URL:

https://pinginfoview.com/wp-content/uploads/2025/01/Downloads.zip

Full analysis: https://app.any.run/tasks/e01f6651-21eb-4285-9f43-da784b997fd4
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 18, 2025, 07:37:51
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
loader
stealer
antivm
Indicators:
MD5:

05302F5C1A9D99EC9D97A7C39E59755C

SHA1:

B8F4C55F0C8EBCCC2DEB121031FFF43D761C5A84

SHA256:

E9C14397354A53B069288DA06106780F040054E640A23A82CA812BBE9B6071D6

SSDEEP:

3:N8I2M2SZ2OlAQyXZ+6zgLcn:2ISLOlAZpvLn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • AvastBrowserInstaller.exe (PID: 4684)
      • AvastBrowser.exe (PID: 7996)
    • Changes the autorun value in the registry

      • instup.exe (PID: 2384)
      • setup.exe (PID: 7588)
      • AvastBrowser.exe (PID: 7816)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • avast_secure_browser_setup.exe (PID: 8132)
      • AvastBrowserInstaller.exe (PID: 4684)
    • Reads security settings of Internet Explorer

      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • AvastBrowserInstaller.exe (PID: 4684)
      • WinRAR.exe (PID: 7928)
      • AvastBrowserUpdate.exe (PID: 5476)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 7424)
      • AvastBrowserInstaller.exe (PID: 7432)
    • Executable content was dropped or overwritten

      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • avast_secure_browser_setup.exe (PID: 8132)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4544)
      • avast_free_antivirus_setup_online_x64.exe (PID: 2692)
      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
      • Instup.exe (PID: 6412)
      • AvastBrowserInstaller.exe (PID: 4012)
      • avast_secure_browser_setup.exe (PID: 5928)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 7424)
      • setup.exe (PID: 7588)
      • AvastBrowserInstaller.exe (PID: 4684)
    • Process requests binary or script from the Internet

      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4544)
      • AvastBrowserUpdate.exe (PID: 8016)
    • The process verifies whether the antivirus software is installed

      • AvastBrowserInstaller.exe (PID: 4684)
      • AvastBrowserUpdate.exe (PID: 5476)
      • AvastBrowserUpdate.exe (PID: 1936)
      • AvastBrowserUpdate.exe (PID: 2664)
      • AvastBrowserUpdateComRegisterShell64.exe (PID: 4844)
      • AvastBrowserUpdateComRegisterShell64.exe (PID: 3944)
      • AvastBrowserUpdateComRegisterShell64.exe (PID: 7888)
      • AvastBrowserUpdate.exe (PID: 6388)
      • AvastBrowserUpdate.exe (PID: 4476)
      • AvastBrowserUpdate.exe (PID: 8016)
      • AvastBrowserInstaller.exe (PID: 4012)
      • setup.exe (PID: 7588)
      • setup.exe (PID: 6508)
      • instup.exe (PID: 2384)
      • AvastBrowserCrashHandler64.exe (PID: 7808)
      • AvastBrowserCrashHandler.exe (PID: 2040)
      • AvastBrowser.exe (PID: 2996)
      • AvastBrowser.exe (PID: 7816)
      • AvastBrowser.exe (PID: 5992)
      • AvastBrowser.exe (PID: 1864)
      • elevation_service.exe (PID: 5928)
      • AvastBrowser.exe (PID: 2032)
      • AvastBrowser.exe (PID: 828)
      • AvastBrowser.exe (PID: 8060)
      • elevation_service.exe (PID: 7768)
      • AvastBrowser.exe (PID: 7800)
      • AvastBrowser.exe (PID: 1576)
      • AvastBrowser.exe (PID: 7652)
      • AvastBrowser.exe (PID: 7996)
      • AvastBrowser.exe (PID: 8012)
      • AvastBrowser.exe (PID: 5884)
      • AvastBrowser.exe (PID: 6428)
    • Potential Corporate Privacy Violation

      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4544)
      • AvastBrowserUpdate.exe (PID: 8016)
    • Starts itself from another location

      • AvastBrowserUpdate.exe (PID: 5476)
      • Instup.exe (PID: 6412)
    • Disables SEHOP

      • AvastBrowserUpdate.exe (PID: 5476)
    • Creates/Modifies COM task schedule object

      • AvastBrowserUpdateComRegisterShell64.exe (PID: 4844)
      • AvastBrowserUpdate.exe (PID: 2664)
      • AvastBrowserUpdateComRegisterShell64.exe (PID: 3944)
      • AvastBrowserUpdateComRegisterShell64.exe (PID: 7888)
      • AvastBrowserUpdate.exe (PID: 5476)
    • Executes as Windows Service

      • AvastBrowserUpdate.exe (PID: 8016)
      • elevation_service.exe (PID: 5928)
      • elevation_service.exe (PID: 7768)
    • Application launched itself

      • setup.exe (PID: 7588)
      • AvastBrowser.exe (PID: 7816)
      • AvastBrowser.exe (PID: 5884)
    • There is functionality for VM detection VMWare (YARA)

      • AvastBrowserInstaller.exe (PID: 4684)
    • There is functionality for VM detection VirtualBox (YARA)

      • AvastBrowserInstaller.exe (PID: 4684)
    • There is functionality for VM detection antiVM strings (YARA)

      • AvastBrowserInstaller.exe (PID: 4684)
    • Process checks presence of unattended files

      • instup.exe (PID: 2384)
    • Searches for installed software

      • setup.exe (PID: 7588)
      • AvastBrowser.exe (PID: 7816)
      • AvastBrowserInstaller.exe (PID: 4684)
    • Creates a software uninstall entry

      • setup.exe (PID: 7588)
      • AvastBrowserInstaller.exe (PID: 4684)
      • elevation_service.exe (PID: 5928)
    • Reads the BIOS version

      • AvastBrowser.exe (PID: 7816)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 6940)
    • Reads the computer name

      • identity_helper.exe (PID: 7580)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4544)
      • AvastBrowserInstaller.exe (PID: 4684)
      • avast_free_antivirus_setup_online_x64.exe (PID: 2692)
      • Instup.exe (PID: 6412)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • AvastBrowserUpdate.exe (PID: 5476)
      • AvastBrowserUpdate.exe (PID: 1936)
      • AvastBrowserUpdate.exe (PID: 2664)
      • AvastBrowserUpdate.exe (PID: 6388)
      • AvastBrowserUpdate.exe (PID: 4476)
      • AvastBrowserUpdate.exe (PID: 8016)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 7424)
      • instup.exe (PID: 2384)
      • AvastBrowserInstaller.exe (PID: 4012)
      • setup.exe (PID: 7588)
      • AvastBrowserInstaller.exe (PID: 7432)
      • AvastBrowser.exe (PID: 7816)
      • AvastBrowser.exe (PID: 1864)
      • elevation_service.exe (PID: 5928)
      • AvastBrowser.exe (PID: 5992)
      • AvastBrowser.exe (PID: 7996)
      • elevation_service.exe (PID: 7768)
      • AvastBrowser.exe (PID: 5884)
    • Reads Environment values

      • identity_helper.exe (PID: 7580)
      • Instup.exe (PID: 6412)
      • instup.exe (PID: 2384)
      • AvastBrowser.exe (PID: 7816)
    • Checks supported languages

      • identity_helper.exe (PID: 7580)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4544)
      • avast_secure_browser_setup.exe (PID: 8132)
      • AvastBrowserInstaller.exe (PID: 4684)
      • avast_free_antivirus_setup_online_x64.exe (PID: 2692)
      • Instup.exe (PID: 6412)
      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
      • AvastBrowserUpdate.exe (PID: 1936)
      • AvastBrowserUpdate.exe (PID: 2664)
      • AvastBrowserUpdateComRegisterShell64.exe (PID: 4844)
      • AvastBrowserUpdateComRegisterShell64.exe (PID: 3944)
      • AvastBrowserUpdate.exe (PID: 6388)
      • AvastBrowserUpdate.exe (PID: 4476)
      • AvastBrowserUpdateComRegisterShell64.exe (PID: 7888)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 7424)
      • instup.exe (PID: 2384)
      • AvastBrowserUpdate.exe (PID: 8016)
      • AvastBrowserInstaller.exe (PID: 4012)
      • setup.exe (PID: 7588)
      • setup.exe (PID: 6508)
      • sbr.exe (PID: 3160)
      • avast_secure_browser_setup.exe (PID: 5928)
      • AvastBrowserInstaller.exe (PID: 7432)
      • AvastBrowserCrashHandler64.exe (PID: 7808)
      • AvastBrowserCrashHandler.exe (PID: 2040)
      • AvastBrowser.exe (PID: 2996)
      • AvastBrowser.exe (PID: 5992)
      • AvastBrowser.exe (PID: 1864)
      • AvastBrowser.exe (PID: 7816)
      • elevation_service.exe (PID: 5928)
      • AvastBrowser.exe (PID: 2032)
      • AvastBrowser.exe (PID: 828)
      • AvastBrowser.exe (PID: 8060)
      • AvastBrowser.exe (PID: 8012)
      • elevation_service.exe (PID: 7768)
      • AvastBrowser.exe (PID: 7800)
      • AvastBrowser.exe (PID: 7652)
      • AvastBrowser.exe (PID: 1576)
      • AvastBrowser.exe (PID: 7996)
      • AvastBrowser.exe (PID: 5884)
      • AvastBrowser.exe (PID: 6428)
    • The sample compiled with english language support

      • msedge.exe (PID: 3400)
      • msedge.exe (PID: 6940)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • avast_secure_browser_setup.exe (PID: 8132)
      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4544)
      • avast_free_antivirus_setup_online_x64.exe (PID: 2692)
      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • WinRAR.exe (PID: 7928)
      • AvastBrowserUpdate.exe (PID: 5476)
      • Instup.exe (PID: 6412)
      • AvastBrowserInstaller.exe (PID: 4012)
      • avast_secure_browser_setup.exe (PID: 5928)
      • setup.exe (PID: 7588)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 6940)
    • Create files in a temporary directory

      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • avast_secure_browser_setup.exe (PID: 8132)
      • AvastBrowserInstaller.exe (PID: 4684)
      • AvastBrowserUpdate.exe (PID: 8016)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 7424)
      • avast_secure_browser_setup.exe (PID: 5928)
      • AvastBrowser.exe (PID: 7816)
    • Creates files or folders in the user directory

      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • AvastBrowserInstaller.exe (PID: 4684)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 7424)
      • AvastBrowser.exe (PID: 7816)
      • AvastBrowser.exe (PID: 1864)
      • AvastBrowser.exe (PID: 5884)
      • AvastBrowser.exe (PID: 6428)
    • Reads the machine GUID from the registry

      • cookie_mmm_irs_ppi_005_888_a.exe (PID: 4544)
      • AvastBrowserInstaller.exe (PID: 4684)
      • avast_free_antivirus_setup_online_x64.exe (PID: 2692)
      • Instup.exe (PID: 6412)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • AvastBrowserUpdate.exe (PID: 5476)
      • instup.exe (PID: 2384)
      • AvastBrowserUpdate.exe (PID: 8016)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 7424)
      • AvastBrowserInstaller.exe (PID: 7432)
      • AvastBrowser.exe (PID: 7816)
    • Reads the software policy settings

      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • avast_free_antivirus_setup_online_x64.exe (PID: 2692)
      • AvastBrowserInstaller.exe (PID: 4684)
      • Instup.exe (PID: 6412)
      • AvastBrowserUpdate.exe (PID: 6388)
      • AvastBrowserUpdate.exe (PID: 8016)
      • instup.exe (PID: 2384)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 7424)
    • Process checks computer location settings

      • AvastBrowserInstaller.exe (PID: 4684)
      • AvastBrowserUpdate.exe (PID: 5476)
      • AvastBrowser.exe (PID: 828)
      • AvastBrowser.exe (PID: 7816)
      • AvastBrowser.exe (PID: 8060)
      • AvastBrowser.exe (PID: 7652)
    • Reads CPU info

      • avast_free_antivirus_setup_online_x64.exe (PID: 2692)
      • Instup.exe (PID: 6412)
      • instup.exe (PID: 2384)
    • Creates files in the program directory

      • avast_free_antivirus_setup_online_x64.exe (PID: 2692)
      • Instup.exe (PID: 6412)
      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
      • AvastBrowserUpdate.exe (PID: 8016)
      • AvastBrowserInstaller.exe (PID: 4012)
      • setup.exe (PID: 7588)
      • instup.exe (PID: 2384)
      • AvastBrowserInstaller.exe (PID: 4684)
    • Checks proxy server information

      • avast_free_antivirus_setup_online_x64.exe (PID: 2692)
      • AvastBrowserInstaller.exe (PID: 4684)
      • Instup.exe (PID: 6412)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 8044)
      • AvastBrowserUpdate.exe (PID: 6388)
      • instup.exe (PID: 2384)
      • pinginfoview-2.22-installer_gW-sh61.exe (PID: 7424)
      • AvastBrowser.exe (PID: 7816)
    • The sample compiled with arabic language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with czech language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with french language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with korean language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with Indonesian language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with Italian language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with japanese language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with russian language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with polish language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with portuguese language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with turkish language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with swedish language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with slovak language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with bulgarian language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with german language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • The sample compiled with chinese language support

      • AvastBrowserUpdateSetup.exe (PID: 4228)
      • AvastBrowserUpdate.exe (PID: 5476)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7928)
    • Launching a file from a Registry key

      • instup.exe (PID: 2384)
      • setup.exe (PID: 7588)
      • AvastBrowser.exe (PID: 7816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
208
Monitored processes
68
Malicious processes
37
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs winrar.exe pinginfoview-2.22-installer_gw-sh61.exe no specs pinginfoview-2.22-installer_gw-sh61.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs cookie_mmm_irs_ppi_005_888_a.exe avast_secure_browser_setup.exe avastbrowserinstaller.exe avast_free_antivirus_setup_online_x64.exe instup.exe avastbrowserupdatesetup.exe avastbrowserupdate.exe avastbrowserupdate.exe no specs avastbrowserupdate.exe no specs avastbrowserupdatecomregistershell64.exe no specs avastbrowserupdatecomregistershell64.exe no specs avastbrowserupdatecomregistershell64.exe no specs avastbrowserupdate.exe avastbrowserupdate.exe no specs avastbrowserupdate.exe slui.exe no specs pinginfoview-2.22-installer_gw-sh61.exe no specs pinginfoview-2.22-installer_gw-sh61.exe instup.exe avastbrowserinstaller.exe setup.exe setup.exe no specs sbr.exe no specs msedge.exe no specs msedge.exe no specs avast_secure_browser_setup.exe avastbrowserinstaller.exe avastbrowsercrashhandler.exe no specs avastbrowsercrashhandler64.exe no specs msedge.exe no specs avastbrowser.exe avastbrowser.exe avastbrowser.exe no specs avastbrowser.exe elevation_service.exe no specs avastbrowser.exe no specs avastbrowser.exe no specs avastbrowser.exe no specs avastbrowser.exe avastbrowser.exe no specs avastbrowser.exe no specs elevation_service.exe no specs avastbrowser.exe no specs avastbrowser.exe no specs avastbrowser.exe no specs avastbrowser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
828"C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --type=renderer --extension-process --force-high-res-timeticks=disabled --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=2068,i,17670250828544161016,17462955532263958310,262144 --variations-seed-version --mojo-platform-channel-handle=3384 /prefetch:2C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exeAvastBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
Avast Secure Browser
Exit code:
0
Version:
137.0.31047.122
Modules
Images
c:\program files\avast software\browser\application\avastbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avast software\browser\application\137.0.31047.122\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1576"C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --force-high-res-timeticks=disabled --field-trial-handle=2068,i,17670250828544161016,17462955532263958310,262144 --variations-seed-version --mojo-platform-channel-handle=3816 /prefetch:8C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exeAvastBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
Avast Secure Browser
Exit code:
0
Version:
137.0.31047.122
Modules
Images
c:\program files\avast software\browser\application\avastbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avast software\browser\application\137.0.31047.122\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1864"C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --force-high-res-timeticks=disabled --field-trial-handle=2068,i,17670250828544161016,17462955532263958310,262144 --variations-seed-version --mojo-platform-channel-handle=2280 /prefetch:3C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe
AvastBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
Avast Secure Browser
Exit code:
0
Version:
137.0.31047.122
Modules
Images
c:\program files\avast software\browser\application\avastbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avast software\browser\application\137.0.31047.122\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1936"C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /regsvcC:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exeAvastBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Browser
Exit code:
0
Version:
1.8.1993.6
Modules
Images
c:\program files (x86)\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2032"C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --force-high-res-timeticks=disabled --field-trial-handle=2068,i,17670250828544161016,17462955532263958310,262144 --variations-seed-version --mojo-platform-channel-handle=2488 /prefetch:8C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exeAvastBrowser.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
LOW
Description:
Avast Secure Browser
Exit code:
0
Version:
137.0.31047.122
Modules
Images
c:\program files\avast software\browser\application\avastbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\avast software\browser\application\137.0.31047.122\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
2040"C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1993.6\AvastBrowserCrashHandler.exe"C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1993.6\AvastBrowserCrashHandler.exeAvastBrowserUpdate.exe
User:
SYSTEM
Company:
Gen Digital Inc.
Integrity Level:
SYSTEM
Description:
Avast Browser Crash Handler
Exit code:
0
Version:
1.8.1993.6
Modules
Images
c:\program files (x86)\avast software\browser\update\1.8.1993.6\avastbrowsercrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\kernel.appcore.dll
c:\windows\syswow64\msvcrt.dll
2312"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4264,i,10093245156811863829,13435504897887328994,262144 --variations-seed-version --mojo-platform-channel-handle=4276 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2384"C:\WINDOWS\Temp\asw.9679271102868f15\New_19061815\instup.exe" /sfx /sfxstorage:C:\WINDOWS\Temp\asw.9679271102868f15 /edition:1 /prod:ais /stub_context:47f0826e-5000-41b3-b6aa-594b16694b42:11665632 /guid:e3a95d10-4f26-443c-a668-c1a6c75731f6 /ga_clientid:5a3b5bd1-5db2-427f-ab92-9c6511bbee36 /silent /ws /psh:4i3U31IH7VYrc6ztLwXuJ4NlhyEzLm78jDVzdJWkB4G4U5A1M3MXomBXLc2Er4aBE3RaF6Gobyz2c /cookie:mmm_irs_ppi_005_888_a /edat_dir:C:\WINDOWS\Temp\asw.897ff28c8c5be08d /online_installerC:\Windows\Temp\asw.9679271102868f15\New_19061815\instup.exe
Instup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Version:
25.6.10221.0
Modules
Images
c:\windows\temp\asw.9679271102868f15\new_19061815\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
2620"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffc43d7f208,0x7ffc43d7f214,0x7ffc43d7f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2664"C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /regserverC:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exeAvastBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Browser
Exit code:
0
Version:
1.8.1993.6
Modules
Images
c:\program files (x86)\avast software\browser\update\avastbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
28 997
Read events
23 836
Write events
5 084
Delete events
77

Modification events

(PID) Process:(6940) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6940) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6940) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(6940) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(6940) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6940) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6940) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
BE61FB7CC5982F00
(PID) Process:(6940) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\1835042
Operation:writeName:WindowTabManagerFileMappingId
Value:
{0FA445C1-A0E0-4FA6-9209-D66C4F150277}
(PID) Process:(6940) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\1835042
Operation:writeName:WindowTabManagerFileMappingId
Value:
{BC0D6DDF-E860-4D21-9BE7-4F84A1280B4E}
(PID) Process:(6940) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
74EF167DC5982F00
Executable files
187
Suspicious files
181
Text files
121
Unknown types
67

Dropped files

PID
Process
Filename
Type
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF18d0f7.TMP
MD5:
SHA256:
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF18d107.TMP
MD5:
SHA256:
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF18d107.TMP
MD5:
SHA256:
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF18d107.TMP
MD5:
SHA256:
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF18d107.TMP
MD5:
SHA256:
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6940msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
47
TCP/UDP connections
117
DNS requests
145
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3400
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:NYUhJ5DRAitegAs_-su-7I0Oqp-B8Pi7G3M9uSDyrUk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
100 b
whitelisted
1468
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
6732
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
420 b
whitelisted
6732
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
8044
pinginfoview-2.22-installer_gW-sh61.exe
GET
200
104.18.20.213:80
http://r10.c.lencr.org/13.crl
unknown
binary
107 Kb
whitelisted
4544
cookie_mmm_irs_ppi_005_888_a.exe
GET
23.48.23.20:80
http://iavs9x.u.avast.com/iavs9x/avast_free_antivirus_setup_online_x64.exe
DE
whitelisted
4544
cookie_mmm_irs_ppi_005_888_a.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
US
whitelisted
4544
cookie_mmm_irs_ppi_005_888_a.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1040
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3400
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3400
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3400
msedge.exe
2.16.241.224:443
copilot.microsoft.com
Akamai International B.V.
DE
whitelisted
3400
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3400
msedge.exe
117.18.117.166:443
pinginfoview.com
HongKong Commercial Internet Exchange
HK
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
pinginfoview.com
  • 117.18.117.166
unknown
copilot.microsoft.com
  • 2.16.241.224
  • 2.16.241.220
whitelisted
update.googleapis.com
  • 142.250.186.131
whitelisted
www.bing.com
  • 2.16.241.204
  • 2.16.241.205
  • 2.16.241.206
  • 2.16.241.225
  • 2.16.241.222
  • 2.16.241.224
  • 2.16.241.200
  • 2.16.241.201
  • 2.16.241.219
  • 2.16.241.211
  • 2.16.241.207
whitelisted
edgeassetservice.azureedge.net
  • 13.107.253.45
whitelisted
www.googleapis.com
  • 142.250.181.234
  • 142.250.186.42
  • 142.250.186.170
  • 142.250.74.202
  • 142.250.186.138
  • 142.250.185.234
  • 142.250.185.106
  • 142.250.185.138
  • 216.58.206.74
  • 142.250.185.170
  • 142.250.185.202
  • 142.250.186.106
  • 216.58.212.170
  • 172.217.16.202
  • 142.250.186.74
  • 142.250.184.202
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.136
  • 20.190.160.5
  • 20.190.160.3
  • 40.126.32.68
  • 20.190.160.65
  • 20.190.160.67
  • 40.126.32.76
whitelisted

Threats

PID
Process
Class
Message
4544
cookie_mmm_irs_ppi_005_888_a.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
8016
AvastBrowserUpdate.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Process
Message
pinginfoview-2.22-installer_gW-sh61.exe
LoadingPage
pinginfoview-2.22-installer_gW-sh61.exe
WelcomePage
pinginfoview-2.22-installer_gW-sh61.exe
ProductPage
pinginfoview-2.22-installer_gW-sh61.exe
ProductPage
pinginfoview-2.22-installer_gW-sh61.exe
DownloadPageDLM
AvastBrowserInstaller.exe
2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:167) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AvastBrowserInstaller.exe
2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:168) Jinx logging started
AvastBrowserInstaller.exe
2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:169) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AvastBrowserInstaller.exe
2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:171) build date: May 12 2025 build number: 1738 build time: 11:01:36 build timestamp: May 12 2025 11:01:36 company: Gen Digital Inc. copyright: (C) 2017-2025 Gen Digital Inc. description: Secure Browser Installer file name: AvastBrowserInstaller.exe file version: 9.1.0.1738 git commit: 8544c67a02049729b6b1157ba0eacf01b83f2405 internal name: jinx-installer product name: Secure Browser Installer product version: 9.1.0.1738 target system: windows
AvastBrowserInstaller.exe
2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:181) Operating system: Windows Enterprise x64 10.0.19045.4046 SP0