File name: | avg_antivirus_free_setup.exe |
Full analysis: | https://app.any.run/tasks/d64356b6-0593-4a14-89e4-7ea8bf87f5a9 |
Verdict: | Malicious activity |
Analysis date: | December 26, 2023, 16:12:34 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 42078CB0F7922CA1CEF79E1D7D633249 |
SHA1: | 44E12AEC1C17507A90E3196DCB40A127A0BEBCF9 |
SHA256: | EA948882C9D6ED4C987915461903DF1A729CC10C3B7931BA71D1070591C39D41 |
SSDEEP: | 3072:whrEcYTuZF3sDmYFDL56DLiSNMWm5RC3Oy1jjHfJWcCAnzuVmoP7wxi6yd+gf8+J:IYTuZFuB66SBRHJWcPz8/JrL9nF |
.exe | | | Win64 Executable (generic) (76.4) |
---|---|---|
.exe | | | Win32 Executable (generic) (12.4) |
.exe | | | Generic Win/DOS Executable (5.5) |
.exe | | | DOS Executable Generic (5.5) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2023:04:12 10:36:29+02:00 |
ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
PEType: | PE32 |
LinkerVersion: | 14.16 |
CodeSize: | 137216 |
InitializedDataSize: | 89088 |
UninitializedDataSize: | - |
EntryPoint: | 0x1020 |
OSVersion: | 5.1 |
ImageVersion: | - |
SubsystemVersion: | 5.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 2.1.99.0 |
ProductVersionNumber: | 2.1.99.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Windows NT 32-bit |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
CompanyName: | AVG Technologies CZ, s.r.o. |
Edition: | 15 |
FileDescription: | AVG Installer |
FileVersion: | 2.1.99.0 |
InternalName: | microstub |
LegalCopyright: | Copyright (C) 2023 AVG Technologies CZ, s.r.o. |
OriginalFileName: | microstub.exe |
ProductName: | AVG |
ProductVersion: | 2.1.99.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
188 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\icarus.exe /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 /er_master:master_ep_8d69ba55-e5ef-474c-b5a0-3f57a45ed3b1 /er_ui:ui_ep_d8377f3e-bb64-4fef-acc1-0084aae1de36 /er_slave:avg-av_slave_ep_517c7f7b-5f22-478f-86c8-d8706ac43b93 /slave:avg-av | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\icarus.exe | icarus.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
668 | "C:\Windows\Temp\asw.34b657f39a1876b7\avg_antivirus_free_online_setup.exe" /cookie:mmm_bav_tst_007_402_a /ga_clientid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 | C:\Windows\Temp\asw.34b657f39a1876b7\avg_antivirus_free_online_setup.exe | avg_antivirus_free_setup.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Self-Extract Package Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
1036 | "C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\aswOfferTool.exe" -checkChromeReactivation -elevated -bc=AWFA | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\aswOfferTool.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Offer Installation Tool Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
1496 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus_ui.exe /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 /er_master:master_ep_8d69ba55-e5ef-474c-b5a0-3f57a45ed3b1 /er_ui:ui_ep_d8377f3e-bb64-4fef-acc1-0084aae1de36 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus_ui.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG UI Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
1864 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus.exe /icarus-info-path:C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\icarus-info.xml /install /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus.exe | avg_antivirus_free_online_setup.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
1892 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av-vps\icarus.exe /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 /er_master:master_ep_8d69ba55-e5ef-474c-b5a0-3f57a45ed3b1 /er_ui:ui_ep_d8377f3e-bb64-4fef-acc1-0084aae1de36 /er_slave:avg-av-vps_slave_ep_524bf678-9e6b-4c0a-ab5c-66e3fde4479a /slave:avg-av-vps | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av-vps\icarus.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
2184 | "C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe" | C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe | — | explorer.exe | |||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: MEDIUM Description: AVG Installer Exit code: 3221226540 Version: 2.1.99.0 Modules
| |||||||||||||||
2208 | "C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe" | C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe | explorer.exe | ||||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 2.1.99.0 Modules
| |||||||||||||||
2660 | "C:\Users\Public\Documents\aswOfferTool.exe" -checkChromeReactivation -bc=AWFA | C:\Users\Public\Documents\aswOfferTool.exe | — | aswOfferTool.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: MEDIUM Description: AVG Offer Installation Tool Exit code: 0 Version: 23.8.6421.0 Modules
|
(PID) Process: | (2208) avg_antivirus_free_setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Windows\Temp\asw.34b657f39a1876b7 | |||
(PID) Process: | (2208) avg_antivirus_free_setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (668) avg_antivirus_free_online_setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
Operation: | write | Name: | 144807F0-DE37-4C62-9C05-EB4CC64A7A2F |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
(PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
Operation: | write | Name: | 56C7A9DA-4B11-406A-8B1A-EFF157C294D6 |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
(PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
Operation: | write | Name: | 5FD38555-4B16-40AE-9A09-E2C969CB74AF |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
(PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
Operation: | write | Name: | 7CCD586D-2ABC-42FF-A23B-3731F4F183D9 |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
(PID) Process: | (188) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
Operation: | write | Name: | 144807F0-DE37-4C62-9C05-EB4CC64A7A2F |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
(PID) Process: | (188) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
Operation: | write | Name: | 56C7A9DA-4B11-406A-8B1A-EFF157C294D6 |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
(PID) Process: | (188) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
Operation: | write | Name: | 5FD38555-4B16-40AE-9A09-E2C969CB74AF |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC |
PID | Process | Filename | Type | |
---|---|---|---|---|
668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\c8a0a5ab-154a-4c93-8dfc-e84849a875bc | binary | |
MD5:4C6ADE41D53BAE584644744F2E6A232F | SHA256:B880331FE25923DF07B3F4110C52D2387F4EFD3B2AEE4B9948BE253D3CCD3EA4 | |||
2208 | avg_antivirus_free_setup.exe | C:\windows\temp\asw.34b657f39a1876b7\ecoo.edat | text | |
MD5:D677CFC138C7E3B65F930CB7D7F1BF69 | SHA256:06BEACE50983367DF6680827C0A601DF8D297C97C09A6CF53E05F3968131A18C | |||
668 | avg_antivirus_free_online_setup.exe | C:\ProgramData\AVG\Icarus\Logs\sfx.log | text | |
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA | SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5 | |||
668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\8cba7e3f-2cd0-459f-85fe-03d8291ebafb | binary | |
MD5:E596094168938D6242C8C2266B47CB4E | SHA256:CAA65B7CE6C9728A01140C07027698B8C84FDED1108E095D9B90AC1D4E16BEA3 | |||
668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\dump_process.exe | executable | |
MD5:8CC5F31FA26AD66EADCE8800FB44DD93 | SHA256:9CAA072C6DC0F31E5731FA8800BD8327CFBBF83373E6211583D21395C8AE842D | |||
668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus_mod.dll | executable | |
MD5:D82C7E7541B0FB4BCC07230A464110F3 | SHA256:787F09B46F996C1835532A9A0BD03D3D02BA200655F59D09067AEA164E581FF7 | |||
668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\bug_report.exe | executable | |
MD5:9672D59B4F4FD4083FACDB53DDC4A83E | SHA256:A1A69486E716550834B0D28E07ED55412157B671B90AEE545EA57649F90AFBDA | |||
668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus.exe | executable | |
MD5:74304FACCD7A95FFF290B0A8AD15EE88 | SHA256:8639967DFE4310D2C942052A45E0C47D7AB4EF6A0EC245AA67DF3A01E81E07A9 | |||
668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\setupui.cont | binary | |
MD5:CAEC84795D36C4FEE0531BD5909CD57F | SHA256:20BE6A7EC202B19F740F397C6BEF348851560FB3CCD60B0B2F0DF90A8E5C192F | |||
668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\product-info.xml | xml | |
MD5:65778E16CBB222FB0400EEA279677D6F | SHA256:BC682E7D273A49660BCCF8612807135D7AAD1E6B0682089E792287BB1795F273 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2208 | avg_antivirus_free_setup.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | — |
2208 | avg_antivirus_free_setup.exe | POST | 200 | 142.250.185.78:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | — |
2208 | avg_antivirus_free_setup.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | — |
2208 | avg_antivirus_free_setup.exe | POST | 200 | 142.250.185.78:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
2208 | avg_antivirus_free_setup.exe | 142.250.185.78:80 | www.google-analytics.com | GOOGLE | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2208 | avg_antivirus_free_setup.exe | 34.117.223.223:80 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2208 | avg_antivirus_free_setup.exe | 23.212.89.10:443 | honzik.avcdn.net | AKAMAI-AS | MX | unknown |
668 | avg_antivirus_free_online_setup.exe | 34.117.223.223:443 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
668 | avg_antivirus_free_online_setup.exe | 23.212.89.10:443 | honzik.avcdn.net | AKAMAI-AS | MX | unknown |
1864 | icarus.exe | 34.117.223.223:443 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1864 | icarus.exe | 34.160.176.28:443 | shepherd.avcdn.net | GOOGLE | US | unknown |
Domain | IP | Reputation |
---|---|---|
www.google-analytics.com |
| unknown |
v7event.stats.avast.com |
| unknown |
honzik.avcdn.net |
| unknown |
analytics.avcdn.net |
| unknown |
shepherd.avcdn.net |
| unknown |