avast_premier_antivirus_setup_online.exe

Avast Antivirus

AVAST Software a.s.

This is a setup and installation application. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
AVAST Software  (signed by AVAST Software a.s.)

Product:
Avast Antivirus

Description:
avast! Antivirus Installer

Version:
11.1.2245.1540

MD5:
6476ed36e07b673ecaf6023dcee13113

SHA-1:
38ab5a9687eabc4f0dd331266651fe26cc0f2c44

SHA-256:
170dfd00a7455e5bb131e77fb70f2a2036108217fb423b8acb69a25dc916d955

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 10:58:43 AM UTC  (today)

File size:
4.8 MB (5,037,264 bytes)

Product version:
11.1.2245.1540

Copyright:
Copyright (c) 2014 AVAST Software

Original file name:
SfxInst.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\avast_premier_antivirus_setup_online.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/11/2013 7:00:00 PM

Valid to:
9/14/2016 7:00:00 AM

Subject:
CN=AVAST Software a.s., O=AVAST Software a.s., L=Praha 4, C=CZ

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0EF5ECA7BD31CFC3A7F8E6259B423359

File PE Metadata
Compilation timestamp:
12/1/2015 2:39:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
98304:jtGdyAgH0VWhQHbn5RRxmsuzsTsOoZRdOXaRblFbFW:g40HbL2qozdlbly

Entry address:
0x168B30

Entry point:
60, BE, 00, A0, 4D, 00, 8D, BE, 00, 70, F2, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.9973

Packer / compiler:
UPX 2.90LZMA

Code size:
572 KB (585,728 bytes)

The file avast_premier_antivirus_setup_online.exe has been seen being distributed by the following 20 URLs.

http://dw.uptodown.com/dwn/-WqTpBRo1hA_bMfjXxBu6MoNf1tK22crf5_ioGMzpBLyMPB-kY6JauB-Kwa2tZzgkFFugkOX7sKLRX8nV5OSf7S5qQwKTlQnON_wngk15FjjqxvVlV6BXEcFq8fOB9-p/ziZUN3D2cEewpSRoO4QMyNv9KMsLjjLRG4tauidz6fkBRu7_yMfqk__uCFSP1OgthzHGrHaPrCmw0V8kb7VwPwK6gryrSYfNegvlY6WRsOX86x0ePxTW9tFD9ww_OPU3/lCDG3KWZc8uNLdBIDmaaP6IOJgI6HxNGhBlA_vQG7AXOC69zanTQOw6aef76jZf-FBj2w6qGjUcuLa4vXpl8O9d9PF5JElxdgEQiPmXvdVLS3rNkiYjD7cKFLm8xjPt0/.../

http://dw.uptodown.com/dwn/vcWDb0BwNuZgJdNuNNClgKifyjsJa-mhtPhyEu5JuiDYmc5iKGRazzX9S2wxnHdUjuzJ8uowAUpfZqPhOkBBbo5hO8Pr9cWErE6OHOeXVwqpkFzMwDJ_3d8UTgGNxwm2/4A3cfPr0fE9U8t9chbTXWMbuEvaaTksROt5D11dpI9ujYeVHELcowqpiqcR7VprvZSsHVF6pLKapYR7wzDrLoXyTemdS7JmCJ-wZG1OGNcauUH8MPc-SlfywJeaZybU2/k9nMuqPW8InNBYvHVy-c7CrQ5BMhIGetjnvI2a6bzijcYvjG01g6DOSRBSucCF-Rgmkbzx_G2H7sEAj4EJJGbmlla3suE3UFwfMXl8-c4Rq0B695qlnxT9o9MqM7DHqK/.../

https://archive.org/download/.../avast_premier_antivirus_setup_online.exe

http://dw.uptodown.com/dwn/e9d_F1TfSNyPFusWe2JPT_mlVovacNinUsyRSCghkFnNTE_W6_j5m7hXNQFP9TM4nOn-pgYUkVjGF1mfdB2oPj5ajC715JkDK-AbvO9rBh_CwGj7UCXjv3fGPDAhTkvq/tT0O_0AD6-RIBgg3aGiy7FVmCohog47W9n7ixPE-RdCCEUeGaRWIVDnlCb07qlosBRcuJou_Bp4VBg5J1PXG6cna4WVJtAj_POjcLvCxrico1eHbBDov_HquF8Bp7uqk/wjlCV4Y_jiFt-PA34wKxURNm8oE7pgpxGSDrlX07DnZ33kFuF0CNcJlOkxT35OiQrbDYHUAPj3G88-IAQMCY7Eybmb5Oi5h3uFaeqshCm64VDOlJAtYgTBHn8OyWD0HR/.../

http://dw9.uptodown.com/dwn/vlMrgeDjWOC1sFM3qbf56DnMs9e792uHV9dU9Wn1ljueK-ny7UPncY3zMOpjoTqULfyenfZbuv7qe2CDuU-ardnvG_sjlksBRtF9FEZgXJIYGAThGJjEH_P1DCv_1MwT/0nqwtdxo9GxZ-xZYhevB4goiuIeCOY-Eqp3SpesAFhuNz9RXd_vvto1n5qLFUZZXGVqcxe0MlR0Vw6qxNdRQ8xfefsvmKvcILOR5IkYIWmJpk0aSQXRxzjcymG-9oUaY/zCaAQjhmsbM9M3djC3oiOPE6BYqd5VzPj_NURnI2V_LEwi-ehw7PhrWVASnNuBEiUFqW8UjzBSCRBdmpC1-Tq49J8ShvynVMsAtLvx-bmjoT3fugVa53sKB6OcsRJGqf/.../avast-internet-security-2016-11-1-2245-multi-win.exe

http://avast-premier-antivirus.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/.../AqKbqDD1uPVy6XIbsuCA1YxjeXJjoYjyQqanN4Jd3gFqcGDrXoPTzEFU3fuvpNxA==

https://mega.nz/temporary/.../oEYVFRKT

http://dw.uptodown.com/dwn/DNlndG2MBMQR-uWqEmf8Tu2eDF8ziZ6FnpVQD45r322YpfY6siuURtNxmUcUZtn3pegbhoXt8xaw3cFAKSQknlto6zXWeSNZwYB8cSCmHy2ZAyVFm4vdqNhNe2KsZ2mt/2pqAK3cXvZ9Vmj5hyqBKAvjnReP7dN5THxZ8rArLr4W2fhZ0BWHeZ4lIgh0vmrbF5JI2DjvEjryehCAXFjJM752_XFFuos3F1nOXCZbQAe2AVlhbMzmBa9_MCB7HpsPo/Qzl8Q71vMd2slup-axmLdxqa_FWFSyiwnjpizylgg6lRwJfuiM63yejJ5_MqbpiEhyU6mFfmBAgMNtflCRKyscSX8kGyewHG1BXyiAjOmqnoaAB319dBoX3FhdHf3_GO/.../

Scan avast_premier_antivirus_setup_online.exe - Powered by Reason Core Security