| File name: | avg_antivirus_free_setup.exe |
| Full analysis: | https://app.any.run/tasks/d64356b6-0593-4a14-89e4-7ea8bf87f5a9 |
| Verdict: | Malicious activity |
| Analysis date: | December 26, 2023, 16:12:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 42078CB0F7922CA1CEF79E1D7D633249 |
| SHA1: | 44E12AEC1C17507A90E3196DCB40A127A0BEBCF9 |
| SHA256: | EA948882C9D6ED4C987915461903DF1A729CC10C3B7931BA71D1070591C39D41 |
| SSDEEP: | 3072:whrEcYTuZF3sDmYFDL56DLiSNMWm5RC3Oy1jjHfJWcCAnzuVmoP7wxi6yd+gf8+J:IYTuZFuB66SBRHJWcPz8/JrL9nF |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:04:12 10:36:29+02:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 137216 |
| InitializedDataSize: | 89088 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1020 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.1.99.0 |
| ProductVersionNumber: | 2.1.99.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | AVG Technologies CZ, s.r.o. |
| Edition: | 15 |
| FileDescription: | AVG Installer |
| FileVersion: | 2.1.99.0 |
| InternalName: | microstub |
| LegalCopyright: | Copyright (C) 2023 AVG Technologies CZ, s.r.o. |
| OriginalFileName: | microstub.exe |
| ProductName: | AVG |
| ProductVersion: | 2.1.99.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\icarus.exe /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 /er_master:master_ep_8d69ba55-e5ef-474c-b5a0-3f57a45ed3b1 /er_ui:ui_ep_d8377f3e-bb64-4fef-acc1-0084aae1de36 /er_slave:avg-av_slave_ep_517c7f7b-5f22-478f-86c8-d8706ac43b93 /slave:avg-av | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\icarus.exe | icarus.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 668 | "C:\Windows\Temp\asw.34b657f39a1876b7\avg_antivirus_free_online_setup.exe" /cookie:mmm_bav_tst_007_402_a /ga_clientid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 | C:\Windows\Temp\asw.34b657f39a1876b7\avg_antivirus_free_online_setup.exe | avg_antivirus_free_setup.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Self-Extract Package Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1036 | "C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\aswOfferTool.exe" -checkChromeReactivation -elevated -bc=AWFA | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\aswOfferTool.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Offer Installation Tool Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1496 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus_ui.exe /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 /er_master:master_ep_8d69ba55-e5ef-474c-b5a0-3f57a45ed3b1 /er_ui:ui_ep_d8377f3e-bb64-4fef-acc1-0084aae1de36 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus_ui.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG UI Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1864 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus.exe /icarus-info-path:C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\icarus-info.xml /install /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\icarus.exe | avg_antivirus_free_online_setup.exe | ||||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 1892 | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av-vps\icarus.exe /cookie:mmm_bav_tst_007_402_a /track-guid:9e7d23e8-8eea-49aa-9678-a74a7d62ed90 /edat_dir:C:\Windows\Temp\asw.34b657f39a1876b7 /sssid:668 /er_master:master_ep_8d69ba55-e5ef-474c-b5a0-3f57a45ed3b1 /er_ui:ui_ep_d8377f3e-bb64-4fef-acc1-0084aae1de36 /er_slave:avg-av-vps_slave_ep_524bf678-9e6b-4c0a-ab5c-66e3fde4479a /slave:avg-av-vps | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av-vps\icarus.exe | — | icarus.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| 2184 | "C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe" | C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe | — | explorer.exe | |||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: MEDIUM Description: AVG Installer Exit code: 3221226540 Version: 2.1.99.0 Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe" | C:\Users\admin\AppData\Local\Temp\avg_antivirus_free_setup.exe | explorer.exe | ||||||||||||
User: admin Company: AVG Technologies CZ, s.r.o. Integrity Level: HIGH Description: AVG Installer Exit code: 0 Version: 2.1.99.0 Modules
| |||||||||||||||
| 2660 | "C:\Users\Public\Documents\aswOfferTool.exe" -checkChromeReactivation -bc=AWFA | C:\Users\Public\Documents\aswOfferTool.exe | — | aswOfferTool.exe | |||||||||||
User: admin Company: AVG Technologies Integrity Level: MEDIUM Description: AVG Offer Installation Tool Exit code: 0 Version: 23.8.6421.0 Modules
| |||||||||||||||
| (PID) Process: | (2208) avg_antivirus_free_setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Windows\Temp\asw.34b657f39a1876b7 | |||
| (PID) Process: | (2208) avg_antivirus_free_setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (668) avg_antivirus_free_online_setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 144807F0-DE37-4C62-9C05-EB4CC64A7A2F |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
| (PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 56C7A9DA-4B11-406A-8B1A-EFF157C294D6 |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
| (PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 5FD38555-4B16-40AE-9A09-E2C969CB74AF |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
| (PID) Process: | (1892) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 7CCD586D-2ABC-42FF-A23B-3731F4F183D9 |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
| (PID) Process: | (188) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 144807F0-DE37-4C62-9C05-EB4CC64A7A2F |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
| (PID) Process: | (188) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\C06AEB9D-8774-46E7-8160-8321BCD14D9F |
| Operation: | write | Name: | 56C7A9DA-4B11-406A-8B1A-EFF157C294D6 |
Value: cb64fbde-333f-432f-850c-745c93588b30 | |||
| (PID) Process: | (188) icarus.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198 |
| Operation: | write | Name: | 5FD38555-4B16-40AE-9A09-E2C969CB74AF |
Value: 138F65F3DE11A9670C8CF1AB7F8C2DEC | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2208 | avg_antivirus_free_setup.exe | C:\Windows\Temp\asw.34b657f39a1876b7\avg_antivirus_free_online_setup.exe | executable | |
MD5:1ECAEBD87C30F9F50EDAC37404EAD036 | SHA256:739BCC9C66B95C704FA5FA6A5FBD49603069FBE7A8542E06FCC75F7B3C117FAC | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\a090509e-3931-433c-adbc-f368c14154cd | binary | |
MD5:A89EA361A78E7F89EFC92F52D9A77619 | SHA256:45B31ABEBF071A43237BC73750A03836F5D4ABC7D0D3B7E5E2772CE518D6268F | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\dump_process.exe | executable | |
MD5:8CC5F31FA26AD66EADCE8800FB44DD93 | SHA256:9CAA072C6DC0F31E5731FA8800BD8327CFBBF83373E6211583D21395C8AE842D | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\bug_report.exe | executable | |
MD5:9672D59B4F4FD4083FACDB53DDC4A83E | SHA256:A1A69486E716550834B0D28E07ED55412157B671B90AEE545EA57649F90AFBDA | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\setupui.cont | binary | |
MD5:CAEC84795D36C4FEE0531BD5909CD57F | SHA256:20BE6A7EC202B19F740F397C6BEF348851560FB3CCD60B0B2F0DF90A8E5C192F | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\8cba7e3f-2cd0-459f-85fe-03d8291ebafb | binary | |
MD5:E596094168938D6242C8C2266B47CB4E | SHA256:CAA65B7CE6C9728A01140C07027698B8C84FDED1108E095D9B90AC1D4E16BEA3 | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\b865d71c-20c2-42f3-89e0-c2dacf146e8c | binary | |
MD5:D354234E9230850AC1018529099B5C9C | SHA256:EFA35BE97D4C194659B5B1CE120E69F431D5B67B83F81B4140ABC14D8FDDAE3E | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\bcc550cd-be0c-4aef-b5e4-31e1e0ffa06b | binary | |
MD5:4873B4A1C60C5210BF0EDEC1D2026E03 | SHA256:0FC29E8B24E13179EDD2268052933B4F0DB19AF8C589F86A14EC642CE8279C5E | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\common\1f8e8bc0-6e46-46c7-9a1b-1f982594d857 | binary | |
MD5:5751F90923D39573F3847A28A6EE4EEE | SHA256:67C3B970F86558F3C769BCB301A89102616E19549DAFDA74E0EF201F023792BF | |||
| 668 | avg_antivirus_free_online_setup.exe | C:\Windows\Temp\asw-08a7f17b-e338-4c21-b1fc-f2a5ab495b2d\avg-av\edition.edat | text | |
MD5:9BF31C7FF062936A96D3C8BD1F8F2FF3 | SHA256:E629FA6598D732768F7C726B4B621285F9C3B85303900AA912017DB7617D8BDB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2208 | avg_antivirus_free_setup.exe | POST | 200 | 142.250.185.78:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | unknown |
2208 | avg_antivirus_free_setup.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | unknown |
2208 | avg_antivirus_free_setup.exe | POST | 204 | 34.117.223.223:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | unknown | — | — | unknown |
2208 | avg_antivirus_free_setup.exe | POST | 200 | 142.250.185.78:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2208 | avg_antivirus_free_setup.exe | 142.250.185.78:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2208 | avg_antivirus_free_setup.exe | 34.117.223.223:80 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2208 | avg_antivirus_free_setup.exe | 23.212.89.10:443 | honzik.avcdn.net | AKAMAI-AS | MX | unknown |
668 | avg_antivirus_free_online_setup.exe | 34.117.223.223:443 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
668 | avg_antivirus_free_online_setup.exe | 23.212.89.10:443 | honzik.avcdn.net | AKAMAI-AS | MX | unknown |
1864 | icarus.exe | 34.117.223.223:443 | v7event.stats.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1864 | icarus.exe | 34.160.176.28:443 | shepherd.avcdn.net | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.google-analytics.com |
| whitelisted |
v7event.stats.avast.com |
| whitelisted |
honzik.avcdn.net |
| unknown |
analytics.avcdn.net |
| unknown |
shepherd.avcdn.net |
| whitelisted |