| download: | /pchelpsoft/Driver_Updater_setup.exe |
| Full analysis: | https://app.any.run/tasks/618586f9-fbf9-4a16-9c62-59dc1ed61b71 |
| Verdict: | Malicious activity |
| Analysis date: | January 31, 2024, 23:01:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | CB055D7DDB5B500C5FCB0051428FC3CC |
| SHA1: | C98493F9809C8FD95FD8067A2F1CADF2EE4CEAD3 |
| SHA256: | 011D634221DC4DE0498600568F37E27DE35CFE60FC2C2B22C2AA87871FB10C0A |
| SSDEEP: | 98304:6+QqZ8fuhL4lMReXlNfUBJYZ35eJHcOpJn5KZD5pk0uypuJTMVLagOVFp+OKCJbP:ari9iJiRLFTA/YNswKfwv5z |
| .exe | | | Inno Setup installer (65.1) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (24.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.9) |
| .exe | | | Win32 Executable (generic) (2.6) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:06:03 10:09:11+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741376 |
| InitializedDataSize: | 68096 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 7.1.1130.0 |
| ProductVersionNumber: | 7.1.1130.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | PC HelpSoft |
| FileDescription: | PC HelpSoft Driver Updater |
| FileVersion: | 7.1.1130.0 |
| LegalCopyright: | PC HelpSoft |
| OriginalFileName: | |
| ProductName: | PC HelpSoft Driver Updater |
| ProductVersion: | 7.1.1130.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1552 --field-trial-handle=1304,i,1225834183918054357,400532810778073595,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 752 | "C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe" | C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe | explorer.exe | ||||||||||||
User: admin Company: PC HelpSoft Integrity Level: MEDIUM Description: PC HelpSoft Driver Updater Exit code: 0 Version: 7.1.1130.0 Modules
| |||||||||||||||
| 796 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1216 --field-trial-handle=1304,i,12365423113159659216,10431407775292495242,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1408 | "C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe" /SPAWNWND=$1001B4 /NOTIFYWND=$F0184 | C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe | Driver_Updater_setup.tmp | ||||||||||||
User: admin Company: PC HelpSoft Integrity Level: HIGH Description: PC HelpSoft Driver Updater Exit code: 0 Version: 7.1.1130.0 Modules
| |||||||||||||||
| 1504 | "C:\Users\admin\AppData\Local\Temp\is-8MQ79.tmp\Driver_Updater_setup.tmp" /SL5="$F0184,5837648,810496,C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe" | C:\Users\admin\AppData\Local\Temp\is-8MQ79.tmp\Driver_Updater_setup.tmp | — | Driver_Updater_setup.exe | |||||||||||
User: admin Company: PC HelpSoft Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1696 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bb3f598,0x6bb3f5a8,0x6bb3f5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1740 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1556 --field-trial-handle=1304,i,12365423113159659216,10431407775292495242,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1768 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2228 --field-trial-handle=1304,i,12365423113159659216,10431407775292495242,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1976 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1652 --field-trial-handle=1304,i,12365423113159659216,10431407775292495242,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2120 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate https://store.pchelpsoft.com/clickgate/join.aspx?ref=pchelpsoft.com&ujid=n4l4AdUDqyE%3D&mkey3=win_cta1&mkey4=0&mkey5=5&mkey6=0&mkey7=NO_TRIAL | C:\Program Files\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2544) PCHelpSoftDriverUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2544) PCHelpSoftDriverUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2544) PCHelpSoftDriverUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2544) PCHelpSoftDriverUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2544) PCHelpSoftDriverUpdater.exe | Key: | HKEY_CURRENT_USER\Software\PC HelpSoft Driver Updater |
| Operation: | write | Name: | last-main-logs |
Value: 120E95B75E21E640 | |||
| (PID) Process: | (3060) PCHelpSoftDriverUpdater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Licenses\b189b15a0bc0169092b613a686c1e5e5I |
| Operation: | delete value | Name: | backupMetrics |
Value: E8F926227E17D8BE2BD6AA0B48BF0517F1ACC4F0={"program":"PCHelpSoftDriverUpdater","version":"7.1.1130.m","compile":"04-12-2023 20-07","days":60,"id":"{7B7ED5FB-246D-4F12-94FA-1681AA74A53B}"}|{"type":"general","name":"install","build":"default"} | |||
| (PID) Process: | (3060) PCHelpSoftDriverUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3060) PCHelpSoftDriverUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3060) PCHelpSoftDriverUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3060) PCHelpSoftDriverUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2868 | Driver_Updater_setup.tmp | C:\Program Files\PC HelpSoft Driver Updater\is-RLH5S.tmp | executable | |
MD5:4947F753EB5C3B1AA3CE496A9AB30130 | SHA256:1CB7131714F41D651792F15B48A128840C959A5190D076A7FEE5FE8B8EFE232D | |||
| 2868 | Driver_Updater_setup.tmp | C:\Program Files\PC HelpSoft Driver Updater\Extra\DriverPro.exe | executable | |
MD5:34392941C1918C5639E8C0CBFA64115E | SHA256:C825552C99C321DFBAAE6B16D797F80A6557C555689BD78AF815B0D48B0CCB05 | |||
| 1408 | Driver_Updater_setup.exe | C:\Users\admin\AppData\Local\Temp\is-DNTSS.tmp\Driver_Updater_setup.tmp | executable | |
MD5:4947F753EB5C3B1AA3CE496A9AB30130 | SHA256:1CB7131714F41D651792F15B48A128840C959A5190D076A7FEE5FE8B8EFE232D | |||
| 2868 | Driver_Updater_setup.tmp | C:\Program Files\PC HelpSoft Driver Updater\Extra\is-D8H8K.tmp | executable | |
MD5:33BEA8D12BB5F49A948B650A882F54FE | SHA256:B82D89D84D2815B550810DCBB7F99E68B793DC152AA3838C8F953A7BE50B750F | |||
| 2868 | Driver_Updater_setup.tmp | C:\Program Files\PC HelpSoft Driver Updater\Extra\HDMSchedule.exe | executable | |
MD5:33BEA8D12BB5F49A948B650A882F54FE | SHA256:B82D89D84D2815B550810DCBB7F99E68B793DC152AA3838C8F953A7BE50B750F | |||
| 2868 | Driver_Updater_setup.tmp | C:\Program Files\PC HelpSoft Driver Updater\Extra\is-O16FJ.tmp | text | |
MD5:C12E324F7BA24C91F31927D7A720294A | SHA256:BAD8F599F3B38B7F67E77E26AEC057FA8849C0CB80B72AC9E7265F9DCB3AF199 | |||
| 2868 | Driver_Updater_setup.tmp | C:\Program Files\PC HelpSoft Driver Updater\Extra\Animation.gif | image | |
MD5:915F2CE934FD4789216B91BF9C2609FD | SHA256:135D81FEEF8BC93E48F3D929D9249ABE56E8B0A566F51964C8CAD28602219250 | |||
| 2868 | Driver_Updater_setup.tmp | C:\Program Files\PC HelpSoft Driver Updater\Extra\is-2B5CK.tmp | image | |
MD5:915F2CE934FD4789216B91BF9C2609FD | SHA256:135D81FEEF8BC93E48F3D929D9249ABE56E8B0A566F51964C8CAD28602219250 | |||
| 2868 | Driver_Updater_setup.tmp | C:\Program Files\PC HelpSoft Driver Updater\Extra\is-LVTN5.tmp | binary | |
MD5:25BB2EAECB641EC8E07C30CA3B8CF387 | SHA256:D4BDFA83D66E9FBFA5B5C0DA832C4766D539FD7B1F2EDDEE53E7DBC7E8E095E9 | |||
| 2868 | Driver_Updater_setup.tmp | C:\Program Files\PC HelpSoft Driver Updater\Extra\is-F8G10.tmp | text | |
MD5:E5AAF0DC24AA8945F9D78CF5238B7E27 | SHA256:EFDA08D39359AEC52DEA7916320770663701771C78DAE8D259C60F12AF779054 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3060 | PCHelpSoftDriverUpdater.exe | POST | 200 | 18.165.183.89:80 | http://api.playanext.com/httpapi | unknown | — | — | unknown |
488 | lsass.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fa455765e490287c | unknown | — | — | unknown |
3060 | PCHelpSoftDriverUpdater.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?afad0c39ac6553e9 | unknown | compressed | 65.2 Kb | unknown |
3060 | PCHelpSoftDriverUpdater.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?4c4c9325601fc74e | unknown | compressed | 65.2 Kb | unknown |
3060 | PCHelpSoftDriverUpdater.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?739bb4969d9b2bff | unknown | compressed | 65.2 Kb | unknown |
3060 | PCHelpSoftDriverUpdater.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6cba3083cea0e54e | unknown | compressed | 65.2 Kb | unknown |
3060 | PCHelpSoftDriverUpdater.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?492c4476eb39153e | unknown | compressed | 65.2 Kb | unknown |
3060 | PCHelpSoftDriverUpdater.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6578879dcf199db3 | unknown | compressed | 65.2 Kb | unknown |
3060 | PCHelpSoftDriverUpdater.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?3aedf03dbcf27fb4 | unknown | compressed | 65.2 Kb | unknown |
488 | lsass.exe | GET | 200 | 18.165.184.219:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | unknown | binary | 1.49 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3060 | PCHelpSoftDriverUpdater.exe | 116.203.251.147:443 | drivers.avqtools.com | Hetzner Online GmbH | DE | unknown |
3060 | PCHelpSoftDriverUpdater.exe | 216.239.34.21:443 | cloud.pchelpsoft.com | GOOGLE | US | whitelisted |
3060 | PCHelpSoftDriverUpdater.exe | 18.165.183.66:443 | offers.playanext.com | — | US | unknown |
3060 | PCHelpSoftDriverUpdater.exe | 18.165.183.89:80 | api.playanext.com | — | US | unknown |
3060 | PCHelpSoftDriverUpdater.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
488 | lsass.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
488 | lsass.exe | 108.138.2.10:80 | o.ss2.us | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
drivers.avqtools.com |
| unknown |
collect.avqtools.com |
| unknown |
cloud.pchelpsoft.com |
| unknown |
offers.playanext.com |
| unknown |
api.playanext.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.r2m01.amazontrust.com |
| whitelisted |