analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://webtools.avanquest.com/download.cfm?key1=Realtek+Audio&cmp=BINGADS&mkey1=PH_WORLD_EN_PP_BI_SE_DU&msclkid=ad478952e349125d0a22eb733f67bbf1&utm_source=bing&utm_medium=cpc&utm_campaign=WORLD_EN_DRIVER-UPDATER_BI_SE_30&utm_content=__DEVICE_Audio_FAB_Realtek&go=https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater.exe&_gl=1*1mai1vs*_ga_T9M0PYG550*MTY0NjM4NjI0NC4xLjAuMTY0NjM4NjI0OC41Ng..

Full analysis: https://app.any.run/tasks/da7a8eb1-e718-4a3c-8fa3-a266f59f559c
Verdict: Malicious activity
Analysis date: March 04, 2022, 11:18:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

BC6A5E9983107877875A78A2E22BA7ED

SHA1:

65B825B45599B3ACD311208A4C6866E3DF487F72

SHA256:

70FD0AF9BC9959C651C3F6339A2B3803419F7EB1904B62D5C3E556505A22CF33

SSDEEP:

12:xD3/K8conUofiWmXse+RMUEoDjs9CV372qn:1nUoMse8MUxo9ClCi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Driver_Updater_5355.exe (PID: 2212)
      • Driver_Updater_5355.exe (PID: 544)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • HDMSchedule.exe (PID: 3852)
      • HDMTray.exe (PID: 3632)
    • Drops executable file immediately after starts

      • Driver_Updater_5355.exe (PID: 544)
      • Driver_Updater_5355.exe (PID: 2212)
    • Loads the Task Scheduler COM API

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
      • schtasks.exe (PID: 2276)
      • schtasks.exe (PID: 2504)
      • schtasks.exe (PID: 2808)
      • schtasks.exe (PID: 2900)
      • schtasks.exe (PID: 3332)
      • schtasks.exe (PID: 3560)
    • Uses Task Scheduler to run other applications

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Changes settings of System certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Loads dropped or rewritten executable

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3140)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2220)
      • Driver_Updater_5355.exe (PID: 2212)
      • iexplore.exe (PID: 3140)
      • Driver_Updater_5355.exe (PID: 544)
      • Driver_Updater_5355.tmp (PID: 776)
    • Checks supported languages

      • Driver_Updater_5355.exe (PID: 2212)
      • Driver_Updater_5355.tmp (PID: 3812)
      • Driver_Updater_5355.exe (PID: 544)
      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • Driver_Updater_5355.tmp (PID: 776)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
      • HDMSchedule.exe (PID: 3852)
      • HDMTray.exe (PID: 3632)
    • Reads the computer name

      • Driver_Updater_5355.tmp (PID: 3812)
      • Driver_Updater_5355.tmp (PID: 776)
      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
      • HDMSchedule.exe (PID: 3852)
      • HDMTray.exe (PID: 3632)
    • Reads the Windows organization settings

      • Driver_Updater_5355.tmp (PID: 776)
    • Reads Windows owner or organization settings

      • Driver_Updater_5355.tmp (PID: 776)
    • Creates a directory in Program Files

      • Driver_Updater_5355.tmp (PID: 776)
    • Creates files in the program directory

      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • HDMTray.exe (PID: 3632)
    • Drops a file that was compiled in debug mode

      • Driver_Updater_5355.tmp (PID: 776)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Drops a file with a compile date too recent

      • Driver_Updater_5355.tmp (PID: 776)
    • Creates files in the user directory

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Adds / modifies Windows certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Searches for installed software

      • HDMSchedule.exe (PID: 3852)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 3140)
      • iexplore.exe (PID: 2220)
      • schtasks.exe (PID: 2504)
      • schtasks.exe (PID: 2276)
      • schtasks.exe (PID: 2900)
      • schtasks.exe (PID: 2808)
      • schtasks.exe (PID: 3332)
      • schtasks.exe (PID: 3560)
    • Reads the computer name

      • iexplore.exe (PID: 3140)
      • iexplore.exe (PID: 2220)
      • schtasks.exe (PID: 2504)
      • schtasks.exe (PID: 2276)
      • schtasks.exe (PID: 2808)
      • schtasks.exe (PID: 3560)
      • schtasks.exe (PID: 3332)
      • schtasks.exe (PID: 2900)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3140)
      • iexplore.exe (PID: 2220)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Application launched itself

      • iexplore.exe (PID: 2220)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3140)
      • iexplore.exe (PID: 2220)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Changes internet zones settings

      • iexplore.exe (PID: 2220)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3140)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 2220)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2220)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2220)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2220)
    • Application was dropped or rewritten from another process

      • Driver_Updater_5355.tmp (PID: 3812)
      • Driver_Updater_5355.tmp (PID: 776)
    • Creates a software uninstall entry

      • Driver_Updater_5355.tmp (PID: 776)
    • Creates files in the program directory

      • Driver_Updater_5355.tmp (PID: 776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
16
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe driver_updater_5355.exe driver_updater_5355.tmp no specs driver_updater_5355.exe driver_updater_5355.tmp pchelpsoftdriverupdater.exe pchelpsoftdriverupdater.exe hdmschedule.exe no specs schtasks.exe no specs schtasks.exe no specs hdmtray.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2220"C:\Program Files\Internet Explorer\iexplore.exe" "http://webtools.avanquest.com/download.cfm?key1=Realtek+Audio&cmp=BINGADS&mkey1=PH_WORLD_EN_PP_BI_SE_DU&msclkid=ad478952e349125d0a22eb733f67bbf1&utm_source=bing&utm_medium=cpc&utm_campaign=WORLD_EN_DRIVER-UPDATER_BI_SE_30&utm_content=__DEVICE_Audio_FAB_Realtek&go=https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater.exe&_gl=1*1mai1vs*_ga_T9M0PYG550*MTY0NjM4NjI0NC4xLjAuMTY0NjM4NjI0OC41Ng.."C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\iertutil.dll
3140"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2220 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\version.dll
2212"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe
iexplore.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.616.0
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\driver_updater_5355.exe
3812"C:\Users\admin\AppData\Local\Temp\is-FPEI5.tmp\Driver_Updater_5355.tmp" /SL5="$201A4,6118523,831488,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe" C:\Users\admin\AppData\Local\Temp\is-FPEI5.tmp\Driver_Updater_5355.tmpDriver_Updater_5355.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-fpei5.tmp\driver_updater_5355.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
544"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe" /SPAWNWND=$201E0 /NOTIFYWND=$201A4 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe
Driver_Updater_5355.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.616.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\driver_updater_5355.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
776"C:\Users\admin\AppData\Local\Temp\is-01VCJ.tmp\Driver_Updater_5355.tmp" /SL5="$501D0,6118523,831488,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe" /SPAWNWND=$201E0 /NOTIFYWND=$201A4 C:\Users\admin\AppData\Local\Temp\is-01VCJ.tmp\Driver_Updater_5355.tmp
Driver_Updater_5355.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-01vcj.tmp\driver_updater_5355.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3660"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /INSTALLC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Driver_Updater_5355.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.616
Modules
Images
c:\windows\system32\kernel32.dll
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
2708"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /STARTC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Driver_Updater_5355.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Version:
5.5.616
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3852"C:\Program Files\PC HelpSoft Driver Updater\Extra\HDMSchedule.exe"C:\Program Files\PC HelpSoft Driver Updater\Extra\HDMSchedule.exeDriver_Updater_5355.tmp
User:
admin
Company:
PC Helpsoft
Integrity Level:
HIGH
Description:
Driver Pro automatic scan and notifications
Version:
6.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\pc helpsoft driver updater\extra\hdmschedule.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
2276"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Schedule" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\schtasks.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
Total events
27 353
Read events
27 111
Write events
231
Delete events
11

Modification events

(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30945209
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30945209
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
21
Suspicious files
20
Text files
72
Unknown types
25

Dropped files

PID
Process
Filename
Type
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_93E4B2BA79A897B3100CCB27F2D3BF4Fbinary
MD5:D2AEAD8D7443E3ECFE14FDB8C3B9B17D
SHA256:878E4B6C0A266CE8F4AC4AA8AE508D1F089E7E7A3359F0BFF58EEEF17547F369
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894der
MD5:7BF469FF4F438BAB44507FD25034D3E5
SHA256:CE4022E6B1DD46B914E122ADCCCBC46DDDB8C1F5FD8C802EEE0E29CC9BC5513C
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D6243C18F0F8F9AEC6638DD210F1984_FC8A1E0AFA8D7AB0F32E313BFA26C6ADder
MD5:758AC4C40F0FCC67BFDAA0229ABFF3F0
SHA256:60A862324E8C4D37D0D4BE526A6CA7B9CF579AFA9FDB7232AEBEAFBF63026278
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_93E4B2BA79A897B3100CCB27F2D3BF4Fder
MD5:8BF22F2707294B191684D9EF8201C188
SHA256:928F5D16DD8841520B4786F1772EA89507BE549CA1CA6B9199E69AED8DD8B375
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D6243C18F0F8F9AEC6638DD210F1984_FC8A1E0AFA8D7AB0F32E313BFA26C6ADbinary
MD5:4411C9B6675A4272C695AEFB96CF5E60
SHA256:B0A3719653E3DDFA0CC1562434C91846EE62999D158ED5D0887C0A2B44092490
3140iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\Driver_Updater_5355[1].exeexecutable
MD5:95058F9F3DB687D038E11BF2DD6A4DF6
SHA256:4DAF0A6CA1275BDE02597CD5D20F5E3869E7D9D8175F55E8BDDF79CF13595A66
2220iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\82CB34DD3343FE727DF8890D352E0D8Fder
MD5:ED57E8C6D5AD03C7166D6872CB194407
SHA256:AC11F24140752E8CBA396A64073D2F293887BF677527FF59BCFAEB5CD7129546
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6A2279C2CA42EBEE26F14589F0736E50der
MD5:8B153254225CF81983BAA0400492B53E
SHA256:A3EB96967C5F501B5E14CF4E0A2BB4B9DFA8933352C973A1EAE89C321804BC25
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:EDFBBF8B21F9D6E7DDBA42C2892C1A57
SHA256:28F99B98FF6B960A72E514DB4ABDCB65FB3A46CC52C9E207E2FE26A29B92DB02
2220iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF1263FB9BF3B35A16.TMPgmc
MD5:2E58EFC9AFC8FD0825A1BE7A7BB96FF5
SHA256:B220D0B1EF9D8DC19D1A05F0AC721D3697E79D190575AEE8AC63AD322BF39732
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
47
DNS requests
24
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3140
iexplore.exe
GET
302
217.195.25.241:80
http://webtools.avanquest.com/download.cfm?key1=Realtek+Audio&cmp=BINGADS&mkey1=PH_WORLD_EN_PP_BI_SE_DU&msclkid=ad478952e349125d0a22eb733f67bbf1&utm_source=bing&utm_medium=cpc&utm_campaign=WORLD_EN_DRIVER-UPDATER_BI_SE_30&utm_content=__DEVICE_Audio_FAB_Realtek&go=https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater.exe&_gl=1*1mai1vs*_ga_T9M0PYG550*MTY0NjM4NjI0NC4xLjAuMTY0NjM4NjI0OC41Ng..
FR
text
208 b
malicious
2708
PCHelpSoftDriverUpdater.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDCPdbqctmTejOYZsLw%3D%3D
US
der
1.40 Kb
whitelisted
2220
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/Omniroot2025.crl
US
der
7.68 Kb
whitelisted
2220
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
3140
iexplore.exe
GET
200
143.204.101.123:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
3140
iexplore.exe
GET
200
143.204.101.188:80
http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAhvbTvAjiMEfTPHbYe3bd4%3D
US
der
471 b
whitelisted
3140
iexplore.exe
GET
200
143.204.101.111:80
http://s.ss2.us/r.crl
US
der
434 b
whitelisted
3140
iexplore.exe
GET
200
143.204.101.124:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
US
der
1.39 Kb
shared
2708
PCHelpSoftDriverUpdater.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
US
der
1.40 Kb
whitelisted
3140
iexplore.exe
GET
200
143.204.101.124:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3140
iexplore.exe
217.195.25.241:80
webtools.avanquest.com
SPIE Cloud Services SAS
FR
malicious
3140
iexplore.exe
23.32.238.201:80
ctldl.windowsupdate.com
XO Communications
US
suspicious
3140
iexplore.exe
143.204.98.2:443
cdn.pchelpsoft.com
US
suspicious
3140
iexplore.exe
23.32.238.178:80
ctldl.windowsupdate.com
XO Communications
US
suspicious
217.195.25.241:80
webtools.avanquest.com
SPIE Cloud Services SAS
FR
malicious
192.168.100.2:53
whitelisted
3140
iexplore.exe
143.204.101.195:80
o.ss2.us
US
unknown
2220
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3140
iexplore.exe
143.204.101.188:80
ocsp.sca1b.amazontrust.com
US
whitelisted
2220
iexplore.exe
131.253.33.200:443
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
whitelisted
webtools.avanquest.com
  • 217.195.25.241
unknown
cdn.pchelpsoft.com
  • 143.204.98.2
  • 143.204.98.44
  • 143.204.98.16
  • 143.204.98.73
malicious
ctldl.windowsupdate.com
  • 23.32.238.178
  • 23.32.238.201
whitelisted
o.ss2.us
  • 143.204.101.195
  • 143.204.101.99
  • 143.204.101.123
  • 143.204.101.177
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 131.253.33.200
  • 13.107.22.200
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
s.ss2.us
  • 143.204.101.111
  • 143.204.101.166
  • 143.204.101.78
  • 143.204.101.119
whitelisted
ocsp.rootg2.amazontrust.com
  • 143.204.101.124
  • 143.204.101.190
  • 143.204.101.74
  • 143.204.101.42
whitelisted

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO Observed ZeroSSL SSL/TLS Certificate
Process
Message
PCHelpSoftDriverUpdater.exe
Thread Exiting: 3640