| File name: | Setup_DriverDoc_2024.exe |
| Full analysis: | https://app.any.run/tasks/ef208bd7-19c0-4663-af90-7cdb2cb5c97b |
| Verdict: | Malicious activity |
| Analysis date: | February 13, 2024, 15:00:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | DC46C709B10BF7BCAC28DD7E80A94091 |
| SHA1: | 7240476F0E1A1FDC1555E220BFE557D92078E2CE |
| SHA256: | 02C87A31BEE95E1CF1AA35B0064D7128CFDD2C685590742C20D5DFEEC12252FE |
| SSDEEP: | 98304:V+cD4dnXhgSK4XTxn25JWKDGF0DrCbcTXjw2pFFiVzLQYc79ZJoSSjEakdj8z7h5:94SqqlKFzL |
| .exe | | | Inno Setup installer (65.1) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (24.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.9) |
| .exe | | | Win32 Executable (generic) (2.6) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 65536 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 7.1.1120.0 |
| ProductVersionNumber: | 7.1.1120.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Solvusoft Corporation |
| FileDescription: | DriverDoc |
| FileVersion: | 7.1.1120.0 |
| LegalCopyright: | Solvusoft Corporation |
| OriginalFileName: | |
| ProductName: | DriverDoc |
| ProductVersion: | 7.1.1120.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3936 --field-trial-handle=1256,i,17854254035947162849,2776040940534439474,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 268 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1240 --field-trial-handle=1256,i,17854254035947162849,2776040940534439474,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 392 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2300 --field-trial-handle=1256,i,17854254035947162849,2776040940534439474,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 664 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1424 --field-trial-handle=1292,i,2583941077074434431,14607286515567245854,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 752 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1540 --field-trial-handle=1256,i,17854254035947162849,2776040940534439474,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 840 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.solvusoft.com/en/driverdoc/install/ | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | DriverDoc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1020 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xe8,0x69c3f598,0x69c3f5a8,0x69c3f5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1092 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3884 --field-trial-handle=1256,i,17854254035947162849,2776040940534439474,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1348 | "C:\Windows\System32\taskkill.exe" /f /im "DOCTray.exe" | C:\Windows\System32\taskkill.exe | — | Setup_DriverDoc_2024.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1492 | "C:\Users\admin\AppData\Local\Temp\is-2PIPS.tmp\Setup_DriverDoc_2024.tmp" /SL5="$100130,5549910,808448,C:\Users\admin\AppData\Local\Temp\Setup_DriverDoc_2024.exe" /SPAWNWND=$16013E /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-2PIPS.tmp\Setup_DriverDoc_2024.tmp | Setup_DriverDoc_2024.exe | ||||||||||||
User: admin Company: Solvusoft Corporation Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: D4050000843C05778D5EDA01 | |||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 47995A7FF14B421F5FCAE249A2A9C2C0D10323FEC3B89A5DF9AE8FD8A4A7790C | |||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (1492) Setup_DriverDoc_2024.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1876 | Setup_DriverDoc_2024.exe | C:\Users\admin\AppData\Local\Temp\is-2PIPS.tmp\Setup_DriverDoc_2024.tmp | executable | |
MD5:10769B81758F0DA3AE536DD80F68859B | SHA256:8163ED7F98F3D07EF9BD9BF25B530BDE0C834B9645BDD394F57A3F74397BB6B4 | |||
| 1492 | Setup_DriverDoc_2024.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 1492 | Setup_DriverDoc_2024.tmp | C:\Users\admin\AppData\Local\Temp\CabFF7E.tmp | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 1492 | Setup_DriverDoc_2024.tmp | C:\Users\admin\AppData\Local\Temp\TarFF7F.tmp | cat | |
MD5:9C0C641C06238516F27941AA1166D427 | SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F | |||
| 1492 | Setup_DriverDoc_2024.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751 | der | |
MD5:822467B728B7A66B081C91795373789A | SHA256:AF2343382B88335EEA72251AD84949E244FF54B6995063E24459A7216E9576B9 | |||
| 1492 | Setup_DriverDoc_2024.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:A9F75B7323CB26A2FB7EDC2DC95AA8CA | SHA256:C649564EDDA7D3F3BAF1A1DABC72E927C72BEB11FF27DED9DFA4CE7BB32541E5 | |||
| 4052 | Setup_DriverDoc_2024.exe | C:\Users\admin\AppData\Local\Temp\is-L19UL.tmp\Setup_DriverDoc_2024.tmp | executable | |
MD5:10769B81758F0DA3AE536DD80F68859B | SHA256:8163ED7F98F3D07EF9BD9BF25B530BDE0C834B9645BDD394F57A3F74397BB6B4 | |||
| 1492 | Setup_DriverDoc_2024.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:DAF53BE293C5846C318525DF1823884A | SHA256:EFC60219B4C45C50A3106955A789AC3F72E7D18F36312FBE5AE62C9A2E1BDEDF | |||
| 1492 | Setup_DriverDoc_2024.tmp | C:\Program Files\DriverDoc\Extra\DriverPro.exe | executable | |
MD5:2ADA6D412A93CFABDCB01E2C1AD1E7B4 | SHA256:D88006D7B0B3C8D23CEC28C1A18EA53932B8782311B89B971CDE6EF974486DBA | |||
| 1492 | Setup_DriverDoc_2024.tmp | C:\Program Files\DriverDoc\is-3J9LS.tmp | executable | |
MD5:C36B429C5D3EA4EF2492287B068213B4 | SHA256:07959A6C60EF0B3E61A79D70E53D579647E0FA4628A83CE3078BD205F27530E5 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1492 | Setup_DriverDoc_2024.tmp | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?04b2dea8abd60a79 | unknown | — | — | unknown |
1492 | Setup_DriverDoc_2024.tmp | GET | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgSTs65R6WLLVADp%2F5w5792ryA%3D%3D | unknown | binary | 503 b | unknown |
1492 | Setup_DriverDoc_2024.tmp | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?1d85e727c79ce7e5 | unknown | compressed | 65.2 Kb | unknown |
1492 | Setup_DriverDoc_2024.tmp | GET | 200 | 2.23.197.184:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
1492 | Setup_DriverDoc_2024.tmp | GET | 200 | 34.243.112.164:80 | http://smart-pc.avanquest.com/check.php?partner=DriverDoc&type=driver&build=7.1.1120 | unknown | text | 5 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1492 | Setup_DriverDoc_2024.tmp | 94.130.13.99:443 | service.smartpcupdate.com | Hetzner Online GmbH | DE | unknown |
1492 | Setup_DriverDoc_2024.tmp | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
1492 | Setup_DriverDoc_2024.tmp | 2.23.197.184:80 | x1.c.lencr.org | CW Vodafone Group PLC | GB | unknown |
1492 | Setup_DriverDoc_2024.tmp | 2.16.202.121:80 | r3.o.lencr.org | Akamai International B.V. | NL | unknown |
1492 | Setup_DriverDoc_2024.tmp | 34.243.112.164:80 | smart-pc.avanquest.com | AMAZON-02 | IE | unknown |
3680 | DriverDoc.exe | 142.132.139.157:443 | receiver.smartpcupdate.com | Hetzner Online GmbH | DE | unknown |
2108 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
service.smartpcupdate.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |
smart-pc.avanquest.com |
| unknown |
receiver.smartpcupdate.com |
| whitelisted |
www.solvusoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3680 | DriverDoc.exe | Misc activity | ET INFO Observed ZeroSSL SSL/TLS Certificate |
752 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code.jquery .com) |