File name:

Memu-Installer_v1.75.32.037.24.exe

Full analysis: https://app.any.run/tasks/5481ead0-8c45-43c5-9517-60a9160fe45f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 30, 2021, 16:52:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

760642232DDC88CD60854C1BE00CF663

SHA1:

701971D064D1590397EC9CB99C7C5CB82915B849

SHA256:

E23A0EBFC6101BDA9F083BD18E2551D771A552F921B055C5266C2B669F9A5708

SSDEEP:

12288:UHbe+NAyYEKAj8vwfsbzxscG9ICqdX7AHpCjcWCCqkE9ijCqciQ:UHWzExkwEbtsV9/qdMHpgqL9imqciQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • Memu-Installer_v1.75.32.037.24.exe (PID: 2620)
      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 864)
      • instup.exe (PID: 3860)
      • saBSI.exe (PID: 1548)
    • Application was dropped or rewritten from another process

      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 864)
      • saBSI.exe (PID: 1548)
      • avast_free_antivirus_setup_online.exe (PID: 1452)
      • instup.exe (PID: 3860)
      • instup.exe (PID: 2156)
      • sbr.exe (PID: 2612)
      • installer.exe (PID: 3788)
      • installer.exe (PID: 2396)
      • ServiceHost.exe (PID: 2284)
    • Loads dropped or rewritten executable

      • instup.exe (PID: 3860)
      • instup.exe (PID: 2156)
      • regsvr32.exe (PID: 3916)
      • regsvr32.exe (PID: 4052)
    • Drops executable file immediately after starts

      • installer.exe (PID: 3788)
    • Changes the autorun value in the registry

      • instup.exe (PID: 2156)
    • Registers / Runs the DLL via REGSVR32.EXE

      • installer.exe (PID: 2396)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Memu-Installer_v1.75.32.037.24.exe (PID: 2620)
      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 864)
      • avast_free_antivirus_setup_online.exe (PID: 1452)
      • instup.exe (PID: 3860)
      • saBSI.exe (PID: 1548)
      • instup.exe (PID: 2156)
      • installer.exe (PID: 3788)
      • installer.exe (PID: 2396)
    • Creates files in the Windows directory

      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 864)
      • avast_free_antivirus_setup_online.exe (PID: 1452)
      • instup.exe (PID: 3860)
      • instup.exe (PID: 2156)
      • ServiceHost.exe (PID: 2284)
    • Drops a file that was compiled in debug mode

      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 864)
      • Memu-Installer_v1.75.32.037.24.exe (PID: 2620)
      • avast_free_antivirus_setup_online.exe (PID: 1452)
      • instup.exe (PID: 3860)
      • saBSI.exe (PID: 1548)
      • instup.exe (PID: 2156)
      • installer.exe (PID: 3788)
      • installer.exe (PID: 2396)
    • Low-level read access rights to disk partition

      • avast_free_antivirus_setup_online.exe (PID: 1452)
      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 864)
      • instup.exe (PID: 3860)
      • instup.exe (PID: 2156)
    • Adds / modifies Windows certificates

      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 864)
      • Memu-Installer_v1.75.32.037.24.exe (PID: 2620)
      • instup.exe (PID: 3860)
      • saBSI.exe (PID: 1548)
    • Creates files in the program directory

      • saBSI.exe (PID: 1548)
      • avast_free_antivirus_setup_online.exe (PID: 1452)
      • instup.exe (PID: 3860)
      • instup.exe (PID: 2156)
      • installer.exe (PID: 3788)
      • ServiceHost.exe (PID: 2284)
      • installer.exe (PID: 2396)
    • Drops a file with a compile date too recent

      • avast_free_antivirus_setup_online.exe (PID: 1452)
      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 864)
      • instup.exe (PID: 3860)
      • instup.exe (PID: 2156)
      • installer.exe (PID: 3788)
      • installer.exe (PID: 2396)
    • Creates or modifies windows services

      • instup.exe (PID: 3860)
    • Removes files from Windows directory

      • instup.exe (PID: 3860)
      • instup.exe (PID: 2156)
      • ServiceHost.exe (PID: 2284)
    • Starts itself from another location

      • instup.exe (PID: 3860)
    • Creates a directory in Program Files

      • installer.exe (PID: 3788)
      • instup.exe (PID: 2156)
      • installer.exe (PID: 2396)
    • Starts SC.EXE for service management

      • installer.exe (PID: 2396)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3916)
      • regsvr32.exe (PID: 4052)
    • Creates a software uninstall entry

      • installer.exe (PID: 2396)
    • Executed as Windows Service

      • ServiceHost.exe (PID: 2284)
  • INFO

    • Reads settings of System Certificates

      • Memu-Installer_v1.75.32.037.24.exe (PID: 2620)
    • Reads the hosts file

      • instup.exe (PID: 3860)
      • instup.exe (PID: 2156)
    • Dropped object may contain Bitcoin addresses

      • installer.exe (PID: 3788)
      • instup.exe (PID: 2156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (49.4)
.scr | Windows screen saver (23.4)
.dll | Win32 Dynamic Link Library (generic) (11.7)
.exe | Win32 Executable (generic) (8)
.exe | Generic Win/DOS Executable (3.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:03:14 12:06:17+01:00
PEType: PE32
LinkerVersion: 8
CodeSize: 648192
InitializedDataSize: 43520
UninitializedDataSize: -
EntryPoint: 0xa02be
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.89.0.7743
ProductVersionNumber: 1.89.0.7743
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Product Installer
CompanyName: -
FileDescription: Product Installer
FileVersion: 1.89.0.7743
InternalName: Microvirt.exe
LegalCopyright: Copyright dotSetup.io Open Source Project
LegalTrademarks: -
OriginalFileName: Microvirt.exe
ProductName: Product Installer
ProductVersion: 1.89.0.7743
AssemblyVersion: 1.89.0.7743

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 14-Mar-2021 11:06:17

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 14-Mar-2021 11:06:17
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00002000
0x0009E2D4
0x0009E400
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
7.26429
.rsrc
0x000A2000
0x0000A655
0x0000A800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.63315
.reloc
0x000AE000
0x0000000C
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.0815394

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.99436
3132
UNKNOWN
UNKNOWN
RT_MANIFEST
2
4.88192
2440
UNKNOWN
UNKNOWN
RT_ICON
3
4.55577
4264
UNKNOWN
UNKNOWN
RT_ICON
4
3.65674
9640
UNKNOWN
UNKNOWN
RT_ICON
5
7.95418
20473
UNKNOWN
UNKNOWN
RT_ICON
32512
2.64638
76
UNKNOWN
UNKNOWN
RT_GROUP_ICON

Imports

mscoree.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
17
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start memu-installer_v1.75.32.037.24.exe cookie_mmm_irs_ppi_005_888_d.exe sabsi.exe avast_free_antivirus_setup_online.exe instup.exe instup.exe installer.exe installer.exe sbr.exe no specs sc.exe no specs regsvr32.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs regsvr32.exe no specs servicehost.exe memu-installer_v1.75.32.037.24.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\Users\admin\AppData\Local\Temp\MEmu_Play_files\cookie_mmm_irs_ppi_005_888_d.exe" /psh:bEsXBLahlWXN5xesdRifdD895KOc0laNcEVsZxz7HRdCPoOaxv7HVlCoUrp9g4dO8rcfcTye5KZiErQUoxbKsI /silent /wsC:\Users\admin\AppData\Local\Temp\MEmu_Play_files\cookie_mmm_irs_ppi_005_888_d.exe
svchost.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast MicroInstaller Installer
Exit code:
0
Version:
2.1.45.0
Modules
Images
c:\users\admin\appdata\local\temp\memu_play_files\cookie_mmm_irs_ppi_005_888_d.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1452"C:\Windows\Temp\asw.a3ea6d01ee4831e8\avast_free_antivirus_setup_online.exe" /psh:bEsXBLahlWXN5xesdRifdD895KOc0laNcEVsZxz7HRdCPoOaxv7HVlCoUrp9g4dO8rcfcTye5KZiErQUoxbKsI /silent /ws /cookie:mmm_irs_ppi_005_888_d /ga_clientid:1ec321b5-2b88-41c6-95df-b8b0cf2dc91c /edat_dir:C:\Windows\Temp\asw.a3ea6d01ee4831e8C:\Windows\Temp\asw.a3ea6d01ee4831e8\avast_free_antivirus_setup_online.exe
cookie_mmm_irs_ppi_005_888_d.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus
Exit code:
0
Version:
21.2.6096.0
Modules
Images
c:\windows\temp\asw.a3ea6d01ee4831e8\avast_free_antivirus_setup_online.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1496sc.exe failure "McAfee WebAdvisor" reset= 3600 actions= restart/1/restart/1000/restart/3000/restart/30000/restart/1800000//0C:\Windows\system32\sc.exeinstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
1548"C:\Users\admin\AppData\Local\Temp\MEmu_Play_files\saBSI.exe" /affid 91082 PaidDistribution=trueC:\Users\admin\AppData\Local\Temp\MEmu_Play_files\saBSI.exe
svchost.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
McAfee WebAdvisor
Exit code:
0
Version:
4,1,0,48
Modules
Images
c:\users\admin\appdata\local\temp\memu_play_files\sabsi.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2156"C:\Windows\Temp\asw.fb97698c716e0a9c\New_15020997\instup.exe" /sfx /sfxstorage:C:\Windows\Temp\asw.fb97698c716e0a9c /edition:1 /prod:ais /guid:06873bcf-2288-4c9d-90a3-73f77f35482e /ga_clientid:1ec321b5-2b88-41c6-95df-b8b0cf2dc91c /psh:bEsXBLahlWXN5xesdRifdD895KOc0laNcEVsZxz7HRdCPoOaxv7HVlCoUrp9g4dO8rcfcTye5KZiErQUoxbKsI /silent /ws /cookie:mmm_irs_ppi_005_888_d /edat_dir:C:\Windows\Temp\asw.a3ea6d01ee4831e8 /online_installerC:\Windows\Temp\asw.fb97698c716e0a9c\New_15020997\instup.exe
instup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Exit code:
0
Version:
21.2.6096.0
Modules
Images
c:\windows\temp\asw.fb97698c716e0a9c\new_15020997\instup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2284"C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe"C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe
services.exe
User:
SYSTEM
Company:
McAfee, LLC
Integrity Level:
SYSTEM
Description:
McAfee WebAdvisor
Exit code:
0
Version:
4,1,1,582
Modules
Images
c:\program files\mcafee\webadvisor\servicehost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2344sc.exe create "McAfee WebAdvisor" binPath= "\"C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe\"" start= auto DisplayName= "McAfee WebAdvisor"C:\Windows\system32\sc.exeinstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
2396"C:\Program Files\McAfee\Temp862897314\installer.exe" /setOem:Affid=91082 /s /thirdparty /upgrade C:\Program Files\McAfee\Temp862897314\installer.exe
installer.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor
Exit code:
0
Version:
4,1,1,582
Modules
Images
c:\program files\mcafee\temp862897314\installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\bcrypt.dll
2612"C:\Windows\Temp\asw.fb97698c716e0a9c\New_15020997\sbr.exe" 2156 "Avast Antivirus setup" "Avast Antivirus is being installed. Do not shut down your computer!"C:\Windows\Temp\asw.fb97698c716e0a9c\New_15020997\sbr.exeinstup.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Shutdown blocker
Exit code:
0
Version:
21.2.6096.0
Modules
Images
c:\windows\temp\asw.fb97698c716e0a9c\new_15020997\sbr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2620"C:\Users\admin\AppData\Local\Temp\Memu-Installer_v1.75.32.037.24.exe" C:\Users\admin\AppData\Local\Temp\Memu-Installer_v1.75.32.037.24.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Product Installer
Exit code:
0
Version:
1.89.0.7743
Modules
Images
c:\users\admin\appdata\local\temp\memu-installer_v1.75.32.037.24.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
5 269
Read events
1 189
Write events
4 072
Delete events
8

Modification events

(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ASP.NET_4.0.30319\Names
Operation:writeName:Pvp9bSrQq9tjMcYXEvzUzUlDYm5HSxkkC67GAZGUlYPoD04Wo3fZiuGb9Kl8isYPo5kRbx4FoUddqmTxuT4EeKji5s4QcoAyZdH8ZRLiJv34EwykMTPeIY
Value:
2620
(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Memu-Installer_v1_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Memu-Installer_v1_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Memu-Installer_v1_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Memu-Installer_v1_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Memu-Installer_v1_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Memu-Installer_v1_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Memu-Installer_v1_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Memu-Installer_v1_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2620) Memu-Installer_v1.75.32.037.24.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Memu-Installer_v1_RASMANCS
Operation:writeName:FileTracingMask
Value:
4294901760
Executable files
53
Suspicious files
323
Text files
921
Unknown types
16

Dropped files

PID
Process
Filename
Type
1452avast_free_antivirus_setup_online.exeC:\ProgramData\Avast Software\Persistent Data\Avast\Logs\Setup.log
MD5:
SHA256:
864cookie_mmm_irs_ppi_005_888_d.exeC:\Windows\Temp\asw.a3ea6d01ee4831e8\avast_free_antivirus_setup_online.exeexecutable
MD5:
SHA256:
1452avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.fb97698c716e0a9c\servers.deftext
MD5:
SHA256:
1452avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.fb97698c716e0a9c\prod-vps.vpxbinary
MD5:
SHA256:
1452avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.fb97698c716e0a9c\config.def.vpxbinary
MD5:
SHA256:
1452avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.fb97698c716e0a9c\part-setup_ais-15020997.vpxbinary
MD5:
SHA256:
1452avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.fb97698c716e0a9c\instup_ais-997.vpx
MD5:
SHA256:
3860instup.exeC:\Windows\Temp\asw.fb97698c716e0a9c\config.def.new
MD5:
SHA256:
1548saBSI.exeC:\ProgramData\McAfee\WebAdvisor\saBSI.exe\log_00000057003F001D0006.txttext
MD5:
SHA256:
1452avast_free_antivirus_setup_online.exeC:\Windows\Temp\asw.fb97698c716e0a9c\part-jrog2-80e.vpxbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
342
TCP/UDP connections
80
DNS requests
61
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
864
cookie_mmm_irs_ppi_005_888_d.exe
GET
200
2.16.107.50:80
http://iavs9x.u.avast.com/iavs9x/avast_free_antivirus_setup_online.exe
unknown
executable
8.18 Mb
whitelisted
3860
instup.exe
GET
200
88.221.134.129:80
http://p1043812.iavs9x.u.avast.com/iavs9x/servers.def.vpx
unknown
binary
3.24 Kb
suspicious
3860
instup.exe
GET
200
88.221.134.105:80
http://m0658849.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
unknown
binary
602 b
whitelisted
1548
saBSI.exe
GET
304
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.2 Kb
whitelisted
1548
saBSI.exe
GET
304
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.2 Kb
whitelisted
2156
instup.exe
GET
200
88.221.134.90:80
http://z4055813.vps18tiny.u.avcdn.net/vps18tiny/part-jrog2-49.vpx
unknown
binary
211 b
suspicious
2156
instup.exe
GET
200
88.221.134.90:80
http://z4055813.vps18tiny.u.avcdn.net/vps18tiny/prod-vps.vpx
unknown
binary
342 b
suspicious
2156
instup.exe
GET
200
88.221.134.90:80
http://z4055813.vps18tiny.u.avcdn.net/vps18tiny/part-vps_windows-21032913.vpx
unknown
binary
6.85 Kb
suspicious
1548
saBSI.exe
GET
304
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.2 Kb
whitelisted
1548
saBSI.exe
GET
304
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.2 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2620
Memu-Installer_v1.75.32.037.24.exe
143.204.214.188:443
dbvpmgqc3t8gs.cloudfront.net
US
unknown
143.204.214.188:443
dbvpmgqc3t8gs.cloudfront.net
US
unknown
864
cookie_mmm_irs_ppi_005_888_d.exe
216.58.212.142:80
www.google-analytics.com
Google Inc.
US
whitelisted
864
cookie_mmm_irs_ppi_005_888_d.exe
5.62.40.213:80
v7event.stats.avast.com
AVAST Software s.r.o.
DE
unknown
864
cookie_mmm_irs_ppi_005_888_d.exe
2.16.107.50:443
iavs9x.u.avast.com
Akamai International B.V.
suspicious
1548
saBSI.exe
2.18.233.229:443
sadownload.mcafee.com
Akamai International B.V.
whitelisted
1548
saBSI.exe
104.208.16.0:443
cu1pehnswad01.servicebus.windows.net
Microsoft Corporation
US
unknown
1452
avast_free_antivirus_setup_online.exe
216.58.212.142:80
www.google-analytics.com
Google Inc.
US
whitelisted
1452
avast_free_antivirus_setup_online.exe
5.62.40.213:443
v7event.stats.avast.com
AVAST Software s.r.o.
DE
unknown
864
cookie_mmm_irs_ppi_005_888_d.exe
2.16.107.50:80
iavs9x.u.avast.com
Akamai International B.V.
suspicious

DNS requests

Domain
IP
Reputation
dbvpmgqc3t8gs.cloudfront.net
  • 143.204.214.188
  • 143.204.214.193
  • 143.204.214.58
  • 143.204.214.151
whitelisted
cu1pehnswad01.servicebus.windows.net
  • 104.208.16.0
whitelisted
iavs9x.u.avast.com
  • 2.16.107.50
  • 2.16.107.98
whitelisted
www.google-analytics.com
  • 216.58.212.142
whitelisted
v7event.stats.avast.com
  • 5.62.40.213
  • 5.62.40.204
  • 69.94.77.206
  • 69.94.77.205
whitelisted
sadownload.mcafee.com
  • 2.18.233.229
whitelisted
shepherd.ff.avast.com
  • 77.234.44.81
  • 5.62.45.42
whitelisted
h4444966.iavs9x.u.avast.com
  • 88.221.134.129
  • 88.221.134.105
whitelisted
m0658849.iavs9x.u.avast.com
  • 88.221.134.129
  • 88.221.134.105
whitelisted
p1043812.iavs9x.u.avast.com
  • 88.221.134.129
  • 88.221.134.105
suspicious

Threats

PID
Process
Class
Message
864
cookie_mmm_irs_ppi_005_888_d.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
saBSI.exe
NotComDllGetInterface: DLL not found in install location, looking in current directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\MEmu_Play_files\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\MEmu_Play_files\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NotComDllGetInterface: DLL not found in install location, looking in current directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\MEmu_Play_files\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\MEmu_Play_files\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NotComDllGetInterface: DLL not found in install location, looking in current directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\MEmu_Play_files\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\MEmu_Play_files\mfeaaca.dll, WinVerifyTrust failed with 80092003
installer.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
installer.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
installer.exe
NotComDllGetInterface: C:\Program Files\McAfee\Temp862897314\installer.exe loading C:\Program Files\McAfee\Temp862897314\mfeaaca.dll, WinVerifyTrust failed with 80092003
installer.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory