| File name: | avg_antivirus_free_setup.exe |
| Full analysis: | https://app.any.run/tasks/d64356b6-0593-4a14-89e4-7ea8bf87f5a9 |
| Verdict: | Malicious activity |
| Analysis date: | December 26, 2023, 16:12:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 42078CB0F7922CA1CEF79E1D7D633249 |
| SHA1: | 44E12AEC1C17507A90E3196DCB40A127A0BEBCF9 |
| SHA256: | EA948882C9D6ED4C987915461903DF1A729CC10C3B7931BA71D1070591C39D41 |
| SSDEEP: | 3072:whrEcYTuZF3sDmYFDL56DLiSNMWm5RC3Oy1jjHfJWcCAnzuVmoP7wxi6yd+gf8+J:IYTuZFuB66SBRHJWcPz8/JrL9nF |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:04:12 10:36:29+02:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 137216 |
| InitializedDataSize: | 89088 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1020 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.1.99.0 |
| ProductVersionNumber: | 2.1.99.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | AVG Technologies CZ, s.r.o. |
| Edition: | 15 |
| FileDescription: | AVG Installer |
| FileVersion: | 2.1.99.0 |
| InternalName: | microstub |
| LegalCopyright: | Copyright (C) 2023 AVG Technologies CZ, s.r.o. |
| OriginalFileName: | microstub.exe |
| ProductName: | AVG |
| ProductVersion: | 2.1.99.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\icarus.exe /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 /er_master:master_ep_8d69ba55-e5ef-474c-b5a0-3f57a45ed3b1 /er_ui:ui_ep_d8377f3e-bb64-4fef-acc1-0084aae1de36 /er_slave:avg-av_slave_ep_517c7f7b-5f22-478f-86c8-d8706ac43b93 /slave:avg-av | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\icarus.exe | icarus.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 668 | "C:\Windows\Temp\asw.34b657f39a1876b7\avg_antivirus_free_online_setup.exe" /cookie:mmm_bav_tst_007_402_a /ga_clientid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 | C:\Windows\Temp\asw.34b657f39a1876b7\avg_antivirus_free_online_setup.exe | avg_antivirus_free_setup.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Self-Extract Package Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1036 | "C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\aswOfferTool.exe" -checkChromeReactivation -elevated -bc=AWFA | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\aswOfferTool.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Offer Installation Tool Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1496 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus_ui.exe /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 /er_master:master_ep_8d69ba55-e5ef-474c-b5a0-3f57a45ed3b1 /er_ui:ui_ep_d8377f3e-bb64-4fef-acc1-0084aae1de36 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus_ui.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG UI Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1864 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus.exe /icarus-info-path:C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\icarus-info.xml /install /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus.exe | avg_antivirus_free_online_setup.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1892 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av-vps\icarus.exe /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 /er_master:master_ep_8d69ba55-e5ef-474c-b5a0-3f57a45ed3b1 /er_ui:ui_ep_d8377f3e-bb64-4fef-acc1-0084aae1de36 /er_slave:avg-av-vps_slave_ep_524bf678-9e6b-4c0a-ab5c-66e3fde4479a /slave:avg-av-vps | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av-vps\icarus.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 2184 | "C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe" | C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe | — | explorer.exe | |||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: MEDIUM Description: AVG Installer Exit code: 3221226540 Version: 2.1.99.0 Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe" | C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe | explorer.exe | ||||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 2.1.99.0 Modules
| |||||||||||||||
| 2660 | "C:\Users\Public\Documents\aswOfferTool.exe" -checkChromeReactivation -bc=AWFA | C:\Users\Public\Documents\aswOfferTool.exe | — | aswOfferTool.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: MEDIUM Description: AVG Offer Installation Tool Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| (PID) Process: | (2208) avg_antivirus_free_setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Windows\Temp\asw.34b657f39a1876b7 | |||
| (PID) Process: | (2208) avg_antivirus_free_setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (668) avg_antivirus_free_online_setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 144807F0-DE37-4C62-9C05-EB4CC64A7A2F |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
| (PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 56C7A9DA-4B11-406A-8B1A-EFF157C294D6 |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
| (PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 5FD38555-4B16-40AE-9A09-E2C969CB74AF |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
| (PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 7CCD586D-2ABC-42FF-A23B-3731F4F183D9 |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
| (PID) Process: | (188) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 144807F0-DE37-4C62-9C05-EB4CC64A7A2F |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
| (PID) Process: | (188) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 56C7A9DA-4B11-406A-8B1A-EFF157C294D6 |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
| (PID) Process: | (188) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 5FD38555-4B16-40AE-9A09-E2C969CB74AF |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2208 | avg_antivirus_free_setup.exe | C:\Windows\Temp\asw.34b657f39a1876b7\avg_antivirus_free_online_setup.exe | executable | |
MD5:1ECAEBD87C30F9F50EDAC37404EAD036 | SHA256:739BCC9C66B95C704FA5FA6A5FBD49603069FBE7A8542E06FCC75F7B3C117FAC | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\product-info.xml | xml | |
MD5:65778E16CBB222FB0400EEA279677D6F | SHA256:BC682E7D273A49660BCCF8612807135D7AAD1E6B0682089E792287BB1795F273 | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\ProgramData\AVG\Icarus\Logs\sfx.log | text | |
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA | SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5 | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus.exe | executable | |
MD5:74304FACCD7A95FFF290B0A8AD15EE88 | SHA256:8639967DFE4310D2C942052A45E0C47D7AB4EF6A0EC245AA67DF3A01E81E07A9 | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\bbc6844a-ff5d-4bda-8419-b5fd2911de31 | binary | |
MD5:8A0ECC6639E0E218CD4D3F3B840C28D2 | SHA256:85FB4F9ECE8E51F33643F3A9FC9E8159C4C5836113B77ED1466E1F7B6ABDAC3C | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus_mod.dll | executable | |
MD5:D82C7E7541B0FB4BCC07230A464110F3 | SHA256:787F09B46F996C1835532A9A0BD03D3D02BA200655F59D09067AEA164E581FF7 | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus_ui.exe | executable | |
MD5:FEF5E959190FDBA9365B3672B117D00F | SHA256:85A35C7B03857C3482526938DA2C912AF6092C251DDD7359973B373153EE6B65 | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\c8a0a5ab-154a-4c93-8dfc-e84849a875bc | binary | |
MD5:4C6ADE41D53BAE584644744F2E6A232F | SHA256:B880331FE25923DF07B3F4110C52D2387F4EFD3B2AEE4B9948BE253D3CCD3EA4 | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\dump_process.exe | executable | |
MD5:8CC5F31FA26AD66EADCE8800FB44DD93 | SHA256:9CAA072C6DC0F31E5731FA8800BD8327CFBBF83373E6211583D21395C8AE842D | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\a090509e-3931-433c-adbc-f368c14154cd | binary | |
MD5:A89EA361A78E7F89EFC92F52D9A77619 | SHA256:45B31ABEBF071A43237BC73750A03836F5D4ABC7D0D3B7E5E2772CE518D6268F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2208 | avg_antivirus_free_setup.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | unknown |
2208 | avg_antivirus_free_setup.exe | POST | 200 | 142.250.185.78:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | unknown |
2208 | avg_antivirus_free_setup.exe | POST | 200 | 142.250.185.78:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | unknown |
2208 | avg_antivirus_free_setup.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2208 | avg_antivirus_free_setup.exe | 142.250.185.78:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2208 | avg_antivirus_free_setup.exe | 34.117.223.223:80 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2208 | avg_antivirus_free_setup.exe | 23.212.89.10:443 | honzik.avcdn.net | AKAMAI-AS | MX | unknown |
668 | avg_antivirus_free_online_setup.exe | 34.117.223.223:443 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
668 | avg_antivirus_free_online_setup.exe | 23.212.89.10:443 | honzik.avcdn.net | AKAMAI-AS | MX | unknown |
1864 | icarus.exe | 34.117.223.223:443 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1864 | icarus.exe | 34.160.176.28:443 | shepherd.avcdn.net | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.google-analytics.com |
| whitelisted |
v7event.stats.avast.com |
| whitelisted |
honzik.avcdn.net |
| unknown |
analytics.avcdn.net |
| unknown |
shepherd.avcdn.net |
| whitelisted |