URL:

http://es.oldversion.com/windows/download/avast-free-antivirus-4-8-1368

Full analysis: https://app.any.run/tasks/18d9a5f1-738c-4277-ac41-39989261a53c
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 10, 2024, 21:50:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

468D6045B387B858F213FFAA48A3891A

SHA1:

EC2B8E08E72E179D81982BCFB82ACA72C7D91164

SHA256:

BDEB9F12452358D582A20CC03B1C9883E05259020F369E9C466854F75A963A77

SSDEEP:

3:N1Kb9lAGL/KJMjKL6E+ELRMyQmdedn:CJaGDKJpz+EWDqedn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
      • avast.setup (PID: 3680)
      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
    • Creates a writable file in the system directory

      • avast.setup (PID: 3680)
    • Changes the autorun value in the registry

      • avast.setup (PID: 3680)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • avast.setup (PID: 3680)
    • Executable content was dropped or overwritten

      • avast.setup (PID: 3680)
      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
    • Process drops legitimate windows executable

      • avast.setup (PID: 3680)
    • The process drops C-runtime libraries

      • avast.setup (PID: 3680)
    • Creates files in the driver directory

      • avast.setup (PID: 3680)
    • Creates/Modifies COM task schedule object

      • avast.setup (PID: 3680)
    • Creates or modifies Windows services

      • avast.setup (PID: 3680)
    • Creates a software uninstall entry

      • avast.setup (PID: 3680)
    • Read startup parameters

      • ashAvast.exe (PID: 1820)
    • Reads Microsoft Outlook installation path

      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
    • Creates file in the systems drive root

      • ashAvast.exe (PID: 1820)
    • Reads the Internet Settings

      • ashSimpl.exe (PID: 3484)
      • avast.setup (PID: 3680)
    • Reads security settings of Internet Explorer

      • ashSimpl.exe (PID: 3484)
    • Reads Internet Explorer settings

      • ashSimpl.exe (PID: 3484)
    • Starts application with an unusual extension

      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
    • Reads the Windows owner or organization settings

      • avast.setup (PID: 3680)
  • INFO

    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3700)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2044)
    • Checks proxy server information

      • avast.setup (PID: 3680)
      • ashSimpl.exe (PID: 3484)
    • Create files in a temporary directory

      • avast.setup (PID: 3680)
      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
      • ashSimpl.exe (PID: 3484)
    • Creates files in the program directory

      • avast.setup (PID: 3680)
      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
    • Application launched itself

      • iexplore.exe (PID: 3700)
      • msedge.exe (PID: 2440)
      • msedge.exe (PID: 3112)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2044)
    • Checks supported languages

      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
      • sched.exe (PID: 1840)
      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
      • avast.setup (PID: 3680)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3700)
    • Manual execution by a user

      • winver.exe (PID: 3620)
      • ashAvast.exe (PID: 1820)
      • ashAvast.exe (PID: 3252)
      • msedge.exe (PID: 3112)
    • Reads the computer name

      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
      • avast.setup (PID: 3680)
    • Reads the machine GUID from the registry

      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
108
Monitored processes
61
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe 4.8.1368_avast_4.8.1368.exe no specs 4.8.1368_avast_4.8.1368.exe avast.setup winver.exe no specs sched.exe no specs bcdedit.exe no specs ashavast.exe no specs ashavast.exe ashsimpl.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2312 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
492"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\4.8.1368_avast_4.8.1368.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\4.8.1368_avast_4.8.1368.exe
iexplore.exe
User:
admin
Integrity Level:
HIGH
Description:
ALWIL Software Setup Engine
Exit code:
536870912
Version:
4.8.1368.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\4.8.1368_avast_4.8.1368.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
696"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3532 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
896"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=41 --mojo-platform-channel-handle=3272 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=1496 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1124"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1288"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.PageScreenshotProcessor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=3616 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1308"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=42 --mojo-platform-channel-handle=480 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1336"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4780 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1336"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=3472 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
57 445
Read events
57 022
Write events
365
Delete events
58

Modification events

(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31093556
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
259365628
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31093557
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
239
Suspicious files
272
Text files
367
Unknown types
205

Dropped files

PID
Process
Filename
Type
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery-ui.min[1].jstext
MD5:02E1058FD3CB0799867BA932A4AD3B22
SHA256:E4BF411611A715A5752D6E80345CD5FA56731A8FF96E54E5212024337A1C6984
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\rss-icon[1].gifimage
MD5:D67F9D0CB69383CC0C15DFF7656FF7A0
SHA256:E1229C6733F07C0ACFF4AF2ED68154E33755B19E14DE94D972DB343252C782C4
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\stats[1].gifimage
MD5:BD83C5D78BA59C56D3EC159F8BCEF043
SHA256:305FC8AC50CF913CD640B7FB625D2B921CF8C55E756498311B5199AF018C720F
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\facebook-icon[1].gifimage
MD5:942E656D9EF756DFDFE4344B207990AF
SHA256:ACD2E4880CAB9DAAD184748D16007BEC9E46773DAA380F690BC8C6EDB771EEE4
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\avast-free-antivirus-4-8-1368[1].htmhtml
MD5:BC261532E975118F7936FB1068AECCCB
SHA256:52B9CDBDF076526B931733EBFBDD05EB0189B1E47F069E0EA4C409F6C2345553
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.colorbox[1].jstext
MD5:AB4C3A44A79078FA7F66BF3F1F7D76FB
SHA256:EF6B61D8F7941A809F56E1128DBD097BE37494976677A3F98B3BEE09711C1CA8
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\_avast!_freeantivirus[1].pngimage
MD5:A5D1ABAAD4FDE971A0EC5BF8E8116B5B
SHA256:87ADC872E0230762A7AA16FDF49061B3D68E9768DD1C3C5608DF58BE47378443
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\poll_popup[1].jstext
MD5:7D69DE5473E06A509C6C5EF11FF3CCD6
SHA256:FE78269BACEFB1BAA8D985A1048CFB2AB8B9315E943C5BEECBE7E4784BBBCEBF
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\colorbox[1].csstext
MD5:AFA7BB17A85CD5EC22220D8B6196305D
SHA256:D8B41CA2983B5C9DF7342CBBC9D3F5C021584056E1E4FAF490DEE98209B89BE6
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\f[1].txttext
MD5:95AE1E9B3ABBB66CE61CAD709E5CF8A2
SHA256:81EBB92FF25C3F4B602234E1CFF3CAB882870834659CE8B8904C269FEE22E230
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
102
TCP/UDP connections
277
DNS requests
243
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2044
iexplore.exe
GET
200
142.250.184.226:80
http://pagead2.googlesyndication.com/pagead/show_ads.js
unknown
text
14.0 Kb
unknown
2044
iexplore.exe
GET
200
3.215.56.8:80
http://es.oldversion.com/windows/avast-free-antivirus-4-8-1368
unknown
html
6.92 Kb
unknown
2044
iexplore.exe
GET
302
3.215.56.8:80
http://es.oldversion.com/windows/download/avast-free-antivirus-4-8-1368
unknown
html
441 b
unknown
2044
iexplore.exe
GET
200
142.250.184.234:80
http://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js
unknown
html
32.5 Kb
unknown
2044
iexplore.exe
GET
200
142.250.184.234:80
http://ajax.googleapis.com/ajax/libs/jqueryui/1.8.18/jquery-ui.min.js
unknown
text
197 Kb
unknown
2044
iexplore.exe
GET
200
3.5.25.114:80
http://assets.oldversion.s3.amazonaws.com/icons/_avast!_freeantivirus.png
unknown
image
1.70 Kb
unknown
2044
iexplore.exe
GET
200
93.184.220.66:80
http://platform.twitter.com/widgets.js
unknown
text
26.9 Kb
unknown
2044
iexplore.exe
GET
200
3.5.25.114:80
http://assets.oldversion.s3.amazonaws.com/bundles/oldversionsite/images/theme/icons/stats.gif
unknown
image
1.05 Kb
unknown
2044
iexplore.exe
GET
200
3.5.25.114:80
http://assets.oldversion.s3.amazonaws.com/bundles/oldversionsite/images/theme/icons/rss-icon.gif
unknown
image
1.22 Kb
unknown
2044
iexplore.exe
GET
200
3.5.25.114:80
http://assets.oldversion.s3.amazonaws.com/bundles/oldversionsite/images/theme/icons/facebook-icon.gif
unknown
image
1.13 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2044
iexplore.exe
3.215.56.8:80
es.oldversion.com
AMAZON-AES
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2044
iexplore.exe
142.250.184.226:80
pagead2.googlesyndication.com
GOOGLE
US
whitelisted
2044
iexplore.exe
142.250.184.234:80
ajax.googleapis.com
GOOGLE
US
whitelisted
2044
iexplore.exe
3.5.25.114:80
assets.oldversion.s3.amazonaws.com
AMAZON-AES
US
unknown
2044
iexplore.exe
142.250.184.232:443
www.googletagmanager.com
GOOGLE
US
unknown
2044
iexplore.exe
142.250.185.206:443
apis.google.com
GOOGLE
US
whitelisted
2044
iexplore.exe
93.184.220.66:80
platform.twitter.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
es.oldversion.com
  • 3.215.56.8
unknown
ajax.googleapis.com
  • 142.250.184.234
whitelisted
assets.oldversion.s3.amazonaws.com
  • 3.5.25.114
  • 3.5.27.138
  • 52.217.139.9
  • 16.182.105.57
  • 52.216.209.9
  • 3.5.21.101
  • 3.5.28.158
  • 52.216.212.145
shared
platform.twitter.com
  • 93.184.220.66
whitelisted
pagead2.googlesyndication.com
  • 142.250.184.226
whitelisted
apis.google.com
  • 142.250.185.206
whitelisted
www.googletagmanager.com
  • 142.250.184.232
whitelisted
www.facebook.com
  • 157.240.0.35
whitelisted
oldversion.disqus.com
  • 199.232.192.134
  • 199.232.196.134
unknown
ctldl.windowsupdate.com
  • 23.65.124.16
  • 23.65.124.8
whitelisted

Threats

PID
Process
Class
Message
2044
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY HTTP POST contains pass= in cleartext
2044
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2044
iexplore.exe
Misc activity
ET INFO EXE - Served Attached HTTP
3460
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
3460
msedge.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PUP Domain (omnatuor .com)
3460
msedge.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PUP Domain (omnatuor .com)
No debug info