| File name: | avast_vpn_online_setup.exe |
| Full analysis: | https://app.any.run/tasks/8ee17571-fc1f-4183-af48-c032a20aac05 |
| Verdict: | Malicious activity |
| Analysis date: | January 08, 2024, 17:09:03 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F0015BD4724E734ADD0161F2D4731CB1 |
| SHA1: | EAE7C6B84E069CEA66E584BDFE7F1B63E6902CC3 |
| SHA256: | BB3EF47058EF096F522BCD4E7B1F26CF4BE6DAC5C5B83D7EB2784C6AD8643665 |
| SSDEEP: | 49152:2GExgdT9v5E9I1jiqvFupkcf0RMEybHZYyMik:5Exgrv5yI1jiqvFursRMEybu |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:12:02 11:00:51+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit, Removable run from swap, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 809472 |
| InitializedDataSize: | 344576 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x286d0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 21.8.3960.0 |
| ProductVersionNumber: | 5.15.5913.3604 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Avast Software |
| FileDescription: | Avast Self-Extract Package |
| FileVersion: | 21.8.3960.0 |
| InternalName: | icarus_sfx |
| LegalCopyright: | © 2021 Avast Software |
| OriginalFileName: | icarus_sfx.exe |
| ProductId: | avast-icarus |
| ProductName: | Avast Installer |
| ProductVersion: | 5.15.5913.3604 |
| Vpnincluded: | 5.15.5913.3604 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | "C:\Users\admin\AppData\Local\Temp\avast_vpn_online_setup.exe" | C:\Users\admin\AppData\Local\Temp\avast_vpn_online_setup.exe | — | explorer.exe | |||||||||||
User: admin Company: Avast Software Integrity Level: MEDIUM Description: Avast Self-Extract Package Exit code: 3221226540 Version: 21.8.3960.0 Modules
| |||||||||||||||
| 1236 | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\icarus_ui.exe /sssid:2420 /er_master:master_ep_673bc5d8-f6af-43e0-92bd-c8d46aba0f4f /er_ui:ui_ep_6c3d3c15-ade7-44a3-b08f-4a5914565895 | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\icarus_ui.exe | — | icarus.exe | |||||||||||
User: admin Company: Avast Software Integrity Level: HIGH Description: Avast UI Exit code: 0 Version: 23.2.5620.0 Modules
| |||||||||||||||
| 1864 | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\icarus.exe /icarus-info-path:C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\icarus-info.xml /install /sssid:2420 | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\icarus.exe | avast_vpn_online_setup.exe | ||||||||||||
User: admin Company: Avast Software Integrity Level: HIGH Description: Avast Installer Exit code: 0 Version: 23.2.5620.0 Modules
| |||||||||||||||
| 2340 | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\avast-vpn\icarus.exe /sssid:2420 /er_master:master_ep_673bc5d8-f6af-43e0-92bd-c8d46aba0f4f /er_ui:ui_ep_6c3d3c15-ade7-44a3-b08f-4a5914565895 /er_slave:avast-vpn_slave_ep_a7402707-9a62-47fd-8f4c-df58fc2afd63 /slave:avast-vpn | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\avast-vpn\icarus.exe | icarus.exe | ||||||||||||
User: admin Company: Avast Software Integrity Level: HIGH Description: Avast Installer Exit code: 0 Version: 23.2.5620.0 Modules
| |||||||||||||||
| 2420 | "C:\Users\admin\AppData\Local\Temp\avast_vpn_online_setup.exe" | C:\Users\admin\AppData\Local\Temp\avast_vpn_online_setup.exe | explorer.exe | ||||||||||||
User: admin Company: Avast Software Integrity Level: HIGH Description: Avast Self-Extract Package Exit code: 0 Version: 21.8.3960.0 Modules
| |||||||||||||||
| (PID) Process: | (2420) avast_vpn_online_setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2340) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | BootExecute |
Value: autocheck autochk * | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2420 | avast_vpn_online_setup.exe | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\bug_report.exe | executable | |
MD5:427360DDFC724244D83D633D03644D0B | SHA256:F81E8E1844166CC73D2C93A255DE9961B9A751F0E8DF8ED9A43CFEE0EFC61FCC | |||
| 1864 | icarus.exe | C:\ProgramData\Avast Software\Icarus\Logs\report.log | — | |
MD5:— | SHA256:— | |||
| 2420 | avast_vpn_online_setup.exe | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\setupui.cont | binary | |
MD5:EB6452DA8A5DA56869CC5354F62A1BC5 | SHA256:B0DCE494EAE002553BCE20BCFF5DD513109C14BF0C0524008CD414CC7CF970B7 | |||
| 2420 | avast_vpn_online_setup.exe | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\59e1dfc4-f49d-4683-b3a1-c2a748f94004 | binary | |
MD5:634090477C1C04F06E2DD15993237FD2 | SHA256:273A824B5734EE7C2E8611D9D5A29C1EC6466AAFFF9D66C551727E8815C70C1C | |||
| 2420 | avast_vpn_online_setup.exe | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\54798b64-f4ae-4afe-87d6-c1ce0dc387b8 | binary | |
MD5:993E986CBAE19CD462A64689184626E9 | SHA256:508ABE57745D9F4CD46F2630ED921B34F36DE6FCCCD4305FDEA1DD52D33CDC9F | |||
| 2420 | avast_vpn_online_setup.exe | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\product-def.xml | xml | |
MD5:2FDB6C2285F7E9B674A23E540332E16D | SHA256:017FB96C1109E87DB4B25C24F443D727035B2D2C1E11489D16F2693BFB6B19B6 | |||
| 2420 | avast_vpn_online_setup.exe | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\common\icarus_ui.exe | executable | |
MD5:BF4545F6EC415EFCC13E1F76E6ACA6EF | SHA256:03B86B1D8FDB076521C2222EC5D9043C2F43F22ADCA4AD9DA5B457AAAF23B16F | |||
| 2420 | avast_vpn_online_setup.exe | C:\ProgramData\Avast Software\Icarus\Logs\sfx.log | text | |
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA | SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5 | |||
| 2420 | avast_vpn_online_setup.exe | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\ecoo.edat | text | |
MD5:C92B1DCEE4FD4AB19A1FDC6369E79E29 | SHA256:1BCC46B9FD6E52CD32E3DAF3805B357D0418B0598AB45B43918B0CA71437FB99 | |||
| 2420 | avast_vpn_online_setup.exe | C:\Windows\Temp\asw-18435c92-fd9f-42c7-b615-8c74d695f021\icarus-info.xml | xml | |
MD5:A45090FB7E4C76ED901AE59BEDCD5D1E | SHA256:139E3589383300D2F2F8BB41B11EB847FAEE62D442B99E85DB0B5D3357EAEBE1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2420 | avast_vpn_online_setup.exe | GET | 404 | 184.30.25.22:80 | http://honzik.avcdn.net/dll/avast-vpn/x86/icarus_mod.dll.lzma | unknown | html | 235 b | unknown |
2340 | icarus.exe | GET | — | 2.18.161.23:80 | http://honzik.avcdn.net//universe/b0e8/c2d7/2395/b0e8c2d7239544001e8bd8d1e79914b122c67b7e1aed3959584ecf15dc5b812f.lzma | unknown | — | — | unknown |
2340 | icarus.exe | GET | — | 2.18.161.23:80 | http://honzik.avcdn.net//universe/b0e8/c2d7/2395/b0e8c2d7239544001e8bd8d1e79914b122c67b7e1aed3959584ecf15dc5b812f.lzma | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2420 | avast_vpn_online_setup.exe | 34.117.223.223:443 | analytics.ff.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2420 | avast_vpn_online_setup.exe | 184.30.25.22:443 | honzik.avcdn.net | AKAMAI-AS | DE | unknown |
2420 | avast_vpn_online_setup.exe | 184.30.25.22:80 | honzik.avcdn.net | AKAMAI-AS | DE | unknown |
1864 | icarus.exe | 34.117.223.223:443 | analytics.ff.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1864 | icarus.exe | 34.160.176.28:443 | shepherd.ff.avast.com | GOOGLE | US | unknown |
1864 | icarus.exe | 184.30.25.22:443 | honzik.avcdn.net | AKAMAI-AS | DE | unknown |
2340 | icarus.exe | 184.30.25.22:443 | honzik.avcdn.net | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
analytics.ff.avast.com |
| whitelisted |
honzik.avcdn.net |
| unknown |
shepherd.ff.avast.com |
| whitelisted |