File name:

Driver_Updater.exe.zip

Full analysis: https://app.any.run/tasks/93e923e1-0bd1-470c-84a7-b1a4bc55de92
Verdict: Malicious activity
Analysis date: February 01, 2022, 04:26:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

19796C93D4EB7E28EF0BEF63603A77A8

SHA1:

7822034AB38922F9276272763DAE1D1099E81DC0

SHA256:

8D27AF8996295C9BB93E6362D80AFD7761559A01663DE03C2C7BB8FCE1B95FB2

SSDEEP:

98304:iHRQg4aSYn2JEf5qkqjbrt72BCLa98m6t7ltXmpXir:KRx43JEfskmbx72Bsah6t7/F

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Driver_Updater.exe (PID: 3348)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • Driver_Updater.exe (PID: 2568)
      • Driver_Updater.exe (PID: 2624)
      • Driver_Updater.exe (PID: 1080)
    • Application was dropped or rewritten from another process

      • Driver_Updater.exe (PID: 2568)
      • Driver_Updater.exe (PID: 3348)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • HDMTray.exe (PID: 2264)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 2572)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • Driver_Updater.exe (PID: 2624)
      • Driver_Updater.exe (PID: 1080)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Loads the Task Scheduler COM API

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • schtasks.exe (PID: 2140)
      • schtasks.exe (PID: 3988)
      • schtasks.exe (PID: 1980)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • schtasks.exe (PID: 2500)
    • Uses Task Scheduler to run other applications

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
    • Loads dropped or rewritten executable

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Changes settings of System certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Steals credentials from Web Browsers

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Actions looks like stealing of personal data

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 2384)
      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 404)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • HDMTray.exe (PID: 2264)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • Driver_Updater.tmp (PID: 2484)
      • Driver_Updater.tmp (PID: 2848)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
    • Checks supported languages

      • Driver_Updater.tmp (PID: 404)
      • Driver_Updater.exe (PID: 2568)
      • Driver_Updater.exe (PID: 3348)
      • Driver_Updater.tmp (PID: 3928)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • HDMTray.exe (PID: 2264)
      • WinRAR.exe (PID: 2384)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • Driver_Updater.tmp (PID: 2848)
      • Driver_Updater.exe (PID: 1080)
      • Driver_Updater.tmp (PID: 2484)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
      • Driver_Updater.exe (PID: 2624)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2384)
      • Driver_Updater.exe (PID: 2568)
      • Driver_Updater.exe (PID: 3348)
      • Driver_Updater.tmp (PID: 3928)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • Driver_Updater.exe (PID: 2624)
      • Driver_Updater.exe (PID: 1080)
      • Driver_Updater.tmp (PID: 2484)
    • Reads Windows owner or organization settings

      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2484)
    • Reads the Windows organization settings

      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2484)
    • Creates a directory in Program Files

      • Driver_Updater.tmp (PID: 3928)
    • Creates files in the program directory

      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Creates files in the user directory

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
    • Drops a file that was compiled in debug mode

      • Driver_Updater.tmp (PID: 3928)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • Driver_Updater.tmp (PID: 2484)
    • Starts itself from another location

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Adds / modifies Windows certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Reads the date of Windows installation

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Searches for installed software

      • Driver_Updater.tmp (PID: 2484)
  • INFO

    • Application was dropped or rewritten from another process

      • Driver_Updater.tmp (PID: 404)
      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2848)
      • Driver_Updater.tmp (PID: 2484)
    • Manual execution by user

      • Driver_Updater.exe (PID: 2568)
      • PCHelpSoftDriverUpdater.exe (PID: 2572)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • Driver_Updater.exe (PID: 2624)
    • Creates files in the program directory

      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2484)
    • Creates a software uninstall entry

      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2484)
    • Checks supported languages

      • schtasks.exe (PID: 2140)
      • schtasks.exe (PID: 3988)
      • schtasks.exe (PID: 1980)
      • schtasks.exe (PID: 2500)
    • Reads the computer name

      • schtasks.exe (PID: 2140)
      • schtasks.exe (PID: 3988)
      • schtasks.exe (PID: 2500)
      • schtasks.exe (PID: 1980)
    • Checks Windows Trust Settings

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Reads settings of System Certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Driver_Updater.exe
ZipUncompressedSize: 6331120
ZipCompressedSize: 5775538
ZipCRC: 0xe6c00e8a
ZipModifyDate: 2022:02:01 03:05:08
ZipCompression: Deflated
ZipBitFlag: 0x0009
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
20
Malicious processes
10
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start winrar.exe driver_updater.exe driver_updater.tmp no specs driver_updater.exe driver_updater.tmp pchelpsoftdriverupdater.exe pchelpsoftdriverupdater.exe schtasks.exe no specs schtasks.exe no specs hdmtray.exe no specs pchelpsoftdriverupdater.exe pchelpsoftdriverupdater.exe no specs pchelpsoftdriverupdater.exe schtasks.exe no specs schtasks.exe no specs driver_updater.exe driver_updater.tmp no specs driver_updater.exe driver_updater.tmp pchelpsoftdriverupdater.exe

Process information

PID
CMD
Path
Indicators
Parent process
404"C:\Users\admin\AppData\Local\Temp\is-LDETQ.tmp\Driver_Updater.tmp" /SL5="$3018A,5382345,831488,C:\Users\admin\Desktop\Driver_Updater.exe" C:\Users\admin\AppData\Local\Temp\is-LDETQ.tmp\Driver_Updater.tmpDriver_Updater.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-ldetq.tmp\driver_updater.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
856"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Explorer.EXE
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.590
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
876"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /INSTALLC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Driver_Updater.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.590
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
876"C:\Users\admin\AppData\Local\Temp\tmp4B91.tmp_collect\PCHelpSoftDriverUpdater.exe" /COLLECTC:\Users\admin\AppData\Local\Temp\tmp4B91.tmp_collect\PCHelpSoftDriverUpdater.exe
PCHelpSoftDriverUpdater.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.590
Modules
Images
c:\users\admin\appdata\local\temp\tmp4b91.tmp_collect\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1080"C:\Users\admin\Desktop\Driver_Updater.exe" /SPAWNWND=$30154 /NOTIFYWND=$500F6 C:\Users\admin\Desktop\Driver_Updater.exe
Driver_Updater.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.590.0
Modules
Images
c:\users\admin\desktop\driver_updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1980"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Schedule" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2140"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Schedule" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2264"C:\Program Files\PC HelpSoft Driver Updater\HDMTray.exe" C:\Program Files\PC HelpSoft Driver Updater\HDMTray.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater Tray
Exit code:
0
Version:
5.5.590
Modules
Images
c:\program files\pc helpsoft driver updater\hdmtray.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2384"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Driver_Updater.exe.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
2484"C:\Users\admin\AppData\Local\Temp\is-GLMU1.tmp\Driver_Updater.tmp" /SL5="$4013E,5382345,831488,C:\Users\admin\Desktop\Driver_Updater.exe" /SPAWNWND=$30154 /NOTIFYWND=$500F6 C:\Users\admin\AppData\Local\Temp\is-GLMU1.tmp\Driver_Updater.tmp
Driver_Updater.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-glmu1.tmp\driver_updater.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
14 725
Read events
14 523
Write events
189
Delete events
13

Modification events

(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2384) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Driver_Updater.exe.zip
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
33
Suspicious files
9
Text files
121
Unknown types
78

Dropped files

PID
Process
Filename
Type
3928Driver_Updater.tmpC:\Users\admin\AppData\Local\Temp\is-9AJ7S.tmp\PC HelpSoft Driver Updater.bmpimage
MD5:5CCDD44CBE9595ABE77A5B2BDF00B25E
SHA256:ABEAD39E36F00EF93F3990075E272AFDC5798F68AB438D3C4AF6B7162D9FE5F6
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\is-Q6RIA.tmpsqlite
MD5:7B5CA14D6613ABE03EE21F5DEBF6AECA
SHA256:39CA88C94613EFA08238DD1E39F8ED2805524DA1DE4814D615DDFE192B5A65FB
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\SList.dbsqlite
MD5:7B5CA14D6613ABE03EE21F5DEBF6AECA
SHA256:39CA88C94613EFA08238DD1E39F8ED2805524DA1DE4814D615DDFE192B5A65FB
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\is-3NUV1.tmptext
MD5:80A353EA8E6A93A016076E538A9B123C
SHA256:F4B39BF16BAA717EBF380C322491E868279DA6CC90155BA1B31634A4B60BCF1A
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\HDMSchedule.exeexecutable
MD5:9438E7FC03F9D50D300D7BFA0156973A
SHA256:ECB638E028315D303D5FD55E5CE247E7F35C54EAA1AFF1ED0B6721110372D8BD
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\SList.txttext
MD5:80A353EA8E6A93A016076E538A9B123C
SHA256:F4B39BF16BAA717EBF380C322491E868279DA6CC90155BA1B31634A4B60BCF1A
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\is-2BE61.tmpexecutable
MD5:E8C8562DCF60B6015A7887F9284A9B7E
SHA256:B324BBF23EC3E59352F62AB3DBE5A546C82EF9954BE8506BF4DD87403DBCDF11
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\unins000.exeexecutable
MD5:E8C8562DCF60B6015A7887F9284A9B7E
SHA256:B324BBF23EC3E59352F62AB3DBE5A546C82EF9954BE8506BF4DD87403DBCDF11
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exeexecutable
MD5:936727121AC49A47EFFE3ADCF6D276B7
SHA256:CC57E17F24C6FE01370A34E59114A387E1E9DB2E826A503554A5DD26579A7780
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\is-80901.tmpexecutable
MD5:9438E7FC03F9D50D300D7BFA0156973A
SHA256:ECB638E028315D303D5FD55E5CE247E7F35C54EAA1AFF1ED0B6721110372D8BD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
37
DNS requests
14
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2680
PCHelpSoftDriverUpdater.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDCPdbqctmTejOYZsLw%3D%3D
US
der
1.41 Kb
whitelisted
2680
PCHelpSoftDriverUpdater.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
US
der
1.40 Kb
whitelisted
2680
PCHelpSoftDriverUpdater.exe
GET
200
8.248.147.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ba831f686dae9e51
US
compressed
4.70 Kb
whitelisted
2680
PCHelpSoftDriverUpdater.exe
GET
302
217.195.25.242:80
http://webtools.pchelpsoft.com/install_success.cfm?redirectId=pchelpsoft/driver_updater_tracked.htm&target=https://www.pchelpsoft.com&&purl=1&mkey1=DEFAULT_REDIRECT_TRACKING&mkey10=DEFAULT_REDIRECT_TRACKING
FR
text
89 b
unknown
2680
PCHelpSoftDriverUpdater.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2680
PCHelpSoftDriverUpdater.exe
116.203.251.147:443
collect.avqtools.com
334,Udyog Vihar
IN
suspicious
876
PCHelpSoftDriverUpdater.exe
116.203.251.147:443
collect.avqtools.com
334,Udyog Vihar
IN
suspicious
116.203.251.147:443
collect.avqtools.com
334,Udyog Vihar
IN
suspicious
2680
PCHelpSoftDriverUpdater.exe
217.195.25.241:443
webtools.avanquest.com
SPIE Cloud Services SAS
FR
malicious
2680
PCHelpSoftDriverUpdater.exe
8.248.147.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
2680
PCHelpSoftDriverUpdater.exe
104.26.0.94:443
www.pchelpsoft.com
Cloudflare Inc
US
unknown
3196
PCHelpSoftDriverUpdater.exe
116.203.251.147:443
collect.avqtools.com
334,Udyog Vihar
IN
suspicious
2680
PCHelpSoftDriverUpdater.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2680
PCHelpSoftDriverUpdater.exe
104.18.20.226:80
ocsp2.globalsign.com
Cloudflare Inc
US
shared
2680
PCHelpSoftDriverUpdater.exe
104.18.21.226:80
ocsp2.globalsign.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
receiver.smartpcupdate.com
  • 142.132.139.157
whitelisted
collect.avqtools.com
  • 116.203.251.147
suspicious
webtools.avanquest.com
  • 217.195.25.241
unknown
ctldl.windowsupdate.com
  • 8.248.147.254
  • 8.248.141.254
  • 8.248.133.254
  • 8.248.137.254
  • 67.27.159.126
whitelisted
ocsp2.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
webtools.pchelpsoft.com
  • 217.195.25.242
unknown
www.pchelpsoft.com
  • 104.26.0.94
  • 104.26.1.94
  • 172.67.69.187
suspicious
ocsp.digicert.com
  • 93.184.220.29
whitelisted
stats.avqtools.com
suspicious

Threats

PID
Process
Class
Message
2680
PCHelpSoftDriverUpdater.exe
Potentially Bad Traffic
ET INFO Observed ZeroSSL SSL/TLS Certificate
Process
Message
PCHelpSoftDriverUpdater.exe
Thread Exiting: 3176
PCHelpSoftDriverUpdater.exe
Thread Exiting: 2640
PCHelpSoftDriverUpdater.exe
Thread Exiting: 3076
PCHelpSoftDriverUpdater.exe
Thread Exiting: 3740
PCHelpSoftDriverUpdater.exe
Thread Exiting: 1240