URL:

http://dl.driverpack.io/soft/Internet-Start.exe

Full analysis: https://app.any.run/tasks/cb615050-d6d9-47ff-bfc1-cd4b491172f3
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: September 05, 2023, 06:56:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

67EB2319461E331A256B4628CB665615

SHA1:

D58E1DDB80A203BB33CB4252D80B383B45DC3838

SHA256:

2175F555B342DF493A376B0A02EA379424EE639F1A7B504473AE302D7B08BB01

SSDEEP:

3:N1KaJdSAXJOL+Ft894An:CaJdSAQqFq/n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Internet-Start.exe (PID: 3988)
      • Internet-Start.exe (PID: 2420)
      • Internet-Start.exe (PID: 2008)
      • Internet-Start.exe (PID: 540)
      • Internet-Start.exe (PID: 2432)
      • Internet-Start.exe (PID: 3720)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Internet-Start.exe (PID: 2420)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3488)
      • firefox.exe (PID: 476)
      • firefox.exe (PID: 3000)
    • Create files in a temporary directory

      • Internet-Start.exe (PID: 2420)
      • Internet-Start.exe (PID: 2008)
      • Internet-Start.exe (PID: 3720)
    • Reads the computer name

      • Internet-Start.exe (PID: 2420)
      • Internet-Start.exe (PID: 2008)
      • Internet-Start.exe (PID: 3720)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3488)
      • firefox.exe (PID: 3000)
    • Checks supported languages

      • Internet-Start.exe (PID: 2420)
      • Internet-Start.exe (PID: 2008)
      • Internet-Start.exe (PID: 3720)
    • Manual execution by a user

      • firefox.exe (PID: 476)
    • Creates files or folders in the user directory

      • Internet-Start.exe (PID: 2420)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 3000)
      • iexplore.exe (PID: 3488)
      • iexplore.exe (PID: 2388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
17
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe internet-start.exe no specs internet-start.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs internet-start.exe no specs internet-start.exe internet-start.exe no specs internet-start.exe

Process information

PID
CMD
Path
Indicators
Parent process
476"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
540"C:\Users\admin\Downloads\Internet-Start.exe" C:\Users\admin\Downloads\Internet-Start.exefirefox.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\internet-start.exe
c:\windows\system32\ntdll.dll
2008"C:\Users\admin\Downloads\Internet-Start.exe" C:\Users\admin\Downloads\Internet-Start.exe
firefox.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\internet-start.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
2028"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3000.1.1199340298\1393247047" -parentBuildID 20230710165010 -prefsHandle 1404 -prefMapHandle 1400 -prefsLen 28102 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {12548625-fe25-48e9-bf4d-5b79c3a2ae6e} 3000 "\\.\pipe\gecko-crash-server-pipe.3000" 1416 dc27db0 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
2388"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3488 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2420"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Internet-Start.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Internet-Start.exe
iexplore.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\internet-start.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
2432"C:\Users\admin\Downloads\Internet-Start.exe" C:\Users\admin\Downloads\Internet-Start.exefirefox.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\internet-start.exe
c:\windows\system32\ntdll.dll
2472"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3000.5.676161049\931555677" -childID 4 -isForBrowser -prefsHandle 3884 -prefMapHandle 3876 -prefsLen 29110 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {788dd751-9ba7-48e6-9141-8227b046d584} 3000 "\\.\pipe\gecko-crash-server-pipe.3000" 3860 187e99b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
2580"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3000.6.62697542\1676433591" -childID 5 -isForBrowser -prefsHandle 3832 -prefMapHandle 3864 -prefsLen 29110 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2ca9dde3-8b8f-4c10-ab87-10fe27147fee} 3000 "\\.\pipe\gecko-crash-server-pipe.3000" 3952 187e9b20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
2660"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3000.0.477574675\334825774" -parentBuildID 20230710165010 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 28025 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c1d7a585-5ff3-4a66-95ff-a2229332a3e1} 3000 "\\.\pipe\gecko-crash-server-pipe.3000" 1180 dce21b0 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
Total events
18 976
Read events
18 825
Write events
150
Delete events
1

Modification events

(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3488) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
11
Suspicious files
127
Text files
51
Unknown types
1

Dropped files

PID
Process
Filename
Type
3488iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF663B923FCC3D68EA.TMPgmc
MD5:7362BD84D810EE0601E526AD84AEA0B5
SHA256:D516E4DBBAFD5C7BE0DC2FCC8D769EB6E4FBD03BC6D0D465CF4BB73631AEF4E4
3488iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFC100302B3048F10A.TMPbinary
MD5:EF979796EF4947E3E43C82BE2956A89E
SHA256:E5BD93315F69A06A68F792C461FA0B7634B9F9AB085DCCAAC8725A4301F6585C
2388iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Internet-Start.exe.jbwbr16.partialexecutable
MD5:26AA60AC5D241CB2119D344943B79BC9
SHA256:F09AAD6A646DD4EBCA7AB20C117B20F86DFFD6A4B0472C2466E3771616E2D7DC
2420Internet-Start.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet-Start.lnklnk
MD5:165C53F7E8CB33B8A4BB8F04DEC8BB03
SHA256:A0B168791AD535FF9AC76186C8609AEFA4E7EC9C540AF5CD005A46F74E01960D
2388iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\Internet-Start[1].exeexecutable
MD5:4474EF97E8E2AC33C0C0FBE5A05E8B13
SHA256:797EB4B2F1741D12A9AA24527626BE79BFFE0B07EEEEF0C26B4423C35F046DB1
3488iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{50D5EB79-4BB9-11EE-ACBF-12A9866C77DE}.datbinary
MD5:6B3A7800EBA39AD798AD84958301DE10
SHA256:B79346B1847B54EE724F550608397AD0DC61A513DD0EA209000EC59AF072CF53
3488iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
3488iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:6D381166C4C1E017443C8013BCCA1707
SHA256:632D5528F2BE597D5DC9EB4AD4A5222314AA1E9D01997F09433C7B3B2EB8E601
3000firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
3488iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Internet-Start.exeexecutable
MD5:26AA60AC5D241CB2119D344943B79BC9
SHA256:F09AAD6A646DD4EBCA7AB20C117B20F86DFFD6A4B0472C2466E3771616E2D7DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
95
DNS requests
144
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2388
iexplore.exe
GET
200
87.117.239.150:80
http://dl.driverpack.io/soft/Internet-Start.exe
unknown
executable
99.4 Kb
suspicious
3000
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
3000
firefox.exe
GET
200
87.117.239.150:80
http://dl.driverpack.io/soft/Internet-Start.exe
unknown
executable
99.4 Kb
suspicious
3000
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
3000
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
3000
firefox.exe
POST
200
184.24.77.52:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
3000
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
3000
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
3000
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
3488
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b5f2963c2eba25ec
unknown
compressed
4.66 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2388
iexplore.exe
87.117.239.150:80
dl.driverpack.io
Iomart Cloud Services Limited
GB
suspicious
4
System
192.168.100.255:137
whitelisted
3284
svchost.exe
239.255.255.250:1900
whitelisted
3488
iexplore.exe
2.23.209.149:443
www.bing.com
Akamai International B.V.
GB
unknown
4
System
192.168.100.255:138
whitelisted
3488
iexplore.exe
2.23.209.148:443
www.bing.com
Akamai International B.V.
GB
unknown
3488
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
whitelisted
3488
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3488
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
3000
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
dl.driverpack.io
  • 87.117.231.157
  • 87.117.239.150
  • 87.117.239.151
  • 81.94.192.167
suspicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.23.209.193
  • 2.23.209.177
  • 2.23.209.149
  • 2.23.209.148
  • 2.23.209.140
  • 2.23.209.176
  • 2.23.209.133
  • 2.23.209.150
  • 2.23.209.158
  • 204.79.197.200
  • 13.107.21.200
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted

Threats

PID
Process
Class
Message
2388
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1088
svchost.exe
Potentially Bad Traffic
ET DNS Query for .su TLD (Soviet Union) Often Malware Related
1088
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP DriverPack Domain in DNS Query
1088
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to DriverPack Domain ( .drp .su)
1088
svchost.exe
Potentially Bad Traffic
ET DNS Query for .su TLD (Soviet Union) Often Malware Related
1088
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP DriverPack Domain in DNS Query
1088
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to DriverPack Domain ( .drp .su)
3000
firefox.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info