drghelpergrp.exe

Beijing Caiyunshidai Technology Co., Ltd.

The application drghelpergrp.exe by Beijing Caiyunshidai Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a windows Service named “Drogoghtsocerse Helper”. While running, it connects to the Internet address server-54-192-159-94.sin3.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:

MD5:
a00ddf9f05b634737c6cfc842620a26e

SHA-1:
d0d64affa85b118ad6e766567fbdea84dc62b750

SHA-256:
9cb93d2cd40e44a783c01ae35a9619eecfef5b9c30928857efcc58c4a5d981e9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 5:17:29 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.ELEX.SpeedSearch (M)
16.9.7.3

File size:
461.1 KB (472,160 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\zemudomkgerpy\drghelpergrp.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
9/2/2016 2:00:00 AM

Valid to:
3/4/2017 1:59:59 AM

Subject:
CN="Beijing Caiyunshidai Technology Co., Ltd.", O="Beijing Caiyunshidai Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
59A2827FE485DDD96ACAAC98C78869D5

File PE Metadata
Compilation timestamp:
9/7/2016 3:24:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:quLnbuHkrRee3EZYYpPWrDRqDGJ1ETO0/aTIaR6w2weetlHF3/7lSK9yDUztJ:qux/3EKYpPeA6JqO0SfVll359yIztJ

Entry address:
0x3E772

Entry point:
E8, 5B, 69, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C...
 
[+]

Entropy:
6.5227

Code size:
360 KB (368,640 bytes)

Service
Display name:
Drogoghtsocerse Helper

Service name:
DrgHelperGrp.exe

Description:
Provides global functions for other parts of Drogoghtsocerse.

Type:
Win32OwnProcess, InteractiveProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-52-85-77-226.lax3.r.cloudfront.net  (52.85.77.226:80)

TCP (HTTP):
Connects to server-52-85-83-135.lax1.r.cloudfront.net  (52.85.83.135:80)

TCP (HTTP):
Connects to server-54-192-19-81.iad12.r.cloudfront.net  (54.192.19.81:80)

TCP (HTTP):
Connects to server-54-230-95-36.fra2.r.cloudfront.net  (54.230.95.36:80)

TCP (HTTP):
Connects to server-54-230-149-244.sin2.r.cloudfront.net  (54.230.149.244:80)

TCP (HTTP):
Connects to server-52-85-83-25.lax1.r.cloudfront.net  (52.85.83.25:80)

TCP (HTTP):
Connects to server-54-192-19-20.iad12.r.cloudfront.net  (54.192.19.20:80)

TCP (HTTP):
Connects to server-54-192-159-156.sin3.r.cloudfront.net  (54.192.159.156:80)

TCP (HTTP):
Connects to server-54-230-206-134.atl50.r.cloudfront.net  (54.230.206.134:80)

TCP (HTTP):
Connects to server-54-230-206-108.atl50.r.cloudfront.net  (54.230.206.108:80)

TCP (HTTP):
Connects to server-54-192-19-137.iad12.r.cloudfront.net  (54.192.19.137:80)

TCP (HTTP):
Connects to server-54-192-159-182.sin3.r.cloudfront.net  (54.192.159.182:80)

TCP (HTTP):
Connects to server-52-85-83-234.lax1.r.cloudfront.net  (52.85.83.234:80)

TCP (HTTP):
Connects to server-54-192-19-111.iad12.r.cloudfront.net  (54.192.19.111:80)

TCP (HTTP):
Connects to server-52-85-77-32.lax3.r.cloudfront.net  (52.85.77.32:80)

TCP (HTTP):
Connects to server-54-230-216-86.mrs50.r.cloudfront.net  (54.230.216.86:80)

TCP (HTTP):
Connects to server-54-230-206-228.atl50.r.cloudfront.net  (54.230.206.228:80)

TCP (HTTP):
Connects to server-54-192-230-193.waw50.r.cloudfront.net  (54.192.230.193:80)

TCP (HTTP):
Connects to server-54-192-159-237.sin3.r.cloudfront.net  (54.192.159.237:80)

TCP (HTTP):
Connects to server-54-192-159-234.sin3.r.cloudfront.net  (54.192.159.234:80)

Remove drghelpergrp.exe - Powered by Reason Core Security