File name:

MDE_File_Sample_68acd154482de8ed56d00471918edc903660c0e5.zip

Full analysis: https://app.any.run/tasks/cd6bf994-5cab-4023-9fb6-477f90409dde
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: October 03, 2025, 17:45:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
adware
innosetup
inno
installer
delphi
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

260A90948E2C0734614259F85BAD77DD

SHA1:

768E1B580C8D772D2B1A2B85BEA3E049B11A9513

SHA256:

E2A858B9D01D15B78C53186E4A5280BE95B1226DDFF63779BA449794DA6ADE33

SSDEEP:

49152:m8EsEX8ADpPVzCqGGqv8Ujh3bOXT2ra7d/Wumbu03qdGcZGajv29lXveilMIeYIu:PmneIUjsqr2T06dGsOD29ILIZouvTHsT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6916)
    • Changes the autorun value in the registry

      • instup.exe (PID: 2328)
    • Executing a file with an untrusted certificate

      • ISBEW64.exe (PID: 8020)
      • ISBEW64.exe (PID: 464)
      • ISBEW64.exe (PID: 8016)
      • ISBEW64.exe (PID: 5096)
      • ISBEW64.exe (PID: 7172)
      • ISBEW64.exe (PID: 4860)
      • ISBEW64.exe (PID: 1388)
      • ISBEW64.exe (PID: 5636)
      • ISBEW64.exe (PID: 4804)
      • ISBEW64.exe (PID: 7036)
      • ISBEW64.exe (PID: 1516)
      • ISBEW64.exe (PID: 3696)
      • ISBEW64.exe (PID: 4344)
      • ISBEW64.exe (PID: 4060)
      • ISBEW64.exe (PID: 3188)
      • ISBEW64.exe (PID: 6344)
      • ISBEW64.exe (PID: 3340)
      • ISBEW64.exe (PID: 4068)
      • ISBEW64.exe (PID: 6128)
      • ISBEW64.exe (PID: 5692)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6916)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 1700)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
    • Executable content was dropped or overwritten

      • spss-29.0-installer_8yA-xh1.exe (PID: 3628)
      • spss-29.0-installer_8yA-xh1.exe (PID: 1532)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4676)
      • avast_free_antivirus_setup_online_x64.exe (PID: 6296)
      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
      • spss-29.0-installer.exe (PID: 4228)
    • Reads the Windows owner or organization settings

      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
    • Potential Corporate Privacy Violation

      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4676)
    • Starts itself from another location

      • Instup.exe (PID: 2368)
      • spss-29.0-installer.exe (PID: 6600)
    • Process checks presence of unattended files

      • instup.exe (PID: 2328)
    • The process verifies whether the antivirus software is installed

      • instup.exe (PID: 2328)
    • Executes application which crashes

      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
    • Process drops legitimate windows executable

      • instup.exe (PID: 2328)
    • The process drops C-runtime libraries

      • instup.exe (PID: 2328)
    • Creates files in the driver directory

      • instup.exe (PID: 2328)
    • Drops a system driver (possible attempt to evade defenses)

      • instup.exe (PID: 2328)
    • Creates or modifies Windows services

      • instup.exe (PID: 2328)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6916)
      • msiexec.exe (PID: 4748)
    • Checks supported languages

      • spss-29.0-installer_8yA-xh1.exe (PID: 3628)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 1700)
      • spss-29.0-installer_8yA-xh1.exe (PID: 1532)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4676)
      • avast_free_antivirus_setup_online_x64.exe (PID: 6296)
      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
      • sbr.exe (PID: 8112)
      • spss-29.0-installer.exe (PID: 6600)
      • spss-29.0-installer.exe (PID: 4228)
      • msiexec.exe (PID: 2488)
      • msiexec.exe (PID: 2260)
      • ISBEW64.exe (PID: 8020)
      • ISBEW64.exe (PID: 464)
      • ISBEW64.exe (PID: 8016)
      • ISBEW64.exe (PID: 5096)
      • ISBEW64.exe (PID: 7172)
      • ISBEW64.exe (PID: 4860)
      • ISBEW64.exe (PID: 1388)
      • ISBEW64.exe (PID: 5636)
      • ISBEW64.exe (PID: 4804)
      • ISBEW64.exe (PID: 7036)
      • ISBEW64.exe (PID: 1516)
      • ISBEW64.exe (PID: 3696)
      • ISBEW64.exe (PID: 4344)
      • ISBEW64.exe (PID: 4060)
      • ISBEW64.exe (PID: 3188)
      • ISBEW64.exe (PID: 6344)
      • ISBEW64.exe (PID: 3340)
      • ISBEW64.exe (PID: 4068)
      • ISBEW64.exe (PID: 6128)
      • ISBEW64.exe (PID: 5692)
    • Create files in a temporary directory

      • spss-29.0-installer_8yA-xh1.exe (PID: 3628)
      • spss-29.0-installer_8yA-xh1.exe (PID: 1532)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
      • spss-29.0-installer.exe (PID: 6600)
      • spss-29.0-installer.exe (PID: 4228)
      • msiexec.exe (PID: 4748)
      • msiexec.exe (PID: 2260)
    • Reads the computer name

      • spss-29.0-installer_8yA-xh1.tmp (PID: 1700)
      • spss-29.0-installer_8yA-xh1.exe (PID: 1532)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4676)
      • avast_free_antivirus_setup_online_x64.exe (PID: 6296)
      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
      • spss-29.0-installer.exe (PID: 6600)
      • spss-29.0-installer.exe (PID: 4228)
      • msiexec.exe (PID: 2488)
      • msiexec.exe (PID: 2260)
      • ISBEW64.exe (PID: 8020)
      • ISBEW64.exe (PID: 464)
      • ISBEW64.exe (PID: 8016)
      • ISBEW64.exe (PID: 5096)
      • ISBEW64.exe (PID: 7172)
      • ISBEW64.exe (PID: 4860)
      • ISBEW64.exe (PID: 1388)
      • ISBEW64.exe (PID: 5636)
      • ISBEW64.exe (PID: 4804)
      • ISBEW64.exe (PID: 7036)
      • ISBEW64.exe (PID: 1516)
      • ISBEW64.exe (PID: 3696)
      • ISBEW64.exe (PID: 4344)
      • ISBEW64.exe (PID: 4060)
      • ISBEW64.exe (PID: 3188)
      • ISBEW64.exe (PID: 6344)
      • ISBEW64.exe (PID: 3340)
      • ISBEW64.exe (PID: 4068)
      • ISBEW64.exe (PID: 6128)
      • ISBEW64.exe (PID: 5692)
    • Process checks computer location settings

      • spss-29.0-installer_8yA-xh1.tmp (PID: 1700)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
    • Reads the software policy settings

      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
      • avast_free_antivirus_setup_online_x64.exe (PID: 6296)
      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
      • slui.exe (PID: 1388)
      • WerFault.exe (PID: 7196)
      • WerFault.exe (PID: 5692)
      • msiexec.exe (PID: 4748)
    • Reads the machine GUID from the registry

      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4676)
      • avast_free_antivirus_setup_online_x64.exe (PID: 6296)
      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
    • Checks proxy server information

      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
      • avast_free_antivirus_setup_online_x64.exe (PID: 6296)
      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
      • slui.exe (PID: 1388)
      • WerFault.exe (PID: 7196)
      • WerFault.exe (PID: 5692)
      • msiexec.exe (PID: 4748)
    • Detects InnoSetup installer (YARA)

      • spss-29.0-installer_8yA-xh1.exe (PID: 3628)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 1700)
      • spss-29.0-installer_8yA-xh1.exe (PID: 1532)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
    • Compiled with Borland Delphi (YARA)

      • spss-29.0-installer_8yA-xh1.exe (PID: 3628)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 1700)
      • spss-29.0-installer_8yA-xh1.exe (PID: 1532)
      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
    • The sample compiled with english language support

      • spss-29.0-installer_8yA-xh1.tmp (PID: 7996)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4676)
      • avast_free_antivirus_setup_online_x64.exe (PID: 6296)
      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
      • spss-29.0-installer.exe (PID: 4228)
      • msiexec.exe (PID: 4748)
    • Reads CPU info

      • avast_free_antivirus_setup_online_x64.exe (PID: 6296)
      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
    • Creates files in the program directory

      • avast_free_antivirus_setup_online_x64.exe (PID: 6296)
      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
    • Reads Environment values

      • Instup.exe (PID: 2368)
      • instup.exe (PID: 2328)
    • Launching a file from a Registry key

      • instup.exe (PID: 2328)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 7196)
      • WerFault.exe (PID: 5692)
      • msiexec.exe (PID: 4748)
    • The sample compiled with french language support

      • spss-29.0-installer.exe (PID: 4228)
    • The sample compiled with Italian language support

      • spss-29.0-installer.exe (PID: 4228)
    • The sample compiled with japanese language support

      • spss-29.0-installer.exe (PID: 4228)
    • The sample compiled with korean language support

      • spss-29.0-installer.exe (PID: 4228)
    • The sample compiled with german language support

      • spss-29.0-installer.exe (PID: 4228)
    • The sample compiled with polish language support

      • spss-29.0-installer.exe (PID: 4228)
    • The sample compiled with portuguese language support

      • spss-29.0-installer.exe (PID: 4228)
    • The sample compiled with russian language support

      • spss-29.0-installer.exe (PID: 4228)
    • The sample compiled with chinese language support

      • spss-29.0-installer.exe (PID: 4228)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 4748)
    • The sample compiled with czech language support

      • instup.exe (PID: 2328)
    • Manages system restore points

      • SrTasks.exe (PID: 532)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2025:10:03 15:13:58
ZipCRC: 0x08212410
ZipCompressedSize: 1394974
ZipUncompressedSize: 1921712
ZipFileName: spss-29.0-installer_8yA-xh1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
214
Monitored processes
41
Malicious processes
4
Suspicious processes
24

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
464C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{69AD52AF-D24B-44D6-9DB7-D1D6B50CF715}C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
HIGH
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.717
Modules
Images
c:\users\admin\appdata\local\temp\{53980d8a-d5fb-4411-a2c0-1f54c12aecd4}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
532C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:14C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1388C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1388C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{11A86434-37C1-45DE-B12C-FD99DACE2260}C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
HIGH
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.717
Modules
Images
c:\users\admin\appdata\local\temp\{53980d8a-d5fb-4411-a2c0-1f54c12aecd4}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1516C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{8BD1567C-6341-476C-B088-5F2DED2823D3}C:\Users\admin\AppData\Local\Temp\{53980D8A-D5FB-4411-A2C0-1F54C12AECD4}\ISBEW64.exemsiexec.exe
User:
admin
Company:
Flexera
Integrity Level:
HIGH
Description:
InstallShield (R) 64-bit Setup Engine
Exit code:
0
Version:
26.0.717
Modules
Images
c:\users\admin\appdata\local\temp\{53980d8a-d5fb-4411-a2c0-1f54c12aecd4}\isbew64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1532"C:\Users\admin\AppData\Local\Temp\Rar$EXb6916.17190\spss-29.0-installer_8yA-xh1.exe" /SPAWNWND=$6026A /NOTIFYWND=$6037C C:\Users\admin\AppData\Local\Temp\Rar$EXb6916.17190\spss-29.0-installer_8yA-xh1.exe
spss-29.0-installer_8yA-xh1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Softonic International
Exit code:
3221226525
Version:
2.41.3.9395
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6916.17190\spss-29.0-installer_8ya-xh1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1700"C:\Users\admin\AppData\Local\Temp\is-O6Q9L.tmp\spss-29.0-installer_8yA-xh1.tmp" /SL5="$6037C,849122,844800,C:\Users\admin\AppData\Local\Temp\Rar$EXb6916.17190\spss-29.0-installer_8yA-xh1.exe" C:\Users\admin\AppData\Local\Temp\is-O6Q9L.tmp\spss-29.0-installer_8yA-xh1.tmpspss-29.0-installer_8yA-xh1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
3221226525
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-o6q9l.tmp\spss-29.0-installer_8ya-xh1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
2260C:\Windows\syswow64\MsiExec.exe -Embedding 4829E23873EE6B0E7463349665108308 CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2328"C:\WINDOWS\Temp\asw.d4930a556df44c51\New_19091821\instup.exe" /sfx /sfxstorage:C:\WINDOWS\Temp\asw.d4930a556df44c51 /edition:1 /prod:ais /stub_context:210cf6c4-5b2d-463c-a653-1b22ed02a666:11812328 /guid:445307ce-fe88-4b99-9fc8-a2dbb64bffcc /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /silent /ws /psh:2bJ1koYmFQ1qzFcLU92XzQ7m7VeTwug3xEPzMfymA7x0X52qVgKhPLaq3f6YgGuvt24Y60wRc9cps /cookie:mmm_irs_ppi_005_888_a /edat_dir:C:\WINDOWS\Temp\asw.bf5885021530f23f /online_installerC:\Windows\Temp\asw.d4930a556df44c51\New_19091821\instup.exe
Instup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Version:
25.9.10453.0
Modules
Images
c:\windows\temp\asw.d4930a556df44c51\new_19091821\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
2368"C:\WINDOWS\Temp\asw.d4930a556df44c51\instup.exe" /sfx:lite /sfxstorage:C:\WINDOWS\Temp\asw.d4930a556df44c51 /edition:1 /prod:ais /stub_context:210cf6c4-5b2d-463c-a653-1b22ed02a666:11812328 /guid:445307ce-fe88-4b99-9fc8-a2dbb64bffcc /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /silent /ws /psh:2bJ1koYmFQ1qzFcLU92XzQ7m7VeTwug3xEPzMfymA7x0X52qVgKhPLaq3f6YgGuvt24Y60wRc9cps /cookie:mmm_irs_ppi_005_888_a /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /edat_dir:C:\WINDOWS\Temp\asw.bf5885021530f23fC:\Windows\Temp\asw.d4930a556df44c51\Instup.exe
avast_free_antivirus_setup_online_x64.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Version:
25.9.10453.0
Modules
Images
c:\windows\temp\asw.d4930a556df44c51\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcp_win.dll
Total events
30 542
Read events
24 242
Write events
6 291
Delete events
9

Modification events

(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_68acd154482de8ed56d00471918edc903660c0e5.zip
(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6916) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
708
Suspicious files
199
Text files
204
Unknown types
0

Dropped files

PID
Process
Filename
Type
7996spss-29.0-installer_8yA-xh1.tmpC:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\is-JH0NQ.tmp
MD5:
SHA256:
7996spss-29.0-installer_8yA-xh1.tmpC:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\is-74PJ2.tmp
MD5:
SHA256:
7996spss-29.0-installer_8yA-xh1.tmpC:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\spss-29.0-installer.exe
MD5:
SHA256:
6916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb6916.17190\spss-29.0-installer_8yA-xh1.exeexecutable
MD5:19621C5778A6C9B73BC140EF3DE1D6FB
SHA256:4F987AD8B165B950CED5806BBB8B6308A0073B8BA080C59D39673B01D72358C5
3628spss-29.0-installer_8yA-xh1.exeC:\Users\admin\AppData\Local\Temp\is-O6Q9L.tmp\spss-29.0-installer_8yA-xh1.tmpexecutable
MD5:A1E3F469D5CE6AB9E93B25AF0EFD31E0
SHA256:165F2E0686659069178F6D30C7385B2FDDFDB267628AD0BF63E361CF4B9C9CAF
1532spss-29.0-installer_8yA-xh1.exeC:\Users\admin\AppData\Local\Temp\is-GHRJB.tmp\spss-29.0-installer_8yA-xh1.tmpexecutable
MD5:A1E3F469D5CE6AB9E93B25AF0EFD31E0
SHA256:165F2E0686659069178F6D30C7385B2FDDFDB267628AD0BF63E361CF4B9C9CAF
7996spss-29.0-installer_8yA-xh1.tmpC:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
7996spss-29.0-installer_8yA-xh1.tmpC:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\is-7SNE7.tmp
MD5:251390CBB5EA35B7F1D479925C7B3F47
SHA256:87D24EF5838C4FA66FAAE6B41BAAD2EA5F6E60B7E0CA0F30725F181B02F36A57
7996spss-29.0-installer_8yA-xh1.tmpC:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\100.pngimage
MD5:251390CBB5EA35B7F1D479925C7B3F47
SHA256:87D24EF5838C4FA66FAAE6B41BAAD2EA5F6E60B7E0CA0F30725F181B02F36A57
7996spss-29.0-installer_8yA-xh1.tmpC:\Users\admin\AppData\Local\Temp\is-VR8QH.tmp\SUCCESS.pngimage
MD5:E8C9048FAF21F1CC959D73A0DE5534FD
SHA256:2B394E114DEB3A0700C70FEB80D74328C4C8668AA221B0E427DE783D1AB8371E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
54
TCP/UDP connections
92
DNS requests
122
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1048
svchost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
3116
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
1048
svchost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
4284
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
2356
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
4676
cookie_mmm_irs_ppi_005_888_a.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
US
whitelisted
2368
Instup.exe
GET
200
2.16.10.82:80
http://n4291289.iavs9x.u.avast.com/iavs9x/servers.def.vpx
AT
binary
2.39 Kb
whitelisted
2368
Instup.exe
GET
200
2.16.10.82:80
http://n4291289.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
AT
binary
571 b
whitelisted
2368
Instup.exe
GET
2.16.10.82:80
http://n4291289.iavs9x.u.avast.com/iavs9x/avbugreport_x64_ais-a7a.vpx
AT
whitelisted
2368
Instup.exe
GET
200
2.16.10.82:80
http://n4291289.iavs9x.u.avast.com/iavs9x/avdump_x64_ais-a7a.vpx
AT
binary
1.05 Mb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6924
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5224
SearchApp.exe
2.16.241.218:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1048
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1048
svchost.exe
172.66.2.5:80
ocsp.digicert.com
US
whitelisted
3116
backgroundTaskHost.exe
2.16.241.218:443
www.bing.com
Akamai International B.V.
DE
whitelisted
3116
backgroundTaskHost.exe
172.66.2.5:80
ocsp.digicert.com
US
whitelisted
3464
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.16.241.218
  • 2.16.241.201
  • 2.16.241.205
  • 2.16.241.207
whitelisted
google.com
  • 142.250.181.238
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.4
  • 40.126.31.130
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.2
  • 40.126.31.3
  • 20.190.159.71
  • 20.190.159.64
  • 40.126.31.73
  • 20.190.159.130
  • 40.126.31.71
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 172.66.2.5
  • 162.159.142.9
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
d1v40plrti2oiz.cloudfront.net
  • 108.138.34.119
  • 108.138.34.146
  • 108.138.34.178
  • 108.138.34.56
malicious
images.sftcdn.net
  • 151.101.1.91
  • 151.101.193.91
  • 151.101.129.91
  • 151.101.65.91
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Generic Protocol Command Decode
SURICATA HTTP Request unrecognized authorization method
A Network Trojan was detected
ET ADWARE_PUP Win32/OfferCore Checkin M1
Generic Protocol Command Decode
SURICATA HTTP Request unrecognized authorization method
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
4676
cookie_mmm_irs_ppi_005_888_a.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
Process
Message
avast_free_antivirus_setup_online_x64.exe
[2025-10-03 17:46:48.192] [notice ] [sfxinst ] [ 6296: 4936] [A199AD: 393] Registry link creation 'SOFTWARE\WOW6432Node\Avast Software' -> 'SOFTWARE\Avast Software' was successful.
avast_free_antivirus_setup_online_x64.exe
[2025-10-03 17:46:48.192] [info ] [sfxinst ] [ 6296: 4936] [A199AD: 410] Running SFX 'C:\WINDOWS\Temp\asw.bf5885021530f23f\avast_free_antivirus_setup_online_x64.exe'
avast_free_antivirus_setup_online_x64.exe
[2025-10-03 17:46:48.254] [info ] [sfxinst ] [ 6296: 4936] [A199AD: 658] Moved extra data file 'ecoo.edat' to 'C:\WINDOWS\Temp\asw.d4930a556df44c51\cookie.bin'.
avast_free_antivirus_setup_online_x64.exe
[2025-10-03 17:46:48.426] [notice ] [burger_rep ] [ 6296: 6404] [E73597: 64] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
avast_free_antivirus_setup_online_x64.exe
[2025-10-03 17:46:48.426] [info ] [sfxstats ] [ 6296: 7920] [CA7C4C: 149] Statistics sent successfully.
avast_free_antivirus_setup_online_x64.exe
[2025-10-03 17:46:49.489] [info ] [sfxinst ] [ 6296: 4936] [A199AD: 964] Starting installer/updater executable 'C:\WINDOWS\Temp\asw.d4930a556df44c51\instup.exe'
Instup.exe
[2025-10-03 17:46:49.817] [debug ] [repsup ] [ 2368: 4312] [15D746: 58] PfroMutant: \PendingRenameMutex mutant has been successfully opened.
Instup.exe
[2025-10-03 17:46:49.817] [info ] [instup ] [ 2368: 4312] [9DE7AD:2658] Command: '"C:\WINDOWS\Temp\asw.d4930a556df44c51\instup.exe" /sfx:lite /sfxstorage:C:\WINDOWS\Temp\asw.d4930a556df44c51 /edition:1 /prod:ais /stub_context:210cf6c4-5b2d-463c-a653-1b22ed02a666:11812328 /guid:445307ce-fe88-4b99-9fc8-a2dbb64bffcc /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /silent /ws /psh:2bJ1koYmFQ1qzFcLU92XzQ7m7VeTwug3xEPzMfymA7x0X52qVgKhPLaq3f6YgGuvt24Y60wRc9cps /cookie:mmm_irs_ppi_005_888_a /ga_clientid:2809f160-c064-469d-bacc-fda4902ec290 /edat_dir:C:\WINDOWS\Temp\asw.bf5885021530f23f'
Instup.exe
[2025-10-03 17:46:49.817] [info ] [instup ] [ 2368: 4312] [9DE7AD:2664] CPU: AMD Ryzen 5 3500 6-Core Processor,6
Instup.exe
[2025-10-03 17:46:49.817] [info ] [instup ] [ 2368: 4312] [9DE7AD:2669] OS: Windows 10 (10.0.19045) x64