File name:

avast_free_antivirus_setup_online.exe

Full analysis: https://app.any.run/tasks/1df2381e-3fba-4565-a023-2114567ec160
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 04, 2024, 18:47:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A17EB3A9296C3D7607DB2851331A679B

SHA1:

DC53C78E236B5D4E06B59A77C2BE1211E08FD3AB

SHA256:

CE142E818D35FCF9214AE04DC7C3CCF02658C031D3FF071A23AFB05F53D2F203

SSDEEP:

3072:phrEcYTuZF3sDmYFDL56DLiSNMWm5RC3Oy1jjHfJWcCAnzuVmoP7wxi6yd+gf8nY:5YTuZFuB66SBRHJWcPz8/JrLAeuTd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads settings of System Certificates

      • avast_free_antivirus_setup_online.exe (PID: 2420)
      • avast_free_antivirus_setup_online.exe (PID: 632)
      • avast_free_antivirus_setup_online.exe (PID: 2740)
      • Instup.exe (PID: 2396)
      • instup.exe (PID: 1860)
    • Reads the Internet Settings

      • instup.exe (PID: 1860)
      • Instup.exe (PID: 2396)
    • The process verifies whether the antivirus software is installed

      • instup.exe (PID: 1860)
  • INFO

    • Checks supported languages

      • avast_free_antivirus_setup_online.exe (PID: 2420)
      • avast_free_antivirus_setup_online.exe (PID: 632)
      • avast_free_antivirus_setup_online.exe (PID: 2740)
      • Instup.exe (PID: 2396)
      • instup.exe (PID: 1860)
      • aswOfferTool.exe (PID: 2520)
      • aswOfferTool.exe (PID: 2500)
      • aswOfferTool.exe (PID: 2496)
      • aswOfferTool.exe (PID: 2492)
      • aswOfferTool.exe (PID: 880)
      • sbr.exe (PID: 2820)
    • Reads the computer name

      • avast_free_antivirus_setup_online.exe (PID: 2420)
      • avast_free_antivirus_setup_online.exe (PID: 632)
      • avast_free_antivirus_setup_online.exe (PID: 2740)
      • Instup.exe (PID: 2396)
      • instup.exe (PID: 1860)
      • aswOfferTool.exe (PID: 2492)
    • Reads the machine GUID from the registry

      • avast_free_antivirus_setup_online.exe (PID: 2420)
      • avast_free_antivirus_setup_online.exe (PID: 632)
      • avast_free_antivirus_setup_online.exe (PID: 2740)
      • Instup.exe (PID: 2396)
      • instup.exe (PID: 1860)
    • Drops the executable file immediately after the start

      • avast_free_antivirus_setup_online.exe (PID: 2420)
      • avast_free_antivirus_setup_online.exe (PID: 632)
      • avast_free_antivirus_setup_online.exe (PID: 2740)
      • Instup.exe (PID: 2396)
      • aswOfferTool.exe (PID: 2492)
      • aswOfferTool.exe (PID: 2496)
      • aswOfferTool.exe (PID: 880)
      • instup.exe (PID: 1860)
    • Process requests binary or script from the Internet

      • avast_free_antivirus_setup_online.exe (PID: 2420)
      • avast_free_antivirus_setup_online.exe (PID: 632)
    • Manual execution by a user

      • avast_free_antivirus_setup_online.exe (PID: 2168)
      • avast_free_antivirus_setup_online.exe (PID: 632)
    • Creates files in the program directory

      • avast_free_antivirus_setup_online.exe (PID: 2740)
      • Instup.exe (PID: 2396)
      • instup.exe (PID: 1860)
    • Reads Environment values

      • Instup.exe (PID: 2396)
      • instup.exe (PID: 1860)
    • Checks proxy server information

      • Instup.exe (PID: 2396)
      • instup.exe (PID: 1860)
    • Dropped object may contain TOR URL's

      • Instup.exe (PID: 2396)
      • aswOfferTool.exe (PID: 2492)
      • instup.exe (PID: 1860)
    • Starts itself from another location

      • Instup.exe (PID: 2396)
      • aswOfferTool.exe (PID: 2492)
    • Reads CPU info

      • Instup.exe (PID: 2396)
      • instup.exe (PID: 1860)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:04:12 10:36:05+02:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 137216
InitializedDataSize: 117760
UninitializedDataSize: -
EntryPoint: 0x1020
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.1.99.0
ProductVersionNumber: 2.1.99.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: AVAST Software
Edition: 1
FileDescription: Avast Installer
FileVersion: 2.1.99.0
InternalName: microstub
LegalCopyright: Copyright (c) 2023 AVAST Software
OriginalFileName: microstub.exe
ProductName: Avast
ProductVersion: 2.1.99.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
13
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start avast_free_antivirus_setup_online.exe avast_free_antivirus_setup_online.exe no specs avast_free_antivirus_setup_online.exe avast_free_antivirus_setup_online.exe instup.exe instup.exe aswoffertool.exe no specs aswoffertool.exe no specs aswoffertool.exe no specs aswoffertool.exe no specs aswoffertool.exe no specs sbr.exe no specs avast_free_antivirus_setup_online.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\avast_free_antivirus_setup_online.exe" C:\Users\admin\AppData\Local\Temp\avast_free_antivirus_setup_online.exeexplorer.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Installer
Exit code:
3221226540
Version:
2.1.99.0
Modules
Images
c:\users\admin\appdata\local\temp\avast_free_antivirus_setup_online.exe
c:\windows\system32\ntdll.dll
632"C:\Users\admin\Desktop\avast_free_antivirus_setup_online.exe" C:\Users\admin\Desktop\avast_free_antivirus_setup_online.exe
explorer.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Installer
Exit code:
0
Version:
2.1.99.0
Modules
Images
c:\users\admin\appdata\local\temp\avast_free_antivirus_setup_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
880"C:\Users\Public\Documents\aswOfferTool.exe" -checkChromeReactivation -bc=AVFAC:\Users\Public\Documents\aswOfferTool.exeaswOfferTool.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Offer Installation Tool
Exit code:
0
Version:
23.12.8700.0
Modules
Images
c:\users\public\documents\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shell32.dll
1860"C:\Windows\Temp\asw.21658850ece95bd3\New_170c17ce\instup.exe" /sfx /sfxstorage:C:\Windows\Temp\asw.21658850ece95bd3 /edition:1 /prod:ais /stub_mapping_guid:9452f3f9-2896-4b4b-a083-eef84f91481d:9543376 /guid:a8e208d3-f5eb-413b-a74e-caed3fb38825 /ga_clientid:b840b984-2c90-4729-aed5-2eae9d9bea54 /cookie:mmm_ava_998_999_000_m:dlid_FAV-ONLINE-FAD /edat_dir:C:\Windows\Temp\asw.4903b762fdf48a1e /online_installerC:\Windows\Temp\asw.21658850ece95bd3\New_170c17ce\instup.exe
Instup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
23.12.8700.0
Modules
Images
c:\windows\temp\asw.21658850ece95bd3\new_170c17ce\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2168"C:\Users\admin\Desktop\avast_free_antivirus_setup_online.exe" C:\Users\admin\Desktop\avast_free_antivirus_setup_online.exeexplorer.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Installer
Exit code:
3221226540
Version:
2.1.99.0
Modules
Images
c:\users\admin\appdata\local\temp\avast_free_antivirus_setup_online.exe
c:\windows\system32\ntdll.dll
2396"C:\Windows\Temp\asw.21658850ece95bd3\instup.exe" /sfx:lite /sfxstorage:C:\Windows\Temp\asw.21658850ece95bd3 /edition:1 /prod:ais /stub_mapping_guid:9452f3f9-2896-4b4b-a083-eef84f91481d:9543376 /guid:a8e208d3-f5eb-413b-a74e-caed3fb38825 /ga_clientid:b840b984-2c90-4729-aed5-2eae9d9bea54 /cookie:mmm_ava_998_999_000_m:dlid_FAV-ONLINE-FAD /ga_clientid:b840b984-2c90-4729-aed5-2eae9d9bea54 /edat_dir:C:\Windows\Temp\asw.4903b762fdf48a1eC:\Windows\Temp\asw.21658850ece95bd3\Instup.exe
avast_free_antivirus_setup_online.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
23.12.8700.0
Modules
Images
c:\windows\temp\asw.21658850ece95bd3\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2420"C:\Users\admin\AppData\Local\Temp\avast_free_antivirus_setup_online.exe" C:\Users\admin\AppData\Local\Temp\avast_free_antivirus_setup_online.exe
explorer.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Installer
Exit code:
2250
Version:
2.1.99.0
Modules
Images
c:\users\admin\appdata\local\temp\avast_free_antivirus_setup_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2492"C:\Windows\Temp\asw.21658850ece95bd3\New_170c17ce\aswOfferTool.exe" -checkChromeReactivation -elevated -bc=AVFAC:\Windows\Temp\asw.21658850ece95bd3\New_170c17ce\aswOfferTool.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Offer Installation Tool
Exit code:
0
Version:
23.12.8700.0
Modules
Images
c:\windows\temp\asw.21658850ece95bd3\new_170c17ce\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shell32.dll
2496"C:\Windows\Temp\asw.21658850ece95bd3\New_170c17ce\aswOfferTool.exe" -checkChrome -elevatedC:\Windows\Temp\asw.21658850ece95bd3\New_170c17ce\aswOfferTool.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Offer Installation Tool
Exit code:
2
Version:
23.12.8700.0
Modules
Images
c:\windows\temp\asw.21658850ece95bd3\new_170c17ce\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shell32.dll
2500"C:\Windows\Temp\asw.21658850ece95bd3\New_170c17ce\aswOfferTool.exe" -checkGToolbar -elevatedC:\Windows\Temp\asw.21658850ece95bd3\New_170c17ce\aswOfferTool.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Offer Installation Tool
Exit code:
2
Version:
23.12.8700.0
Modules
Images
c:\windows\temp\asw.21658850ece95bd3\new_170c17ce\aswoffertool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shell32.dll
Total events
21 323
Read events
16 033
Write events
5 287
Delete events
3

Modification events

(PID) Process:(2420) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Windows\Temp\asw.152ac8803fee528f
(PID) Process:(2420) avast_free_antivirus_setup_online.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(632) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Windows\Temp\asw.152ac8803fee528f
(PID) Process:(632) avast_free_antivirus_setup_online.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2740) avast_free_antivirus_setup_online.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2740) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
0
(PID) Process:(2740) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
7
(PID) Process:(2740) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
14
(PID) Process:(2740) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
21
(PID) Process:(2740) avast_free_antivirus_setup_online.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
28
Executable files
97
Suspicious files
105
Text files
50
Unknown types
0

Dropped files

PID
Process
Filename
Type
2420avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.152ac8803fee528f\avast_free_antivirus_setup_online.exe
MD5:
SHA256:
2420avast_free_antivirus_setup_online.exeC:\windows\temp\asw.152ac8803fee528f\ecoo.edattext
MD5:BECF40C99CEBB8C75F02968502839AD3
SHA256:1DD1226BE9BEBECF9B526E5AD68B5D1C26C2D9D5DC375CE715C3FB010EA4E519
2740avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.21658850ece95bd3\servers.deftext
MD5:0C282E2638C4FFBCA99189EE61645781
SHA256:B04F0AA613C67C7CB3735D8B86CD44C073C0BCF9F604B9451F5D86755D51A322
632avast_free_antivirus_setup_online.exeC:\windows\temp\asw.4903b762fdf48a1e\ecoo.edattext
MD5:BECF40C99CEBB8C75F02968502839AD3
SHA256:1DD1226BE9BEBECF9B526E5AD68B5D1C26C2D9D5DC375CE715C3FB010EA4E519
2740avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.21658850ece95bd3\part-vps_windows-23121202.vpxbinary
MD5:854A691D96779CF04F891493DED23F6C
SHA256:E8EA9E7F99A285659D1DD08C1F1E2C7AF274662AA08CEFE7442068B00BCE5F6C
2740avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.21658850ece95bd3\config.def.vpxbinary
MD5:A1FEAC8CAC28A0F94B81BC2946E40B8F
SHA256:40CA71CEB0D85041CC54C81D98682604245136E9B74CDE678FA2594101D97664
2740avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.21658850ece95bd3\cookie.bintext
MD5:BECF40C99CEBB8C75F02968502839AD3
SHA256:1DD1226BE9BEBECF9B526E5AD68B5D1C26C2D9D5DC375CE715C3FB010EA4E519
2740avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.21658850ece95bd3\config.deftext
MD5:6E180520DD210F57F70BF5B79340DCEE
SHA256:0225CC6628BD817A27AD5C39C0C78ED1287DF90B820412AEBF0C1843CFBC8E0C
2740avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.21658850ece95bd3\part-jrog2-128b.vpxbinary
MD5:E18C174A377465D3E1212FD001C8751F
SHA256:59418DC377AF88D26C84E288129BB6C846FE48281BA7B62470FADAA04E8CE146
2740avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.21658850ece95bd3\prod-pgm.vpxbinary
MD5:170D316AD7477DE660A5836EE9DE8ECB
SHA256:1D0B140E6FD8DFD46FE4977CACA98A2132A9E767417CABDD07B9845F11C5C587
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
48
TCP/UDP connections
77
DNS requests
57
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2420
avast_free_antivirus_setup_online.exe
POST
200
142.250.185.238:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2420
avast_free_antivirus_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
GET
2.19.126.76:80
http://iavs9x.u.avcdn.net/iavs9x/avast_free_antivirus_setup_online.exe
unknown
unknown
2420
avast_free_antivirus_setup_online.exe
GET
200
193.108.153.12:80
http://iavs9x.u.avcdn.net/iavs9x/avast_free_antivirus_setup_online.exe
unknown
executable
9.10 Mb
unknown
2420
avast_free_antivirus_setup_online.exe
POST
200
216.239.38.178:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2420
avast_free_antivirus_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
632
avast_free_antivirus_setup_online.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
632
avast_free_antivirus_setup_online.exe
POST
200
216.239.38.178:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
632
avast_free_antivirus_setup_online.exe
GET
200
193.108.153.12:80
http://iavs9x.u.avcdn.net/iavs9x/avast_free_antivirus_setup_online.exe
unknown
executable
9.10 Mb
unknown
632
avast_free_antivirus_setup_online.exe
POST
200
216.239.38.178:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2420
avast_free_antivirus_setup_online.exe
34.117.223.223:80
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2420
avast_free_antivirus_setup_online.exe
142.250.185.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
2420
avast_free_antivirus_setup_online.exe
23.50.131.213:443
iavs9x.u.avcdn.net
Akamai International B.V.
DE
unknown
2420
avast_free_antivirus_setup_online.exe
2.19.126.76:80
iavs9x.u.avcdn.net
Akamai International B.V.
DE
unknown
2420
avast_free_antivirus_setup_online.exe
193.108.153.12:80
iavs9x.u.avcdn.net
Akamai International B.V.
DE
unknown
2420
avast_free_antivirus_setup_online.exe
193.108.153.12:443
iavs9x.u.avcdn.net
Akamai International B.V.
DE
unknown
2420
avast_free_antivirus_setup_online.exe
193.108.153.18:443
iavs9x.u.avcdn.net
Akamai International B.V.
DE
unknown
2420
avast_free_antivirus_setup_online.exe
216.239.38.178:80
www.google-analytics.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
iavs9x.u.avcdn.net
  • 23.50.131.213
  • 23.50.131.198
  • 2.19.126.76
  • 2.19.126.98
  • 193.108.153.12
  • 193.108.153.18
unknown
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
www.google-analytics.com
  • 142.250.185.238
  • 216.239.38.178
  • 216.239.34.178
  • 216.239.36.178
  • 216.239.32.178
whitelisted
analytics.avcdn.net
  • 34.117.223.223
unknown
shepherd.ff.avast.com
  • 34.160.176.28
whitelisted
b7210692.iavs9x.u.avast.com
  • 184.86.251.133
  • 184.86.251.136
  • 2a02:26f0:1700:15::b856:fb88
  • 2a02:26f0:1700:15::b856:fb85
whitelisted
l4691727.iavs9x.u.avast.com
  • 184.86.251.136
  • 184.86.251.133
  • 2a02:26f0:1700:15::b856:fb88
  • 2a02:26f0:1700:15::b856:fb85
whitelisted
l7814800.iavs9x.u.avast.com
  • 184.86.251.136
  • 184.86.251.133
  • 2a02:26f0:1700:15::b856:fb88
  • 2a02:26f0:1700:15::b856:fb85
whitelisted
r6726306.iavs9x.u.avast.com
  • 184.86.251.136
  • 184.86.251.133
  • 2a02:26f0:1700:15::b856:fb85
  • 2a02:26f0:1700:15::b856:fb88
whitelisted
s-iavs9x.avcdn.net
  • 23.35.225.27
  • 2a02:26f0:ab00:490::240d
  • 2a02:26f0:ab00:4af::240d
whitelisted

Threats

PID
Process
Class
Message
2420
avast_free_antivirus_setup_online.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2420
avast_free_antivirus_setup_online.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
632
avast_free_antivirus_setup_online.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
avast_free_antivirus_setup_online.exe
[2024-01-04 18:50:48.210] [info ] [sfxinst ] [ 2740: 2572] [000000: 0] Running SFX 'C:\Windows\Temp\asw.4903b762fdf48a1e\avast_free_antivirus_setup_online.exe'
avast_free_antivirus_setup_online.exe
[2024-01-04 18:50:48.491] [info ] [sfxinst ] [ 2740: 2572] [000000: 0] Moved extra data file 'ecoo.edat' to 'C:\Windows\Temp\asw.21658850ece95bd3\cookie.bin'.
avast_free_antivirus_setup_online.exe
[2024-01-04 18:50:48.835] [info ] [sfxstats ] [ 2740: 996] [000000: 0] Statistics sent successfully.
avast_free_antivirus_setup_online.exe
[2024-01-04 18:50:48.835] [notice ] [burger_rep ] [ 2740: 2468] [000000: 0] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
avast_free_antivirus_setup_online.exe
[2024-01-04 18:50:50.319] [info ] [sfxinst ] [ 2740: 2572] [000000: 0] Starting installer/updater executable 'C:\Windows\Temp\asw.21658850ece95bd3\instup.exe'
Instup.exe
[2024-01-04 18:50:50.991] [info ] [instup ] [ 2396: 2760] [000000: 0] OS: Windows 7 SP1 x86
Instup.exe
[2024-01-04 18:50:50.991] [info ] [instup ] [ 2396: 2760] [000000: 0] CPU: Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz,4
Instup.exe
[2024-01-04 18:50:50.991] [info ] [instup ] [ 2396: 2760] [000000: 0] setup: x86
Instup.exe
[2024-01-04 18:50:50.991] [info ] [instup ] [ 2396: 2760] [000000: 0] Memory: 17% load. Phys:2583180/3145208K free, Page:4194303/4194303K free, Virt:1990888/2097024K free
Instup.exe
[2024-01-04 18:50:50.991] [info ] [instup ] [ 2396: 2760] [000000: 0] Command: '"C:\Windows\Temp\asw.21658850ece95bd3\instup.exe" /sfx:lite /sfxstorage:C:\Windows\Temp\asw.21658850ece95bd3 /edition:1 /prod:ais /stub_mapping_guid:9452f3f9-2896-4b4b-a083-eef84f91481d:9543376 /guid:a8e208d3-f5eb-413b-a74e-caed3fb38825 /ga_clientid:b840b984-2c90-4729-aed5-2eae9d9bea54 /cookie:mmm_ava_998_999_000_m:dlid_FAV-ONLINE-FAD /ga_clientid:b840b984-2c90-4729-aed5-2eae9d9bea54 /edat_dir:C:\Windows\Temp\asw.4903b762fdf48a1e'