| File name: | MDE_File_Sample_68acd154482de8ed56d00471918edc903660c0e5.zip |
| Full analysis: | https://app.any.run/tasks/cd6bf994-5cab-4023-9fb6-477f90409dde |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | October 03, 2025, 17:45:16 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 260A90948E2C0734614259F85BAD77DD |
| SHA1: | 768E1B580C8D772D2B1A2B85BEA3E049B11A9513 |
| SHA256: | E2A858B9D01D15B78C53186E4A5280BE95B1226DDFF63779BA449794DA6ADE33 |
| SSDEEP: | 49152:m8EsEX8ADpPVzCqGGqv8Ujh3bOXT2ra7d/Wumbu03qdGcZGajv29lXveilMIeYIu:PmneIUjsqr2T06dGsOD29ILIZouvTHsT |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0001 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2025:10:03 15:13:58 |
| ZipCRC: | 0x08212410 |
| ZipCompressedSize: | 1394974 |
| ZipUncompressedSize: | 1921712 |
| ZipFileName: | spss-29.0-installer_8yA-xh1.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 464 | C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{69AD52AF-D24B-44D6-9DB7-D1D6B50CF715} | C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exe | — | msiexec.exe | |||||||||||
User: admin Company: Flexera Integrity Level: HIGH Description: InstallShield (R) 64-bit Setup Engine Exit code: 0 Version: 26.0.717 Modules
| |||||||||||||||
| 532 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:14 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1388 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1388 | C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{11A86434-37C1-45DE-B12C-FD99DACE2260} | C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exe | — | msiexec.exe | |||||||||||
User: admin Company: Flexera Integrity Level: HIGH Description: InstallShield (R) 64-bit Setup Engine Exit code: 0 Version: 26.0.717 Modules
| |||||||||||||||
| 1516 | C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{8BD1567C-6341-476C-B088-5F2DED2823D3} | C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exe | — | msiexec.exe | |||||||||||
User: admin Company: Flexera Integrity Level: HIGH Description: InstallShield (R) 64-bit Setup Engine Exit code: 0 Version: 26.0.717 Modules
| |||||||||||||||
| 1532 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb6916.17190\spss-29.0-installer_8yA-xh1.exe" /SPAWNWND=$6026A /NOTIFYWND=$6037C | C:\Users\admin\AppData\Local\Temp\Rar$EXb6916.17190\spss-29.0-installer_8yA-xh1.exe | spss-29.0-installer_8yA-xh1.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Softonic International Exit code: 3221226525 Version: 2.41.3.9395 Modules
| |||||||||||||||
| 1700 | "C:\Users\admin\AppData\Local\Temp\is-O6Q9L.tmp\spss-29.0-installer_8yA-xh1.tmp" /SL5="$6037C,849122,844800,C:\Users\admin\AppData\Local\Temp\Rar$EXb6916.17190\spss-29.0-installer_8yA-xh1.exe" | C:\Users\admin\AppData\Local\Temp\is-O6Q9L.tmp\spss-29.0-installer_8yA-xh1.tmp | — | spss-29.0-installer_8yA-xh1.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 3221226525 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2260 | C:\Windows\syswow64\MsiExec.exe -Embedding 4829E23873EE6B0E7463349665108308 C | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2328 | "C:\WINDOWS\Temp\asw.d4930a556df44c51\New_19091821\instup.exe" /sfx /sfxstorage:C:\WINDOWS\Temp\asw.d4930a556df44c51 /edition:1 /prod:ais /stub_context:210cf6c4-5b2d-463c-a653-1b22ed02a666:11812328 /guid:445307ce-fe88-4b99-9fc8-a2dbb64bffcc /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /silent /ws /psh:2bJ1koYmFQ1qzFcLU92XzQ7m7VeTwug3xEPzMfymA7x0X52qVgKhPLaq3f6YgGuvt24Y60wRc9cps /cookie:mmm_irs_ppi_005_888_a /edat_dir:C:\WINDOWS\Temp\asw.bf5885021530f23f /online_installer | C:\Windows\Temp\asw.d4930a556df44c51\New_19091821\instup.exe | Instup.exe | ||||||||||||
User: admin Company: Gen Digital Inc. Integrity Level: HIGH Description: Avast Antivirus Installer Version: 25.9.10453.0 Modules
| |||||||||||||||
| 2368 | "C:\WINDOWS\Temp\asw.d4930a556df44c51\instup.exe" /sfx:lite /sfxstorage:C:\WINDOWS\Temp\asw.d4930a556df44c51 /edition:1 /prod:ais /stub_context:210cf6c4-5b2d-463c-a653-1b22ed02a666:11812328 /guid:445307ce-fe88-4b99-9fc8-a2dbb64bffcc /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /silent /ws /psh:2bJ1koYmFQ1qzFcLU92XzQ7m7VeTwug3xEPzMfymA7x0X52qVgKhPLaq3f6YgGuvt24Y60wRc9cps /cookie:mmm_irs_ppi_005_888_a /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /edat_dir:C:\WINDOWS\Temp\asw.bf5885021530f23f | C:\Windows\Temp\asw.d4930a556df44c51\Instup.exe | avast_free_antivirus_setup_online_x64.exe | ||||||||||||
User: admin Company: Gen Digital Inc. Integrity Level: HIGH Description: Avast Antivirus Installer Version: 25.9.10453.0 Modules
| |||||||||||||||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_68acd154482de8ed56d00471918edc903660c0e5.zip | |||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6916) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7996 | spss-29.0-installer_8yA-xh1.tmp | C:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\is-JH0NQ.tmp | — | |
MD5:— | SHA256:— | |||
| 7996 | spss-29.0-installer_8yA-xh1.tmp | C:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\is-74PJ2.tmp | — | |
MD5:— | SHA256:— | |||
| 7996 | spss-29.0-installer_8yA-xh1.tmp | C:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\spss-29.0-installer.exe | — | |
MD5:— | SHA256:— | |||
| 7996 | spss-29.0-installer_8yA-xh1.tmp | C:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\SUCCESS.png | image | |
MD5:E8C9048FAF21F1CC959D73A0DE5534FD | SHA256:2B394E114DEB3A0700C70FEB80D74328C4C8668AA221B0E427DE783D1AB8371E | |||
| 7996 | spss-29.0-installer_8yA-xh1.tmp | C:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\100.png | image | |
MD5:251390CBB5EA35B7F1D479925C7B3F47 | SHA256:87D24EF5838C4FA66FAAE6B41BAAD2EA5F6E60B7E0CA0F30725F181B02F36A57 | |||
| 6296 | avast_free_antivirus_setup_online_x64.exe | C:\Windows\Temp\asw.d4930a556df44c51\cookie.bin | text | |
MD5:C1C3F32398130DFB38F9847F02F6786E | SHA256:25EC04BCE97A15D7ABF948FEFAEEAD48E95ABC5F945361759D8BCC05BB20638F | |||
| 4676 | cookie_mmm_irs_ppi_005_888_a.exe | C:\Windows\Temp\asw.bf5885021530f23f\ecoo.edat | text | |
MD5:C1C3F32398130DFB38F9847F02F6786E | SHA256:25EC04BCE97A15D7ABF948FEFAEEAD48E95ABC5F945361759D8BCC05BB20638F | |||
| 3628 | spss-29.0-installer_8yA-xh1.exe | C:\Users\admin\AppData\Local\Temp\is-O6Q9L.tmp\spss-29.0-installer_8yA-xh1.tmp | executable | |
MD5:A1E3F469D5CE6AB9E93B25AF0EFD31E0 | SHA256:165F2E0686659069178F6D30C7385B2FDDFDB267628AD0BF63E361CF4B9C9CAF | |||
| 6916 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb6916.17190\spss-29.0-installer_8yA-xh1.exe | executable | |
MD5:19621C5778A6C9B73BC140EF3DE1D6FB | SHA256:4F987AD8B165B950CED5806BBB8B6308A0073B8BA080C59D39673B01D72358C5 | |||
| 7996 | spss-29.0-installer_8yA-xh1.tmp | C:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\is-7SNE7.tmp | — | |
MD5:251390CBB5EA35B7F1D479925C7B3F47 | SHA256:87D24EF5838C4FA66FAAE6B41BAAD2EA5F6E60B7E0CA0F30725F181B02F36A57 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1048 | svchost.exe | GET | 200 | 172.66.2.5:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
3116 | backgroundTaskHost.exe | GET | 200 | 172.66.2.5:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | US | binary | 313 b | whitelisted |
4284 | backgroundTaskHost.exe | GET | 200 | 172.66.2.5:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | US | binary | 471 b | whitelisted |
2356 | backgroundTaskHost.exe | GET | 200 | 172.66.2.5:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | US | binary | 471 b | whitelisted |
4676 | cookie_mmm_irs_ppi_005_888_a.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | US | — | — | whitelisted |
4676 | cookie_mmm_irs_ppi_005_888_a.exe | GET | — | 2.16.168.206:80 | http://iavs9x.u.avast.com/iavs9x/avast_free_antivirus_setup_online_x64.exe | RU | — | — | whitelisted |
4676 | cookie_mmm_irs_ppi_005_888_a.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | US | — | — | whitelisted |
2368 | Instup.exe | GET | 200 | 2.16.10.82:80 | http://n4291289.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx | AT | binary | 571 b | whitelisted |
2368 | Instup.exe | GET | 200 | 2.16.10.82:80 | http://n4291289.iavs9x.u.avast.com/iavs9x/servers.def.vpx | AT | binary | 2.39 Kb | whitelisted |
2368 | Instup.exe | GET | 200 | 2.16.10.82:80 | http://n4291289.iavs9x.u.avast.com/iavs9x/avdump_x64_ais-a7a.vpx | AT | binary | 1.05 Mb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6924 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5224 | SearchApp.exe | 2.16.241.218:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1048 | svchost.exe | 20.190.159.23:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1048 | svchost.exe | 172.66.2.5:80 | ocsp.digicert.com | — | US | whitelisted |
3116 | backgroundTaskHost.exe | 2.16.241.218:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
3116 | backgroundTaskHost.exe | 172.66.2.5:80 | ocsp.digicert.com | — | US | whitelisted |
3464 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
d1v40plrti2oiz.cloudfront.net |
| malicious |
images.sftcdn.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | A Network Trojan was detected | ET ADWARE_PUP Win32/OfferCore Checkin M1 |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] InnoSetup Installer |
— | — | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] InnoSetup Installer |
4676 | cookie_mmm_irs_ppi_005_888_a.exe | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
— | — | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] InnoSetup Installer |
Process | Message |
|---|---|
avast_free_antivirus_setup_online_x64.exe | [2025-10-03 17:46:48.192] [notice ] [sfxinst ] [ 6296: 4936] [A199AD: 393] Registry link creation 'SOFTWARE\WOW6432Node\Avast Software' -> 'SOFTWARE\Avast Software' was successful.
|
avast_free_antivirus_setup_online_x64.exe | [2025-10-03 17:46:48.192] [info ] [sfxinst ] [ 6296: 4936] [A199AD: 410] Running SFX 'C:\WINDOWS\Temp\asw.bf5885021530f23f\avast_free_antivirus_setup_online_x64.exe'
|
avast_free_antivirus_setup_online_x64.exe | [2025-10-03 17:46:48.254] [info ] [sfxinst ] [ 6296: 4936] [A199AD: 658] Moved extra data file 'ecoo.edat' to 'C:\WINDOWS\Temp\asw.d4930a556df44c51\cookie.bin'.
|
avast_free_antivirus_setup_online_x64.exe | [2025-10-03 17:46:48.426] [notice ] [burger_rep ] [ 6296: 6404] [E73597: 64] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
|
avast_free_antivirus_setup_online_x64.exe | [2025-10-03 17:46:48.426] [info ] [sfxstats ] [ 6296: 7920] [CA7C4C: 149] Statistics sent successfully.
|
avast_free_antivirus_setup_online_x64.exe | [2025-10-03 17:46:49.489] [info ] [sfxinst ] [ 6296: 4936] [A199AD: 964] Starting installer/updater executable 'C:\WINDOWS\Temp\asw.d4930a556df44c51\instup.exe'
|
Instup.exe | [2025-10-03 17:46:49.817] [debug ] [repsup ] [ 2368: 4312] [15D746: 58] PfroMutant: \PendingRenameMutex mutant has been successfully opened.
|
Instup.exe | [2025-10-03 17:46:49.817] [info ] [instup ] [ 2368: 4312] [9DE7AD:2658] Command: '"C:\WINDOWS\Temp\asw.d4930a556df44c51\instup.exe" /sfx:lite /sfxstorage:C:\WINDOWS\Temp\asw.d4930a556df44c51 /edition:1 /prod:ais /stub_context:210cf6c4-5b2d-463c-a653-1b22ed02a666:11812328 /guid:445307ce-fe88-4b99-9fc8-a2dbb64bffcc /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /silent /ws /psh:2bJ1koYmFQ1qzFcLU92XzQ7m7VeTwug3xEPzMfymA7x0X52qVgKhPLaq3f6YgGuvt24Y60wRc9cps /cookie:mmm_irs_ppi_005_888_a /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /edat_dir:C:\WINDOWS\Temp\asw.bf5885021530f23f'
|
Instup.exe | [2025-10-03 17:46:49.817] [info ] [instup ] [ 2368: 4312] [9DE7AD:2664] CPU: AMD Ryzen 5 3500 6-Core Processor,6
|
Instup.exe | [2025-10-03 17:46:49.817] [info ] [instup ] [ 2368: 4312] [9DE7AD:2669] OS: Windows 10 (10.0.19045) x64
|