File name:

atube-catcher-10.8.9-installer_xnz-3F1.exe

Full analysis: https://app.any.run/tasks/9dc405c7-1784-494f-8069-ff6c0e903fe9
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: August 30, 2024, 17:49:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

415924CE8C8CC60486081115387ABDF0

SHA1:

3FC29830F03790C8F38252343E0765D509C47E9C

SHA256:

E3B3D1EF8FF00CE2EB0E59E9A2B9ACEED7301EB149FF5E3AFFE2D498B8FF53FB

SSDEEP:

49152:c7HecD4dnbibBlI2zWoFgu66s26ibzpzYP0eR7lflBSx10Lf3k2A6tOmwOdxRxHx:Q+cD4dnVDoKualGzpCFlfaxqf3kAOmJq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • avg_secure_browser_setup.exe (PID: 3032)
    • Steals credentials from Web Browsers

      • avg_secure_browser_setup.exe (PID: 3032)
    • Changes the autorun value in the registry

      • instup.exe (PID: 3520)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • atube-catcher-10.8.9-installer_xnz-3F1.exe (PID: 2712)
      • avg_secure_browser_setup.exe (PID: 3032)
      • atube-catcher-10.8.9-installer.exe (PID: 2080)
      • AVGBrowserUpdateSetup.exe (PID: 3528)
      • AVGBrowserUpdate.exe (PID: 3096)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 3400)
      • avast_free_antivirus_setup_online.exe (PID: 3676)
      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
      • Instup.exe (PID: 1608)
    • Drops the executable file immediately after the start

      • atube-catcher-10.8.9-installer_xnz-3F1.exe (PID: 2712)
      • avg_secure_browser_setup.exe (PID: 3032)
      • atube-catcher-10.8.9-installer.exe (PID: 2080)
      • AVGBrowserUpdateSetup.exe (PID: 3528)
      • AVGBrowserUpdate.exe (PID: 3096)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 3400)
      • avast_free_antivirus_setup_online.exe (PID: 3676)
      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
      • Instup.exe (PID: 1608)
    • Process requests binary or script from the Internet

      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 3400)
    • Potential Corporate Privacy Violation

      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 3400)
      • AVGBrowserUpdate.exe (PID: 1476)
    • The process verifies whether the antivirus software is installed

      • avg_secure_browser_setup.exe (PID: 3032)
      • AVGBrowserUpdate.exe (PID: 2420)
      • AVGBrowserUpdate.exe (PID: 2500)
      • AVGBrowserUpdate.exe (PID: 2796)
      • AVGBrowserUpdate.exe (PID: 2504)
      • AVGBrowserUpdate.exe (PID: 1476)
      • AVGBrowserUpdate.exe (PID: 3096)
      • instup.exe (PID: 3520)
    • Searches for installed software

      • avg_secure_browser_setup.exe (PID: 3032)
    • Reads the Internet Settings

      • avg_secure_browser_setup.exe (PID: 3032)
      • AVGBrowserUpdate.exe (PID: 2796)
      • Instup.exe (PID: 1608)
      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
      • instup.exe (PID: 3520)
    • Reads security settings of Internet Explorer

      • avg_secure_browser_setup.exe (PID: 3032)
    • Reads settings of System Certificates

      • avg_secure_browser_setup.exe (PID: 3032)
      • avast_free_antivirus_setup_online.exe (PID: 3676)
      • AVGBrowserUpdate.exe (PID: 2796)
      • Instup.exe (PID: 1608)
      • instup.exe (PID: 3520)
    • Checks Windows Trust Settings

      • avg_secure_browser_setup.exe (PID: 3032)
    • Reads the Windows owner or organization settings

      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
    • Starts itself from another location

      • AVGBrowserUpdate.exe (PID: 3096)
      • Instup.exe (PID: 1608)
    • Disables SEHOP

      • AVGBrowserUpdate.exe (PID: 3096)
    • Creates/Modifies COM task schedule object

      • AVGBrowserUpdate.exe (PID: 2500)
      • AVGBrowserUpdate.exe (PID: 3096)
    • Executes as Windows Service

      • AVGBrowserUpdate.exe (PID: 1476)
    • Adds/modifies Windows certificates

      • AVGBrowserUpdate.exe (PID: 1476)
    • Process drops legitimate windows executable

      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
    • Starts POWERSHELL.EXE for commands execution

      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
    • The process drops C-runtime libraries

      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
  • INFO

    • Checks supported languages

      • atube-catcher-10.8.9-installer_xnz-3F1.exe (PID: 2712)
      • atube-catcher-10.8.9-installer_xnz-3F1.tmp (PID: 2472)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 3400)
      • avg_secure_browser_setup.exe (PID: 3032)
      • atube-catcher-10.8.9-installer.exe (PID: 2080)
      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
      • AVGBrowserUpdateSetup.exe (PID: 3528)
      • AVGBrowserUpdate.exe (PID: 3096)
      • AVGBrowserUpdate.exe (PID: 2420)
      • avast_free_antivirus_setup_online.exe (PID: 3676)
      • AVGBrowserUpdate.exe (PID: 2500)
      • AVGBrowserUpdate.exe (PID: 2504)
      • AVGBrowserUpdate.exe (PID: 1476)
      • AVGBrowserUpdate.exe (PID: 2796)
      • Instup.exe (PID: 1608)
      • instup.exe (PID: 3520)
      • sbr.exe (PID: 3612)
    • Reads the computer name

      • atube-catcher-10.8.9-installer_xnz-3F1.tmp (PID: 2472)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 3400)
      • avg_secure_browser_setup.exe (PID: 3032)
      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
      • AVGBrowserUpdate.exe (PID: 3096)
      • avast_free_antivirus_setup_online.exe (PID: 3676)
      • AVGBrowserUpdate.exe (PID: 2420)
      • AVGBrowserUpdate.exe (PID: 2504)
      • AVGBrowserUpdate.exe (PID: 2796)
      • AVGBrowserUpdate.exe (PID: 1476)
      • Instup.exe (PID: 1608)
      • instup.exe (PID: 3520)
    • Reads the machine GUID from the registry

      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 3400)
      • avg_secure_browser_setup.exe (PID: 3032)
      • avast_free_antivirus_setup_online.exe (PID: 3676)
      • AVGBrowserUpdate.exe (PID: 3096)
      • AVGBrowserUpdate.exe (PID: 2504)
      • AVGBrowserUpdate.exe (PID: 1476)
      • AVGBrowserUpdate.exe (PID: 2796)
      • Instup.exe (PID: 1608)
      • instup.exe (PID: 3520)
    • Reads Environment values

      • avg_secure_browser_setup.exe (PID: 3032)
      • Instup.exe (PID: 1608)
      • instup.exe (PID: 3520)
    • Process checks computer location settings

      • avg_secure_browser_setup.exe (PID: 3032)
    • Create files in a temporary directory

      • avg_secure_browser_setup.exe (PID: 3032)
      • atube-catcher-10.8.9-installer_xnz-3F1.exe (PID: 2712)
      • atube-catcher-10.8.9-installer.exe (PID: 2080)
      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
      • AVGBrowserUpdate.exe (PID: 1476)
    • Checks proxy server information

      • avg_secure_browser_setup.exe (PID: 3032)
      • Instup.exe (PID: 1608)
      • instup.exe (PID: 3520)
    • Creates files or folders in the user directory

      • avg_secure_browser_setup.exe (PID: 3032)
    • Reads the software policy settings

      • avg_secure_browser_setup.exe (PID: 3032)
      • avast_free_antivirus_setup_online.exe (PID: 3676)
      • AVGBrowserUpdate.exe (PID: 2796)
      • AVGBrowserUpdate.exe (PID: 1476)
      • Instup.exe (PID: 1608)
      • instup.exe (PID: 3520)
    • Creates files in the program directory

      • AVGBrowserUpdate.exe (PID: 3096)
      • AVGBrowserUpdateSetup.exe (PID: 3528)
      • avast_free_antivirus_setup_online.exe (PID: 3676)
      • AVGBrowserUpdate.exe (PID: 1476)
      • Instup.exe (PID: 1608)
      • atube-catcher-10.8.9-installer.tmp (PID: 2580)
      • instup.exe (PID: 3520)
    • Reads CPU info

      • avast_free_antivirus_setup_online.exe (PID: 3676)
      • Instup.exe (PID: 1608)
      • instup.exe (PID: 3520)
    • Application launched itself

      • msedge.exe (PID: 972)
      • msedge.exe (PID: 2040)
    • Manual execution by a user

      • msedge.exe (PID: 2040)
    • Dropped object may contain TOR URL's

      • Instup.exe (PID: 1608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 423.56.98.8907
ProductVersionNumber: 423.56.98.8907
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Softonic International SA
FileVersion: 423.56.98.8907
LegalCopyright: ©2023 Softonic International SA
OriginalFileName:
ProductName: Softonic International SA
ProductVersion: 3.1.5.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
85
Monitored processes
35
Malicious processes
14
Suspicious processes
0

Behavior graph

Click at the process to see the details
start atube-catcher-10.8.9-installer_xnz-3f1.exe atube-catcher-10.8.9-installer_xnz-3f1.tmp no specs cookie_mmm_irs_ppi_005_888_a.exe avg_secure_browser_setup.exe atube-catcher-10.8.9-installer.exe atube-catcher-10.8.9-installer.tmp avgbrowserupdatesetup.exe avgbrowserupdate.exe avgbrowserupdate.exe no specs avast_free_antivirus_setup_online.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe instup.exe powershell.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs instup.exe sbr.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
972"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.catalog.update.microsoft.com/Search.aspx?q=KB4457144C:\Program Files\Microsoft\Edge\Application\msedge.exeatube-catcher-10.8.9-installer.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1476"C:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exe" /svcC:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exe
services.exe
User:
SYSTEM
Company:
Gen Digital Inc.
Integrity Level:
SYSTEM
Description:
AVG Browser
Version:
1.8.1693.6
Modules
Images
c:\program files\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1608"C:\Windows\Temp\asw.809192f8dfbc1dc6\instup.exe" /sfx:lite /sfxstorage:C:\Windows\Temp\asw.809192f8dfbc1dc6 /edition:1 /prod:ais /stub_context:3676:228 /guid:a4f856d6-a01b-4d42-bab6-ee0ee59d27f8 /ga_clientid:8dc95639-13ed-42c1-92ff-987eaa09ce31 /silent /ws /psh:2bJ1kmA8kow9wPhXyNvF9cZjLDukYFwojMhVRGUsvRlSFfSSD7JypT1I6TEqJTJ15y52l6hogaXHw /cookie:mmm_irs_ppi_005_888_a /ga_clientid:8dc95639-13ed-42c1-92ff-987eaa09ce31 /edat_dir:C:\Windows\Temp\asw.5512de578cdd0beeC:\Windows\Temp\asw.809192f8dfbc1dc6\Instup.exe
avast_free_antivirus_setup_online.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Version:
24.8.9372.0
Modules
Images
c:\windows\temp\asw.809192f8dfbc1dc6\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1784"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1528 --field-trial-handle=1340,i,208876879365841268,5055460248165971412,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1904"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2164 --field-trial-handle=1340,i,208876879365841268,5055460248165971412,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2040"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate https://www.catalog.update.microsoft.com/Search.aspx?q=KB4457144C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2080"C:\Users\admin\Downloads\atube-catcher-10.8.9-installer.exe" C:\Users\admin\Downloads\atube-catcher-10.8.9-installer.exe
atube-catcher-10.8.9-installer_xnz-3F1.tmp
User:
admin
Company:
DsNET Corp. - Diego Uscanga
Integrity Level:
HIGH
Description:
aTube Catcher Setup
Version:
10.8.9
Modules
Images
c:\users\admin\downloads\atube-catcher-10.8.9-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2292"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1480 --field-trial-handle=1340,i,208876879365841268,5055460248165971412,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2420"C:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exe" /regsvcC:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exeAVGBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Browser
Exit code:
0
Version:
1.8.1693.6
Modules
Images
c:\program files\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2472"C:\Users\admin\AppData\Local\Temp\is-T614V.tmp\atube-catcher-10.8.9-installer_xnz-3F1.tmp" /SL5="$30214,837598,832512,C:\Users\admin\Desktop\atube-catcher-10.8.9-installer_xnz-3F1.exe" C:\Users\admin\AppData\Local\Temp\is-T614V.tmp\atube-catcher-10.8.9-installer_xnz-3F1.tmpatube-catcher-10.8.9-installer_xnz-3F1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t614v.tmp\atube-catcher-10.8.9-installer_xnz-3f1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
50 224
Read events
44 354
Write events
5 834
Delete events
36

Modification events

(PID) Process:(3400) cookie_mmm_irs_ppi_005_888_a.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Windows\Temp\asw.5512de578cdd0bee
(PID) Process:(3032) avg_secure_browser_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\AVG\Browser
Operation:writeName:installer_run_count
Value:
1
(PID) Process:(3032) avg_secure_browser_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\AVG\Browser
Operation:writeName:machine_id
Value:
000044C3FD2CD9540FF4BAF5D88EE93E
(PID) Process:(3032) avg_secure_browser_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3032) avg_secure_browser_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3032) avg_secure_browser_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3032) avg_secure_browser_setup.exeKey:HKEY_CURRENT_USER\Software\AVG\Browser
Operation:writeName:user_id
Value:
e7afdb7229f44ac6842235131ef8d683
(PID) Process:(3032) avg_secure_browser_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3032) avg_secure_browser_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3032) avg_secure_browser_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
Executable files
865
Suspicious files
174
Text files
271
Unknown types
44

Dropped files

PID
Process
Filename
Type
3032avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nse5A.tmp\FF.places.tmp
MD5:
SHA256:
3032avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nse5A.tmp\jsis.dllexecutable
MD5:4B27DF9758C01833E92C51C24CE9E1D5
SHA256:D37408F77B7A4E7C60800B6D60C47305B487E8E21C82A416784864BD9F26E7BB
3032avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nse5A.tmp\jsisdl.dllexecutable
MD5:7100B585987B70E4F85686E78C52F283
SHA256:937DCAF57370AF649133E5F48AAFED6E25345C93D599A981ACA520CE6DA8C1C0
3032avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nse5A.tmp\StdUtils.dllexecutable
MD5:7602B88D488E54B717A7086605CD6D8D
SHA256:2640E4F09AA4C117036BFDDD12DC02834E66400392761386BD1FE172A6DDFA11
3400cookie_mmm_irs_ppi_005_888_a.exeC:\Windows\Temp\asw.5512de578cdd0bee\ecoo.edattext
MD5:C1C3F32398130DFB38F9847F02F6786E
SHA256:25EC04BCE97A15D7ABF948FEFAEEAD48E95ABC5F945361759D8BCC05BB20638F
3032avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nse5A.tmp\nsJSON.dllexecutable
MD5:DDB56A646AEA54615B29CE7DF8CD31B8
SHA256:07E602C54086A8FA111F83A38C2F3EE239F49328990212C2B3A295FADE2B5069
3032avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nse5A.tmp\thirdparty.dllexecutable
MD5:070335E8E52A288BDB45DB1C840D446B
SHA256:C8CF0CF1C2B8B14CBEDFE621D81A79C80D70F587D698AD6DFB54BBE8E346FBBC
3032avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nse5A.tmp\reboot.dllexecutable
MD5:0F3432346A273777B5F4D2E6A3BCA343
SHA256:4853D61601A860C628771993F3A57B5AB842C88D696235FEBFAA3CD890EBCD1E
3032avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nse5A.tmp\Midex.dllexecutable
MD5:581C4A0B8DE60868B89074FE94EB27B9
SHA256:B13C23AF49DA0A21959E564CBCA8E6B94C181C5EEB95150B29C94FF6AFB8F9DD
3032avg_secure_browser_setup.exeC:\Users\admin\AppData\Local\Temp\nse5A.tmp\sciterui.dllexecutable
MD5:F40C5626532C77B9B4A6BB384DB48BBE
SHA256:E6D594047DEECB0F3D49898475084D286072B6E3E4A30EB9D0D03E9B3228D60F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
99
DNS requests
105
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
173.222.107.15:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
whitelisted
1372
svchost.exe
GET
200
92.123.101.200:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1060
svchost.exe
GET
304
173.222.107.15:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?67a3611ec3c0260d
unknown
whitelisted
1372
svchost.exe
GET
200
2.22.33.235:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3400
cookie_mmm_irs_ppi_005_888_a.exe
POST
200
142.250.203.110:80
http://www.google-analytics.com/collect
unknown
3400
cookie_mmm_irs_ppi_005_888_a.exe
POST
403
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
3400
cookie_mmm_irs_ppi_005_888_a.exe
GET
200
92.123.101.131:80
http://iavs9x.u.avast.com/iavs9x/avast_free_antivirus_setup_online.exe
unknown
whitelisted
3400
cookie_mmm_irs_ppi_005_888_a.exe
POST
200
142.250.203.110:80
http://www.google-analytics.com/collect
unknown
3520
instup.exe
GET
200
92.123.101.123:80
http://f3461309.iavs9x.u.avast.com/iavs9x/prod-pgm.vpx
unknown
whitelisted
3520
instup.exe
GET
200
92.123.101.104:80
http://r3802239.vps18tiny.u.avcdn.net/vps18tiny/prod-vps.vpx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1372
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
3760
atube-catcher-10.8.9-installer_xnz-3F1.tmp
18.165.185.127:443
d25qho5rs4tpl0.cloudfront.net
US
whitelisted
3760
atube-catcher-10.8.9-installer_xnz-3F1.tmp
151.101.241.91:443
images.sftcdn.net
FASTLY
IT
whitelisted
1372
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1372
svchost.exe
173.222.107.15:80
ctldl.windowsupdate.com
Akamai International B.V.
IT
whitelisted
3760
atube-catcher-10.8.9-installer_xnz-3F1.tmp
151.101.242.133:443
gsf-fl.softonic.com
FASTLY
IT
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.168.14
whitelisted
d25qho5rs4tpl0.cloudfront.net
  • 18.165.185.127
whitelisted
images.sftcdn.net
  • 151.101.241.91
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
ctldl.windowsupdate.com
  • 173.222.107.15
whitelisted
crl.microsoft.com
  • 92.123.101.200
whitelisted
gsf-fl.softonic.com
  • 151.101.242.133
whitelisted
www.microsoft.com
  • 2.22.33.235
whitelisted
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
iavs9x.u.avast.com
  • 92.123.101.131
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
avg_secure_browser_setup.exe
2024-08-30T18:52:46 [libnsis] {00000bd8:00000cc0} <2:Info> (893f00f663353e48\src\jsis-plugins\plugins\Plugin.cpp:82) JSIS Plugin logging enabled
avg_secure_browser_setup.exe
2024-08-30T18:52:47 [libnsis] {00000bd8:00000cc0} <1:Debug> (91aa05bf654a77ad\src\sbplugins\windows\RCData.cpp:62) Throwing exception 0x00000400000715
avg_secure_browser_setup.exe
2024-08-30T18:52:47 [libnsis] {00000bd8:00000cc0} <4:Error> (893f00f663353e48\src\jsis-plugins\plugins\UtilitiesPlugin\TagData.cpp:85) 0x00000400000715 91aa05bf654a77ad\src\sbplugins\windows\RCData.cpp:62
avg_secure_browser_setup.exe
2024-08-30T18:52:47 [libnsis] {00000bd8:00000cc0} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nse5A.tmp\CR.History.tmp
avg_secure_browser_setup.exe
2024-08-30T18:52:47 [libnsis] {00000bd8:00000cc0} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT ((visits.visit_time/1000000)-11644473600) /60 /60 / 24 AS vtime FROM 'visits' WHERE vtime >= 19935 AND vtime <= 19966 GROUP BY vtime
avg_secure_browser_setup.exe
2024-08-30T18:52:48 [libnsis] {00000bd8:00000cc0} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nse5A.tmp\CR.History.tmp
avg_secure_browser_setup.exe
2024-08-30T18:52:48 [libnsis] {00000bd8:00000cc0} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT ((visits.visit_time/1000000)-11644473600) /60 /60 / 24 AS vtime FROM 'visits' WHERE vtime >= 19935 AND vtime <= 19966 GROUP BY vtime
avg_secure_browser_setup.exe
2024-08-30T18:52:48 [libnsis] {00000bd8:00000cc0} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:75) Execute Sqlite query SELECT last_visit_date / 1000000 /60 /60 / 24 AS vtime FROM 'moz_places' WHERE vtime >= 19935 AND vtime <= 19966 GROUP BY vtime
avg_secure_browser_setup.exe
2024-08-30T18:52:48 [libnsis] {00000bd8:00000cc0} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nse5A.tmp\FF.places.tmp
avg_secure_browser_setup.exe
2024-08-30T18:52:48 [libnsis] {00000bd8:00000cc0} <1:Debug> (6641f181bd7f7928\src\acu\database\Sqlite.cpp:38) Oepn Sqlite DB C:\Users\admin\AppData\Local\Temp\nse5A.tmp\FF.places.tmp