| URL: | https://pinginfoview.com/wp-content/uploads/2025/01/Downloads.zip |
| Full analysis: | https://app.any.run/tasks/e01f6651-21eb-4285-9f43-da784b997fd4 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | July 18, 2025, 07:37:51 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 05302F5C1A9D99EC9D97A7C39E59755C |
| SHA1: | B8F4C55F0C8EBCCC2DEB121031FFF43D761C5A84 |
| SHA256: | E9C14397354A53B069288DA06106780F040054E640A23A82CA812BBE9B6071D6 |
| SSDEEP: | 3:N8I2M2SZ2OlAQyXZ+6zgLcn:2ISLOlAZpvLn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 828 | "C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --type=renderer --extension-process --force-high-res-timeticks=disabled --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=2068,i,17670250828544161016,17462955532263958310,262144 --variations-seed-version --mojo-platform-channel-handle=3384 /prefetch:2 | C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe | — | AvastBrowser.exe | |||||||||||
User: admin Company: Gen Digital Inc. Integrity Level: LOW Description: Avast Secure Browser Exit code: 0 Version: 137.0.31047.122 Modules
| |||||||||||||||
| 1576 | "C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --force-high-res-timeticks=disabled --field-trial-handle=2068,i,17670250828544161016,17462955532263958310,262144 --variations-seed-version --mojo-platform-channel-handle=3816 /prefetch:8 | C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe | — | AvastBrowser.exe | |||||||||||
User: admin Company: Gen Digital Inc. Integrity Level: LOW Description: Avast Secure Browser Exit code: 0 Version: 137.0.31047.122 Modules
| |||||||||||||||
| 1864 | "C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --force-high-res-timeticks=disabled --field-trial-handle=2068,i,17670250828544161016,17462955532263958310,262144 --variations-seed-version --mojo-platform-channel-handle=2280 /prefetch:3 | C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe | AvastBrowser.exe | ||||||||||||
User: admin Company: Gen Digital Inc. Integrity Level: MEDIUM Description: Avast Secure Browser Exit code: 0 Version: 137.0.31047.122 Modules
| |||||||||||||||
| 1936 | "C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /regsvc | C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe | — | AvastBrowserUpdate.exe | |||||||||||
User: admin Company: Gen Digital Inc. Integrity Level: HIGH Description: Avast Browser Exit code: 0 Version: 1.8.1993.6 Modules
| |||||||||||||||
| 2032 | "C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --force-high-res-timeticks=disabled --field-trial-handle=2068,i,17670250828544161016,17462955532263958310,262144 --variations-seed-version --mojo-platform-channel-handle=2488 /prefetch:8 | C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe | — | AvastBrowser.exe | |||||||||||
User: admin Company: Gen Digital Inc. Integrity Level: LOW Description: Avast Secure Browser Exit code: 0 Version: 137.0.31047.122 Modules
| |||||||||||||||
| 2040 | "C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1993.6\AvastBrowserCrashHandler.exe" | C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1993.6\AvastBrowserCrashHandler.exe | — | AvastBrowserUpdate.exe | |||||||||||
User: SYSTEM Company: Gen Digital Inc. Integrity Level: SYSTEM Description: Avast Browser Crash Handler Exit code: 0 Version: 1.8.1993.6 Modules
| |||||||||||||||
| 2312 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4264,i,10093245156811863829,13435504897887328994,262144 --variations-seed-version --mojo-platform-channel-handle=4276 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2384 | "C:\WINDOWS\Temp\asw.9679271102868f15\New_19061815\instup.exe" /sfx /sfxstorage:C:\WINDOWS\Temp\asw.9679271102868f15 /edition:1 /prod:ais /stub_context:47f0826e-5000-41b3-b6aa-594b16694b42:11665632 /guid:e3a95d10-4f26-443c-a668-c1a6c75731f6 /ga_clientid:5a3b5bd1-5db2-427f-ab92-9c6511bbee36 /silent /ws /psh:4i3U31IH7VYrc6ztLwXuJ4NlhyEzLm78jDVzdJWkB4G4U5A1M3MXomBXLc2Er4aBE3RaF6Gobyz2c /cookie:mmm_irs_ppi_005_888_a /edat_dir:C:\WINDOWS\Temp\asw.897ff28c8c5be08d /online_installer | C:\Windows\Temp\asw.9679271102868f15\New_19061815\instup.exe | Instup.exe | ||||||||||||
User: admin Company: Gen Digital Inc. Integrity Level: HIGH Description: Avast Antivirus Installer Version: 25.6.10221.0 Modules
| |||||||||||||||
| 2620 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffc43d7f208,0x7ffc43d7f214,0x7ffc43d7f220 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2664 | "C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /regserver | C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe | — | AvastBrowserUpdate.exe | |||||||||||
User: admin Company: Gen Digital Inc. Integrity Level: HIGH Description: Avast Browser Exit code: 0 Version: 1.8.1993.6 Modules
| |||||||||||||||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: BE61FB7CC5982F00 | |||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\1835042 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {0FA445C1-A0E0-4FA6-9209-D66C4F150277} | |||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\1835042 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {BC0D6DDF-E860-4D21-9BE7-4F84A1280B4E} | |||
| (PID) Process: | (6940) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: 74EF167DC5982F00 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF18d0f7.TMP | — | |
MD5:— | SHA256:— | |||
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF18d107.TMP | — | |
MD5:— | SHA256:— | |||
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF18d107.TMP | — | |
MD5:— | SHA256:— | |||
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF18d107.TMP | — | |
MD5:— | SHA256:— | |||
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF18d107.TMP | — | |
MD5:— | SHA256:— | |||
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6940 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3400 | msedge.exe | GET | 200 | 150.171.28.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:NYUhJ5DRAitegAs_-su-7I0Oqp-B8Pi7G3M9uSDyrUk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 100 b | whitelisted |
1468 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | DE | binary | 471 b | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 814 b | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
6732 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | DE | binary | 420 b | whitelisted |
6732 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | DE | binary | 408 b | whitelisted |
8044 | pinginfoview-2.22-installer_gW-sh61.exe | GET | 200 | 104.18.20.213:80 | http://r10.c.lencr.org/13.crl | unknown | binary | 107 Kb | whitelisted |
4544 | cookie_mmm_irs_ppi_005_888_a.exe | GET | — | 23.48.23.20:80 | http://iavs9x.u.avast.com/iavs9x/avast_free_antivirus_setup_online_x64.exe | DE | — | — | whitelisted |
4544 | cookie_mmm_irs_ppi_005_888_a.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | US | — | — | whitelisted |
4544 | cookie_mmm_irs_ppi_005_888_a.exe | POST | 200 | 142.250.186.78:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1040 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3400 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3400 | msedge.exe | 150.171.28.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3400 | msedge.exe | 2.16.241.224:443 | copilot.microsoft.com | Akamai International B.V. | DE | whitelisted |
3400 | msedge.exe | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3400 | msedge.exe | 117.18.117.166:443 | pinginfoview.com | HongKong Commercial Internet Exchange | HK | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
pinginfoview.com |
| unknown |
copilot.microsoft.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
www.bing.com |
| whitelisted |
edgeassetservice.azureedge.net |
| whitelisted |
www.googleapis.com |
| whitelisted |
login.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
4544 | cookie_mmm_irs_ppi_005_888_a.exe | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
8016 | AvastBrowserUpdate.exe | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
pinginfoview-2.22-installer_gW-sh61.exe | LoadingPage
|
pinginfoview-2.22-installer_gW-sh61.exe | WelcomePage
|
pinginfoview-2.22-installer_gW-sh61.exe | ProductPage
|
pinginfoview-2.22-installer_gW-sh61.exe | ProductPage
|
pinginfoview-2.22-installer_gW-sh61.exe | DownloadPageDLM
|
AvastBrowserInstaller.exe | 2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:167) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
AvastBrowserInstaller.exe | 2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:168) Jinx logging started
|
AvastBrowserInstaller.exe | 2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:169) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
AvastBrowserInstaller.exe | 2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:171)
build date: May 12 2025
build number: 1738
build time: 11:01:36
build timestamp: May 12 2025 11:01:36
company: Gen Digital Inc.
copyright: (C) 2017-2025 Gen Digital Inc.
description: Secure Browser Installer
file name: AvastBrowserInstaller.exe
file version: 9.1.0.1738
git commit: 8544c67a02049729b6b1157ba0eacf01b83f2405
internal name: jinx-installer
product name: Secure Browser Installer
product version: 9.1.0.1738
target system: windows
|
AvastBrowserInstaller.exe | 2025-07-18T07:38:42 [installer] {0000124c:00000864} <2:Info> (4bbd888238eee7c1\src\jinx\Logging.cpp:181) Operating system: Windows Enterprise x64 10.0.19045.4046 SP0
|