File name:

myfile (2).exe

Full analysis: https://app.any.run/tasks/b8114f6f-04a5-49fd-96f3-3ce8742fdebc
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: November 25, 2019, 00:51:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

5ADCE8282F6C9FD837C1CFC5047A31B7

SHA1:

DC92A06AA067794266D63660B523E9864B2AEA52

SHA256:

4AD5640133B0DA9E2E5C5514C1AEF41DCEB4B10AA424AF6D734160D4B117D906

SSDEEP:

393216:aNFKK1NBfXG4pj++CL6DiTlQa+mGyzKbEVaZAAG:aNFKOVGKyL6eyauUraZBG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • myfile (2).exe (PID: 2124)
      • DriverTalent.exe (PID: 2548)
      • svchost.exe (PID: 2056)
      • rundll32.exe (PID: 3756)
      • DriverTalent.exe (PID: 1016)
    • Connects to CnC server

      • myfile (2).exe (PID: 2124)
    • Changes settings of System certificates

      • myfile (2).exe (PID: 2124)
      • DriverTalent.exe (PID: 2548)
    • Application was dropped or rewritten from another process

      • DriverTalent.exe (PID: 2548)
      • Upg.exe (PID: 2556)
      • DriverTalent.exe (PID: 1016)
    • Creates or modifies windows services

      • DriverTalent.exe (PID: 2548)
      • DriverTalent.exe (PID: 1016)
  • SUSPICIOUS

    • Adds / modifies Windows certificates

      • myfile (2).exe (PID: 2124)
      • DriverTalent.exe (PID: 2548)
    • Creates a software uninstall entry

      • myfile (2).exe (PID: 2124)
    • Changes IE settings (feature browser emulation)

      • DriverTalent.exe (PID: 2548)
    • Reads internet explorer settings

      • DriverTalent.exe (PID: 2548)
    • Uses RUNDLL32.EXE to load library

      • DriverTalent.exe (PID: 2548)
    • Starts Internet Explorer

      • myfile (2).exe (PID: 2124)
    • Executable content was dropped or overwritten

      • myfile (2).exe (PID: 2124)
      • Upg.exe (PID: 2556)
      • svchost.exe (PID: 2056)
    • Low-level read access rights to disk partition

      • DriverTalent.exe (PID: 2548)
    • Creates files in the program directory

      • DriverTalent.exe (PID: 2548)
      • Upg.exe (PID: 2556)
      • svchost.exe (PID: 2056)
      • myfile (2).exe (PID: 2124)
    • Reads Internet Cache Settings

      • DriverTalent.exe (PID: 2548)
    • Creates files in the user directory

      • DriverTalent.exe (PID: 2548)
    • Modifies the open verb of a shell class

      • DriverTalent.exe (PID: 2548)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • myfile (2).exe (PID: 2124)
      • Upg.exe (PID: 2556)
    • Changes internet zones settings

      • iexplore.exe (PID: 2284)
    • Reads settings of System Certificates

      • DriverTalent.exe (PID: 2548)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3352)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3352)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3352)
      • iexplore.exe (PID: 2284)
    • Creates files in the user directory

      • iexplore.exe (PID: 3352)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (43.7)
.exe | UPX compressed Win32 Executable (42.8)
.exe | Win32 Executable (generic) (7.1)
.exe | Generic Win/DOS Executable (3.1)
.exe | DOS Executable Generic (3.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:08:15 08:40:37+02:00
PEType: PE32
LinkerVersion: 11
CodeSize: 225280
InitializedDataSize: 12771328
UninitializedDataSize: 13119488
EntryPoint: 0xcba940
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 6.5.56.164
ProductVersionNumber: 6.5.56.164
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 6.5.56.164
ProductVersion: 6.5.56.164
ProductName: Driver Talent
FileDescription: Driver Talent Setup
CompanyName: OSToto Co., Ltd.
LegalCopyright: Copyright (C) 2008-2017 OSToto. All rights reserved.

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 15-Aug-2017 06:40:37
Detected languages:
  • Chinese - PRC
  • English - United States
FileVersion: 6.5.56.164
ProductVersion: 6.5.56.164
ProductName: Driver Talent
FileDescription: Driver Talent Setup
CompanyName: OSToto Co., Ltd.
LegalCopyright: Copyright (C) 2008-2017 OSToto. All rights reserved.

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000100

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 15-Aug-2017 06:40:37
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x00C83000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x00C84000
0x00037000
0x00036C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.92505
.rsrc
0x00CBB000
0x00C2E000
0x00C2DA00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.9926

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.31018
1010
Latin 1 / Western European
English - United States
RT_MANIFEST
2
4.26811
67624
Latin 1 / Western European
Chinese - PRC
RT_ICON
3
4.55703
38056
Latin 1 / Western European
Chinese - PRC
RT_ICON
4
4.5382
21640
Latin 1 / Western European
Chinese - PRC
RT_ICON
5
4.43243
16936
Latin 1 / Western European
Chinese - PRC
RT_ICON
6
4.71488
9640
Latin 1 / Western European
Chinese - PRC
RT_ICON
7
4.7171
4264
Latin 1 / Western European
Chinese - PRC
RT_ICON
8
4.97457
2440
Latin 1 / Western European
Chinese - PRC
RT_ICON
9
4.97408
1128
Latin 1 / Western European
Chinese - PRC
RT_ICON
128
3.01379
132
Latin 1 / Western European
Chinese - PRC
RT_GROUP_ICON

Imports

ADVAPI32.dll
KERNEL32.DLL
PSAPI.DLL
SHELL32.dll
SHLWAPI.dll
USER32.dll
VERSION.dll
ole32.dll
urlmon.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
9
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start myfile (2).exe drivertalent.exe iexplore.exe iexplore.exe svchost.exe upg.exe rundll32.exe no specs drivertalent.exe no specs myfile (2).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1016"c:\program files\ostotosoft\drivertalent\DriverTalent.exe" /update_start_to_servicec:\program files\ostotosoft\drivertalent\DriverTalent.exeUpg.exe
User:
admin
Company:
OSToto Co., Ltd.
Integrity Level:
HIGH
Description:
Driver Talent
Exit code:
0
Version:
6, 5, 56, 164
Modules
Images
c:\program files\ostotosoft\drivertalent\drivertalent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2056C:\Windows\System32\svchost.exe -k LocalDriverServiceC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\ostotosoft\drivertalent\ldrvsvc.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2124"C:\Users\admin\AppData\Local\Temp\myfile (2).exe" C:\Users\admin\AppData\Local\Temp\myfile (2).exe
explorer.exe
User:
admin
Company:
OSToto Co., Ltd.
Integrity Level:
HIGH
Description:
Driver Talent Setup
Exit code:
1
Version:
6.5.56.164
Modules
Images
c:\users\admin\appdata\local\temp\myfile (2).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2284"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
myfile (2).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2548"C:\Program Files\OSTotoSoft\DriverTalent\DriverTalent.exe" C:\Program Files\OSTotoSoft\DriverTalent\DriverTalent.exe
myfile (2).exe
User:
admin
Company:
OSToto Co., Ltd.
Integrity Level:
HIGH
Description:
Driver Talent
Exit code:
0
Version:
6, 5, 56, 164
Modules
Images
c:\program files\ostotosoft\drivertalent\drivertalent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2556"c:\program files\ostotosoft\drivertalent\updater\Upg.exe" "<update><sft>dtlabroad</sft><act>repair</act><arp><![CDATA[c:\program files\ostotosoft\drivertalent]]></arp><afn><![CDATA[DriverTalent.exe]]></afn><urp><![CDATA[c:\program files\ostotosoft\drivertalent\updater]]></urp><ucfn><![CDATA[update.xml]]></ucfn><hash>20a7929ee1aee5e737d642aba9943612</hash><url><![CDATA[http://dtlabroad.fileupdate.drivethelife.com/dtlabroad/UpdateCompress/20A7929EE1AEE5E737D642ABA9943612.7z]]></url><param><![CDATA[/update_start_to_service]]></param><pcid>984b5b092eba532d83d286ef2da80ff6</pcid><union>2548</union><ip>52.53.192.135</ip><port>4040</port><wndcls></wndcls><inservice>1</inservice><rafn>1</rafn></update>"c:\program files\ostotosoft\drivertalent\updater\Upg.exe
svchost.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
更新程序
Exit code:
0
Version:
1.0.1.39
Modules
Images
c:\program files\ostotosoft\drivertalent\updater\upg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3352"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2284 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3460"C:\Users\admin\AppData\Local\Temp\myfile (2).exe" C:\Users\admin\AppData\Local\Temp\myfile (2).exeexplorer.exe
User:
admin
Company:
OSToto Co., Ltd.
Integrity Level:
MEDIUM
Description:
Driver Talent Setup
Exit code:
3221226540
Version:
6.5.56.164
Modules
Images
c:\users\admin\appdata\local\temp\myfile (2).exe
c:\systemroot\system32\ntdll.dll
3756C:\Windows\system32\rundll32.exe "C:\Program Files\OSTotoSoft\DriverTalent\pcidetect.dll",HDRundllDetectC:\Windows\system32\rundll32.exeDriverTalent.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
806
Read events
630
Write events
174
Delete events
2

Modification events

(PID) Process:(2124) myfile (2).exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2124) myfile (2).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\myfile (2)_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2124) myfile (2).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\myfile (2)_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2124) myfile (2).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\myfile (2)_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2124) myfile (2).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\myfile (2)_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(2124) myfile (2).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\myfile (2)_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2124) myfile (2).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\myfile (2)_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2124) myfile (2).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\myfile (2)_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2124) myfile (2).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\myfile (2)_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2124) myfile (2).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\myfile (2)_RASMANCS
Operation:writeName:FileTracingMask
Value:
4294901760
Executable files
85
Suspicious files
29
Text files
282
Unknown types
21

Dropped files

PID
Process
Filename
Type
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\instlan\English.initext
MD5:
SHA256:
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\DTInstUI.dllexecutable
MD5:
SHA256:
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\softconfig.dllexecutable
MD5:
SHA256:
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\substat.dllexecutable
MD5:
SHA256:
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\2548_20191125005155.xmlbinary
MD5:
SHA256:
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\pcid.dllexecutable
MD5:
SHA256:
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\instlan\Armenian.initext
MD5:477E56882AF75A082F45CFB4E67BC834
SHA256:9C5B3CDD0CB9A66AF0836936304855B13F6DE2ECC6A3C244F579FD472BA69084
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\instlan\Japanese.initext
MD5:725D679274128A159D8E9A822837BD80
SHA256:8043E971886D9419D446981D81D5985907EDFA37F31EA908FEE94103A1E4704F
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\instlan\Polish.initext
MD5:D3A6D66B591B77EF3803F19BFE43357F
SHA256:FC7D4EC739D7DAC3DB77D8760FF3BE519ED4325F4712F37C967056ABCB5BC11C
2124myfile (2).exeC:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\instlan\Spanish.initext
MD5:5AA1FE95F88A79A5D2181855A9228033
SHA256:9542C5A7E26273AE8D78A61BCE81C911A859A87A78B9C125CFDD6E77F6F093E2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
50
DNS requests
25
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2548
DriverTalent.exe
GET
200
13.57.8.139:80
http://int.qudong.drivethelife.com/api/gamelist_component
US
text
33.6 Kb
suspicious
2548
DriverTalent.exe
GET
200
13.57.8.139:80
http://int.qudong.drivethelife.com/api/externalapp
US
xml
5.69 Kb
suspicious
2548
DriverTalent.exe
POST
200
106.52.82.175:80
http://int.updrv.com/feed/UpdrvFeedBack.aspx
CN
unknown
2556
Upg.exe
GET
200
209.58.131.165:80
http://dtlabroad.fileupdate.drivethelife.com/dtlabroad/UpdateCompress/931/7z.7z
US
compressed
325 Kb
malicious
2548
DriverTalent.exe
GET
200
13.57.8.139:80
http://int.qudong.drivethelife.com/uploadfile/20170831/Audio_Repair_2.png
US
image
5.12 Kb
suspicious
2548
DriverTalent.exe
GET
200
13.57.8.139:80
http://int.qudong.drivethelife.com/uploadfile/20170831/Audio_Repair_1.png
US
image
935 b
suspicious
2556
Upg.exe
GET
200
209.58.131.165:80
http://dtlabroad.fileupdate.drivethelife.com/dtlabroad/UpdateCompress/20A7929EE1AEE5E737D642ABA9943612.7z
US
compressed
8.01 Kb
malicious
2548
DriverTalent.exe
GET
200
13.57.8.139:80
http://int.qudong.drivethelife.com/uploadfile/20170831/WPS2.png
US
image
5.07 Kb
suspicious
2548
DriverTalent.exe
POST
200
106.52.82.175:80
http://dtlsearch.updrv.com/drvsearch.ashx
CN
binary
79 b
unknown
2548
DriverTalent.exe
POST
200
106.52.82.175:80
http://dtlsearch.updrv.com/drvsearch.ashx
CN
abr
15 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2548
DriverTalent.exe
209.58.131.173:3800
dispatch.integrate.drivethelife.com
Leaseweb USA, Inc.
US
unknown
2548
DriverTalent.exe
13.57.8.139:80
int.qudong.drivethelife.com
Amazon.com, Inc.
US
unknown
2056
svchost.exe
209.58.131.173:3800
dispatch.integrate.drivethelife.com
Leaseweb USA, Inc.
US
unknown
2056
svchost.exe
52.53.192.135:4040
int.softconfig.drivethelife.com
Amazon.com, Inc.
US
malicious
2556
Upg.exe
209.58.131.165:80
dtlabroad.fileupdate.drivethelife.com
Leaseweb USA, Inc.
US
suspicious
2284
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2124
myfile (2).exe
209.58.131.173:3800
dispatch.integrate.drivethelife.com
Leaseweb USA, Inc.
US
unknown
2124
myfile (2).exe
52.53.192.135:80
int.softconfig.drivethelife.com
Amazon.com, Inc.
US
malicious
3352
iexplore.exe
13.57.8.139:80
int.qudong.drivethelife.com
Amazon.com, Inc.
US
unknown
2548
DriverTalent.exe
52.53.192.135:4300
int.softconfig.drivethelife.com
Amazon.com, Inc.
US
malicious

DNS requests

Domain
IP
Reputation
int.softconfig.drivethelife.com
  • 52.53.192.135
malicious
dispatch.integrate.drivethelife.com
  • 209.58.131.173
unknown
online1.integrate.drivethelife.com
  • 209.58.131.173
unknown
behaviorgather.integrate.drivethelife.com
  • 209.58.131.173
malicious
install.integrate.drivethelife.com
  • 209.58.131.173
malicious
install.integrate.updrv.com
  • 49.235.202.167
unknown
int.qudong.drivethelife.com
  • 13.57.8.139
suspicious
dtlabroad.update.drivethelife.com
  • 52.53.192.135
malicious
www.drivethelife.com
  • 13.57.8.139
suspicious
www.ostoto.com
  • 13.57.8.139
unknown

Threats

PID
Process
Class
Message
2124
myfile (2).exe
A Network Trojan was detected
ADWARE [PTsecurity] Win32/Deceptor.DriverTalent.A Check-in
2124
myfile (2).exe
Misc activity
ADWARE [PTsecurity] Win32/Deceptor.DriverTalent.A Response
Process
Message
myfile (2).exe
hwang Create Directory C:\Users\admin\AppData\Local\Temp\HotC7AF.tmp!
myfile (2).exe
hwang UnCompress EXT to C:\Users\admin\AppData\Local\Temp\HotC7AF.tmp .
myfile (2).exe
hwang UnCompress successful.
myfile (2).exe
hwang Create Directory C:\Program Files\OSTotoSoft\DriverTalent!
myfile (2).exe
hwang UnCompress DATA to C:\Program Files\OSTotoSoft\DriverTalent .
myfile (2).exe
hwang UnCompress successful.
myfile (2).exe
hwang Copy C:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\DTInstUI.dll to C:\Program Files\OSTotoSoft\DriverTalent !
myfile (2).exe
hwang Copy C:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\substat.dll to C:\Program Files\OSTotoSoft\DriverTalent !
myfile (2).exe
hwang Copy C:\Users\admin\AppData\Local\Temp\HotC7AF.tmp\pcid.dll to C:\Program Files\OSTotoSoft\DriverTalent !
myfile (2).exe
hwang DeleteSubKey SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29FE44D7-BC89-4188-8B0E-F6BA073C15A5}_is1 failed, errcode: 2