File name:

AESHEADL82223_2023-11-29_10_43_44.704.zip

Full analysis: https://app.any.run/tasks/46cc22fc-d58a-45be-8637-0ab9dd588715
Verdict: Malicious activity
Analysis date: November 29, 2023, 10:56:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract
MD5:

4E09400731978B95B8404889AA5DCF97

SHA1:

D874DA30B5F5E259ED9605CC5D8988036057A5FD

SHA256:

CBFCF418A35BF421844119F9285E6928A5782C6F5BF0EA6B3893DA546DCD694C

SSDEEP:

6144:cOxJg4aH8wd/T5ZEqLPchT3uq8KY3lEnjtEDE3kEdcaXAE:cOvazd/T57Lchiq8KcEnjiDofdTXAE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
    • Reads the Internet Settings

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
      • AppHelper.exe (PID: 1984)
    • Checks Windows Trust Settings

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
    • Reads security settings of Internet Explorer

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
    • Reads settings of System Certificates

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
    • Starts application with an unusual extension

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2708)
    • Reads the computer name

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
      • wmpnscfg.exe (PID: 824)
      • AppHelper.exe (PID: 1984)
    • Checks supported languages

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
      • wmpnscfg.exe (PID: 824)
      • ns9B4B.tmp (PID: 2760)
      • AppHelper.exe (PID: 1984)
    • Create files in a temporary directory

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
    • Checks proxy server information

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
    • Creates files or folders in the user directory

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
    • Reads the machine GUID from the registry

      • SF-Helper-[af1c3268e6084f7b#300#].exe (PID: 3376)
      • wmpnscfg.exe (PID: 824)
      • AppHelper.exe (PID: 1984)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 824)
    • Application launched itself

      • chrome.exe (PID: 3940)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0xc76d6863
ZipCompressedSize: 190763
ZipUncompressedSize: 300920
ZipFileName: Device/HarddiskVolume3/Users/82223/Downloads/SF-Helper-[af1c3268e6084f7b#300#].exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
24
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs sf-helper-[af1c3268e6084f7b#300#].exe wmpnscfg.exe no specs ns9b4b.tmp no specs apphelper.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
824"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
1208"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --mojo-platform-channel-handle=3748 --field-trial-handle=1172,i,10721797007652552220,17455909759186219652,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1984"C:\Users\admin\AppData\Local\Programs\AppHelper\Bin\AppHelper.exe" install sf_helper_chromeC:\Users\admin\AppData\Local\Programs\AppHelper\Bin\AppHelper.exens9B4B.tmp
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\programs\apphelper\bin\apphelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2444"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1476 --field-trial-handle=1172,i,10721797007652552220,17455909759186219652,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2524"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3752 --field-trial-handle=1172,i,10721797007652552220,17455909759186219652,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2708"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AESHEADL82223_2023-11-29_10_43_44.704.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2760"C:\Users\admin\AppData\Local\Temp\nsc24A7.tmp\ns9B4B.tmp" "C:\Users\admin\AppData\Local\Programs\AppHelper\Bin\AppHelper.exe" install sf_helper_chromeC:\Users\admin\AppData\Local\Temp\nsc24A7.tmp\ns9B4B.tmpSF-Helper-[af1c3268e6084f7b#300#].exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsc24a7.tmp\ns9b4b.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2928"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3292 --field-trial-handle=1172,i,10721797007652552220,17455909759186219652,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3088"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3568 --field-trial-handle=1172,i,10721797007652552220,17455909759186219652,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3132"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3732 --field-trial-handle=1172,i,10721797007652552220,17455909759186219652,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
8 159
Read events
8 074
Write events
80
Delete events
5

Modification events

(PID) Process:(2708) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2708) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2708) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2708) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2708) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2708) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2708) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2708) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2708) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2708) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
12
Suspicious files
66
Text files
46
Unknown types
0

Dropped files

PID
Process
Filename
Type
2708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2708.40284\manifest.jsontext
MD5:53456230EDD1DE357F65F91F4DE61145
SHA256:AB04EC8D02934F959CD5FE5A7F37B24F923342C6C669B2F7C88E515DE2DA8EB2
3376SF-Helper-[af1c3268e6084f7b#300#].exeC:\Users\admin\AppData\Local\Temp\nsl3922.tmpimage
MD5:28D6814F309EA289F847C69CF91194C6
SHA256:8337212354871836E6763A41E615916C89BAC5B3F1F0ADF60BA43C7C806E1015
3376SF-Helper-[af1c3268e6084f7b#300#].exeC:\Users\admin\AppData\Local\Temp\nsa3893.tmpimage
MD5:28D6814F309EA289F847C69CF91194C6
SHA256:8337212354871836E6763A41E615916C89BAC5B3F1F0ADF60BA43C7C806E1015
3376SF-Helper-[af1c3268e6084f7b#300#].exeC:\Users\admin\AppData\Local\Programs\AppHelper\Tools\sf-helper-default\sf-helper-default-installer.logtext
MD5:D56EF4A64544C61F975026B4C320F192
SHA256:3BD994DA5A3A4AEC818C86478D41AAB350B13CE9F0CC1526AC28DB55BFD1537B
3376SF-Helper-[af1c3268e6084f7b#300#].exeC:\Users\admin\AppData\Local\Programs\AppHelper\Tools\sf-helper-default\sf-helper-default-uninstaller.initext
MD5:B0F4E21A21492ED19A0DE5763CB86C36
SHA256:B39E2485BAB0A4B61590E969C438916B77F72ED03BA9F9B8A09A6B61CB7F54B6
3376SF-Helper-[af1c3268e6084f7b#300#].exeC:\Users\admin\AppData\Local\Temp\nss2556.tmpimage
MD5:28D6814F309EA289F847C69CF91194C6
SHA256:8337212354871836E6763A41E615916C89BAC5B3F1F0ADF60BA43C7C806E1015
3376SF-Helper-[af1c3268e6084f7b#300#].exeC:\Users\admin\AppData\Local\Temp\nsc24A7.tmp\modern-wizard.bmpimage
MD5:B389AA47CDF437B61A8DB884F3FE7E0D
SHA256:513B1DBB2AC822CFF2A2A8B8A017849D4DAB7D7AA2AE09322605AA30BA1D861F
3376SF-Helper-[af1c3268e6084f7b#300#].exeC:\Users\admin\AppData\Local\Temp\nss24B8.tmpimage
MD5:28D6814F309EA289F847C69CF91194C6
SHA256:8337212354871836E6763A41E615916C89BAC5B3F1F0ADF60BA43C7C806E1015
3376SF-Helper-[af1c3268e6084f7b#300#].exeC:\Users\admin\AppData\Local\Temp\nsc2545.tmpimage
MD5:28D6814F309EA289F847C69CF91194C6
SHA256:8337212354871836E6763A41E615916C89BAC5B3F1F0ADF60BA43C7C806E1015
3376SF-Helper-[af1c3268e6084f7b#300#].exeC:\Users\admin\AppData\Local\Temp\nsd2596.tmpimage
MD5:28D6814F309EA289F847C69CF91194C6
SHA256:8337212354871836E6763A41E615916C89BAC5B3F1F0ADF60BA43C7C806E1015
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
58
DNS requests
56
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
172.217.18.4:80
http://google-analytics.com/collect?v=1&an=helper_clear&av=1.7.0.1&tid=UA-181312972-6&cid=af1c3268e6084f7b&cd1=sf-helper-default-installer&cd2=2023-06-08-0932&cd3=no&t=event&ec=browsers&ea=none&el=edge&aiid=300&ua=Mozilla%2F5%2E0%20%28Windows%20NT%206%2E1%3B%20en-US%29&ul=en-US
unknown
image
35 b
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
172.217.18.4:80
http://google-analytics.com/collect?v=1&an=helper_clear&av=1.7.0.1&tid=UA-181312972-6&cid=af1c3268e6084f7b&cd1=sf-helper-default-installer&cd2=2023-06-08-0932&cd3=no&t=event&ec=browsers&ea=none&el=opera&aiid=300&ua=Mozilla%2F5%2E0%20%28Windows%20NT%206%2E1%3B%20en-US%29&ul=en-US
unknown
image
35 b
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
172.217.18.4:80
http://google-analytics.com/collect?v=1&an=helper_clear&av=1.7.0.1&tid=UA-181312972-6&cid=af1c3268e6084f7b&cd1=sf-helper-default-installer&cd2=2023-06-08-0932&cd3=no&t=event&ec=browsers&ea=none&el=yawser&aiid=300&ua=Mozilla%2F5%2E0%20%28Windows%20NT%206%2E1%3B%20en-US%29&ul=en-US
unknown
image
35 b
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
172.217.18.4:80
http://google-analytics.com/collect?v=1&an=helper_clear&av=1.7.0.1&tid=UA-181312972-6&cid=af1c3268e6084f7b&cd1=sf-helper-default-installer&cd2=2023-06-08-0932&cd3=no&t=screenview&cd=license&aiid=300&ua=Mozilla%2F5%2E0%20%28Windows%20NT%206%2E1%3B%20en-US%29
unknown
image
35 b
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
172.217.18.4:80
http://google-analytics.com/collect?v=1&an=helper_clear&av=1.7.0.1&tid=UA-181312972-6&cid=af1c3268e6084f7b&cd1=sf-helper-default-installer&cd2=2023-06-08-0932&cd3=no&t=screenview&cd=install&aiid=300&ua=Mozilla%2F5%2E0%20%28Windows%20NT%206%2E1%3B%20en-US%29
unknown
image
35 b
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
172.217.18.4:80
http://google-analytics.com/collect?v=1&an=helper_clear&av=1.7.0.1&tid=UA-181312972-6&cid=af1c3268e6084f7b&cd1=sf-helper-default-installer&cd2=2023-06-08-0932&cd3=no&t=screenview&cd=option&aiid=300&ua=Mozilla%2F5%2E0%20%28Windows%20NT%206%2E1%3B%20en-US%29
unknown
image
35 b
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
172.217.18.4:80
http://google-analytics.com/collect?v=1&an=helper_clear&av=1.7.0.1&tid=UA-181312972-6&cid=af1c3268e6084f7b&cd1=sf-helper-default-installer&cd2=2023-06-08-0932&cd3=no&t=event&ec=browsers&ea=yes&el=chrome&aiid=300&ua=Mozilla%2F5%2E0%20%28Windows%20NT%206%2E1%3B%20en-US%29&ul=en-US
unknown
image
35 b
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
172.217.18.4:80
http://google-analytics.com/collect?v=1&an=helper_clear&av=1.7.0.1&tid=UA-181312972-6&cid=af1c3268e6084f7b&cd1=sf-helper-default-installer&cd2=2023-06-08-0932&cd3=no&t=event&ec=browsers&ea=yes&el=firefox&aiid=300&ua=Mozilla%2F5%2E0%20%28Windows%20NT%206%2E1%3B%20en-US%29&ul=en-US
unknown
image
35 b
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
172.217.18.4:80
http://google-analytics.com/collect?v=1&an=helper_clear&av=1.7.0.1&tid=UA-181312972-6&cid=af1c3268e6084f7b&cd1=sf-helper-default-installer&cd2=2023-06-08-0932&cd3=no&t=event&ec=browsers&ea=yes&el=all&aiid=300&ua=Mozilla%2F5%2E0%20%28Windows%20NT%206%2E1%3B%20en-US%29&ul=en-US
unknown
image
35 b
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
172.217.18.4:80
google-analytics.com
GOOGLE
US
whitelisted
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
188.114.96.3:443
apphelper.pro
CLOUDFLARENET
NL
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
188.114.97.3:443
apphelper.pro
CLOUDFLARENET
NL
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
8.248.149.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3376
SF-Helper-[af1c3268e6084f7b#300#].exe
142.250.185.163:80
ocsp.pki.goog
GOOGLE
US
whitelisted
1080
svchost.exe
8.248.149.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown

DNS requests

Domain
IP
Reputation
google-analytics.com
  • 172.217.18.4
whitelisted
apphelper.pro
  • 188.114.96.3
  • 188.114.97.3
unknown
ctldl.windowsupdate.com
  • 8.248.149.254
  • 8.241.123.126
  • 8.241.122.126
  • 8.238.189.126
  • 67.27.235.126
whitelisted
ocsp.pki.goog
  • 142.250.185.163
whitelisted
clientservices.googleapis.com
  • 142.250.185.67
whitelisted
savefrom.net
  • 104.22.41.216
  • 172.67.43.182
  • 104.22.40.216
whitelisted
accounts.google.com
  • 172.217.16.205
shared
en.savefrom.net
  • 104.22.40.216
  • 104.22.41.216
  • 172.67.43.182
unknown
safebrowsing.googleapis.com
  • 142.250.185.106
whitelisted
sfstatic.net
  • 104.26.7.99
  • 104.26.6.99
  • 172.67.68.85
unknown

Threats

No threats detected
No debug info