URL:

https://download.winzipdriverupdater.com/wzdu/wzdu53.exe

Full analysis: https://app.any.run/tasks/a74a5f06-2e3c-44fe-bb30-6bc8922e6bc6
Verdict: Malicious activity
Analysis date: October 26, 2020, 11:10:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

BF473CF071815FC11E756832BDAB3D59

SHA1:

A36DC92359BC32D74BF0016AB5506177D966589B

SHA256:

BD5C1FD231394B0F1D8ED7B88CFA5E0D6F8A705B8F73906CE4104B93603B9CF8

SSDEEP:

3:N8SElDUaT8mqBQQQCn:2SKDnADmQ9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 4004)
      • wzdu53.exe (PID: 3304)
      • ga_utility.exe (PID: 2068)
      • wzdu53.exe (PID: 2596)
      • WinZipSmartMonitorSetup.exe (PID: 2336)
      • WinZipSmartMonitor.exe (PID: 2560)
      • WinZip Smart Monitor Service.exe (PID: 3348)
      • WinZip Smart Monitor Service.exe (PID: 116)
      • Settings.exe (PID: 668)
      • DriverUpdater.exe (PID: 124)
      • DriverUpdater.exe (PID: 968)
      • ga_utility.exe (PID: 3780)
      • DriverUpdater.exe (PID: 3040)
      • DriverUpdater.exe (PID: 3292)
      • DriverUpdater.exe (PID: 3180)
      • DriverUpdater.exe (PID: 960)
      • Settings.exe (PID: 984)
      • WinZipSmartMonitor.exe (PID: 1076)
    • Changes settings of System certificates

      • ga_utility.exe (PID: 2068)
      • Settings.exe (PID: 668)
      • WinZip Smart Monitor Service.exe (PID: 116)
      • DriverUpdater.exe (PID: 3040)
    • Loads dropped or rewritten executable

      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 4004)
      • WinZipSmartMonitorSetup.exe (PID: 2336)
      • DriverUpdater.exe (PID: 124)
      • DriverUpdater.exe (PID: 968)
      • DriverUpdater.exe (PID: 3292)
      • DriverUpdater.exe (PID: 3180)
      • DriverUpdater.exe (PID: 960)
      • DriverUpdater.exe (PID: 3040)
    • Loads the Task Scheduler DLL interface

      • DriverUpdater.exe (PID: 124)
      • DriverUpdater.exe (PID: 3040)
    • Loads the Task Scheduler COM API

      • DriverUpdater.exe (PID: 124)
      • DriverUpdater.exe (PID: 3040)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2428)
      • wzdu53.exe (PID: 2596)
      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 4004)
      • WinZipSmartMonitorSetup.exe (PID: 2336)
      • DriverUpdater.exe (PID: 124)
    • Reads Internet Cache Settings

      • ga_utility.exe (PID: 2068)
      • DriverUpdater.exe (PID: 124)
      • ga_utility.exe (PID: 3780)
      • DriverUpdater.exe (PID: 3040)
      • WinZipSmartMonitor.exe (PID: 1076)
    • Adds / modifies Windows certificates

      • ga_utility.exe (PID: 2068)
      • Settings.exe (PID: 668)
      • WinZip Smart Monitor Service.exe (PID: 116)
      • DriverUpdater.exe (PID: 3040)
    • Creates files in the program directory

      • WinZipSmartMonitorSetup.exe (PID: 2336)
      • WinZipSmartMonitor.exe (PID: 2560)
      • DriverUpdater.exe (PID: 124)
      • DriverUpdater.exe (PID: 968)
      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 4004)
      • Settings.exe (PID: 984)
      • DriverUpdater.exe (PID: 3040)
    • Starts SC.EXE for service management

      • WinZipSmartMonitorSetup.exe (PID: 2336)
    • Creates files in the Windows directory

      • WinZip Smart Monitor Service.exe (PID: 116)
    • Executed as Windows Service

      • WinZip Smart Monitor Service.exe (PID: 116)
    • Removes files from Windows directory

      • WinZip Smart Monitor Service.exe (PID: 116)
    • Creates a software uninstall entry

      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 4004)
      • DriverUpdater.exe (PID: 3292)
    • Executed via COM

      • Settings.exe (PID: 984)
    • Starts Internet Explorer

      • DriverUpdater.exe (PID: 3180)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2428)
      • iexplore.exe (PID: 2072)
      • iexplore.exe (PID: 2268)
      • iexplore.exe (PID: 548)
    • Application launched itself

      • iexplore.exe (PID: 2428)
      • iexplore.exe (PID: 2268)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2072)
      • iexplore.exe (PID: 2428)
      • iexplore.exe (PID: 548)
      • DriverUpdater.exe (PID: 3040)
      • iexplore.exe (PID: 2268)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2428)
      • iexplore.exe (PID: 548)
    • Changes internet zones settings

      • iexplore.exe (PID: 2428)
      • iexplore.exe (PID: 2268)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2428)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2428)
      • iexplore.exe (PID: 548)
    • Reads internet explorer settings

      • iexplore.exe (PID: 548)
    • Creates files in the user directory

      • iexplore.exe (PID: 548)
      • iexplore.exe (PID: 2428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
23
Malicious processes
11
Suspicious processes
5

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe wzdu53.exe no specs wzdu53.exe c5164949-5a29-4ee1-b858-e90ed8c69b81.exe ga_utility.exe winzipsmartmonitorsetup.exe settings.exe no specs winzip smart monitor service.exe no specs winzipsmartmonitor.exe no specs sc.exe no specs winzip smart monitor service.exe driverupdater.exe driverupdater.exe no specs ga_utility.exe driverupdater.exe no specs driverupdater.exe driverupdater.exe no specs driverupdater.exe no specs settings.exe no specs iexplore.exe iexplore.exe winzipsmartmonitor.exe

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe"C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe
services.exe
User:
SYSTEM
Company:
Corel Corporation
Integrity Level:
SYSTEM
Description:
WinZip Smart Monitor Service
Exit code:
0
Version:
2,11,3,8
Modules
Images
c:\program files\winzip smart monitor\winzip smart monitor service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
124"C:\Program Files\WinZip Driver Updater\DriverUpdater.exe" install lang=English -guid "65CE3E99-99E8-48FC-BF8C-A8E04897196A"C:\Program Files\WinZip Driver Updater\DriverUpdater.exe
c5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Driver Updater
Exit code:
0
Version:
5,34,3,2
Modules
Images
c:\program files\winzip driver updater\driverupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
548"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2268 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
668"C:\Program Files\WinZip Smart Monitor\Settings.exe" /RegServerC:\Program Files\WinZip Smart Monitor\Settings.exeWinZipSmartMonitorSetup.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
Settings
Exit code:
0
Version:
2,11,3,8
Modules
Images
c:\program files\winzip smart monitor\settings.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
960"C:\Program Files\WinZip Driver Updater\DriverUpdater.exe" -syncSMSettingsC:\Program Files\WinZip Driver Updater\DriverUpdater.exec5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Driver Updater
Exit code:
0
Version:
5,34,3,2
Modules
Images
c:\program files\winzip driver updater\driverupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
968"C:\Program Files\WinZip Driver Updater\DriverUpdater.exe" -build_id 53 -guid "65CE3E99-99E8-48FC-BF8C-A8E04897196A"C:\Program Files\WinZip Driver Updater\DriverUpdater.exec5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Driver Updater
Exit code:
0
Version:
5,34,3,2
Modules
Images
c:\program files\winzip driver updater\driverupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
984"C:\Program Files\WinZip Smart Monitor\Settings.exe" -EmbeddingC:\Program Files\WinZip Smart Monitor\Settings.exesvchost.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
Settings
Exit code:
0
Version:
2,11,3,8
Modules
Images
c:\program files\winzip smart monitor\settings.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1076"C:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exe" -runC:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exe
WinZip Smart Monitor Service.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Smart Monitor
Exit code:
0
Version:
2,11,3,8
Modules
Images
c:\program files\winzip smart monitor\winzipsmartmonitor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1968sc start "WinZip Smart Monitor Service"C:\Windows\system32\sc.exeWinZipSmartMonitorSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2068"C:\Users\admin\AppData\Local\Temp\nsi73CF.tmp\ga_utility.exe" -install_start -guid "65CE3E99-99E8-48FC-BF8C-A8E04897196A" -language "en" -app_version "5.34.3.2" -product_code "DU" -app_name "WinZip Driver Updater" -track_id "UA-66457935-11"C:\Users\admin\AppData\Local\Temp\nsi73CF.tmp\ga_utility.exe
c5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Integrity Level:
HIGH
Description:
ga_utility
Exit code:
0
Version:
1,0,0,6
Modules
Images
c:\users\admin\appdata\local\temp\nsi73cf.tmp\ga_utility.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\wininet.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
Total events
2 313
Read events
1 922
Write events
387
Delete events
4

Modification events

(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
3397270978
(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30845832
(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
69
Suspicious files
182
Text files
444
Unknown types
75

Dropped files

PID
Process
Filename
Type
2072iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab4163.tmp
MD5:
SHA256:
2072iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar4164.tmp
MD5:
SHA256:
2072iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\wzdu53[1].exe
MD5:
SHA256:
2072iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\wzdu53.exe.xm06lbd.partial
MD5:
SHA256:
2428iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF331B92A8A52F0F3B.TMP
MD5:
SHA256:
2428iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\wzdu53.exe.xm06lbd.partial:Zone.Identifier
MD5:
SHA256:
2068ga_utility.exeC:\Users\admin\AppData\Local\Temp\Cab8477.tmp
MD5:
SHA256:
2068ga_utility.exeC:\Users\admin\AppData\Local\Temp\Tar8478.tmp
MD5:
SHA256:
2072iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_9487BC0D4381A7CDEB9A8CC43F66D27Cbinary
MD5:
SHA256:
2428iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{F63AD883-177B-11EB-85AF-12A9866C77DE}.datbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
72
TCP/UDP connections
108
DNS requests
45
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
548
iexplore.exe
GET
200
143.204.208.173:80
http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAm5ABaQImYavmuQQF9NSrY%3D
US
der
471 b
whitelisted
548
iexplore.exe
GET
200
143.204.208.173:80
http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAcsB%2BSe%2B6FZVmCEI1dDRtw%3D
US
der
471 b
whitelisted
548
iexplore.exe
GET
200
143.204.208.173:80
http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAm5ABaQImYavmuQQF9NSrY%3D
US
der
471 b
whitelisted
116
WinZip Smart Monitor Service.exe
GET
200
143.204.208.127:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
2072
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D
US
der
471 b
whitelisted
3040
DriverUpdater.exe
GET
200
13.35.253.198:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
548
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
116
WinZip Smart Monitor Service.exe
GET
200
13.35.253.198:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
3040
DriverUpdater.exe
GET
200
13.35.253.5:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
US
der
1.39 Kb
shared
2072
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2072
iexplore.exe
104.84.56.34:443
download.winzipdriverupdater.com
Vodafone NZ Ltd.
US
malicious
2072
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2068
ga_utility.exe
172.217.23.99:80
ocsp.pki.goog
Google Inc.
US
whitelisted
2068
ga_utility.exe
216.58.207.72:443
ssl.google-analytics.com
Google Inc.
US
whitelisted
116
WinZip Smart Monitor Service.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
124
DriverUpdater.exe
216.58.207.72:443
ssl.google-analytics.com
Google Inc.
US
whitelisted
116
WinZip Smart Monitor Service.exe
34.207.20.230:443
updaterv.winzip.com
Amazon.com, Inc.
US
unknown
3780
ga_utility.exe
216.58.207.72:443
ssl.google-analytics.com
Google Inc.
US
whitelisted
116
WinZip Smart Monitor Service.exe
13.35.253.198:80
ocsp.rootg2.amazontrust.com
US
whitelisted
116
WinZip Smart Monitor Service.exe
143.204.208.127:80
o.ss2.us
US
malicious

DNS requests

Domain
IP
Reputation
download.winzipdriverupdater.com
  • 104.84.56.34
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
ssl.google-analytics.com
  • 216.58.207.72
whitelisted
ocsp.pki.goog
  • 172.217.23.99
whitelisted
updaterv.winzip.com
  • 34.207.20.230
  • 52.205.79.166
unknown
o.ss2.us
  • 143.204.208.127
  • 143.204.208.165
  • 143.204.208.79
  • 143.204.208.160
whitelisted
ocsp.rootg2.amazontrust.com
  • 13.35.253.198
  • 13.35.253.185
  • 13.35.253.148
  • 13.35.253.5
whitelisted
ocsp.rootca1.amazontrust.com
  • 13.35.253.5
  • 13.35.253.198
  • 13.35.253.185
  • 13.35.253.148
shared
ocsp.sca1b.amazontrust.com
  • 143.204.208.173
  • 143.204.208.79
  • 143.204.208.145
  • 143.204.208.150
whitelisted
goto.winzip.com
  • 34.231.69.13
  • 3.91.136.233
unknown

Threats

No threats detected
No debug info