File name:

Purple Bit - Linkvertise Downloader_kCHx-K1.exe

Full analysis: https://app.any.run/tasks/56ef1ff3-cbcd-4717-82cb-a962534b56d8
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 05, 2022, 05:44:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

CDC432222C4365D28E17521565387064

SHA1:

41E716ABA50EE0CD10DB20FEBC8F3A160305E3AC

SHA256:

E6DE6CAB2E7845B05CE76A32566DC5C023C1029CE2956A29F55BF5254FC0693E

SSDEEP:

98304:cSiF6hoXOWZ3lsuUxqxgWphviLx137O5M:zoXOM1ughC7SM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • avg_secure_browser_setup.exe (PID: 2904)
      • avg_antivirus_free_setup.exe (PID: 2888)
      • cookie_mmm_irs_ppi_902_451_o.exe (PID: 2668)
      • AVGBrowserUpdateSetup.exe (PID: 2320)
      • AVGBrowserUpdate.exe (PID: 3152)
      • instup.exe (PID: 1064)
      • AVGBrowserUpdate.exe (PID: 2196)
      • AVGBrowserUpdate.exe (PID: 2600)
      • AVGBrowserUpdate.exe (PID: 3608)
      • setup.exe (PID: 124)
      • setup.exe (PID: 3580)
      • AVGBrowserUpdate.exe (PID: 2336)
      • AVGBrowserUpdate.exe (PID: 2920)
      • instup.exe (PID: 4004)
      • sbr.exe (PID: 1876)
    • Loads dropped or rewritten executable

      • avg_secure_browser_setup.exe (PID: 2904)
      • AVGBrowserUpdate.exe (PID: 2920)
      • AVGBrowserUpdate.exe (PID: 2600)
      • AVGBrowserUpdate.exe (PID: 3152)
      • AVGBrowserUpdate.exe (PID: 2336)
      • instup.exe (PID: 1064)
      • AVGBrowserUpdate.exe (PID: 2196)
      • AVGBrowserUpdate.exe (PID: 3608)
      • instup.exe (PID: 4004)
  • SUSPICIOUS

    • Starts itself from another location

      • AVGBrowserUpdate.exe (PID: 2600)
      • instup.exe (PID: 1064)
    • Application launched itself

      • setup.exe (PID: 124)
  • INFO

    • Application was dropped or rewritten from another process

      • Purple Bit - Linkvertise Downloader_kCHx-K1.tmp (PID: 520)
      • Purple Bit - Linkvertise Downloader_kCHx-K1.tmp (PID: 4048)
    • Loads dropped or rewritten executable

      • Purple Bit - Linkvertise Downloader_kCHx-K1.tmp (PID: 520)
    • Application launched itself

      • iexplore.exe (PID: 3908)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2021-Jun-03 08:09:11
Detected languages:
  • English - United States
Comments: This installation was built with Inno Setup.
CompanyName: -
FileDescription: Linkvertise GmbH & Co. KG
FileVersion: 2.0.0.15
LegalCopyright: -
OriginalFileName: -
ProductName: Linkvertise GmbH & Co. KG
ProductVersion: 2.0.0.15

DOS Header

e_magic: MZ
e_cblp: 80
e_cp: 2
e_crlc: -
e_cparhdr: 4
e_minalloc: 15
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: 26
e_oemid: -
e_oeminfo: -
e_lfanew: 256

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 10
TimeDateStamp: 2021-Jun-03 08:09:11
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_BYTES_REVERSED_HI
  • IMAGE_FILE_BYTES_REVERSED_LO
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
4096
734748
735232
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.35606
.itext
741376
5768
6144
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.97275
.data
749568
14244
14336
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.0444
.bss
765952
28136
0
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.idata
794624
3894
4096
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.8987
.didata
798720
420
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.75636
.edata
802816
154
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
1.87222
.tls
806912
24
0
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rdata
811008
93
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
1.38389
.rsrc
815104
472684
473088
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.9711

Resources

Title
Entropy
Size
Codepage
Language
Type
1
2.53418
74792
Latin 1 / Western European
English - United States
RT_ICON
2
3.30061
19496
Latin 1 / Western European
English - United States
RT_ICON
3
4.23227
3752
Latin 1 / Western European
English - United States
RT_ICON
4
4.59583
2216
Latin 1 / Western European
English - United States
RT_ICON
5
5.29635
1736
Latin 1 / Western European
English - United States
RT_ICON
6
4.32066
1384
Latin 1 / Western European
English - United States
RT_ICON
7
3.50817
270376
Latin 1 / Western European
English - United States
RT_ICON
8
4.33111
67624
Latin 1 / Western European
English - United States
RT_ICON
9
5.37856
9640
Latin 1 / Western European
English - United States
RT_ICON
10
5.68979
4264
Latin 1 / Western European
English - United States
RT_ICON

Imports

advapi32.dll
comctl32.dll
kernel32.dll
kernel32.dll (delay-loaded)
netapi32.dll
oleaut32.dll
user32.dll
version.dll

Exports

Title
Ordinal
Address
dbkFCallWrapperAddr
1
779836
__dbk_fcall_wrapper
2
53408
TMethodImplementationIntercept
3
344160
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
22
Malicious processes
11
Suspicious processes
7

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start purple bit - linkvertise downloader_kchx-k1.exe no specs purple bit - linkvertise downloader_kchx-k1.tmp no specs purple bit - linkvertise downloader_kchx-k1.exe purple bit - linkvertise downloader_kchx-k1.tmp cookie_mmm_irs_ppi_902_451_o.exe avg_secure_browser_setup.exe iexplore.exe iexplore.exe avg_antivirus_free_setup.exe instup.exe avgbrowserupdatesetup.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe instup.exe sbr.exe no specs avgbrowserinstaller.exe no specs setup.exe no specs setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\AVG\Browser\Update\Install\{7E62F6C5-DBA5-40FD-B2F3-E566A716BC54}\CR_AB409.tmp\setup.exe" --install-archive="C:\Program Files\AVG\Browser\Update\Install\{7E62F6C5-DBA5-40FD-B2F3-E566A716BC54}\CR_AB409.tmp\SECURE.PACKED.7Z" --chrome --do-not-launch-chrome --hide-browser-override --show-developer-mode --suppress-first-run-bubbles --default-search-id=1003 --default-search=bing.com --adblock-mode-default=0 --make-chrome-default --force-default-win10 --reset-default-win10 --auto-import-data=iexplore --import-cookies --auto-launch-chrome --private-browsing --system-levelC:\Program Files\AVG\Browser\Update\Install\{7E62F6C5-DBA5-40FD-B2F3-E566A716BC54}\CR_AB409.tmp\setup.exeAVGBrowserInstaller.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Secure Browser Installer
Exit code:
0
Version:
105.0.18468.128
Modules
Images
c:\program files\avg\browser\update\install\{7e62f6c5-dba5-40fd-b2f3-e566a716bc54}\cr_ab409.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shell32.dll
520"C:\Users\admin\AppData\Local\Temp\is-JS0LH.tmp\Purple Bit - Linkvertise Downloader_kCHx-K1.tmp" /SL5="$2013A,3586129,1235456,C:\Users\admin\AppData\Local\Temp\Purple Bit - Linkvertise Downloader_kCHx-K1.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\is-JS0LH.tmp\Purple Bit - Linkvertise Downloader_kCHx-K1.tmp
Purple Bit - Linkvertise Downloader_kCHx-K1.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-js0lh.tmp\purple bit - linkvertise downloader_kchx-k1.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
872"C:\Users\admin\AppData\Local\Temp\Purple Bit - Linkvertise Downloader_kCHx-K1.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\Purple Bit - Linkvertise Downloader_kCHx-K1.exe
Purple Bit - Linkvertise Downloader_kCHx-K1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Linkvertise GmbH & Co. KG
Exit code:
0
Version:
2.0.0.15
Modules
Images
c:\users\admin\appdata\local\temp\purple bit - linkvertise downloader_kchx-k1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
892"C:\Users\admin\AppData\Local\Temp\Purple Bit - Linkvertise Downloader_kCHx-K1.exe" C:\Users\admin\AppData\Local\Temp\Purple Bit - Linkvertise Downloader_kCHx-K1.exeExplorer.EXE
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Linkvertise GmbH & Co. KG
Exit code:
0
Version:
2.0.0.15
Modules
Images
c:\users\admin\appdata\local\temp\purple bit - linkvertise downloader_kchx-k1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1064"C:\Windows\Temp\asw.9df8a55a6b1b87ea\instup.exe" /sfx:lite /sfxstorage:C:\Windows\Temp\asw.9df8a55a6b1b87ea /edition:15 /prod:ais /guid:e4ec6b25-ded4-4807-b36f-3f14fbbfb545 /ga_clientid:0bd8de41-dc2f-4078-9383-f73f315604a4 /silent /ws /psh:92pTtLC14DkVy5lBWvVWtPJdxYeFPEST4YHLBQw4ZiK3L6AyyrLPOtogzAJTzRnQHJSjsEPUSOqtRc /cookie:mmm_irs_ppi_902_451_o /ga_clientid:0bd8de41-dc2f-4078-9383-f73f315604a4 /edat_dir:C:\Windows\Temp\asw.daff02292c355969C:\Windows\Temp\asw.9df8a55a6b1b87ea\instup.exe
avg_antivirus_free_setup.exe
User:
admin
Company:
AVG Technologies CZ, s.r.o.
Integrity Level:
HIGH
Description:
AVG Antivirus Installer
Exit code:
0
Version:
22.9.7554.0
Modules
Images
c:\windows\temp\asw.9df8a55a6b1b87ea\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
1876"C:\Windows\Temp\asw.9df8a55a6b1b87ea\New_16090cb6\sbr.exe" 4004 "AVG Antivirus setup" "AVG Antivirus is being installed. Do not shut down your computer!"C:\Windows\Temp\asw.9df8a55a6b1b87ea\New_16090cb6\sbr.exeinstup.exe
User:
admin
Company:
AVG Technologies CZ, s.r.o.
Integrity Level:
HIGH
Description:
AVG Shutdown blocker
Exit code:
0
Version:
22.9.7554.0
Modules
Images
c:\windows\temp\asw.9df8a55a6b1b87ea\new_16090cb6\sbr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2196"C:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exe" /regserverC:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exeAVGBrowserUpdate.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Browser
Exit code:
0
Version:
1.8.1207.2
Modules
Images
c:\program files\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2320"C:\Users\admin\AppData\Local\Temp\nsz7DD.tmp\AVGBrowserUpdateSetup.exe" /silent /install "bundlename=AVG Secure Browser&appguid={48F69C39-1356-4A7B-A899-70E3539D4982}&appname=AVG Secure Browser&needsadmin=true&lang=en-US&brand=9145&installargs=--make-chrome-default --force-default-win10 --reset-default-win10 --auto-import-data%3Diexplore --import-cookies --auto-launch-chrome --private-browsing" C:\Users\admin\AppData\Local\Temp\nsz7DD.tmp\AVGBrowserUpdateSetup.exeavg_secure_browser_setup.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Browser Setup
Exit code:
0
Version:
1.8.1207.2
Modules
Images
c:\users\admin\appdata\local\temp\nsz7dd.tmp\avgbrowserupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2332"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3908 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2336"C:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exe" /handoff "bundlename=AVG Secure Browser&appguid={48F69C39-1356-4A7B-A899-70E3539D4982}&appname=AVG Secure Browser&needsadmin=true&lang=en-US&brand=9145&installargs=--make-chrome-default --force-default-win10 --reset-default-win10 --auto-import-data%3Diexplore --import-cookies --auto-launch-chrome --private-browsing" /installsource otherinstallcmd /sessionid "{CBE947BB-B7CA-470E-8DC6-F6D075CE4EF9}" /silentC:\Program Files\AVG\Browser\Update\AVGBrowserUpdate.exeAVGBrowserUpdate.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Browser
Exit code:
0
Version:
1.8.1207.2
Modules
Images
c:\program files\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\gdi32.dll
Total events
60 587
Read events
54 295
Write events
6 275
Delete events
17

Modification events

(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
08020000C4E0F7917DD8D801
(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
E5F8943FD6AED534C8DB02AC529C783A4951D9F7B9AD2562A10D53A0A84F1799
(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Operation:writeName:Implementing
Value:
1C00000001000000E6070A000300050005002D0009003601010000001E768127E028094199FEB9D127C57AFE
(PID) Process:(520) Purple Bit - Linkvertise Downloader_kCHx-K1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
01000000000000001C5521A17DD8D801
Executable files
190
Suspicious files
63
Text files
60
Unknown types
10

Dropped files

PID
Process
Filename
Type
892Purple Bit - Linkvertise Downloader_kCHx-K1.exeC:\Users\admin\AppData\Local\Temp\is-15NSU.tmp\Purple Bit - Linkvertise Downloader_kCHx-K1.tmpexecutable
MD5:
SHA256:
872Purple Bit - Linkvertise Downloader_kCHx-K1.exeC:\Users\admin\AppData\Local\Temp\is-JS0LH.tmp\Purple Bit - Linkvertise Downloader_kCHx-K1.tmpexecutable
MD5:
SHA256:
520Purple Bit - Linkvertise Downloader_kCHx-K1.tmpC:\Users\admin\AppData\Local\Temp\is-84F91.tmp\is-OKI72.tmpcompressed
MD5:
SHA256:
520Purple Bit - Linkvertise Downloader_kCHx-K1.tmpC:\Users\admin\AppData\Local\Temp\is-84F91.tmp\prod1compressed
MD5:
SHA256:
520Purple Bit - Linkvertise Downloader_kCHx-K1.tmpC:\Users\admin\AppData\Local\Temp\is-84F91.tmp\botva2.dllexecutable
MD5:67965A5957A61867D661F05AE1F4773E
SHA256:450B9B0BA25BF068AFBC2B23D252585A19E282939BF38326384EA9112DFD0105
520Purple Bit - Linkvertise Downloader_kCHx-K1.tmpC:\Users\admin\AppData\Local\Temp\is-84F91.tmp\is-TLVBN.tmpimage
MD5:0B4FA89D69051DF475B75CA654752EF6
SHA256:60A9085CEA2E072D4B65748CC71F616D3137C1F0B7EED4F77E1B6C9E3AA78B7E
520Purple Bit - Linkvertise Downloader_kCHx-K1.tmpC:\Users\admin\AppData\Local\Temp\is-84F91.tmp\error.pngimage
MD5:49C631D696316E3BD64C329DD371E20E
SHA256:177C744BE364460669C7F4CB9E047880A3EBDFA2246CBE7972BC23B9FC5C66D6
520Purple Bit - Linkvertise Downloader_kCHx-K1.tmpC:\Users\admin\AppData\Local\Temp\is-84F91.tmp\AppUtils.dllexecutable
MD5:43CE6D593ABD5141A3139603F352AE05
SHA256:94E874F2702EA6BE50E7D74864B66E7F763449C3DB237803F3FAD6ADFD64ED3D
520Purple Bit - Linkvertise Downloader_kCHx-K1.tmpC:\Users\admin\AppData\Local\Temp\is-84F91.tmp\ConversionUtils.dllexecutable
MD5:11A2B396E54D876BF7E775F8F46198C5
SHA256:E4374170EB83AF2EF83759BA9D35A168802A3FE48F30C5E5E1B259BEBB682B1E
520Purple Bit - Linkvertise Downloader_kCHx-K1.tmpC:\Users\admin\AppData\Local\Temp\is-84F91.tmp\is-3010D.tmpimage
MD5:5EF5291810C454A35F76D976105F37CC
SHA256:03E69E8C87732C625DF2F628AC63BD145268F9DEA9C5F3DD3670B1CF349A995C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
88
DNS requests
82
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2668
cookie_mmm_irs_ppi_902_451_o.exe
GET
200
2.16.107.98:80
http://iavs9x.avg.u.avcdn.net/avg/iavs9x/avg_antivirus_free_setup.exe
unknown
executable
8.44 Mb
whitelisted
2920
AVGBrowserUpdate.exe
GET
200
2.16.107.73:80
http://browser-update.avg.com/browser-avg/win/x86/105.0.18468.128/AVGBrowserInstaller.exe
unknown
executable
93.8 Mb
whitelisted
2668
cookie_mmm_irs_ppi_902_451_o.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
US
whitelisted
2904
avg_secure_browser_setup.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
2332
iexplore.exe
GET
200
67.27.235.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d78716e20aef36f8
US
compressed
60.9 Kb
whitelisted
2332
iexplore.exe
GET
200
2.16.218.170:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOzJpQ%2FGujoyQ4OpCfBtBDStQ%3D%3D
unknown
der
503 b
shared
1064
instup.exe
GET
200
2.22.146.136:80
http://k8136955.iavs9x.avg.u.avcdn.net/avg/iavs9x/avdump_x86_ais-cb6.vpx
GB
binary
380 Kb
suspicious
1064
instup.exe
GET
200
2.22.146.136:80
http://k8136955.iavs9x.avg.u.avcdn.net/avg/iavs9x/avbugreport_ais-cb6.vpx
GB
binary
1.17 Mb
suspicious
3908
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2BnRyLFPYjID1ie%2Bx%2BdSjo%3D
US
der
1.47 Kb
whitelisted
1064
instup.exe
GET
200
2.22.146.136:80
http://s8784910.iavs9x.avg.u.avcdn.net/avg/iavs9x/servers.def.vpx
GB
binary
1.36 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
520
Purple Bit - Linkvertise Downloader_kCHx-K1.tmp
99.86.1.227:443
d2khbwcectqqex.cloudfront.net
AMAZON-02
US
unknown
2668
cookie_mmm_irs_ppi_902_451_o.exe
2.16.107.98:80
iavs9x.avg.u.avcdn.net
Akamai International B.V.
DE
suspicious
2668
cookie_mmm_irs_ppi_902_451_o.exe
34.117.223.223:80
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2668
cookie_mmm_irs_ppi_902_451_o.exe
142.250.187.110:80
www.google-analytics.com
GOOGLE
US
whitelisted
2904
avg_secure_browser_setup.exe
104.22.64.125:443
stats.avgbrowser.com
CLOUDFLARENET
whitelisted
2904
avg_secure_browser_setup.exe
67.27.235.254:80
ctldl.windowsupdate.com
LEVEL3
US
suspicious
2332
iexplore.exe
107.189.8.5:443
rentry.co
PONYNET
LU
unknown
2888
avg_antivirus_free_setup.exe
34.117.223.223:443
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2888
avg_antivirus_free_setup.exe
142.250.187.110:80
www.google-analytics.com
GOOGLE
US
whitelisted
2332
iexplore.exe
67.27.235.254:80
ctldl.windowsupdate.com
LEVEL3
US
suspicious

DNS requests

Domain
IP
Reputation
d2khbwcectqqex.cloudfront.net
  • 99.86.1.227
  • 99.86.1.160
  • 99.86.1.8
  • 99.86.1.72
suspicious
iavs9x.avg.u.avcdn.net
  • 2.16.107.98
  • 2.16.107.50
whitelisted
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
www.google-analytics.com
  • 142.250.187.110
whitelisted
stats.avgbrowser.com
  • 104.22.64.125
  • 104.22.65.125
  • 172.67.5.41
suspicious
rentry.co
  • 107.189.8.5
suspicious
ctldl.windowsupdate.com
  • 67.27.235.254
  • 67.27.235.126
  • 8.241.122.254
  • 8.241.121.254
  • 8.241.121.126
whitelisted
v7event.stats.avcdn.net
  • 34.117.223.223
whitelisted
analytics.ff.avast.com
  • 34.117.223.223
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

PID
Process
Class
Message
2668
cookie_mmm_irs_ppi_902_451_o.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2920
AVGBrowserUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
instup.exe
[2022-10-05 05:45:26.997] [error ] [shepsync ] [ 4004: 3860] [F13050: 194] Exception: WinHttpSendRequest failed. WinHTTP error code: 12175. 'A security error occurred' Code: 0x00002f8f (12175)
avg_antivirus_free_setup.exe
[2022-10-05 05:45:27.997] [error ] [sfxstats ] [ 2888: 1700] [7997C7: 153] Unable to send statistics with error 0x00002f8f (Unable to send statistics!)
instup.exe
[2022-10-05 05:45:48.060] [error ] [shepsync ] [ 4004: 3860] [F13050: 194] Exception: CURL request failed (https://shepherd.avcdn.net/). CURL error code: 28. Timeout was reached. Failed to connect to shepherd.avcdn.net port 443 after 526 ms: Timed out Code: 0x0000001c (28)