Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | July 3, 2024, 9:32 a.m. | July 3, 2024, 9:35 a.m. |
-
-
Installer.exe "C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\Installer.exe" /spid:3060 /splha:8005536
1188-
ServiceHelper.Agent.exe "C:\Program Files (x86)\Outbyte\Driver Updater\ServiceHelper.Agent.exe" /install /silent
2116 -
DriverUpdater.exe "C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" /Install /AutoStart /CreateOSSnapshot
2904 -
sc.exe sc start OutbyteDUHelper
3156 -
DriverUpdater.exe "C:\Program Files (x86)\Outbyte\Driver Updater\DriverUpdater.exe" /AutoScan /FromInstaller
3280
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
Name | Response | Post-Analysis Lookup |
---|---|---|
www.google-analytics.com | 142.250.206.206 | |
outbyte.com | 45.33.97.245 | |
ssl.outbyte.com | 45.33.97.245 | |
api.outbyte.com | 192.155.86.205 | |
du.outbyte.com | 51.81.185.149 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49164 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49167 142.250.207.78:443 |
C=US, O=Google Trust Services, CN=WR2 | CN=*.google-analytics.com | ba:5d:a9:7f:41:46:b0:37:01:9e:05:b0:92:ba:41:c9:31:5b:4b:4a |
TLSv1 192.168.56.102:49165 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49166 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49226 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49237 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49192 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49227 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49257 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49163 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49240 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49254 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49253 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49282 45.33.97.245:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | CN=*.outbyte.com | d0:6e:29:18:9d:1c:99:37:a3:15:37:81:63:0c:69:08:8a:6c:31:4f |
TLSv1 192.168.56.102:49233 142.250.207.78:443 |
C=US, O=Google Trust Services, CN=WR2 | CN=*.google-analytics.com | ba:5d:a9:7f:41:46:b0:37:01:9e:05:b0:92:ba:41:c9:31:5b:4b:4a |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\MachineGuid |
file | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
file | C:\Program Files\Mozilla Firefox\firefox.exe |
section | .itext |
section | .didata |
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST https://www.google-analytics.com/mp/collect?measurement_id=G-SEW4YMR3XJ&api_secret=Bwp8gLa9SqG7iUYK8RMmcg |
request | POST https://www.google-analytics.com/mp/collect?measurement_id=G-SEW4YMR3XJ&api_secret=Bwp8gLa9SqG7iUYK8RMmcg |
request | POST https://www.google-analytics.com/mp/collect?measurement_id=G-SEW4YMR3XJ&api_secret=Bwp8gLa9SqG7iUYK8RMmcg |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\History |
file | C:\Users\test22\AppData\Local\Yandex\YandexBrowser\Application\browser.exe |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\CommonForms.Site.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\BrowserHelper.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\GoogleAnalyticsHelper.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\Downloader.exe |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\__setup\islzma.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\GoogleAnalyticsHelperIV.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\Localizer.dll |
file | C:\Users\test22\Desktop\Driver Updater.lnk |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\CFAHelper.dll |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outbyte\Driver Updater\Outbyte Driver Updater Uninstall.lnk |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\SetupHelper.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\InstallerUtils.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\Installer.exe |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\DriverUpdater.exe |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outbyte\Driver Updater\Outbyte Driver Updater.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outbyte\Driver Updater\Outbyte Driver Updater.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outbyte\Driver Updater\Outbyte Driver Updater Uninstall.lnk |
file | C:\Users\test22\Desktop\Driver Updater.lnk |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\CFAHelper.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\GoogleAnalyticsHelperIV.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\__setup\islzma.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\vclie250.bpl |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\Installer.exe |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\CommonForms.Site.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\Downloader.exe |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\SetupHelper.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\vcl250.bpl |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\Localizer.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\GoogleAnalyticsHelper.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\vclimg250.bpl |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\AxComponentsVCL.bpl |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\InstallerUtils.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\rtl250.bpl |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\OxComponentsRTL.bpl |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\AxComponentsRTL.bpl |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\BrowserHelper.dll |
file | C:\Users\test22\AppData\Local\Temp\is-27611082.tmp\DriverUpdater.exe |
wmi | select * from Win32_PnPEntity where (ClassGuid = "{5175d334-c371-4806-b3ba-71fd53c9258d}") |
wmi | SELECT Name, Description, DeviceID, Manufacturer, Family, Level, Stepping, Version, Revision, SocketDesignation, OtherFamilyDescription, ProcessorType, NumberOfCores, NumberOfLogicalProcessors, Architecture, AddressWidth, DataWidth, MaxClockSpeed, VoltageCaps, ProcessorId, UniqueId, Role, CurrentClockSpeed, ExtClock, CurrentVoltage, CpuStatus, Status FROM Win32_Processor |
wmi | select ChassisTypes from Win32_SystemEnclosure |
wmi | select Model, PNPDeviceID, InterfaceType from Win32_DiskDrive where Index = 0 |
ESET-NOD32 | a variant of Generik.IXKVLWK potentially unwanted |
DrWeb | Program.Unwanted.5457 |
Malwarebytes | PUP.Optional.Outbyte |
CrowdStrike | win/grayware_confidence_90% (D) |
cmdline | sc start OutbyteDUHelper |
wmi | SELECT Name, Description, DeviceID, Manufacturer, Family, Level, Stepping, Version, Revision, SocketDesignation, OtherFamilyDescription, ProcessorType, NumberOfCores, NumberOfLogicalProcessors, Architecture, AddressWidth, DataWidth, MaxClockSpeed, VoltageCaps, ProcessorId, UniqueId, Role, CurrentClockSpeed, ExtClock, CurrentVoltage, CpuStatus, Status FROM Win32_Processor |
wmi | select Model, PNPDeviceID, InterfaceType from Win32_DiskDrive where Index = 0 |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion |
service_name | OutbyteDUHelper | service_path | C:\Windows\System32\"C:\Program Files (x86)\Outbyte\Driver Updater\ServiceHelper.Agent.exe" |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92C1588E85AF2201CE7915E8538B492F605B80C6\Blob |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\60EE3FC53D4BDFD1697AE5BEAE1CAB1C0F3AD4E3\Blob |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob |
mutex | 8D622ABC-7F4F-49CF-A95A-86F8A21753BA_local_outbyte_driver updater_driverupdater |
mutex | INSTALLER_8D622ABC-7F4F-49CF-A95A-86F8A21753BA_local_outbyte_driver updater_installer |
mutex | INSTALLER_8D622ABC-7F4F-49CF-A95A-86F8A21753BA_global_outbyte_driver updater |
mutex | {08586C4E-62C4-4a4e-8271-C2A20530AF62}_M_S-1-5-21-3832866432-4053218753-3017428901-1001 |
mutex | {B38B494B-46F8-4765-8D92-31B8F10D8FD3}_SETUP |
mutex | {C48CB245-2929-4724-9EEC-3BCCB48C78DE}-{42EDCAAA-67F6-42D0-A9C3-4291C4042352}-Protection |
mutex | Global\PML_Factory{440657CF-E3B8-421C-997A-4C9C9D9D4A42}_Mutex_4 |
mutex | Global\PML_Factory{1337A543-0E3F-4433-9C4D-CC6DAEE73E90}_Mutex_4 |
mutex | 8D622ABC-7F4F-49CF-A95A-86F8A21753BA_global_outbyte_driver updater |
udp | {u'src': u'192.168.56.102', u'dst': u'239.255.255.250', u'offset': 6615284, u'time': 5.470577001571655, u'dport': 3702, u'sport': 49152} |
udp | {u'src': u'192.168.56.102', u'dst': u'239.255.255.250', u'offset': 6623660, u'time': 61.76822090148926, u'dport': 1900, u'sport': 62849} |