File name:

avast_free_antivirus_setup_online.exe

Full analysis: https://app.any.run/tasks/6b58095e-5938-4ce1-84c0-dc4f67c25ed6
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 28, 2024, 09:57:06
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D07C602BAC96CEAC50AD156102028FE0

SHA1:

AD6BE849084C9BB1AEC7B3A84CCD508A3D5E50F4

SHA256:

C9496F3EAE906F35076F1C25D9E640B8ABC5170CB0CF601120ACD7CE4F184061

SSDEEP:

3072:nhrEcYTuZF3sDmYFDL56DLiSNMWm5RC3Oy1jjHfJWcCAnzuVmoP7wxi6yd+gf8n1:HYTuZFuB66SBRHJWcPz8/JrLASuTD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • avast_free_antivirus_setup_online.exe (PID: 7188)
      • avast_free_antivirus_setup_online_x64.exe (PID: 7992)
      • Instup.exe (PID: 8120)
      • aswOfferTool.exe (PID: 996)
      • aswOfferTool.exe (PID: 7464)
      • aswOfferTool.exe (PID: 4992)
    • Changes the autorun value in the registry

      • instup.exe (PID: 4940)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • avast_free_antivirus_setup_online.exe (PID: 7188)
      • avast_free_antivirus_setup_online_x64.exe (PID: 7992)
      • Instup.exe (PID: 8120)
      • aswOfferTool.exe (PID: 996)
      • aswOfferTool.exe (PID: 7464)
      • aswOfferTool.exe (PID: 4992)
    • Potential Corporate Privacy Violation

      • avast_free_antivirus_setup_online.exe (PID: 7188)
    • The process verifies whether the antivirus software is installed

      • instup.exe (PID: 4940)
    • Process checks presence of unattended files

      • instup.exe (PID: 4940)
    • Starts itself from another location

      • Instup.exe (PID: 8120)
      • aswOfferTool.exe (PID: 7464)
    • Likely accesses (executes) a file from the Public directory

      • aswOfferTool.exe (PID: 4992)
  • INFO

    • Reads the software policy settings

      • avast_free_antivirus_setup_online.exe (PID: 7188)
      • avast_free_antivirus_setup_online_x64.exe (PID: 7992)
      • Instup.exe (PID: 8120)
      • instup.exe (PID: 4940)
    • Checks supported languages

      • avast_free_antivirus_setup_online.exe (PID: 7188)
      • avast_free_antivirus_setup_online_x64.exe (PID: 7992)
      • Instup.exe (PID: 8120)
      • instup.exe (PID: 4940)
      • aswOfferTool.exe (PID: 4704)
      • aswOfferTool.exe (PID: 364)
      • aswOfferTool.exe (PID: 996)
      • aswOfferTool.exe (PID: 7464)
      • aswOfferTool.exe (PID: 4992)
      • sbr.exe (PID: 7752)
    • Reads the computer name

      • avast_free_antivirus_setup_online.exe (PID: 7188)
      • avast_free_antivirus_setup_online_x64.exe (PID: 7992)
      • Instup.exe (PID: 8120)
      • instup.exe (PID: 4940)
      • aswOfferTool.exe (PID: 7464)
    • Reads the machine GUID from the registry

      • avast_free_antivirus_setup_online.exe (PID: 7188)
      • avast_free_antivirus_setup_online_x64.exe (PID: 7992)
      • Instup.exe (PID: 8120)
      • instup.exe (PID: 4940)
    • Reads CPU info

      • avast_free_antivirus_setup_online_x64.exe (PID: 7992)
      • Instup.exe (PID: 8120)
      • instup.exe (PID: 4940)
    • Creates files in the program directory

      • avast_free_antivirus_setup_online_x64.exe (PID: 7992)
      • Instup.exe (PID: 8120)
      • instup.exe (PID: 4940)
    • Checks proxy server information

      • avast_free_antivirus_setup_online_x64.exe (PID: 7992)
      • Instup.exe (PID: 8120)
      • instup.exe (PID: 4940)
    • Reads Environment values

      • Instup.exe (PID: 8120)
      • instup.exe (PID: 4940)
    • Dropped object may contain TOR URL's

      • aswOfferTool.exe (PID: 7464)
      • Instup.exe (PID: 8120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:04:12 08:36:05+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 137216
InitializedDataSize: 117760
UninitializedDataSize: -
EntryPoint: 0x1020
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.1.99.0
ProductVersionNumber: 2.1.99.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: AVAST Software
Edition: 1
FileDescription: Avast Installer
FileVersion: 2.1.99.0
InternalName: microstub
LegalCopyright: Copyright (c) 2023 AVAST Software
OriginalFileName: microstub.exe
ProductName: Avast
ProductVersion: 2.1.99.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
12
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start avast_free_antivirus_setup_online.exe slui.exe no specs avast_free_antivirus_setup_online_x64.exe instup.exe instup.exe aswoffertool.exe no specs aswoffertool.exe no specs aswoffertool.exe aswoffertool.exe aswoffertool.exe sbr.exe no specs avast_free_antivirus_setup_online.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
364"C:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\aswOfferTool.exe" -checkGToolbar -elevatedC:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\aswOfferTool.exeinstup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Offer Installation Tool
Exit code:
2
Version:
24.7.9311.0
Modules
Images
c:\windows\temp\asw.d6d057f845947dd9\new_180717ec\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
996"C:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\aswOfferTool.exe" -checkChrome -elevatedC:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\aswOfferTool.exe
instup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Offer Installation Tool
Exit code:
2
Version:
24.7.9311.0
Modules
Images
c:\windows\temp\asw.d6d057f845947dd9\new_180717ec\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
4704"C:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\aswOfferTool.exe" /check_secure_browserC:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\aswOfferTool.exeinstup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Offer Installation Tool
Exit code:
0
Version:
24.7.9311.0
Modules
Images
c:\windows\temp\asw.d6d057f845947dd9\new_180717ec\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
4940"C:\WINDOWS\Temp\asw.d6d057f845947dd9\New_180717ec\instup.exe" /sfx /sfxstorage:C:\WINDOWS\Temp\asw.d6d057f845947dd9 /edition:1 /prod:ais /stub_context:1ec28375-b4f4-4a80-ad3c-5f51b7b2bc06:9931880 /guid:8db1836f-8701-48c6-b34a-4d525284c190 /ga_clientid:881d754d-e310-4afb-aadc-3790acdae88c /cookie:mmm_sft_dlp_007_800_m /edat_dir:C:\WINDOWS\Temp\asw.36ce8b9c8d196f51 /online_installerC:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\instup.exe
Instup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Version:
24.7.9311.0
Modules
Images
c:\windows\temp\asw.d6d057f845947dd9\new_180717ec\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wininet.dll
4992"C:\Users\Public\Documents\aswOfferTool.exe" -checkChromeReactivation -bc=AVFCC:\Users\Public\Documents\aswOfferTool.exe
aswOfferTool.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
Avast Offer Installation Tool
Exit code:
0
Version:
24.7.9311.0
Modules
Images
c:\users\public\documents\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\wtsapi32.dll
5272"C:\Users\admin\AppData\Local\Temp\avast_free_antivirus_setup_online.exe" C:\Users\admin\AppData\Local\Temp\avast_free_antivirus_setup_online.exeexplorer.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Installer
Exit code:
3221226540
Version:
2.1.99.0
Modules
Images
c:\users\admin\appdata\local\temp\avast_free_antivirus_setup_online.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7188"C:\Users\admin\AppData\Local\Temp\avast_free_antivirus_setup_online.exe" C:\Users\admin\AppData\Local\Temp\avast_free_antivirus_setup_online.exe
explorer.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Installer
Version:
2.1.99.0
Modules
Images
c:\users\admin\appdata\local\temp\avast_free_antivirus_setup_online.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7464"C:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\aswOfferTool.exe" -checkChromeReactivation -elevated -bc=AVFCC:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\aswOfferTool.exe
instup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Offer Installation Tool
Exit code:
0
Version:
24.7.9311.0
Modules
Images
c:\windows\temp\asw.d6d057f845947dd9\new_180717ec\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
7752"C:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\sbr.exe" 4940 "Avast Antivirus setup" "Avast Antivirus is being installed. Do not shut down your computer!"C:\Windows\Temp\asw.d6d057f845947dd9\New_180717ec\sbr.exeinstup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Shutdown blocker
Version:
24.7.9311.0
Modules
Images
c:\windows\temp\asw.d6d057f845947dd9\new_180717ec\sbr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7912C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
8 077
Read events
5 288
Write events
2 785
Delete events
4

Modification events

(PID) Process:(7188) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\WINDOWS\Temp\asw.36ce8b9c8d196f51
(PID) Process:(7992) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avast Software
Operation:delete keyName:(default)
Value:
(PID) Process:(7992) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avast Software
Operation:writeName:SymbolicLinkValue
Value:
\Registry\MACHINE\SOFTWARE\Avast Software
(PID) Process:(7992) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
0
(PID) Process:(7992) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
7
(PID) Process:(7992) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
14
(PID) Process:(7992) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
21
(PID) Process:(7992) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
28
(PID) Process:(7992) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
35
(PID) Process:(7992) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
42
Executable files
27
Suspicious files
34
Text files
24
Unknown types
0

Dropped files

PID
Process
Filename
Type
7992avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.d6d057f845947dd9\part-prg_ais-180717ec.vpxbinary
MD5:863FC6CED83C3C1D2C0F86BB13C2ECE5
SHA256:C2A34DA73D79E47045F9393B8647C19F76E5A65275B183688E8C86365D92EBEE
7992avast_free_antivirus_setup_online_x64.exeC:\ProgramData\Avast Software\Persistent Data\Avast\Logs\Setup.logtext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
7992avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.d6d057f845947dd9\uata64.vpxbinary
MD5:48E949CC88D14AE464758D092E0A146E
SHA256:1D7B0513CC1AD2CB00BF3713EF896F7867A3A5D2700778870108700EA3ACA833
7992avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.d6d057f845947dd9\uat.vpxbinary
MD5:534B2BAD93BB812AE191B5506AE23565
SHA256:7A31F6F6CB37D42A0356AEB5DD2D803B6634DC6EFE1763BED59ACA6431B955AF
7992avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.d6d057f845947dd9\config.defini
MD5:FCF68190FC0BA5391E263B655517AAA8
SHA256:16C38A08F2CA7DEAE058EE282251E0D9E35CD6796B7329EBA3E17C7131663F62
7992avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.d6d057f845947dd9\part-jrog2-1523.vpxbinary
MD5:F86F404DB4551F2B29007E8353842A9D
SHA256:D02A702AEF6DE2BB6EDD3938A4F85EC493B84AB5E187D60E3804727449258F01
7992avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.d6d057f845947dd9\prod-vps.vpxbinary
MD5:CB735F402A40AF7524E40C985F2D6A73
SHA256:3DA748535868AF14439A64817A334DAF08C6C7D6F865AF5D5130E22D49A270B0
7992avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.d6d057f845947dd9\prod-pgm.vpxbinary
MD5:1EDD4C0A0428F8F05DF0AD463224C839
SHA256:FA8EB5231CC8EFEFE0B9E5F3FD50B90234E46A2DD3EC8469C3E783D0F5398CF6
7992avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.d6d057f845947dd9\uat64.vpxbinary
MD5:E7908971C7F59401CEB35DB59CBADDED
SHA256:0BF0605894B5660DAF656C950606F1FCFEBC480921F1BC09C5726AF08C1D16F4
7992avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.d6d057f845947dd9\HTMLayout.dllexecutable
MD5:110089114750B59CDB11577A55847B4A
SHA256:E3F9EB4243A735283FB32FD6FC0E3A37B0B761C56E913198ED4B5ED81F9CC122
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
79
DNS requests
122
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8120
Instup.exe
GET
200
23.48.23.157:80
http://r0965026.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
unknown
whitelisted
8120
Instup.exe
GET
23.48.23.157:80
http://r0965026.iavs9x.u.avast.com/iavs9x/avbugreport_x64_ais-a45.vpx
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
8120
Instup.exe
GET
200
23.48.23.157:80
http://r0965026.iavs9x.u.avast.com/iavs9x/avdump_x64_ais-a45.vpx
unknown
whitelisted
8120
Instup.exe
GET
200
23.48.23.157:80
http://r0965026.iavs9x.u.avast.com/iavs9x/avdump_x86_ais-a45.vpx
unknown
whitelisted
8120
Instup.exe
GET
200
23.48.23.157:80
http://r0965026.iavs9x.u.avast.com/iavs9x/instcont_x64_ais-a45.vpx
unknown
whitelisted
8120
Instup.exe
GET
200
23.48.23.157:80
http://r0965026.iavs9x.u.avast.com/iavs9x/offertool_x64_ais-a45.vpx
unknown
whitelisted
8120
Instup.exe
GET
200
23.48.23.157:80
http://r0965026.iavs9x.u.avast.com/iavs9x/instup_x64_ais-a45.vpx
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:138
whitelisted
4648
slui.exe
40.91.76.224:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5368
SearchApp.exe
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
5368
SearchApp.exe
92.123.104.10:443
www.bing.com
Akamai International B.V.
DE
unknown
3952
svchost.exe
239.255.255.250:1900
whitelisted
5368
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:137
whitelisted
4424
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3296
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 92.123.104.10
  • 92.123.104.11
  • 92.123.104.7
  • 92.123.104.13
  • 92.123.104.18
  • 92.123.104.12
  • 92.123.104.9
  • 92.123.104.17
  • 92.123.104.14
whitelisted
google.com
  • 142.250.186.46
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.4
  • 40.126.31.67
  • 20.190.159.73
  • 20.190.159.68
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
www.google-analytics.com
  • 142.250.181.238
whitelisted

Threats

PID
Process
Class
Message
7188
avast_free_antivirus_setup_online.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
avast_free_antivirus_setup_online_x64.exe
[2024-07-28 09:57:26.667] [info ] [sfxinst ] [ 7992: 7996] [F8CC93: 395] Running SFX 'C:\WINDOWS\Temp\asw.36ce8b9c8d196f51\avast_free_antivirus_setup_online_x64.exe'
avast_free_antivirus_setup_online_x64.exe
[2024-07-28 09:57:26.995] [info ] [sfxinst ] [ 7992: 7996] [F8CC93: 629] Moved extra data file 'ecoo.edat' to 'C:\WINDOWS\Temp\asw.d6d057f845947dd9\cookie.bin'.
avast_free_antivirus_setup_online_x64.exe
[2024-07-28 09:57:27.120] [notice ] [burger_rep ] [ 7992: 8032] [DC075C: 64] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
avast_free_antivirus_setup_online_x64.exe
[2024-07-28 09:57:27.120] [info ] [sfxstats ] [ 7992: 8028] [9A143C: 149] Statistics sent successfully.
avast_free_antivirus_setup_online_x64.exe
[2024-07-28 09:57:27.698] [info ] [sfxinst ] [ 7992: 7996] [F8CC93: 919] Starting installer/updater executable 'C:\WINDOWS\Temp\asw.d6d057f845947dd9\instup.exe'
Instup.exe
[2024-07-28 09:57:28.166] [debug ] [repsup ] [ 8120: 8124] [84102E: 58] PfroMutant: \PendingRenameMutex mutant has been successfully opened.
Instup.exe
[2024-07-28 09:57:28.166] [info ] [instup ] [ 8120: 8124] [EE4A6B:2658] Command: '"C:\WINDOWS\Temp\asw.d6d057f845947dd9\instup.exe" /sfx:lite /sfxstorage:C:\WINDOWS\Temp\asw.d6d057f845947dd9 /edition:1 /prod:ais /stub_context:1ec28375-b4f4-4a80-ad3c-5f51b7b2bc06:9931880 /guid:8db1836f-8701-48c6-b34a-4d525284c190 /ga_clientid:881d754d-e310-4afb-aadc-3790acdae88c /cookie:mmm_sft_dlp_007_800_m /ga_clientid:881d754d-e310-4afb-aadc-3790acdae88c /edat_dir:C:\WINDOWS\Temp\asw.36ce8b9c8d196f51'
Instup.exe
[2024-07-28 09:57:28.166] [info ] [instup ] [ 8120: 8124] [EE4A6B:2664] CPU: Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz,4
Instup.exe
[2024-07-28 09:57:28.166] [info ] [instup ] [ 8120: 8124] [EE4A6B:2669] OS: Windows 10 (10.0.19045) x64
Instup.exe
[2024-07-28 09:57:28.166] [info ] [instup ] [ 8120: 8124] [EE4A6B:2675] setup: x64