File name:

Driver Easy Pro 5.8.1.41398 Portable - HaxPC.net.rar

Full analysis: https://app.any.run/tasks/38a9a94c-5d70-4d4a-9ebf-9e9b6378e70b
Verdict: Malicious activity
Analysis date: March 23, 2024, 13:22:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

89C2B3C33F08F985A0ACA3CF0F6717D6

SHA1:

C8D0F31ED3DAF8635AECB273571E333558AE7373

SHA256:

69CAFF89BF71E9DFCA61BD741BA7B302EF1BB261270A42B81DF2703A9FC9D280

SSDEEP:

98304:+aJOQNibHAi4+bMxoeb4NKz/0HQmLfnq8eRZjvDavO9KagfukIR8h9po9wEcF29h:YKPvD3AlXop

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2120)
      • DriverEasy.exe (PID: 1656)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 2956)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 3540)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 2956)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • WinRAR.exe (PID: 2120)
    • Reads the Internet Settings

      • DriverEasy.exe (PID: 1656)
    • Reads settings of System Certificates

      • DriverEasy.exe (PID: 1656)
    • Adds/modifies Windows certificates

      • DriverEasy.exe (PID: 1656)
    • Reads security settings of Internet Explorer

      • DriverEasy.exe (PID: 1656)
    • Checks Windows Trust Settings

      • DriverEasy.exe (PID: 1656)
      • drvinst.exe (PID: 3540)
      • drvinst.exe (PID: 3556)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 2956)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3540)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 2956)
    • Executable content was dropped or overwritten

      • DriverEasy.exe (PID: 1656)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 2956)
    • Drops a system driver (possible attempt to evade defenses)

      • DriverEasy.exe (PID: 1656)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 2956)
    • Creates file in the systems drive root

      • drvinst.exe (PID: 2956)
      • DriverEasy.exe (PID: 1656)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 2956)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2120)
    • Reads the computer name

      • DriverEasyPortable.exe (PID: 1928)
      • DriverEasy.exe (PID: 1656)
      • drvinst.exe (PID: 3540)
      • drvinst.exe (PID: 2096)
      • drvinst.exe (PID: 3088)
      • drvinst.exe (PID: 3616)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 2956)
      • drvinst.exe (PID: 3556)
      • wmpnscfg.exe (PID: 2268)
      • wmpnscfg.exe (PID: 2880)
    • Manual execution by a user

      • DriverEasyPortable.exe (PID: 1928)
      • DriverEasyPortable.exe (PID: 4044)
      • wmpnscfg.exe (PID: 2268)
      • wmpnscfg.exe (PID: 2880)
    • Checks supported languages

      • DriverEasyPortable.exe (PID: 1928)
      • DriverEasy.exe (PID: 1656)
      • drvinst.exe (PID: 3540)
      • drvinst.exe (PID: 2096)
      • drvinst.exe (PID: 3088)
      • drvinst.exe (PID: 3616)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 2956)
      • drvinst.exe (PID: 3556)
      • wmpnscfg.exe (PID: 2268)
      • wmpnscfg.exe (PID: 2880)
    • Creates files or folders in the user directory

      • DriverEasyPortable.exe (PID: 1928)
      • DriverEasy.exe (PID: 1656)
    • Reads the machine GUID from the registry

      • DriverEasyPortable.exe (PID: 1928)
      • DriverEasy.exe (PID: 1656)
      • drvinst.exe (PID: 3540)
      • drvinst.exe (PID: 3088)
      • drvinst.exe (PID: 2096)
      • drvinst.exe (PID: 3616)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 3556)
      • drvinst.exe (PID: 2956)
    • Reads Environment values

      • DriverEasy.exe (PID: 1656)
    • Reads the software policy settings

      • DriverEasy.exe (PID: 1656)
      • drvinst.exe (PID: 3540)
      • drvinst.exe (PID: 1592)
      • drvinst.exe (PID: 3556)
      • drvinst.exe (PID: 2956)
    • Create files in a temporary directory

      • DriverEasy.exe (PID: 1656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
14
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe drivereasyportable.exe no specs drivereasyportable.exe drivereasy.exe drvinst.exe no specs drvinst.exe no specs rundll32.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe drvinst.exe wmpnscfg.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
712C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1592DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{555adf97-88e1-19fe-4d43-641ec59daa3d}\e1g6032.inf" "0" "6efe00be3" "0000060C" "WinSta0\Default" "0000062C" "208" "c:\users\admin\appdata\local\temp\prowin7_32\prowin7_32"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1656C:\Users\admin\Desktop\App\DriverEasy\DriverEasy.exeC:\Users\admin\Desktop\App\DriverEasy\DriverEasy.exe
DriverEasyPortable.exe
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
DriverEasy
Version:
5.8.1
Modules
Images
c:\users\admin\desktop\app\drivereasy\drivereasy.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1928"C:\Users\admin\Desktop\DriverEasyPortable.exe" C:\Users\admin\Desktop\DriverEasyPortable.exe
explorer.exe
User:
admin
Company:
downtopc.com
Integrity Level:
HIGH
Description:
DriverEasy Portable Launcher
Version:
2.2.1.1
Modules
Images
c:\users\admin\desktop\drivereasyportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2096DrvInst.exe "2" "211" "PCI\VEN_8086&DEV_2934&SUBSYS_11001AF4&REV_03\3&13C0B0C5&0&20" "C:\Windows\INF\oem2.inf" "ich9usb.inf:INTEL.NT.5.1:Intel_OHCI.Dev.NT.Services:9.1.9.1006:pci\ven_8086&dev_2934" "6ba1a1a37" "00000550" "000005EC" "000005F0"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2120"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Driver Easy Pro 5.8.1.41398 Portable - HaxPC.net.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2268"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2880"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2956DrvInst.exe "2" "211" "PCI\VEN_8086&DEV_100E&SUBSYS_11001AF4&REV_03\3&13C0B0C5&0&18" "C:\Windows\INF\oem4.inf" "e1g6032.inf:Intel.NTx86.6.0.1:E100E:8.3.15.0:pci\ven_8086&dev_100e" "6efe00be3" "0000060C" "000005EC" "00000300"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3088DrvInst.exe "2" "211" "PCI\VEN_8086&DEV_2935&SUBSYS_11001AF4&REV_03\3&13C0B0C5&0&21" "C:\Windows\INF\oem2.inf" "ich9usb.inf:INTEL.NT.5.1:Intel_OHCI.Dev.NT.Services:9.1.9.1006:pci\ven_8086&dev_2935" "6415d1aa7" "00000550" "000005F0" "000005EC"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
44 023
Read events
43 148
Write events
741
Delete events
134

Modification events

(PID) Process:(2120) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2120) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2120) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2120) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2120) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2120) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2120) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Driver Easy Pro 5.8.1.41398 Portable - HaxPC.net.rar
(PID) Process:(2120) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2120) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2120) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
44
Suspicious files
40
Text files
22
Unknown types
21

Dropped files

PID
Process
Filename
Type
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\appicon_256.pngimage
MD5:AAC0500FD2C2811D9F0AAB65DFEA8F20
SHA256:75E7BE552E63CCAD820295E31C27045D7D6EA496E5FCC0CAE0F51560DFE42AC5
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\appicon_16.pngimage
MD5:0EE689B9ADE882B80AA4E60E29A3955E
SHA256:EA66F1F340001B59A76029A86B98767C02AE3BB2F279C42D4955718CAC705269
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\appicon.icoimage
MD5:01BA073479ACD1317FDA6A56E81BD2A2
SHA256:9BED06583CBF0254821161D26D68AC8943FC8456D74B60977E4DE8D066B76D63
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\appicon_128.pngimage
MD5:140D0A92D02EF45194D25897869A4571
SHA256:240B4E0142FAFC96BE0DA49E3DB22F38247D04F0719271D653E3C90C8E5E1097
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\Launcher\Splash.jpgimage
MD5:8E9A20D94799B119FA51AC3EBE9EFFA5
SHA256:6ED41F710C72C2C39D1FDDBC1968595ADE5F05F01EC165912244E770A481C2A5
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\appinfo.iniini
MD5:CD703872AE20B6EC201EC154AB03DB89
SHA256:E8C6ED333749D65CD5FB3E33B8CDAD707A5BF16F031F2196B68A8A9A1AF0A89A
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\Launcher\DriverEasyPortable.iniini
MD5:6B657766851CF72808568243B7350673
SHA256:EF0C4F3FBA4589CA29475474E6224513BA777A21DB3C4C834625E199A58B59D5
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\appicon_32.pngimage
MD5:F4372D544BA6F4FA4CEF9D2EF5E38E05
SHA256:CA9DD0AD4CD3195076EA350165CA39C85DB43B49B812E2C6940FB51F5C62CF3B
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\DriverEasy\7z\7z86.dllexecutable
MD5:0FAD10490F029B4728B48DEB6F0B8DE9
SHA256:A4A9F63BF607BD73C66C55082E78D261220F33FF9BACFFEBC504D010738577DE
2120WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2120.15000\App\AppInfo\Launcher\Custom.nshtext
MD5:91089853B38AF3F28DBFE8AE4B608F7D
SHA256:665B4FFA10FBF5AEDBA58D38A34BFAF9E5EC9961C5DE7B3447A705E57C8E3523
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
18
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1656
DriverEasy.exe
GET
200
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?239a80fe3a94dd28
unknown
compressed
67.5 Kb
1656
DriverEasy.exe
GET
200
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?41244c754090c3c6
unknown
compressed
67.5 Kb
1656
DriverEasy.exe
GET
200
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?53c50ebd11a047c3
unknown
compressed
67.5 Kb
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1656
DriverEasy.exe
51.38.74.198:443
www.drivereasy.com
OVH SAS
FR
unknown
1656
DriverEasy.exe
167.114.130.158:443
ann.drivereasy.com
OVH SAS
US
unknown
1656
DriverEasy.exe
2.19.126.163:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1656
DriverEasy.exe
52.116.161.7:443
download.drivereasy.com
SOFTLAYER
US
unknown
1656
DriverEasy.exe
142.44.218.29:443
app1.drivereasy.com
OVH SAS
CA
unknown
1656
DriverEasy.exe
141.94.197.25:443
dow1.drivereasy.com
OVH SAS
FR
unknown

DNS requests

Domain
IP
Reputation
www.drivereasy.com
  • 51.38.74.198
unknown
ann.drivereasy.com
  • 167.114.130.158
unknown
ctldl.windowsupdate.com
  • 2.19.126.163
  • 2.19.126.137
unknown
download.drivereasy.com
  • 52.116.161.7
unknown
app1.drivereasy.com
  • 142.44.218.29
unknown
dow1.drivereasy.com
  • 141.94.197.25
  • 15.235.82.85
  • 51.79.83.221
unknown

Threats

No threats detected
No debug info