whitelisted
74.125.71.84:443
accounts.google.com
GOOGLE
US
unknown
104.18.86.42:443
cdn.cookielaw.org
CLOUDFLARENET
whitelisted
69.192.160.133:443
s.go-mpulse.net
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.35
  • 23.216.77.38
  • 23.216.77.39
  • 23.216.77.41
  • 23.216.77.31
  • 23.216.77.30
  • 23.216.77.36
  • 23.216.77.32
  • 23.216.77.37
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
www.avast.com
  • 23.206.210.36
whitelisted
accounts.google.com
  • 74.125.71.84
whitelisted
cdn.cookielaw.org
  • 104.18.86.42
  • 104.18.87.42
whitelisted
s.go-mpulse.net
  • 69.192.160.133
whitelisted
www.google-analytics.com
  • 142.250.185.78
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
8188
avast_free_antivirus_online-installation.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
No debug info