URL:

http://es.oldversion.com/windows/download/avast-free-antivirus-4-8-1368

Full analysis: https://app.any.run/tasks/18d9a5f1-738c-4277-ac41-39989261a53c
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 10, 2024, 21:50:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

468D6045B387B858F213FFAA48A3891A

SHA1:

EC2B8E08E72E179D81982BCFB82ACA72C7D91164

SHA256:

BDEB9F12452358D582A20CC03B1C9883E05259020F369E9C466854F75A963A77

SSDEEP:

3:N1Kb9lAGL/KJMjKL6E+ELRMyQmdedn:CJaGDKJpz+EWDqedn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
      • avast.setup (PID: 3680)
      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
    • Creates a writable file in the system directory

      • avast.setup (PID: 3680)
    • Changes the autorun value in the registry

      • avast.setup (PID: 3680)
  • SUSPICIOUS

    • Starts application with an unusual extension

      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
    • Reads the Windows owner or organization settings

      • avast.setup (PID: 3680)
    • Executable content was dropped or overwritten

      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
      • avast.setup (PID: 3680)
      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
    • Reads the Internet Settings

      • avast.setup (PID: 3680)
      • ashSimpl.exe (PID: 3484)
    • Drops a system driver (possible attempt to evade defenses)

      • avast.setup (PID: 3680)
    • Process drops legitimate windows executable

      • avast.setup (PID: 3680)
    • The process drops C-runtime libraries

      • avast.setup (PID: 3680)
    • Creates/Modifies COM task schedule object

      • avast.setup (PID: 3680)
    • Creates or modifies Windows services

      • avast.setup (PID: 3680)
    • Creates files in the driver directory

      • avast.setup (PID: 3680)
    • Creates a software uninstall entry

      • avast.setup (PID: 3680)
    • Reads Microsoft Outlook installation path

      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
    • Read startup parameters

      • ashAvast.exe (PID: 1820)
    • Creates file in the systems drive root

      • ashAvast.exe (PID: 1820)
    • Reads security settings of Internet Explorer

      • ashSimpl.exe (PID: 3484)
    • Reads Internet Explorer settings

      • ashSimpl.exe (PID: 3484)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3700)
      • msedge.exe (PID: 2440)
      • msedge.exe (PID: 3112)
    • Checks supported languages

      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
      • avast.setup (PID: 3680)
      • sched.exe (PID: 1840)
      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
    • Create files in a temporary directory

      • 4.8.1368_avast_4.8.1368.exe (PID: 492)
      • avast.setup (PID: 3680)
      • ashSimpl.exe (PID: 3484)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2044)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2044)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3700)
    • Reads the computer name

      • avast.setup (PID: 3680)
      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3700)
    • Checks proxy server information

      • avast.setup (PID: 3680)
      • ashSimpl.exe (PID: 3484)
    • Creates files in the program directory

      • avast.setup (PID: 3680)
      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
    • Manual execution by a user

      • ashAvast.exe (PID: 1820)
      • ashAvast.exe (PID: 3252)
      • winver.exe (PID: 3620)
      • msedge.exe (PID: 3112)
    • Reads the machine GUID from the registry

      • ashAvast.exe (PID: 1820)
      • ashSimpl.exe (PID: 3484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
108
Monitored processes
61
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe 4.8.1368_avast_4.8.1368.exe no specs 4.8.1368_avast_4.8.1368.exe avast.setup winver.exe no specs sched.exe no specs bcdedit.exe no specs ashavast.exe no specs ashavast.exe ashsimpl.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2312 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
492"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\4.8.1368_avast_4.8.1368.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\4.8.1368_avast_4.8.1368.exe
iexplore.exe
User:
admin
Integrity Level:
HIGH
Description:
ALWIL Software Setup Engine
Exit code:
536870912
Version:
4.8.1368.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\4.8.1368_avast_4.8.1368.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
696"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3532 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
896"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=41 --mojo-platform-channel-handle=3272 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=1496 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1124"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1288"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.PageScreenshotProcessor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=3616 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1308"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=42 --mojo-platform-channel-handle=480 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1336"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4780 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1336"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=3472 --field-trial-handle=1372,i,2356960430327918975,9941273306037942446,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
57 445
Read events
57 022
Write events
365
Delete events
58

Modification events

(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31093556
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
259365628
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31093557
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
239
Suspicious files
272
Text files
367
Unknown types
205

Dropped files

PID
Process
Filename
Type
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\widgets[1].jstext
MD5:824BEB891744DB98CCBD3A456E59E0F7
SHA256:173460E89E6A7244218BADAE2016F65C48A3EAE9D400802273EECA18B07336F1
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\stats[1].gifimage
MD5:BD83C5D78BA59C56D3EC159F8BCEF043
SHA256:305FC8AC50CF913CD640B7FB625D2B921CF8C55E756498311B5199AF018C720F
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\avast-free-antivirus-4-8-1368[1].htmhtml
MD5:BC261532E975118F7936FB1068AECCCB
SHA256:52B9CDBDF076526B931733EBFBDD05EB0189B1E47F069E0EA4C409F6C2345553
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery.min[1].jshtml
MD5:DDB84C1587287B2DF08966081EF063BF
SHA256:88171413FC76DDA23AB32BAA17B11E4FFF89141C633ECE737852445F1BA6C1BD
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\f[1].txttext
MD5:95AE1E9B3ABBB66CE61CAD709E5CF8A2
SHA256:81EBB92FF25C3F4B602234E1CFF3CAB882870834659CE8B8904C269FEE22E230
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\rss-icon[1].gifimage
MD5:D67F9D0CB69383CC0C15DFF7656FF7A0
SHA256:E1229C6733F07C0ACFF4AF2ED68154E33755B19E14DE94D972DB343252C782C4
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\jquery-ui.min[1].jstext
MD5:02E1058FD3CB0799867BA932A4AD3B22
SHA256:E4BF411611A715A5752D6E80345CD5FA56731A8FF96E54E5212024337A1C6984
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\google-plus-icon[1].gifimage
MD5:26D6B36EBC48943A28F76AA11C88F5C1
SHA256:09FE9F97361A8E23B31BF05610243F5CFED4ABBDCCA55CEEAAFDBF5CC2868E3B
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\poll_popup[1].jstext
MD5:7D69DE5473E06A509C6C5EF11FF3CCD6
SHA256:FE78269BACEFB1BAA8D985A1048CFB2AB8B9315E943C5BEECBE7E4784BBBCEBF
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\facebook-icon[1].gifimage
MD5:942E656D9EF756DFDFE4344B207990AF
SHA256:ACD2E4880CAB9DAAD184748D16007BEC9E46773DAA380F690BC8C6EDB771EEE4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
102
TCP/UDP connections
277
DNS requests
243
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2044
iexplore.exe
GET
200
142.250.184.226:80
http://pagead2.googlesyndication.com/pagead/show_ads.js
unknown
text
14.0 Kb
unknown
2044
iexplore.exe
GET
200
142.250.184.234:80
http://ajax.googleapis.com/ajax/libs/jqueryui/1.8.18/jquery-ui.min.js
unknown
text
197 Kb
unknown
2044
iexplore.exe
GET
302
3.215.56.8:80
http://es.oldversion.com/windows/download/avast-free-antivirus-4-8-1368
unknown
html
441 b
unknown
2044
iexplore.exe
GET
200
3.215.56.8:80
http://es.oldversion.com/windows/avast-free-antivirus-4-8-1368
unknown
html
6.92 Kb
unknown
2044
iexplore.exe
GET
200
142.250.184.234:80
http://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js
unknown
html
32.5 Kb
unknown
2044
iexplore.exe
GET
200
93.184.220.66:80
http://platform.twitter.com/widgets.js
unknown
text
26.9 Kb
unknown
2044
iexplore.exe
GET
200
3.5.25.114:80
http://assets.oldversion.s3.amazonaws.com/bundles/oldversionsite/images/theme/icons/stats.gif
unknown
image
1.05 Kb
unknown
2044
iexplore.exe
GET
200
3.5.25.114:80
http://assets.oldversion.s3.amazonaws.com/bundles/oldversionsite/images/theme/icons/rss-icon.gif
unknown
image
1.22 Kb
unknown
2044
iexplore.exe
GET
200
3.5.25.114:80
http://assets.oldversion.s3.amazonaws.com/icons/_avast!_freeantivirus.png
unknown
image
1.70 Kb
unknown
2044
iexplore.exe
GET
200
3.5.25.114:80
http://assets.oldversion.s3.amazonaws.com/bundles/oldversionsite/images/theme/icons/google-plus-icon.gif
unknown
image
823 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2044
iexplore.exe
3.215.56.8:80
es.oldversion.com
AMAZON-AES
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2044
iexplore.exe
142.250.184.226:80
pagead2.googlesyndication.com
GOOGLE
US
whitelisted
2044
iexplore.exe
142.250.184.234:80
ajax.googleapis.com
GOOGLE
US
whitelisted
2044
iexplore.exe
3.5.25.114:80
assets.oldversion.s3.amazonaws.com
AMAZON-AES
US
unknown
2044
iexplore.exe
142.250.184.232:443
www.googletagmanager.com
GOOGLE
US
unknown
2044
iexplore.exe
142.250.185.206:443
apis.google.com
GOOGLE
US
whitelisted
2044
iexplore.exe
93.184.220.66:80
platform.twitter.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
es.oldversion.com
  • 3.215.56.8
unknown
ajax.googleapis.com
  • 142.250.184.234
whitelisted
assets.oldversion.s3.amazonaws.com
  • 3.5.25.114
  • 3.5.27.138
  • 52.217.139.9
  • 16.182.105.57
  • 52.216.209.9
  • 3.5.21.101
  • 3.5.28.158
  • 52.216.212.145
shared
platform.twitter.com
  • 93.184.220.66
whitelisted
pagead2.googlesyndication.com
  • 142.250.184.226
whitelisted
apis.google.com
  • 142.250.185.206
whitelisted
www.googletagmanager.com
  • 142.250.184.232
whitelisted
www.facebook.com
  • 157.240.0.35
whitelisted
oldversion.disqus.com
  • 199.232.192.134
  • 199.232.196.134
unknown
ctldl.windowsupdate.com
  • 23.65.124.16
  • 23.65.124.8
whitelisted

Threats

PID
Process
Class
Message
2044
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY HTTP POST contains pass= in cleartext
2044
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2044
iexplore.exe
Misc activity
ET INFO EXE - Served Attached HTTP
3460
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
3460
msedge.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PUP Domain (omnatuor .com)
3460
msedge.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to PUP Domain (omnatuor .com)
No debug info