File name:

driver-hub-install__28.exe

Full analysis: https://app.any.run/tasks/91dc1b3d-227d-4a36-93cd-2e1cb9119da4
Verdict: Malicious activity
Analysis date: June 30, 2025, 06:33:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

33F914D2A2C1D8A6F4CEA578A4A76DC5

SHA1:

FFC43D087DE95280B1D11C878A17D328A0BFEBF1

SHA256:

838C1A1B83127539DC1483CD66741C9208810C780BFE79FEBA3D7787875A7E9F

SSDEEP:

12288:9khvJnlf3lOOxNFQBOgwxb3+tO55BaQ7D59oyobDBr:9khz1OOxNWgga3+tO5CwF96

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • driver-hub-install__28.exe (PID: 6720)
      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
    • Application launched itself

      • driver-hub-install__28.exe (PID: 6720)
    • Executable content was dropped or overwritten

      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
    • The process drops C-runtime libraries

      • driver-hub-install__28.exe (PID: 6656)
    • Searches for installed software

      • driver-hub-install__28.exe (PID: 6656)
    • Process drops legitimate windows executable

      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
    • Creates a software uninstall entry

      • driver-hub-install__28.exe (PID: 6656)
  • INFO

    • Reads the computer name

      • driver-hub-install__28.exe (PID: 6720)
      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
      • PDClient.exe (PID: 4132)
    • Reads the machine GUID from the registry

      • driver-hub-install__28.exe (PID: 6720)
      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
      • PDClient.exe (PID: 4132)
    • Checks supported languages

      • driver-hub-install__28.exe (PID: 6720)
      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
      • PDClient.exe (PID: 4132)
    • Process checks computer location settings

      • driver-hub-install__28.exe (PID: 6720)
      • driver-hub-install__28.exe (PID: 6656)
    • Reads the software policy settings

      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
    • Disables trace logs

      • driver-hub-install__28.exe (PID: 6656)
    • Checks proxy server information

      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
    • Creates files in the program directory

      • driver-hub-install__28.exe (PID: 6656)
    • The sample compiled with english language support

      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
    • The sample compiled with russian language support

      • driver-hub-install__28.exe (PID: 6656)
    • Creates files or folders in the user directory

      • driver-hub-install__28.exe (PID: 6656)
      • DriverHub.exe (PID: 5780)
      • PDClient.exe (PID: 4132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2097:11:25 01:06:42+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 694272
InitializedDataSize: 85504
UninitializedDataSize: -
EntryPoint: 0xab5ba
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.3.0.0
ProductVersionNumber: 4.3.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Install DriverHub
FileVersion: 4.3.0.0
InternalName: DriverHubInstaller.exe
LegalCopyright: © ROSTPAY LTD. All rights reserved.
LegalTrademarks: -
OriginalFileName: DriverHubInstaller.exe
ProductName: DriverHub
ProductVersion: 4.3.0.0
AssemblyVersion: 4.3.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start driver-hub-install__28.exe no specs driver-hub-install__28.exe driverhub.exe pdclient.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3580C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4132"C:\Program Files (x86)\DriverHub\PDClient.exe" init DriverHub /p=DrvhubSoftC:\Program Files (x86)\DriverHub\PDClient.exeDriverHub.exe
User:
admin
Company:
ProxymaData
Integrity Level:
HIGH
Description:
ProxymaData client
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\program files (x86)\driverhub\pdclient.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5780"C:\Program Files (x86)\DriverHub\DriverHub.exe" C:\Program Files (x86)\DriverHub\DriverHub.exe
driver-hub-install__28.exe
User:
admin
Company:
ROSTPAY LTD
Integrity Level:
HIGH
Description:
DriverHub
Version:
1.3.18.2147
Modules
Images
c:\program files (x86)\driverhub\driverhub.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6656"C:\Users\admin\AppData\Local\Temp\driver-hub-install__28.exe" /install /pos=220,20 /lang=en "/dir.install=C:\Program Files (x86)\DriverHub"C:\Users\admin\AppData\Local\Temp\driver-hub-install__28.exe
driver-hub-install__28.exe
User:
admin
Integrity Level:
HIGH
Description:
Install DriverHub
Exit code:
0
Version:
4.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\driver-hub-install__28.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6720"C:\Users\admin\AppData\Local\Temp\driver-hub-install__28.exe" C:\Users\admin\AppData\Local\Temp\driver-hub-install__28.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Install DriverHub
Exit code:
0
Version:
4.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\driver-hub-install__28.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
14 843
Read events
14 809
Write events
34
Delete events
0

Modification events

(PID) Process:(6720) driver-hub-install__28.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\CUAS\DefaultCompositionWindow
Operation:writeName:Left
Value:
0
(PID) Process:(6720) driver-hub-install__28.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\CUAS\DefaultCompositionWindow
Operation:writeName:Top
Value:
0
(PID) Process:(6656) driver-hub-install__28.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\driver-hub-install__28_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6656) driver-hub-install__28.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\driver-hub-install__28_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6656) driver-hub-install__28.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\driver-hub-install__28_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6656) driver-hub-install__28.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\driver-hub-install__28_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6656) driver-hub-install__28.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\driver-hub-install__28_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6656) driver-hub-install__28.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\driver-hub-install__28_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6656) driver-hub-install__28.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\driver-hub-install__28_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6656) driver-hub-install__28.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\driver-hub-install__28_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
Executable files
59
Suspicious files
163
Text files
549
Unknown types
28

Dropped files

PID
Process
Filename
Type
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\libcrypto-1_1.dllexecutable
MD5:D588D5B4162D2C66071A171A903AC8A1
SHA256:F1B06DB34B6BC09738FA66AC2103F7F47BA58F9BB6D1A518112F42846B6DC8EA
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\imageformats\qgif.dllexecutable
MD5:A7D24E2226FF09208E22FC6F70BF0DE7
SHA256:6356257682FB64D28AD68DEBEA96E1A0104C273E8838953459A110933F0A84BE
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\d3dcompiler_47.dllexecutable
MD5:C5B362BCE86BB0AD3149C4540201331D
SHA256:EFBDBBCD0D954F8FDC53467DE5D89AD525E4E4A9CFFF8A15D07C6FDB350C407F
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\DriverHub.exebinary
MD5:85CDD0909F9AE260B024A8D5B29039AF
SHA256:03823D9D40A102CC742C1D3AFFC79689FBE725DF7296654219373682F6F6135D
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\imageformats\qjpeg.dllexecutable
MD5:35AA301AF3284B1349C4229B8937C895
SHA256:8A7B522660C91AA5463C5A9534C9B4959E3055448E6B9428ED8F1352549B088C
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\Images\DriverHubLogo.pngimage
MD5:451B153070269850DA133D4E493A1BD6
SHA256:91D221FE4045038100274A1A32F8155C0195517C51A712B1F742A4F5BBB45E4B
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\DriverHubUninstaller.exeexecutable
MD5:80B76037F21558ADD4B505BC5CB7722E
SHA256:65831CAE481B3B30E76901A513070536D005DDB12859358403CA906D9492DE2B
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\msvcp140_1.dllexecutable
MD5:56E81CA2C439956FBEA6D04891BEC541
SHA256:F0FB70B0801432A89EBCC301F289C78FFB6D3F06BFB691A5782D7A309D1386C6
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\libEGL.dllexecutable
MD5:E0E4011346A86083A0EC8EB01136D0BA
SHA256:411966CE4F8FEBB2FE3AB84B97ED9FB9062AB60C6211FC3B3E4A25A5EE607ECB
6656driver-hub-install__28.exeC:\Program Files (x86)\DriverHub\libssl-1_1.dllexecutable
MD5:4A1BD71115017098E6B75570A61B6DC3
SHA256:244AE1F0EF1AD908B54068EB13611FBA58C8F78BA2F126ACDE7379A0C823123F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
34
DNS requests
22
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
420
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
764
lsass.exe
GET
200
104.18.20.213:80
http://e5.c.lencr.org/121.crl
unknown
whitelisted
5780
DriverHub.exe
POST
200
172.217.16.206:80
http://www.google-analytics.com/collect
unknown
whitelisted
2668
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
420
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5780
DriverHub.exe
POST
200
172.217.16.206:80
http://www.google-analytics.com/collect
unknown
whitelisted
5780
DriverHub.exe
POST
200
172.217.16.206:80
http://www.google-analytics.com/collect
unknown
whitelisted
5780
DriverHub.exe
POST
200
172.217.16.206:80
http://www.google-analytics.com/collect
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5504
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2668
svchost.exe
20.190.160.5:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2668
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.46
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
login.live.com
  • 20.190.160.5
  • 20.190.160.22
  • 20.190.160.64
  • 20.190.160.3
  • 40.126.32.68
  • 40.126.32.133
  • 20.190.160.128
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
api.az-partners.net
  • 188.130.153.32
  • 188.130.153.33
unknown
drvhub.net
  • 188.130.153.32
  • 188.130.153.33
whitelisted
www.drvhub.net
  • 188.130.153.32
  • 188.130.153.33
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
DriverHub.exe
qrc:/main.qml:655:13: QML Connections: Implicitly defined onFoo properties in Connections are deprecated. Use this syntax instead: function onFoo(<arguments>) { ... }
DriverHub.exe
qrc:/UpdateProgressDialog.qml:11:5: QML Connections: Implicitly defined onFoo properties in Connections are deprecated. Use this syntax instead: function onFoo(<arguments>) { ... }
DriverHub.exe
qrc:/main.qml:453:31: QML ItemDelegate: Binding loop detected for property "height"
DriverHub.exe
file:///C:/Program Files (x86)/DriverHub/QtQuick/Dialogs/DefaultFileDialog.qml:102:33: QML Settings: The following application identifiers have not been set: QVector("organizationName", "organizationDomain")
DriverHub.exe
file:///C:/Program Files (x86)/DriverHub/QtQuick/Dialogs/DefaultFileDialog.qml:102:33: QML Settings: Failed to initialize QSettings instance. Status code is: 1
DriverHub.exe
qrc:/SettingsPage.qml:29:9: QML MyCheckBox: Binding loop detected for property "width"
DriverHub.exe
qrc:/SettingsPage.qml:29:9: QML MyCheckBox: Binding loop detected for property "width"
DriverHub.exe
qrc:/SettingsPage.qml:47:9: QML MyCheckBox: Binding loop detected for property "width"
DriverHub.exe
qrc:/SettingsPage.qml:29:9: QML MyCheckBox: Binding loop detected for property "width"
DriverHub.exe
qrc:/SettingsPage.qml:47:9: QML MyCheckBox: Binding loop detected for property "width"