| URL: | http://dl.driverpack.io/soft/Internet-Start.exe |
| Full analysis: | https://app.any.run/tasks/cb615050-d6d9-47ff-bfc1-cd4b491172f3 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | September 05, 2023, 06:56:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 67EB2319461E331A256B4628CB665615 |
| SHA1: | D58E1DDB80A203BB33CB4252D80B383B45DC3838 |
| SHA256: | 2175F555B342DF493A376B0A02EA379424EE639F1A7B504473AE302D7B08BB01 |
| SSDEEP: | 3:N1KaJdSAXJOL+Ft894An:CaJdSAQqFq/n |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 476 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 540 | "C:\Users\admin\Downloads\Internet-Start.exe" | C:\Users\admin\Downloads\Internet-Start.exe | — | firefox.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2008 | "C:\Users\admin\Downloads\Internet-Start.exe" | C:\Users\admin\Downloads\Internet-Start.exe | firefox.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3000.1.1199340298\1393247047" -parentBuildID 20230710165010 -prefsHandle 1404 -prefMapHandle 1400 -prefsLen 28102 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {12548625-fe25-48e9-bf4d-5b79c3a2ae6e} 3000 "\\.\pipe\gecko-crash-server-pipe.3000" 1416 dc27db0 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2388 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3488 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2420 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Internet-Start.exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Internet-Start.exe | iexplore.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2432 | "C:\Users\admin\Downloads\Internet-Start.exe" | C:\Users\admin\Downloads\Internet-Start.exe | — | firefox.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2472 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3000.5.676161049\931555677" -childID 4 -isForBrowser -prefsHandle 3884 -prefMapHandle 3876 -prefsLen 29110 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {788dd751-9ba7-48e6-9141-8227b046d584} 3000 "\\.\pipe\gecko-crash-server-pipe.3000" 3860 187e99b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2580 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3000.6.62697542\1676433591" -childID 5 -isForBrowser -prefsHandle 3832 -prefMapHandle 3864 -prefsLen 29110 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2ca9dde3-8b8f-4c10-ab87-10fe27147fee} 3000 "\\.\pipe\gecko-crash-server-pipe.3000" 3952 187e9b20 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2660 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3000.0.477574675\334825774" -parentBuildID 20230710165010 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 28025 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c1d7a585-5ff3-4a66-95ff-a2229332a3e1} 3000 "\\.\pipe\gecko-crash-server-pipe.3000" 1180 dce21b0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3488) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3488 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF663B923FCC3D68EA.TMP | gmc | |
MD5:7362BD84D810EE0601E526AD84AEA0B5 | SHA256:D516E4DBBAFD5C7BE0DC2FCC8D769EB6E4FBD03BC6D0D465CF4BB73631AEF4E4 | |||
| 3488 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFC100302B3048F10A.TMP | binary | |
MD5:EF979796EF4947E3E43C82BE2956A89E | SHA256:E5BD93315F69A06A68F792C461FA0B7634B9F9AB085DCCAAC8725A4301F6585C | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Internet-Start.exe.jbwbr16.partial | executable | |
MD5:26AA60AC5D241CB2119D344943B79BC9 | SHA256:F09AAD6A646DD4EBCA7AB20C117B20F86DFFD6A4B0472C2466E3771616E2D7DC | |||
| 2420 | Internet-Start.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet-Start.lnk | lnk | |
MD5:165C53F7E8CB33B8A4BB8F04DEC8BB03 | SHA256:A0B168791AD535FF9AC76186C8609AEFA4E7EC9C540AF5CD005A46F74E01960D | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\Internet-Start[1].exe | executable | |
MD5:4474EF97E8E2AC33C0C0FBE5A05E8B13 | SHA256:797EB4B2F1741D12A9AA24527626BE79BFFE0B07EEEEF0C26B4423C35F046DB1 | |||
| 3488 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{50D5EB79-4BB9-11EE-ACBF-12A9866C77DE}.dat | binary | |
MD5:6B3A7800EBA39AD798AD84958301DE10 | SHA256:B79346B1847B54EE724F550608397AD0DC61A513DD0EA209000EC59AF072CF53 | |||
| 3488 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\favicon[1].ico | image | |
MD5:DA597791BE3B6E732F0BC8B20E38EE62 | SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07 | |||
| 3488 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:6D381166C4C1E017443C8013BCCA1707 | SHA256:632D5528F2BE597D5DC9EB4AD4A5222314AA1E9D01997F09433C7B3B2EB8E601 | |||
| 3000 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 3488 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Internet-Start.exe | executable | |
MD5:26AA60AC5D241CB2119D344943B79BC9 | SHA256:F09AAD6A646DD4EBCA7AB20C117B20F86DFFD6A4B0472C2466E3771616E2D7DC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2388 | iexplore.exe | GET | 200 | 87.117.239.150:80 | http://dl.driverpack.io/soft/Internet-Start.exe | unknown | executable | 99.4 Kb | suspicious |
3000 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
3000 | firefox.exe | GET | 200 | 87.117.239.150:80 | http://dl.driverpack.io/soft/Internet-Start.exe | unknown | executable | 99.4 Kb | suspicious |
3000 | firefox.exe | POST | 200 | 95.101.54.131:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
3000 | firefox.exe | POST | 200 | 95.101.54.131:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
3000 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
3000 | firefox.exe | POST | 200 | 95.101.54.131:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
3000 | firefox.exe | POST | 200 | 95.101.54.131:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
3000 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
3488 | iexplore.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b5f2963c2eba25ec | unknown | compressed | 4.66 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2388 | iexplore.exe | 87.117.239.150:80 | dl.driverpack.io | Iomart Cloud Services Limited | GB | suspicious |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3284 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3488 | iexplore.exe | 2.23.209.149:443 | www.bing.com | Akamai International B.V. | GB | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3488 | iexplore.exe | 2.23.209.148:443 | www.bing.com | Akamai International B.V. | GB | unknown |
3488 | iexplore.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | STACKPATH-CDN | US | whitelisted |
3488 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3488 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | EDGECAST | US | whitelisted |
3000 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
dl.driverpack.io |
| suspicious |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
dns.msftncsi.com |
| shared |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2388 | iexplore.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1088 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .su TLD (Soviet Union) Often Malware Related |
1088 | svchost.exe | Possibly Unwanted Program Detected | ET ADWARE_PUP DriverPack Domain in DNS Query |
1088 | svchost.exe | Possibly Unwanted Program Detected | ET ADWARE_PUP Observed DNS Query to DriverPack Domain ( .drp .su) |
1088 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .su TLD (Soviet Union) Often Malware Related |
1088 | svchost.exe | Possibly Unwanted Program Detected | ET ADWARE_PUP DriverPack Domain in DNS Query |
1088 | svchost.exe | Possibly Unwanted Program Detected | ET ADWARE_PUP Observed DNS Query to DriverPack Domain ( .drp .su) |
3000 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |