wzdrvupdt3.exe

WinZip Driver Updater

WinZip Computing

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from dl.cleverbridge.com and multiple other hosts.
Publisher:
WinZip Computing, S.L. (WinZip Computing)   (signed by WinZip Computing)

Product:
WinZip Driver Updater

Version:
WinZip Driver Update

MD5:
c004c5bd7680f732f10f94b32c36ae5d

SHA-1:
4b4cd04bbc20f715ccd8ed1da6f29774b6235e74

SHA-256:
792e12de703860bc7317c7a3fdcdf5a7c0aa02b2e781e4c4fc15c45f8a3cc4cf

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 3:21:18 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Program.Raxco.4
9.0.1.0225

File size:
3.4 MB (3,573,000 bytes)

Product version:
1.0.648.15141

Copyright:
© WinZip Computing, S.L. (WinZip Computing)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\outlook.com - aronaboy19@live.com_files\wzdrvupdt3.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/16/2012 12:00:00 AM

Valid to:
4/14/2014 12:59:59 AM

Subject:
CN=WinZip Computing, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WinZip Computing, L=Mansfield, S=Connecticut, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E4842AC9691630B45F8266C0ADB1206

File PE Metadata
Compilation timestamp:
7/9/2012 2:41:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:v/ht043I8aNNxyb3aktoadPnu7uKUZX8VtR0OU0NkMtcX7+u19yL5wVenHbunQA0:H8448aJy6ao0mBNkAtu19vVAk6T

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B8, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 56, EC, FF, FF, E8, FD, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, E8, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, D6, 41, 00, B2, 01...
 
[+]

Entropy:
7.9820

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file wzdrvupdt3.exe has been seen being distributed by the following 18 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to st.openinstall.com  (184.168.221.46:80)

TCP (HTTP):
Connects to oi.cloud.avg.com  (204.193.144.33:80)

TCP (HTTP):
Connects to inst.avg.com  (204.193.144.89:80)

Scan wzdrvupdt3.exe - Powered by Reason Core Security