File name:

Driver_Updater.exe.zip

Full analysis: https://app.any.run/tasks/93e923e1-0bd1-470c-84a7-b1a4bc55de92
Verdict: Malicious activity
Analysis date: February 01, 2022, 04:26:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

19796C93D4EB7E28EF0BEF63603A77A8

SHA1:

7822034AB38922F9276272763DAE1D1099E81DC0

SHA256:

8D27AF8996295C9BB93E6362D80AFD7761559A01663DE03C2C7BB8FCE1B95FB2

SSDEEP:

98304:iHRQg4aSYn2JEf5qkqjbrt72BCLa98m6t7ltXmpXir:KRx43JEfskmbx72Bsah6t7/F

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Driver_Updater.exe (PID: 2568)
      • Driver_Updater.exe (PID: 3348)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • HDMTray.exe (PID: 2264)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 2572)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • Driver_Updater.exe (PID: 2624)
      • Driver_Updater.exe (PID: 1080)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Drops executable file immediately after starts

      • Driver_Updater.exe (PID: 2568)
      • Driver_Updater.exe (PID: 3348)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • Driver_Updater.exe (PID: 2624)
      • Driver_Updater.exe (PID: 1080)
    • Uses Task Scheduler to run other applications

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
    • Loads the Task Scheduler COM API

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • schtasks.exe (PID: 2140)
      • schtasks.exe (PID: 3988)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • schtasks.exe (PID: 1980)
      • schtasks.exe (PID: 2500)
    • Loads dropped or rewritten executable

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Changes settings of System certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Steals credentials from Web Browsers

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Actions looks like stealing of personal data

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2384)
      • Driver_Updater.exe (PID: 2568)
      • Driver_Updater.exe (PID: 3348)
      • Driver_Updater.tmp (PID: 3928)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • Driver_Updater.exe (PID: 2624)
      • Driver_Updater.exe (PID: 1080)
      • Driver_Updater.tmp (PID: 2484)
    • Reads the computer name

      • WinRAR.exe (PID: 2384)
      • Driver_Updater.tmp (PID: 404)
      • Driver_Updater.tmp (PID: 3928)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • HDMTray.exe (PID: 2264)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • Driver_Updater.tmp (PID: 2848)
      • Driver_Updater.tmp (PID: 2484)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Checks supported languages

      • WinRAR.exe (PID: 2384)
      • Driver_Updater.tmp (PID: 404)
      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.exe (PID: 3348)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • HDMTray.exe (PID: 2264)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • Driver_Updater.exe (PID: 2624)
      • Driver_Updater.exe (PID: 1080)
      • Driver_Updater.tmp (PID: 2848)
      • Driver_Updater.exe (PID: 2568)
      • Driver_Updater.tmp (PID: 2484)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Reads the Windows organization settings

      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2484)
    • Reads Windows owner or organization settings

      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2484)
    • Creates a directory in Program Files

      • Driver_Updater.tmp (PID: 3928)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Creates files in the user directory

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • PCHelpSoftDriverUpdater.exe (PID: 876)
    • Drops a file that was compiled in debug mode

      • Driver_Updater.tmp (PID: 3928)
      • PCHelpSoftDriverUpdater.exe (PID: 2680)
      • Driver_Updater.tmp (PID: 2484)
    • Creates files in the program directory

      • PCHelpSoftDriverUpdater.exe (PID: 876)
      • PCHelpSoftDriverUpdater.exe (PID: 3196)
    • Adds / modifies Windows certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Starts itself from another location

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Reads the date of Windows installation

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Searches for installed software

      • Driver_Updater.tmp (PID: 2484)
  • INFO

    • Application was dropped or rewritten from another process

      • Driver_Updater.tmp (PID: 404)
      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2848)
      • Driver_Updater.tmp (PID: 2484)
    • Manual execution by user

      • Driver_Updater.exe (PID: 2568)
      • PCHelpSoftDriverUpdater.exe (PID: 856)
      • PCHelpSoftDriverUpdater.exe (PID: 2572)
      • Driver_Updater.exe (PID: 2624)
    • Creates files in the program directory

      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2484)
    • Creates a software uninstall entry

      • Driver_Updater.tmp (PID: 3928)
      • Driver_Updater.tmp (PID: 2484)
    • Checks supported languages

      • schtasks.exe (PID: 2140)
      • schtasks.exe (PID: 3988)
      • schtasks.exe (PID: 1980)
      • schtasks.exe (PID: 2500)
    • Reads the computer name

      • schtasks.exe (PID: 2140)
      • schtasks.exe (PID: 3988)
      • schtasks.exe (PID: 2500)
      • schtasks.exe (PID: 1980)
    • Checks Windows Trust Settings

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
    • Reads settings of System Certificates

      • PCHelpSoftDriverUpdater.exe (PID: 2680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Driver_Updater.exe
ZipUncompressedSize: 6331120
ZipCompressedSize: 5775538
ZipCRC: 0xe6c00e8a
ZipModifyDate: 2022:02:01 03:05:08
ZipCompression: Deflated
ZipBitFlag: 0x0009
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
20
Malicious processes
10
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start winrar.exe driver_updater.exe driver_updater.tmp no specs driver_updater.exe driver_updater.tmp pchelpsoftdriverupdater.exe pchelpsoftdriverupdater.exe schtasks.exe no specs schtasks.exe no specs hdmtray.exe no specs pchelpsoftdriverupdater.exe pchelpsoftdriverupdater.exe no specs pchelpsoftdriverupdater.exe schtasks.exe no specs schtasks.exe no specs driver_updater.exe driver_updater.tmp no specs driver_updater.exe driver_updater.tmp pchelpsoftdriverupdater.exe

Process information

PID
CMD
Path
Indicators
Parent process
404"C:\Users\admin\AppData\Local\Temp\is-LDETQ.tmp\Driver_Updater.tmp" /SL5="$3018A,5382345,831488,C:\Users\admin\Desktop\Driver_Updater.exe" C:\Users\admin\AppData\Local\Temp\is-LDETQ.tmp\Driver_Updater.tmpDriver_Updater.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-ldetq.tmp\driver_updater.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
856"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Explorer.EXE
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.590
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
876"C:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /INSTALLC:\Program Files\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Driver_Updater.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.590
Modules
Images
c:\program files\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
876"C:\Users\admin\AppData\Local\Temp\tmp4B91.tmp_collect\PCHelpSoftDriverUpdater.exe" /COLLECTC:\Users\admin\AppData\Local\Temp\tmp4B91.tmp_collect\PCHelpSoftDriverUpdater.exe
PCHelpSoftDriverUpdater.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.590
Modules
Images
c:\users\admin\appdata\local\temp\tmp4b91.tmp_collect\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1080"C:\Users\admin\Desktop\Driver_Updater.exe" /SPAWNWND=$30154 /NOTIFYWND=$500F6 C:\Users\admin\Desktop\Driver_Updater.exe
Driver_Updater.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
5.5.590.0
Modules
Images
c:\users\admin\desktop\driver_updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1980"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Schedule" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2140"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Schedule" /FC:\Windows\System32\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2264"C:\Program Files\PC HelpSoft Driver Updater\HDMTray.exe" C:\Program Files\PC HelpSoft Driver Updater\HDMTray.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater Tray
Exit code:
0
Version:
5.5.590
Modules
Images
c:\program files\pc helpsoft driver updater\hdmtray.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2384"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Driver_Updater.exe.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
2484"C:\Users\admin\AppData\Local\Temp\is-GLMU1.tmp\Driver_Updater.tmp" /SL5="$4013E,5382345,831488,C:\Users\admin\Desktop\Driver_Updater.exe" /SPAWNWND=$30154 /NOTIFYWND=$500F6 C:\Users\admin\AppData\Local\Temp\is-GLMU1.tmp\Driver_Updater.tmp
Driver_Updater.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-glmu1.tmp\driver_updater.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
14 725
Read events
14 523
Write events
189
Delete events
13

Modification events

(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2384) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Driver_Updater.exe.zip
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
33
Suspicious files
9
Text files
121
Unknown types
78

Dropped files

PID
Process
Filename
Type
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\unins000.exeexecutable
MD5:E8C8562DCF60B6015A7887F9284A9B7E
SHA256:B324BBF23EC3E59352F62AB3DBE5A546C82EF9954BE8506BF4DD87403DBCDF11
3348Driver_Updater.exeC:\Users\admin\AppData\Local\Temp\is-95KSR.tmp\Driver_Updater.tmpexecutable
MD5:1E519549380BDC8D587DF487797EB7B5
SHA256:B64FC87064EBAA1371883BE4DB8180A55D1B9734B7D240F855B89B51D03CECA7
3928Driver_Updater.tmpC:\Users\admin\AppData\Local\Temp\is-9AJ7S.tmp\PC HelpSoft Driver Updater.bmpimage
MD5:5CCDD44CBE9595ABE77A5B2BDF00B25E
SHA256:ABEAD39E36F00EF93F3990075E272AFDC5798F68AB438D3C4AF6B7162D9FE5F6
2568Driver_Updater.exeC:\Users\admin\AppData\Local\Temp\is-LDETQ.tmp\Driver_Updater.tmpexecutable
MD5:1E519549380BDC8D587DF487797EB7B5
SHA256:B64FC87064EBAA1371883BE4DB8180A55D1B9734B7D240F855B89B51D03CECA7
2384WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2384.27949\Driver_Updater.exeexecutable
MD5:4693463A3DD431B6BB25707E1113A2C2
SHA256:D3DE9FDED4C25CAA924CB6E3FBDA43EB105493CEB662848FEBA0FEFF9E8E1713
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\is-48CGQ.tmpexecutable
MD5:9CE7A89675EE686F1F55537EA9B58475
SHA256:071024A48C1F9A8BB8B568E9AA361A2768E66A5E96B14B523D2C546D8EB18C0A
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\is-Q6RIA.tmpsqlite
MD5:7B5CA14D6613ABE03EE21F5DEBF6AECA
SHA256:39CA88C94613EFA08238DD1E39F8ED2805524DA1DE4814D615DDFE192B5A65FB
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\is-5NG0K.tmpchm
MD5:165FB666397DF8FCEF10EF65E09CA6DB
SHA256:5AC0DF7C2A51A88244038AA9A12F64D2E2FF97B9979E0B157C7BE559868D5016
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\English.initext
MD5:15F624E9EB35870EDC5B526D41F78799
SHA256:F6BB4B2C7A95D44DB477211907FF2B2B908315E99DE491ED8EDB51B0D864564E
3928Driver_Updater.tmpC:\Program Files\PC HelpSoft Driver Updater\is-7NOKP.tmpexecutable
MD5:936727121AC49A47EFFE3ADCF6D276B7
SHA256:CC57E17F24C6FE01370A34E59114A387E1E9DB2E826A503554A5DD26579A7780
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
37
DNS requests
14
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2680
PCHelpSoftDriverUpdater.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDCPdbqctmTejOYZsLw%3D%3D
US
der
1.41 Kb
whitelisted
2680
PCHelpSoftDriverUpdater.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
US
der
1.40 Kb
whitelisted
2680
PCHelpSoftDriverUpdater.exe
GET
200
8.248.147.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ba831f686dae9e51
US
compressed
4.70 Kb
whitelisted
2680
PCHelpSoftDriverUpdater.exe
GET
302
217.195.25.242:80
http://webtools.pchelpsoft.com/install_success.cfm?redirectId=pchelpsoft/driver_updater_tracked.htm&target=https://www.pchelpsoft.com&&purl=1&mkey1=DEFAULT_REDIRECT_TRACKING&mkey10=DEFAULT_REDIRECT_TRACKING
FR
text
89 b
unknown
2680
PCHelpSoftDriverUpdater.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
876
PCHelpSoftDriverUpdater.exe
116.203.251.147:443
collect.avqtools.com
334,Udyog Vihar
IN
suspicious
2680
PCHelpSoftDriverUpdater.exe
217.195.25.241:443
webtools.avanquest.com
SPIE Cloud Services SAS
FR
malicious
2680
PCHelpSoftDriverUpdater.exe
116.203.251.147:443
collect.avqtools.com
334,Udyog Vihar
IN
suspicious
116.203.251.147:443
collect.avqtools.com
334,Udyog Vihar
IN
suspicious
2680
PCHelpSoftDriverUpdater.exe
8.248.147.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
2680
PCHelpSoftDriverUpdater.exe
104.26.0.94:443
www.pchelpsoft.com
Cloudflare Inc
US
unknown
2680
PCHelpSoftDriverUpdater.exe
142.132.139.157:443
receiver.smartpcupdate.com
MRNet
CA
suspicious
2680
PCHelpSoftDriverUpdater.exe
217.195.25.242:80
webtools.pchelpsoft.com
SPIE Cloud Services SAS
FR
unknown
2680
PCHelpSoftDriverUpdater.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3196
PCHelpSoftDriverUpdater.exe
116.203.251.147:443
collect.avqtools.com
334,Udyog Vihar
IN
suspicious

DNS requests

Domain
IP
Reputation
receiver.smartpcupdate.com
  • 142.132.139.157
whitelisted
collect.avqtools.com
  • 116.203.251.147
suspicious
webtools.avanquest.com
  • 217.195.25.241
unknown
ctldl.windowsupdate.com
  • 8.248.147.254
  • 8.248.141.254
  • 8.248.133.254
  • 8.248.137.254
  • 67.27.159.126
whitelisted
ocsp2.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
webtools.pchelpsoft.com
  • 217.195.25.242
unknown
www.pchelpsoft.com
  • 104.26.0.94
  • 104.26.1.94
  • 172.67.69.187
suspicious
ocsp.digicert.com
  • 93.184.220.29
whitelisted
stats.avqtools.com
suspicious

Threats

PID
Process
Class
Message
2680
PCHelpSoftDriverUpdater.exe
Potentially Bad Traffic
ET INFO Observed ZeroSSL SSL/TLS Certificate
Process
Message
PCHelpSoftDriverUpdater.exe
Thread Exiting: 3176
PCHelpSoftDriverUpdater.exe
Thread Exiting: 2640
PCHelpSoftDriverUpdater.exe
Thread Exiting: 3076
PCHelpSoftDriverUpdater.exe
Thread Exiting: 3740
PCHelpSoftDriverUpdater.exe
Thread Exiting: 1240