URL:

https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater__5513.exe

Full analysis: https://app.any.run/tasks/7594fbcc-7dac-46f5-9dca-bd02428c1667
Verdict: Malicious activity
Analysis date: December 30, 2023, 21:56:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

27883C30897604ACAF75D15DD64E10F9

SHA1:

726FDA360C37EDCA9A3CB4B038B6AEB3A0CC863A

SHA256:

122D6C2B700D597610E8701CB73B59C9524789522D6852FFDD3B3C1D8458F9BB

SSDEEP:

3:N8cESGGs6VKcTeVyyQQPJ:2cJRs67K9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • PCHelpSoftDriverUpdater.exe (PID: 1748)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
    • Changes the autorun value in the registry

      • drvinst.exe (PID: 2104)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Driver_Updater__5513.tmp (PID: 2312)
    • Reads the Internet Settings

      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
    • Reads settings of System Certificates

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Checks Windows Trust Settings

      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 2104)
      • drvinst.exe (PID: 3428)
    • Reads security settings of Internet Explorer

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Searches for installed software

      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • dllhost.exe (PID: 3076)
    • Adds/modifies Windows certificates

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Drops a system driver (possible attempt to evade defenses)

      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2104)
      • drvinst.exe (PID: 3428)
    • Creates/Modifies COM task schedule object

      • drvinst.exe (PID: 2104)
    • Creates a software uninstall entry

      • drvinst.exe (PID: 2104)
    • Reads the BIOS version

      • drvinst.exe (PID: 2104)
  • INFO

    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 324)
      • Driver_Updater__5513.exe (PID: 1236)
      • iexplore.exe (PID: 128)
      • Driver_Updater__5513.exe (PID: 1540)
      • Driver_Updater__5513.tmp (PID: 2312)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Application launched itself

      • iexplore.exe (PID: 128)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Checks supported languages

      • Driver_Updater__5513.exe (PID: 1236)
      • Driver_Updater__5513.tmp (PID: 1936)
      • Driver_Updater__5513.exe (PID: 1540)
      • Driver_Updater__5513.tmp (PID: 2312)
      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • DriverPro.exe (PID: 2464)
      • drvinst.exe (PID: 3428)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
      • drvinst.exe (PID: 2104)
    • Create files in a temporary directory

      • Driver_Updater__5513.exe (PID: 1236)
      • Driver_Updater__5513.exe (PID: 1540)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • The process uses the downloaded file

      • iexplore.exe (PID: 128)
    • Reads the computer name

      • Driver_Updater__5513.tmp (PID: 1936)
      • Driver_Updater__5513.tmp (PID: 2312)
      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • DriverPro.exe (PID: 2464)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
    • Creates files in the program directory

      • Driver_Updater__5513.tmp (PID: 2312)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 2104)
    • Drops 7-zip archiver for unpacking

      • Driver_Updater__5513.tmp (PID: 2312)
    • Reads the machine GUID from the registry

      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
    • Creates files or folders in the user directory

      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Checks proxy server information

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Process checks computer location settings

      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
    • Process drops legitimate windows executable

      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2968)
    • Reads product name

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Reads Environment values

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Manual execution by a user

      • explorer.exe (PID: 1492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
17
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe driver_updater__5513.exe no specs driver_updater__5513.tmp no specs driver_updater__5513.exe driver_updater__5513.tmp no specs pchelpsoftdriverupdater.exe no specs schtasks.exe no specs schtasks.exe no specs pchelpsoftdriverupdater.exe driverpro.exe no specs SPPSurrogate no specs vssvc.exe no specs drvinst.exe no specs drvinst.exe pchelpsoftdriverupdater.exe explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\Internet Explorer\iexplore.exe" "https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater__5513.exe"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
324"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:128 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
376"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /START /INSTALLEDC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Driver_Updater__5513.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
6.4.988
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1236"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exeiexplore.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
6.4.988.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\driver_updater__5513.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1492"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1540"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exe" /SPAWNWND=$40146 /NOTIFYWND=$3014A C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exe
Driver_Updater__5513.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
6.4.988.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\driver_updater__5513.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1748"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /INSTALLC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exeDriver_Updater__5513.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
6.4.988
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1936"C:\Users\admin\AppData\Local\Temp\is-T7Q3A.tmp\Driver_Updater__5513.tmp" /SL5="$3014A,6120102,810496,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exe" C:\Users\admin\AppData\Local\Temp\is-T7Q3A.tmp\Driver_Updater__5513.tmpDriver_Updater__5513.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t7q3a.tmp\driver_updater__5513.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2028"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Monitoring" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2104DrvInst.exe "2" "211" "ACPI\PNP0F13\4&3B4F7DA4&0" "C:\Windows\INF\oem2.inf" "apfiltr.inf:CompanyMfg:MouFilter_Inst.NT:8.0.1611.211:acpi\pnp0f13:*pnp0f13:*pnp0f0e" "748f38903" "000003DC" "000005E4" "000005E0"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
51 362
Read events
50 733
Write events
606
Delete events
23

Modification events

(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
140
Suspicious files
515
Text files
133
Unknown types
0

Dropped files

PID
Process
Filename
Type
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:73108EBC834537C38B80845E5C92F574
SHA256:D9F800336A4762BAD1A6B156EE14B17097A9C4EAE7D9B30FB83FEAA0666F19C9
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:6397ED88E838F570EDFD686298423D86
SHA256:8435009C3D467562C0C995EBEE824FFAAF10029E6340F55F0631E09AC0BBDC8F
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:77E05AA2D2BE953F667E21250793C64B
SHA256:0ACA86F77D897D8C3CBDC26A0A021FA11AE424BC201A8293B6A26C2583117F25
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:33A521A9015100FD6BEC651F6BFD5FD8
SHA256:F1BE57E80399911300D867AAD9ABE98ED01DE2AE7C1C46902FF5DF4EBC84D0C9
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8der
MD5:DAC4EC1CEFCAD484AE85D8013A98CCEE
SHA256:CC5DB4C5C06F2F5B230D82F582AECC34BC3F3A636C7F6E4FB9FC1855F65AB55A
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:80EF0E72EAA7394CF0831EF2EFF0B925
SHA256:4A7D6B4F67339D4302D2708A2E7D78D49C4FCE811C222141005949DE72E4A9EB
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D03E46CD585BBE111C712E6577BC5F07_8EA13E673F47888C21BC1937C6F7B3C0binary
MD5:B5920788299B14E9696E844250ACF443
SHA256:1B345965DA1420EE41ADE450ABC127DA2D92FF06100362C329B2AE8B6DA02308
324iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\Driver_Updater__5513[1].exeexecutable
MD5:CDAD8B2ED12415387AA110FAAF5833AA
SHA256:9DC4120E9599FEE0CA1CB579B1FEE18A24312C9BD50652378F27CF29242C6409
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D03E46CD585BBE111C712E6577BC5F07_8EA13E673F47888C21BC1937C6F7B3C0binary
MD5:58BFF27B74FFFA1CF8A0F5841865B5CC
SHA256:F277B170A653F37D2408A5C7B6E5185C0DE1F04B957B3AD3B9F975D71C8468FA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
102
DNS requests
30
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
324
iexplore.exe
GET
200
108.138.2.10:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
binary
2.02 Kb
324
iexplore.exe
GET
200
18.66.142.79:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
binary
1.49 Kb
324
iexplore.exe
GET
200
13.32.26.76:80
http://ocsp.r2m01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEA%2F9uaMA2YcblYIoqSnlhn8%3D
unknown
binary
471 b
324
iexplore.exe
GET
200
18.66.142.79:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
binary
1.37 Kb
128
iexplore.exe
GET
200
184.24.77.207:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?08d91df001b427ad
unknown
compressed
65.2 Kb
376
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.26:80
http://api.playanext.com/httpapi
unknown
128
iexplore.exe
GET
200
151.101.2.133:80
http://secure.globalsign.com/cacert/codesigningrootr45.crt
unknown
binary
1.37 Kb
488
lsass.exe
GET
304
184.24.77.207:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fa455765e490287c
unknown
376
PCHelpSoftDriverUpdater.exe
GET
304
184.24.77.207:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6ebdea9eea6b350b
unknown
488
lsass.exe
GET
200
13.32.26.76:80
http://ocsp.r2m01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEApw3wLW6pUG4n83G8W195k%3D
unknown
binary
471 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
324
iexplore.exe
143.204.98.16:443
cdn.pchelpsoft.com
AMAZON-02
US
unknown
324
iexplore.exe
184.24.77.207:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
324
iexplore.exe
108.138.2.10:80
o.ss2.us
AMAZON-02
US
unknown
324
iexplore.exe
18.66.142.79:80
ocsp.rootg2.amazontrust.com
AMAZON-02
US
unknown
324
iexplore.exe
13.32.26.76:80
ocsp.r2m01.amazontrust.com
AMAZON-02
US
unknown
128
iexplore.exe
151.101.2.133:80
secure.globalsign.com
FASTLY
US
unknown
128
iexplore.exe
184.24.77.207:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
cdn.pchelpsoft.com
  • 143.204.98.16
  • 143.204.98.73
  • 143.204.98.2
  • 143.204.98.44
unknown
ctldl.windowsupdate.com
  • 184.24.77.207
  • 184.24.77.199
  • 184.24.77.191
unknown
o.ss2.us
  • 108.138.2.10
  • 108.138.2.195
  • 108.138.2.107
  • 108.138.2.173
unknown
ocsp.rootg2.amazontrust.com
  • 18.66.142.79
unknown
ocsp.rootca1.amazontrust.com
  • 18.66.142.79
unknown
ocsp.r2m01.amazontrust.com
  • 13.32.26.76
unknown
secure.globalsign.com
  • 151.101.2.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
unknown
drivers.avqtools.com
  • 116.203.251.147
unknown
offers.playanext.com
  • 99.86.4.76
  • 99.86.4.92
  • 99.86.4.23
  • 99.86.4.112
unknown
api.playanext.com
  • 18.245.86.26
  • 18.245.86.84
  • 18.245.86.79
  • 18.245.86.105
  • 18.239.36.117
  • 18.239.36.26
  • 18.239.36.31
  • 18.239.36.72
unknown

Threats

No threats detected
Process
Message
drvinst.exe
WdfCoInstaller: [12/30/2023 21:58.44.400] DIF_INSTALLDEVICE: Pre-Processing
drvinst.exe
WdfCoInstaller: [12/30/2023 21:58.44.447] ReadComponents: WdfSection for Driver Service ApfiltrService using KMDF lib version Major 0x1, minor 0x9
drvinst.exe
WdfCoInstaller: [12/30/2023 21:58.46.322] DIF_INSTALLDEVICE: Post-Processing