File name:

avast_secureline_setup.exe

Full analysis: https://app.any.run/tasks/46cada45-bcf4-476d-bc0d-a5575325ca11
Verdict: Malicious activity
Analysis date: October 15, 2024, 11:19:51
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

674F9D5FE03295810657E3654482F4CC

SHA1:

9A5F7432A1E34DBDE10E80865EA3D57747FD675F

SHA256:

C5C01D714C9BC9470EAFFAB7D60CCA1176A739579B8A640139FC2A5E455E0294

SSDEEP:

98304:Y0dmfB3TfRnHy4D85dF+IN6v2s6ZRLLs9t9jYwVeN0wbqJ9QnegAiJ8ZNj1WGjoQ:Evf6n5CB1OM6FyurY9Ds3sCZk7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • avast_secureline_setup.exe (PID: 5512)
      • avast_secureline_setup.exe (PID: 3912)
      • avast_secureline_setup.tmp (PID: 6716)
      • TiWorker.exe (PID: 6896)
    • Reads security settings of Internet Explorer

      • avast_secureline_setup.tmp (PID: 5616)
    • Process drops legitimate windows executable

      • avast_secureline_setup.tmp (PID: 6716)
      • TiWorker.exe (PID: 6896)
    • Drops a system driver (possible attempt to evade defenses)

      • avast_secureline_setup.tmp (PID: 6716)
    • The process drops C-runtime libraries

      • avast_secureline_setup.tmp (PID: 6716)
      • TiWorker.exe (PID: 6896)
    • Executes as Windows Service

      • VpnSvc.exe (PID: 6432)
  • INFO

    • Create files in a temporary directory

      • avast_secureline_setup.exe (PID: 5512)
      • avast_secureline_setup.exe (PID: 3912)
    • Checks supported languages

      • avast_secureline_setup.exe (PID: 5512)
      • avast_secureline_setup.exe (PID: 3912)
      • avast_secureline_setup.tmp (PID: 5616)
      • avast_secureline_setup.tmp (PID: 6716)
    • Reads the computer name

      • avast_secureline_setup.tmp (PID: 5616)
      • avast_secureline_setup.tmp (PID: 6716)
    • Process checks computer location settings

      • avast_secureline_setup.tmp (PID: 5616)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:07:09 07:58:13+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 120320
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.2.366.0
ProductVersionNumber: 1.2.366.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: AVAST Software
FileDescription: Avast SecureLine Setup
FileVersion: 1.2.366.0
LegalCopyright: Copyright © 2014 AVAST Software
ProductName: Avast SecureLine
ProductVersion: 1.2.366.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
12
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start avast_secureline_setup.exe avast_secureline_setup.tmp no specs avast_secureline_setup.exe avast_secureline_setup.tmp installcrt.exe no specs conhost.exe no specs tiworker.exe vpnsvc.exe vpnupdate.exe no specs vpn.exe no specs vpnupdate.exe no specs vpn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
916"C:\Program Files\AVAST Software\SecureLine\VpnUpdate.exe" /regC:\Program Files\AVAST Software\SecureLine\VpnUpdate.exeVpnSvc.exe
User:
SYSTEM
Company:
AVAST Software
Integrity Level:
SYSTEM
Description:
Avast SecureLine Update
Exit code:
0
Version:
1.2.366.0
Modules
Images
c:\program files\avast software\secureline\vpnupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\rpcrt4.dll
c:\windows\syswow64\psapi.dll
1584\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeInstallCrt.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3004"C:\Program Files\AVAST Software\SecureLine\Vpn.exe"C:\Program Files\AVAST Software\SecureLine\Vpn.exeavast_secureline_setup.tmp
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast SecureLine
Exit code:
0
Version:
1.2.366.0
Modules
Images
c:\program files\avast software\secureline\vpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3912"C:\Users\admin\AppData\Local\Temp\avast_secureline_setup.exe" /SPAWNWND=$70214 /NOTIFYWND=$50292 C:\Users\admin\AppData\Local\Temp\avast_secureline_setup.exe
avast_secureline_setup.tmp
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast SecureLine Setup
Exit code:
0
Version:
1.2.366.0
Modules
Images
c:\users\admin\appdata\local\temp\avast_secureline_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5232"C:\Program Files\AVAST Software\SecureLine\CRT\InstallCrt.exe" /avast /v140 /releaseC:\Program Files\AVAST Software\SecureLine\CRT\InstallCrt.exeavast_secureline_setup.tmp
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
17.7.1027.0
Modules
Images
c:\program files\avast software\secureline\crt\installcrt.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5512"C:\Users\admin\AppData\Local\Temp\avast_secureline_setup.exe" C:\Users\admin\AppData\Local\Temp\avast_secureline_setup.exe
explorer.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast SecureLine Setup
Exit code:
0
Version:
1.2.366.0
Modules
Images
c:\users\admin\appdata\local\temp\avast_secureline_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5616"C:\Users\admin\AppData\Local\Temp\is-SOHAL.tmp\avast_secureline_setup.tmp" /SL5="$50292,13518682,186368,C:\Users\admin\AppData\Local\Temp\avast_secureline_setup.exe" C:\Users\admin\AppData\Local\Temp\is-SOHAL.tmp\avast_secureline_setup.tmpavast_secureline_setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-sohal.tmp\avast_secureline_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5820"C:\Program Files\AVAST Software\SecureLine\Vpn.exe" /noguiC:\Program Files\AVAST Software\SecureLine\Vpn.exeavast_secureline_setup.tmp
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast SecureLine
Version:
1.2.366.0
Modules
Images
c:\program files\avast software\secureline\vpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5840"C:\Program Files\AVAST Software\SecureLine\VpnUpdate.exe" /regC:\Program Files\AVAST Software\SecureLine\VpnUpdate.exeavast_secureline_setup.tmp
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast SecureLine Update
Exit code:
0
Version:
1.2.366.0
Modules
Images
c:\program files\avast software\secureline\vpnupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
6432"C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe"C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
services.exe
User:
SYSTEM
Company:
AVAST Software
Integrity Level:
SYSTEM
Description:
Avast SecureLine Service
Version:
1.2.366.0
Modules
Images
c:\program files\avast software\secureline\vpnsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
Total events
4 652
Read events
4 412
Write events
179
Delete events
61

Modification events

(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software\SecureLine
Operation:writeName:FreeMode
Value:
Unused
(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software\SecureLine
Operation:writeName:DataFolder
Value:
C:\ProgramData\AVAST Software\SecureLine
(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software\SecureLine
Operation:writeName:LangID
Value:
1033
(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software\SecureLine
Operation:writeName:ProgramFolder
Value:
C:\Program Files\AVAST Software\SecureLine
(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software\SecureLine
Operation:writeName:VersionBuild
Value:
366
(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software\SecureLine
Operation:writeName:SetupCookie
Value:
(PID) Process:(6716) avast_secureline_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avastvpn
Operation:writeName:Content Type
Value:
application/avast-avastvpn
Executable files
255
Suspicious files
67
Text files
49
Unknown types
18

Dropped files

PID
Process
Filename
Type
6716avast_secureline_setup.tmpC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\cef_3.2623.1396[1].htm
MD5:
SHA256:
6716avast_secureline_setup.tmpC:\Users\admin\AppData\Local\Temp\is-J7AKU.tmp\cef_3.2623.1396.cab
MD5:
SHA256:
5512avast_secureline_setup.exeC:\Users\admin\AppData\Local\Temp\is-SOHAL.tmp\avast_secureline_setup.tmpexecutable
MD5:3FBDF753CB148BF2D5623CD0CC746D35
SHA256:A338F50B98260C68C94BF6B96F60C84532E9E19096176DBD6532B441CC88F0F1
6716avast_secureline_setup.tmpC:\Program Files\AVAST Software\SecureLine\locales\bn.pakbinary
MD5:1442225A0A7FD12CA7ED34F6ED37FF22
SHA256:5328BFD92B9C1AC61CA43591574118D970AE7B158ABBD9D331668E94583E5B14
6716avast_secureline_setup.tmpC:\Program Files\AVAST Software\SecureLine\locales\fa.pakbinary
MD5:8B70D5FD5CD6756F1741BF06BC45440C
SHA256:1C0AF7FA747D3C5906191FE47C1D17F7FEA3984C42F0432927E5E52D02DBC64E
3912avast_secureline_setup.exeC:\Users\admin\AppData\Local\Temp\is-2RG8A.tmp\avast_secureline_setup.tmpexecutable
MD5:3FBDF753CB148BF2D5623CD0CC746D35
SHA256:A338F50B98260C68C94BF6B96F60C84532E9E19096176DBD6532B441CC88F0F1
6716avast_secureline_setup.tmpC:\Users\admin\AppData\Local\Temp\is-J7AKU.tmp\SetupHelper.dllexecutable
MD5:E1D10A2F668B08D984E1F69B5A43B185
SHA256:FFE44B472C7F99D15E7BF46D1C2A154CC5A1E3E903952A481B02BE2D9974D499
6716avast_secureline_setup.tmpC:\Users\admin\AppData\Local\Temp\is-J7AKU.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
6716avast_secureline_setup.tmpC:\Program Files\AVAST Software\SecureLine\locales\am.pakbinary
MD5:C8E9074FAA1D9428089FE39A6340C43D
SHA256:3ABF4B49EC48EA46D97C7DEF4C4DBCE5D24D452710E8BD113CD7CFCF6280F95E
6716avast_secureline_setup.tmpC:\Users\admin\AppData\Local\Temp\is-J7AKU.tmp\_isetup\_setup64.tmpexecutable
MD5:526426126AE5D326D0A24706C77D8C5C
SHA256:B20A8D88C550981137ED831F2015F5F11517AEB649C29642D9D61DEA5EBC37D1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
81
DNS requests
50
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
6944
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
4700
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
6044
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
6044
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
2464
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
6716
avast_secureline_setup.tmp
GET
200
2.19.126.158:80
http://secureline.avast.tools.avcdn.net/tools/avast/secureline/cef_3.2623.1396.cab
DE
compressed
30.3 Mb
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
US
binary
471 b
whitelisted
748
lsass.exe
GET
200
142.250.185.227:80
http://o.pki.goog/s/wr3/vp8/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQSq0i5t2Pafi2Gw9uzwnc7KTctWgQUx4H1%2FY6I2QA8TWOiUDEkoM4j%2FiMCEQC%2BnwWNvi8IjxKialflPP66
US
binary
472 b
whitelisted
748
lsass.exe
GET
200
172.217.16.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
binary
1.41 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1584
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4360
SearchApp.exe
2.23.209.151:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.104.136.2
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.23.209.151
  • 2.23.209.156
  • 2.23.209.153
  • 2.23.209.143
  • 2.23.209.149
  • 2.23.209.154
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.150
  • 2.23.209.158
  • 2.23.209.142
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.4
  • 20.190.159.0
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.2
  • 20.190.159.73
  • 40.126.31.73
whitelisted
th.bing.com
  • 2.23.209.156
  • 2.23.209.162
  • 2.23.209.167
  • 2.23.209.171
  • 2.23.209.174
  • 2.23.209.166
  • 2.23.209.168
  • 2.23.209.160
  • 2.23.209.158
  • 2.23.209.181
  • 2.23.209.179
  • 2.23.209.175
  • 2.23.209.176
  • 2.23.209.178
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
secureline.avast.tools.avcdn.net
  • 2.19.126.158
  • 2.19.126.159
whitelisted

Threats

No threats detected
Process
Message
VpnSvc.exe
[2024-10-15 11:21:05.942] [error ] [ffl2 ] [ 6432: 3600] failed to load key 0 (error 2)
VpnSvc.exe
[2024-10-15 11:21:28.664] [error ] [AlphaClient] [ 6432: 3600] Communication with http://alpha-license-dealer.ff.avast.com/common/v1/device/unattendedtrial failed with code 268435459: 'HTTP request failed. CURL code: 7, HTTP status code: 0'.
VpnSvc.exe
[2024-10-15 11:21:28.664] [error ] [AlphaClient] [ 6432: 3600] Failure. Code: 0x10000003, message: HTTP request failed. CURL code: 7, HTTP status code: 0
VpnSvc.exe
[2024-10-15 11:21:51.192] [error ] [AlphaClient] [ 6432: 3600] Communication with http://alpha-license-dealer.ff.avast.com/common/v1/device/discoverwks failed with code 268435459: 'HTTP request failed. CURL code: 7, HTTP status code: 0'.
VpnSvc.exe
[2024-10-15 11:21:51.192] [error ] [AlphaClient] [ 6432: 3600] Failure of discover WKs. Code: 0x10000003, message: HTTP request failed. CURL code: 7, HTTP status code: 0
VpnSvc.exe
[2024-10-15 11:21:51.192] [error ] [lif ] [ 6432: 3600] Failure during regular license check. Exception: HTTP request failed. CURL code: 7, HTTP status code: 0 Code: 0x10000003 (268435459)
VpnSvc.exe
[2024-10-15 11:22:13.707] [error ] [AlphaClient] [ 6432: 948] Communication with http://alpha-license-dealer.ff.avast.com/common/v1/device/availabletrials failed with code 268435459: 'HTTP request failed. CURL code: 7, HTTP status code: 0'.
VpnSvc.exe
[2024-10-15 11:22:13.707] [error ] [AlphaClient] [ 6432: 948] Failure. Code: 0x10000003, message: HTTP request failed. CURL code: 7, HTTP status code: 0
VpnSvc.exe
[2024-10-15 11:22:13.707] [error ] [lif ] [ 6432: 948] Failure during regular attend trial check. Exception: HTTP request failed. CURL code: 7, HTTP status code: 0 Code: 0x10000003 (268435459)