| File name: | Driver Easy Pro 5.8.1.41398 Portable - HaxPC.net.rar |
| Full analysis: | https://app.any.run/tasks/38a9a94c-5d70-4d4a-9ebf-9e9b6378e70b |
| Verdict: | Malicious activity |
| Analysis date: | March 23, 2024, 13:22:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 89C2B3C33F08F985A0ACA3CF0F6717D6 |
| SHA1: | C8D0F31ED3DAF8635AECB273571E333558AE7373 |
| SHA256: | 69CAFF89BF71E9DFCA61BD741BA7B302EF1BB261270A42B81DF2703A9FC9D280 |
| SSDEEP: | 98304:+aJOQNibHAi4+bMxoeb4NKz/0HQmLfnq8eRZjvDavO9KagfukIR8h9po9wEcF29h:YKPvD3AlXop |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 712 | C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1592 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{555adf97-88e1-19fe-4d43-641ec59daa3d}\e1g6032.inf" "0" "6efe00be3" "0000060C" "WinSta0\Default" "0000062C" "208" "c:\users\admin\appdata\local\temp\prowin7_32\prowin7_32" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1656 | C:\Users\admin\Desktop\App\DriverEasy\DriverEasy.exe | C:\Users\admin\Desktop\App\DriverEasy\DriverEasy.exe | DriverEasyPortable.exe | ||||||||||||
User: admin Company: Easeware Integrity Level: HIGH Description: DriverEasy Version: 5.8.1 Modules
| |||||||||||||||
| 1928 | "C:\Users\admin\Desktop\DriverEasyPortable.exe" | C:\Users\admin\Desktop\DriverEasyPortable.exe | explorer.exe | ||||||||||||
User: admin Company: downtopc.com Integrity Level: HIGH Description: DriverEasy Portable Launcher Version: 2.2.1.1 Modules
| |||||||||||||||
| 2096 | DrvInst.exe "2" "211" "PCI\VEN_8086&DEV_2934&SUBSYS_11001AF4&REV_03\3&13C0B0C5&0&20" "C:\Windows\INF\oem2.inf" "ich9usb.inf:INTEL.NT.5.1:Intel_OHCI.Dev.NT.Services:9.1.9.1006:pci\ven_8086&dev_2934" "6ba1a1a37" "00000550" "000005EC" "000005F0" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2120 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Driver Easy Pro 5.8.1.41398 Portable - HaxPC.net.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 2268 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2880 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2956 | DrvInst.exe "2" "211" "PCI\VEN_8086&DEV_100E&SUBSYS_11001AF4&REV_03\3&13C0B0C5&0&18" "C:\Windows\INF\oem4.inf" "e1g6032.inf:Intel.NTx86.6.0.1:E100E:8.3.15.0:pci\ven_8086&dev_100e" "6efe00be3" "0000060C" "000005EC" "00000300" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3088 | DrvInst.exe "2" "211" "PCI\VEN_8086&DEV_2935&SUBSYS_11001AF4&REV_03\3&13C0B0C5&0&21" "C:\Windows\INF\oem2.inf" "ich9usb.inf:INTEL.NT.5.1:Intel_OHCI.Dev.NT.Services:9.1.9.1006:pci\ven_8086&dev_2935" "6415d1aa7" "00000550" "000005F0" "000005EC" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Driver Easy Pro 5.8.1.41398 Portable - HaxPC.net.rar | |||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\DriverEasyPortable.exe | executable | |
MD5:807321B12FC37504D70E11185F880970 | SHA256:7CEA2674D295A17C2AABA8042BA14459EEB09FD161E93807184BA6958BF468DC | |||
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\appicon.ico | image | |
MD5:01BA073479ACD1317FDA6A56E81BD2A2 | SHA256:9BED06583CBF0254821161D26D68AC8943FC8456D74B60977E4DE8D066B76D63 | |||
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\appicon_256.png | image | |
MD5:AAC0500FD2C2811D9F0AAB65DFEA8F20 | SHA256:75E7BE552E63CCAD820295E31C27045D7D6EA496E5FCC0CAE0F51560DFE42AC5 | |||
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\Launcher\Custom.nsh | text | |
MD5:91089853B38AF3F28DBFE8AE4B608F7D | SHA256:665B4FFA10FBF5AEDBA58D38A34BFAF9E5EC9961C5DE7B3447A705E57C8E3523 | |||
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\DriverEasy\Easeware.ConfigLanguageFromSetup.exe.config | xml | |
MD5:357195CEB812BEB8702453E21728D0B1 | SHA256:12A8B7A1E3FD311CA61042456F20CBB3EF06CABC113C6308C4EDED25B449085C | |||
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\DefaultData\license.dat | xml | |
MD5:0854AA82716F42D0847FDC3BF204C9A2 | SHA256:A2B658A30A1A8594DB620E80DECC8237E24AFA09F1D45289F77F170C16923969 | |||
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\appicon_32.png | image | |
MD5:F4372D544BA6F4FA4CEF9D2EF5E38E05 | SHA256:CA9DD0AD4CD3195076EA350165CA39C85DB43B49B812E2C6940FB51F5C62CF3B | |||
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\Launcher\DriverEasyPortable.ini | ini | |
MD5:6B657766851CF72808568243B7350673 | SHA256:EF0C4F3FBA4589CA29475474E6224513BA777A21DB3C4C834625E199A58B59D5 | |||
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\DriverEasy\7z\7z.dll | executable | |
MD5:C8EBD08661F8DC6A31DBA48E24D009BA | SHA256:21E6A4D99D0CABD9AAC0713E334520BE8304C1D3C2BD10F1AD2B5D4256AD688E | |||
| 2120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\DriverEasy\DriverEasy.exe | executable | |
MD5:63438907638E855C4206211DC598A7C0 | SHA256:34DF3FF60F527BF05FA1D926917890001C9318DE97628F4A3935145400417A2E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1656 | DriverEasy.exe | GET | 200 | 2.19.126.163:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?239a80fe3a94dd28 | unknown | compressed | 67.5 Kb | unknown |
1656 | DriverEasy.exe | GET | 200 | 2.19.126.163:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?53c50ebd11a047c3 | unknown | compressed | 67.5 Kb | unknown |
1656 | DriverEasy.exe | GET | 200 | 2.19.126.163:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?41244c754090c3c6 | unknown | compressed | 67.5 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1656 | DriverEasy.exe | 51.38.74.198:443 | www.drivereasy.com | OVH SAS | FR | unknown |
1656 | DriverEasy.exe | 167.114.130.158:443 | ann.drivereasy.com | OVH SAS | US | unknown |
1656 | DriverEasy.exe | 2.19.126.163:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1656 | DriverEasy.exe | 52.116.161.7:443 | download.drivereasy.com | SOFTLAYER | US | unknown |
1656 | DriverEasy.exe | 142.44.218.29:443 | app1.drivereasy.com | OVH SAS | CA | unknown |
1656 | DriverEasy.exe | 141.94.197.25:443 | dow1.drivereasy.com | OVH SAS | FR | unknown |
Domain | IP | Reputation |
|---|---|---|
www.drivereasy.com |
| unknown |
ann.drivereasy.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
download.drivereasy.com |
| unknown |
app1.drivereasy.com |
| unknown |
dow1.drivereasy.com |
| unknown |