URL:

https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater__5513.exe

Full analysis: https://app.any.run/tasks/7594fbcc-7dac-46f5-9dca-bd02428c1667
Verdict: Malicious activity
Analysis date: December 30, 2023, 21:56:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

27883C30897604ACAF75D15DD64E10F9

SHA1:

726FDA360C37EDCA9A3CB4B038B6AEB3A0CC863A

SHA256:

122D6C2B700D597610E8701CB73B59C9524789522D6852FFDD3B3C1D8458F9BB

SSDEEP:

3:N8cESGGs6VKcTeVyyQQPJ:2cJRs67K9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • PCHelpSoftDriverUpdater.exe (PID: 1748)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 2104)
      • drvinst.exe (PID: 3428)
    • Changes the autorun value in the registry

      • drvinst.exe (PID: 2104)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Driver_Updater__5513.tmp (PID: 2312)
    • Reads the Internet Settings

      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
    • Reads settings of System Certificates

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Checks Windows Trust Settings

      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
    • Reads security settings of Internet Explorer

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Adds/modifies Windows certificates

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Searches for installed software

      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • dllhost.exe (PID: 3076)
    • Drops a system driver (possible attempt to evade defenses)

      • drvinst.exe (PID: 3428)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 2104)
    • Creates/Modifies COM task schedule object

      • drvinst.exe (PID: 2104)
    • Creates a software uninstall entry

      • drvinst.exe (PID: 2104)
    • Reads the BIOS version

      • drvinst.exe (PID: 2104)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2104)
      • drvinst.exe (PID: 3428)
  • INFO

    • Drops the executable file immediately after the start

      • Driver_Updater__5513.exe (PID: 1236)
      • iexplore.exe (PID: 128)
      • iexplore.exe (PID: 324)
      • Driver_Updater__5513.exe (PID: 1540)
      • Driver_Updater__5513.tmp (PID: 2312)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 2104)
      • drvinst.exe (PID: 3428)
    • Create files in a temporary directory

      • Driver_Updater__5513.exe (PID: 1540)
      • Driver_Updater__5513.exe (PID: 1236)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Checks supported languages

      • Driver_Updater__5513.tmp (PID: 1936)
      • Driver_Updater__5513.tmp (PID: 2312)
      • Driver_Updater__5513.exe (PID: 1236)
      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • Driver_Updater__5513.exe (PID: 1540)
      • DriverPro.exe (PID: 2464)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
    • The process uses the downloaded file

      • iexplore.exe (PID: 128)
    • Application launched itself

      • iexplore.exe (PID: 128)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Reads the computer name

      • Driver_Updater__5513.tmp (PID: 2312)
      • Driver_Updater__5513.tmp (PID: 1936)
      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • DriverPro.exe (PID: 2464)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
    • Creates files in the program directory

      • Driver_Updater__5513.tmp (PID: 2312)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 2104)
    • Drops 7-zip archiver for unpacking

      • Driver_Updater__5513.tmp (PID: 2312)
    • Reads the machine GUID from the registry

      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
    • Creates files or folders in the user directory

      • PCHelpSoftDriverUpdater.exe (PID: 1748)
      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
    • Checks proxy server information

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Process checks computer location settings

      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • PCHelpSoftDriverUpdater.exe (PID: 3972)
    • Process drops legitimate windows executable

      • PCHelpSoftDriverUpdater.exe (PID: 376)
      • drvinst.exe (PID: 3428)
      • drvinst.exe (PID: 2104)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2968)
    • Reads Environment values

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Reads product name

      • PCHelpSoftDriverUpdater.exe (PID: 376)
    • Manual execution by a user

      • explorer.exe (PID: 1492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
17
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe driver_updater__5513.exe no specs driver_updater__5513.tmp no specs driver_updater__5513.exe driver_updater__5513.tmp no specs pchelpsoftdriverupdater.exe no specs schtasks.exe no specs schtasks.exe no specs pchelpsoftdriverupdater.exe driverpro.exe no specs SPPSurrogate no specs vssvc.exe no specs drvinst.exe no specs drvinst.exe pchelpsoftdriverupdater.exe explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\Internet Explorer\iexplore.exe" "https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater__5513.exe"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
324"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:128 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
376"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /START /INSTALLEDC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Driver_Updater__5513.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
6.4.988
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1236"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exeiexplore.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
6.4.988.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\driver_updater__5513.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1492"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1540"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exe" /SPAWNWND=$40146 /NOTIFYWND=$3014A C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exe
Driver_Updater__5513.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
6.4.988.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\driver_updater__5513.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1748"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /INSTALLC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exeDriver_Updater__5513.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
6.4.988
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1936"C:\Users\admin\AppData\Local\Temp\is-T7Q3A.tmp\Driver_Updater__5513.tmp" /SL5="$3014A,6120102,810496,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exe" C:\Users\admin\AppData\Local\Temp\is-T7Q3A.tmp\Driver_Updater__5513.tmpDriver_Updater__5513.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t7q3a.tmp\driver_updater__5513.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2028"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Monitoring" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2104DrvInst.exe "2" "211" "ACPI\PNP0F13\4&3B4F7DA4&0" "C:\Windows\INF\oem2.inf" "apfiltr.inf:CompanyMfg:MouFilter_Inst.NT:8.0.1611.211:acpi\pnp0f13:*pnp0f13:*pnp0f0e" "748f38903" "000003DC" "000005E4" "000005E0"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
51 362
Read events
50 733
Write events
606
Delete events
23

Modification events

(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
140
Suspicious files
515
Text files
133
Unknown types
0

Dropped files

PID
Process
Filename
Type
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:6397ED88E838F570EDFD686298423D86
SHA256:8435009C3D467562C0C995EBEE824FFAAF10029E6340F55F0631E09AC0BBDC8F
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:D4DA58AF6C4FD3234FEF4CCE05AAF8C1
SHA256:7B47C9D50DF9324B8566699B5CB2D763ACA366D3E319019DA5DDC1031EA795DF
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:73108EBC834537C38B80845E5C92F574
SHA256:D9F800336A4762BAD1A6B156EE14B17097A9C4EAE7D9B30FB83FEAA0666F19C9
128iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C5C8CC0A7FE31816B4641D0465402560binary
MD5:E94FB54871208C00DF70F708AC47085B
SHA256:7B9D553E1C92CB6E8803E137F4F287D4363757F5D44B37D52F9FCA22FB97DF86
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:33A521A9015100FD6BEC651F6BFD5FD8
SHA256:F1BE57E80399911300D867AAD9ABE98ED01DE2AE7C1C46902FF5DF4EBC84D0C9
128iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:D9A513429F8A044F3992D7C94D53AE0C
SHA256:52E75D4A644C52FE7F41977BEAE16C880B79BB59C249D30909BC471C06A45371
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:80EF0E72EAA7394CF0831EF2EFF0B925
SHA256:4A7D6B4F67339D4302D2708A2E7D78D49C4FCE811C222141005949DE72E4A9EB
324iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Driver_Updater__5513.exe.yofcgvy.partialexecutable
MD5:0D7313A93D2FAF450CE6F179F208B0CE
SHA256:280E2039EE839DC6173D5846491DFCB4DACFBE421653EC62EC6492E01B5F2D21
324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D03E46CD585BBE111C712E6577BC5F07_8EA13E673F47888C21BC1937C6F7B3C0binary
MD5:B5920788299B14E9696E844250ACF443
SHA256:1B345965DA1420EE41ADE450ABC127DA2D92FF06100362C329B2AE8B6DA02308
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
102
DNS requests
30
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
324
iexplore.exe
GET
200
184.24.77.207:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6b21170b0e7a1648
unknown
compressed
4.66 Kb
unknown
324
iexplore.exe
GET
200
108.138.2.10:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
binary
2.02 Kb
unknown
324
iexplore.exe
GET
200
184.24.77.207:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?53bfb7cf8a6cf97e
unknown
compressed
4.66 Kb
unknown
324
iexplore.exe
GET
200
18.66.142.79:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
binary
1.49 Kb
unknown
324
iexplore.exe
GET
200
18.66.142.79:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
binary
1.37 Kb
unknown
324
iexplore.exe
GET
200
13.32.26.76:80
http://ocsp.r2m01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEA%2F9uaMA2YcblYIoqSnlhn8%3D
unknown
binary
471 b
unknown
376
PCHelpSoftDriverUpdater.exe
GET
304
184.24.77.207:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6ebdea9eea6b350b
unknown
unknown
128
iexplore.exe
GET
200
184.24.77.207:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?08d91df001b427ad
unknown
compressed
65.2 Kb
unknown
128
iexplore.exe
GET
200
151.101.2.133:80
http://secure.globalsign.com/cacert/codesigningrootr45.crt
unknown
binary
1.37 Kb
unknown
376
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.26:80
http://api.playanext.com/httpapi
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
324
iexplore.exe
143.204.98.16:443
cdn.pchelpsoft.com
AMAZON-02
US
unknown
324
iexplore.exe
184.24.77.207:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
324
iexplore.exe
108.138.2.10:80
o.ss2.us
AMAZON-02
US
unknown
324
iexplore.exe
18.66.142.79:80
ocsp.rootg2.amazontrust.com
AMAZON-02
US
unknown
324
iexplore.exe
13.32.26.76:80
ocsp.r2m01.amazontrust.com
AMAZON-02
US
unknown
128
iexplore.exe
151.101.2.133:80
secure.globalsign.com
FASTLY
US
unknown
128
iexplore.exe
184.24.77.207:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
cdn.pchelpsoft.com
  • 143.204.98.16
  • 143.204.98.73
  • 143.204.98.2
  • 143.204.98.44
unknown
ctldl.windowsupdate.com
  • 184.24.77.207
  • 184.24.77.199
  • 184.24.77.191
whitelisted
o.ss2.us
  • 108.138.2.10
  • 108.138.2.195
  • 108.138.2.107
  • 108.138.2.173
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.66.142.79
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.66.142.79
shared
ocsp.r2m01.amazontrust.com
  • 13.32.26.76
whitelisted
secure.globalsign.com
  • 151.101.2.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
whitelisted
drivers.avqtools.com
  • 116.203.251.147
unknown
offers.playanext.com
  • 99.86.4.76
  • 99.86.4.92
  • 99.86.4.23
  • 99.86.4.112
unknown
api.playanext.com
  • 18.245.86.26
  • 18.245.86.84
  • 18.245.86.79
  • 18.245.86.105
  • 18.239.36.117
  • 18.239.36.26
  • 18.239.36.31
  • 18.239.36.72
whitelisted

Threats

No threats detected
Process
Message
drvinst.exe
WdfCoInstaller: [12/30/2023 21:58.44.400] DIF_INSTALLDEVICE: Pre-Processing
drvinst.exe
WdfCoInstaller: [12/30/2023 21:58.44.447] ReadComponents: WdfSection for Driver Service ApfiltrService using KMDF lib version Major 0x1, minor 0x9
drvinst.exe
WdfCoInstaller: [12/30/2023 21:58.46.322] DIF_INSTALLDEVICE: Post-Processing