URL:

https://jp.drvhub.net/devices/network/intel/usb-3-0-extensible-host-controller-1/download

Full analysis: https://app.any.run/tasks/8b70b10d-4d99-4758-a433-788169f7a8c5
Verdict: Malicious activity
Analysis date: February 02, 2024, 00:07:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

C52B34399FB4358AEBD0BF1229BF5C10

SHA1:

1AB2BC0EB53175287C06EF5AC98EE4C56B354B1C

SHA256:

0C0006BDA081D1592920BA3A2603B972A2C071308AD1C9E7957987C2E50286E2

SSDEEP:

3:N8xmoFTgZ0SjmJKWRuWmJQRagUXz:2xmoFTc0SmAJQRY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • driver-hub-install__28.exe (PID: 4012)
  • SUSPICIOUS

    • Reads the Internet Settings

      • driver-hub-install__28.exe (PID: 3884)
      • driver-hub-install__28.exe (PID: 4012)
    • Reads Internet Explorer settings

      • driver-hub-install__28.exe (PID: 3884)
      • driver-hub-install__28.exe (PID: 4012)
    • Reads Microsoft Outlook installation path

      • driver-hub-install__28.exe (PID: 3884)
      • driver-hub-install__28.exe (PID: 4012)
    • Application launched itself

      • driver-hub-install__28.exe (PID: 3884)
    • Executable content was dropped or overwritten

      • driver-hub-install__28.exe (PID: 4012)
    • Process drops legitimate windows executable

      • driver-hub-install__28.exe (PID: 4012)
    • Reads settings of System Certificates

      • driver-hub-install__28.exe (PID: 4012)
    • Adds/modifies Windows certificates

      • driver-hub-install__28.exe (PID: 4012)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1392)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2416)
      • iexplore.exe (PID: 1392)
    • Checks supported languages

      • driver-hub-install__28.exe (PID: 3884)
      • driver-hub-install__28.exe (PID: 4012)
    • Reads the computer name

      • driver-hub-install__28.exe (PID: 3884)
      • driver-hub-install__28.exe (PID: 4012)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 1392)
      • iexplore.exe (PID: 2416)
    • The process uses the downloaded file

      • iexplore.exe (PID: 1392)
    • Reads the machine GUID from the registry

      • driver-hub-install__28.exe (PID: 3884)
      • driver-hub-install__28.exe (PID: 4012)
    • Checks proxy server information

      • driver-hub-install__28.exe (PID: 3884)
      • driver-hub-install__28.exe (PID: 4012)
    • Process checks whether UAC notifications are on

      • driver-hub-install__28.exe (PID: 4012)
    • Creates files in the program directory

      • driver-hub-install__28.exe (PID: 4012)
    • Creates files or folders in the user directory

      • driver-hub-install__28.exe (PID: 4012)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe driver-hub-install__28.exe no specs driver-hub-install__28.exe

Process information

PID
CMD
Path
Indicators
Parent process
1392"C:\Program Files\Internet Explorer\iexplore.exe" "https://jp.drvhub.net/devices/network/intel/usb-3-0-extensible-host-controller-1/download"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2416"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1392 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3884"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\driver-hub-install__28.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\driver-hub-install__28.exeiexplore.exe
User:
admin
Company:
ROSTPAY LTD.
Integrity Level:
MEDIUM
Description:
Install DriverHub
Exit code:
0
Version:
3.4.1
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\driver-hub-install__28.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4012"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\driver-hub-install__28.exe" /screen=proc /pos=240,46 /lang=enC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\driver-hub-install__28.exe
driver-hub-install__28.exe
User:
admin
Company:
ROSTPAY LTD.
Integrity Level:
HIGH
Description:
Install DriverHub
Exit code:
0
Version:
3.4.1
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\driver-hub-install__28.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
27 993
Read events
27 842
Write events
143
Delete events
8

Modification events

(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
43
Suspicious files
70
Text files
591
Unknown types
0

Dropped files

PID
Process
Filename
Type
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:B438FE1050A430886CE0FB610A260B35
SHA256:84D99C4181A31FEB5FCEC7523F56DB82BC66B0844D253649B4AB973070B74B88
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:9024E5302DA9F95FE7A8CB2A9A4969B1
SHA256:F1F82B07E4B0C69D1E818C8DD1CA2C08762E6C3AC3ECFA7F4A2C4327CB4DA063
2416iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZQPS0YVW.txttext
MD5:2146CF2679F68239E0DE40E96EDCE0D0
SHA256:0E97BDDA231C2740C92B81E933EEA7F2FE2E04ABB8EF08C127849375AB280484
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:60FE01DF86BE2E5331B0CDBE86165686
SHA256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
2416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\logo-mod[1].svgimage
MD5:1199FC218D48A8AA09A90B48B2513642
SHA256:5A2F4B78B2EA6F1F933317868DDE4470A562EC42FC297FEEF2849D5DA3CB0C25
2416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\manifest[1].jstext
MD5:5DECAAA64F07C18E51BF42630DB5A594
SHA256:394958ED50AAA762B38AEC94855F7F94F6B9D191CBF283BF7278F3733AADBDB7
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\26DF8C0D1C43A276268AA575925267F4binary
MD5:1D9B40E95053B97CF71C6FDE6D4C02FD
SHA256:EDA7B216696DD54B547CADDE2207B4FC0EBFA2A1554A826EA8066021C732B4D8
2416iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar3732.tmpbinary
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
2416iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab3731.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
63
DNS requests
30
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2416
iexplore.exe
GET
304
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d7a4c83e7f191cf0
unknown
unknown
2416
iexplore.exe
GET
304
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f324de6a56943962
unknown
unknown
2416
iexplore.exe
GET
200
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?5da2680ebcdcdef2
unknown
compressed
65.2 Kb
unknown
2416
iexplore.exe
GET
200
173.222.108.226:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?48d4a7991bcbd006
unknown
compressed
65.2 Kb
unknown
2416
iexplore.exe
GET
200
2.19.105.18:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2416
iexplore.exe
GET
200
95.101.54.114:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgR%2FvyiDg0G65bijhTOMwZPa6Q%3D%3D
unknown
binary
503 b
unknown
2416
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2416
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
2416
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2416
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEE80yiW5Mf2wCipGbb3nZn0%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2416
iexplore.exe
188.130.153.32:443
jp.drvhub.net
Rostpay Ltd
RU
unknown
2416
iexplore.exe
173.222.108.226:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2416
iexplore.exe
2.19.105.18:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
2416
iexplore.exe
95.101.54.114:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
2416
iexplore.exe
142.250.186.136:443
www.googletagmanager.com
GOOGLE
US
unknown
2416
iexplore.exe
104.16.87.20:443
cdn.jsdelivr.net
CLOUDFLARENET
shared
2416
iexplore.exe
142.250.186.35:80
ocsp.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
jp.drvhub.net
  • 188.130.153.32
  • 188.130.153.33
unknown
ctldl.windowsupdate.com
  • 173.222.108.226
  • 173.222.108.210
whitelisted
x1.c.lencr.org
  • 2.19.105.18
whitelisted
r3.o.lencr.org
  • 95.101.54.114
  • 95.101.54.131
shared
cdn.jsdelivr.net
  • 104.16.87.20
  • 104.16.86.20
  • 104.16.88.20
  • 104.16.89.20
  • 104.16.85.20
whitelisted
www.googletagmanager.com
  • 142.250.186.136
whitelisted
ocsp.pki.goog
  • 142.250.186.35
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
use.fontawesome.com
  • 172.64.207.38
  • 172.64.206.38
whitelisted
mc.yandex.ru
  • 77.88.21.119
  • 87.250.251.119
  • 93.158.134.119
  • 87.250.250.119
whitelisted

Threats

PID
Process
Class
Message
2416
iexplore.exe
Not Suspicious Traffic
INFO [ANY.RUN] A free CDN for open source projects (jsdelivr .net)
2416
iexplore.exe
Not Suspicious Traffic
INFO [ANY.RUN] A free CDN for open source projects (jsdelivr .net)
No debug info