URL:

http://webtools.avanquest.com/download.cfm?key1=Realtek+Audio&cmp=BINGADS&mkey1=PH_WORLD_EN_PP_BI_SE_DU&msclkid=ad478952e349125d0a22eb733f67bbf1&utm_source=bing&utm_medium=cpc&utm_campaign=WORLD_EN_DRIVER-UPDATER_BI_SE_30&utm_content=__DEVICE_Audio_FAB_Realtek&go=https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater.exe&_gl=1*1mai1vs*_ga_T9M0PYG550*MTY0NjM4NjI0NC4xLjAuMTY0NjM4NjI0OC41Ng..

Full analysis: https://app.any.run/tasks/da7a8eb1-e718-4a3c-8fa3-a266f59f559c
Verdict: Malicious activity
Analysis date: March 04, 2022, 11:18:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

BC6A5E9983107877875A78A2E22BA7ED

SHA1:

65B825B45599B3ACD311208A4C6866E3DF487F72

SHA256:

70FD0AF9BC9959C651C3F6339A2B3803419F7EB1904B62D5C3E556505A22CF33

SSDEEP:

12:xD3/K8conUofiWmXse+RMUEoDjs9CV372qn:1nUoMse8MUxo9ClCi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Driver_Updater_5355.exe (PID: 2212)
      • Driver_Updater_5355.exe (PID: 544)
      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
      • HDMSchedule.exe (PID: 3852)
      • HDMTray.exe (PID: 3632)
    • Drops executable file immediately after starts

      • Driver_Updater_5355.exe (PID: 2212)
      • Driver_Updater_5355.exe (PID: 544)
    • Uses Task Scheduler to run other applications

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 2276)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
      • schtasks.exe (PID: 2504)
      • schtasks.exe (PID: 2808)
      • schtasks.exe (PID: 2900)
      • schtasks.exe (PID: 3332)
      • schtasks.exe (PID: 3560)
    • Changes settings of System certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Loads dropped or rewritten executable

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3140)
    • Checks supported languages

      • Driver_Updater_5355.exe (PID: 2212)
      • Driver_Updater_5355.tmp (PID: 3812)
      • Driver_Updater_5355.exe (PID: 544)
      • Driver_Updater_5355.tmp (PID: 776)
      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • HDMSchedule.exe (PID: 3852)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
      • HDMTray.exe (PID: 3632)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2220)
      • iexplore.exe (PID: 3140)
      • Driver_Updater_5355.exe (PID: 2212)
      • Driver_Updater_5355.exe (PID: 544)
      • Driver_Updater_5355.tmp (PID: 776)
    • Reads the computer name

      • Driver_Updater_5355.tmp (PID: 3812)
      • Driver_Updater_5355.tmp (PID: 776)
      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • HDMSchedule.exe (PID: 3852)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
      • HDMTray.exe (PID: 3632)
    • Reads Windows owner or organization settings

      • Driver_Updater_5355.tmp (PID: 776)
    • Reads the Windows organization settings

      • Driver_Updater_5355.tmp (PID: 776)
    • Drops a file that was compiled in debug mode

      • Driver_Updater_5355.tmp (PID: 776)
    • Creates a directory in Program Files

      • Driver_Updater_5355.tmp (PID: 776)
    • Drops a file with a compile date too recent

      • Driver_Updater_5355.tmp (PID: 776)
    • Creates files in the program directory

      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • HDMTray.exe (PID: 3632)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 3660)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Creates files in the user directory

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Adds / modifies Windows certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Searches for installed software

      • HDMSchedule.exe (PID: 3852)
  • INFO

    • Reads the computer name

      • iexplore.exe (PID: 2220)
      • iexplore.exe (PID: 3140)
      • schtasks.exe (PID: 2276)
      • schtasks.exe (PID: 2504)
      • schtasks.exe (PID: 2808)
      • schtasks.exe (PID: 2900)
      • schtasks.exe (PID: 3560)
      • schtasks.exe (PID: 3332)
    • Application launched itself

      • iexplore.exe (PID: 2220)
    • Checks supported languages

      • iexplore.exe (PID: 3140)
      • iexplore.exe (PID: 2220)
      • schtasks.exe (PID: 2504)
      • schtasks.exe (PID: 2276)
      • schtasks.exe (PID: 2900)
      • schtasks.exe (PID: 2808)
      • schtasks.exe (PID: 3332)
      • schtasks.exe (PID: 3560)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3140)
      • iexplore.exe (PID: 2220)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Changes internet zones settings

      • iexplore.exe (PID: 2220)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3140)
      • iexplore.exe (PID: 2220)
      • PCHelpSoftDriverUpdater.exe (PID: 2708)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3140)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 2220)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2220)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2220)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2220)
    • Application was dropped or rewritten from another process

      • Driver_Updater_5355.tmp (PID: 3812)
      • Driver_Updater_5355.tmp (PID: 776)
    • Creates files in the program directory

      • Driver_Updater_5355.tmp (PID: 776)
    • Creates a software uninstall entry

      • Driver_Updater_5355.tmp (PID: 776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
16
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe driver_updater_5355.exe driver_updater_5355.tmp no specs driver_updater_5355.exe driver_updater_5355.tmp pchelpsoftdriverupdater.exe pchelpsoftdriverupdater.exe hdmschedule.exe no specs schtasks.exe no specs schtasks.exe no specs hdmtray.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
544"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe" /SPAWNWND=$201E0 /NOTIFYWND=$201A4 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe
Driver_Updater_5355.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.616.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\driver_updater_5355.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
776"C:\Users\admin\AppData\Local\Temp\is-01VCJ.tmp\Driver_Updater_5355.tmp" /SL5="$501D0,6118523,831488,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe" /SPAWNWND=$201E0 /NOTIFYWND=$201A4 C:\Users\admin\AppData\Local\Temp\is-01VCJ.tmp\Driver_Updater_5355.tmp
Driver_Updater_5355.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-01vcj.tmp\driver_updater_5355.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2212"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Driver_Updater_5355.exe
iexplore.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.616.0
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\driver_updater_5355.exe
2220"C:\Program Files\Internet Explorer\iexplore.exe" "http://webtools.avanquest.com/download.cfm?key1=Realtek+Audio&cmp=BINGADS&mkey1=PH_WORLD_EN_PP_BI_SE_DU&msclkid=ad478952e349125d0a22eb733f67bbf1&utm_source=bing&utm_medium=cpc&utm_campaign=WORLD_EN_DRIVER-UPDATER_BI_SE_30&utm_content=__DEVICE_Audio_FAB_Realtek&go=https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater.exe&_gl=1*1mai1vs*_ga_T9M0PYG550*MTY0NjM4NjI0NC4xLjAuMTY0NjM4NjI0OC41Ng.."C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\iertutil.dll
2276"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Schedule" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\schtasks.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
2504"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Monitoring" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
2708"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /STARTC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Driver_Updater_5355.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.616
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2808"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Schedule" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\schtasks.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
2900"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Monitoring" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
3140"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2220 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\version.dll
Total events
27 353
Read events
27 111
Write events
231
Delete events
11

Modification events

(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30945209
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30945209
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2220) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
21
Suspicious files
20
Text files
72
Unknown types
25

Dropped files

PID
Process
Filename
Type
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6A2279C2CA42EBEE26F14589F0736E50der
MD5:
SHA256:
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6A2279C2CA42EBEE26F14589F0736E50binary
MD5:
SHA256:
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894der
MD5:
SHA256:
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_93E4B2BA79A897B3100CCB27F2D3BF4Fder
MD5:
SHA256:
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:
SHA256:
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_93E4B2BA79A897B3100CCB27F2D3BF4Fbinary
MD5:
SHA256:
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D6243C18F0F8F9AEC6638DD210F1984_FC8A1E0AFA8D7AB0F32E313BFA26C6ADbinary
MD5:
SHA256:
3140iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D6243C18F0F8F9AEC6638DD210F1984_FC8A1E0AFA8D7AB0F32E313BFA26C6ADder
MD5:
SHA256:
3140iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\Driver_Updater_5355[1].exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
47
DNS requests
24
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2220
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/Omniroot2025.crl
US
der
7.68 Kb
whitelisted
3140
iexplore.exe
GET
200
143.204.101.123:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
3140
iexplore.exe
GET
200
143.204.101.188:80
http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAhvbTvAjiMEfTPHbYe3bd4%3D
US
der
471 b
whitelisted
2708
PCHelpSoftDriverUpdater.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
US
der
1.40 Kb
whitelisted
2708
PCHelpSoftDriverUpdater.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDCPdbqctmTejOYZsLw%3D%3D
US
der
1.40 Kb
whitelisted
3140
iexplore.exe
GET
200
143.204.101.111:80
http://s.ss2.us/r.crl
US
der
434 b
whitelisted
3140
iexplore.exe
GET
200
143.204.101.124:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
US
der
1.39 Kb
shared
3140
iexplore.exe
GET
200
143.204.101.124:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
3140
iexplore.exe
GET
302
217.195.25.241:80
http://webtools.avanquest.com/download.cfm?key1=Realtek+Audio&cmp=BINGADS&mkey1=PH_WORLD_EN_PP_BI_SE_DU&msclkid=ad478952e349125d0a22eb733f67bbf1&utm_source=bing&utm_medium=cpc&utm_campaign=WORLD_EN_DRIVER-UPDATER_BI_SE_30&utm_content=__DEVICE_Audio_FAB_Realtek&go=https://cdn.pchelpsoft.com/pchelpsoft/Driver_Updater.exe&_gl=1*1mai1vs*_ga_T9M0PYG550*MTY0NjM4NjI0NC4xLjAuMTY0NjM4NjI0OC41Ng..
FR
text
208 b
malicious
3140
iexplore.exe
GET
200
23.32.238.178:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e4ca16984262fb9f
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3140
iexplore.exe
143.204.101.111:80
s.ss2.us
US
suspicious
3140
iexplore.exe
143.204.101.188:80
ocsp.sca1b.amazontrust.com
US
whitelisted
3140
iexplore.exe
143.204.101.124:80
ocsp.rootg2.amazontrust.com
US
whitelisted
3140
iexplore.exe
143.204.101.99:80
o.ss2.us
US
suspicious
2220
iexplore.exe
152.199.19.161:443
r20swj13mr.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3660
PCHelpSoftDriverUpdater.exe
116.203.251.147:443
collect.avqtools.com
334,Udyog Vihar
IN
suspicious
2708
PCHelpSoftDriverUpdater.exe
217.195.25.241:443
webtools.avanquest.com
SPIE Cloud Services SAS
FR
malicious
3140
iexplore.exe
217.195.25.241:80
webtools.avanquest.com
SPIE Cloud Services SAS
FR
malicious
3140
iexplore.exe
143.204.98.2:443
cdn.pchelpsoft.com
US
suspicious
3140
iexplore.exe
23.32.238.178:80
ctldl.windowsupdate.com
XO Communications
US
suspicious

DNS requests

Domain
IP
Reputation
www.microsoft.com
whitelisted
webtools.avanquest.com
  • 217.195.25.241
unknown
cdn.pchelpsoft.com
  • 143.204.98.2
  • 143.204.98.44
  • 143.204.98.16
  • 143.204.98.73
malicious
ctldl.windowsupdate.com
  • 23.32.238.178
  • 23.32.238.201
whitelisted
o.ss2.us
  • 143.204.101.195
  • 143.204.101.99
  • 143.204.101.123
  • 143.204.101.177
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 131.253.33.200
  • 13.107.22.200
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
s.ss2.us
  • 143.204.101.111
  • 143.204.101.166
  • 143.204.101.78
  • 143.204.101.119
whitelisted
ocsp.rootg2.amazontrust.com
  • 143.204.101.124
  • 143.204.101.190
  • 143.204.101.74
  • 143.204.101.42
whitelisted

Threats

PID
Process
Class
Message
2708
PCHelpSoftDriverUpdater.exe
Potentially Bad Traffic
ET INFO Observed ZeroSSL SSL/TLS Certificate
Process
Message
PCHelpSoftDriverUpdater.exe
Thread Exiting: 3640