| File name: | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe |
| Full analysis: | https://app.any.run/tasks/2045a106-6fab-4173-ba17-eb74c705da0e |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | September 26, 2024, 06:19:40 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C582132EF3C98335DCD3D44BDB503893 |
| SHA1: | 8C695E5EE46C86BE0A0345214C88767A1EDCD296 |
| SHA256: | 8E195B74F3AF8CB4BA82A48AF893B436CC93C814B2721CB16C97E3247FCD6D4E |
| SSDEEP: | 49152:x5/yDsDyQF0DYgIefiGkvUKLUx77aNigJS1kLCLJ17s5s4vBF7rCRGqa9nj8DS/7:LN+B/QUP7s3z7rCRGmG/ccH |
| .exe | | | Inno Setup installer (81.5) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10.5) |
| .exe | | | Win32 Executable (generic) (3.3) |
| .exe | | | Win16/32 Executable Delphi generic (1.5) |
| .exe | | | Generic Win/DOS Executable (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 1299456 |
| InitializedDataSize: | 1800704 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13e380 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.1.0.2 |
| ProductVersionNumber: | 2.1.0.2 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Innovative Solutions |
| FileDescription: | Driver Installer |
| FileVersion: | 2.1.0.2 |
| InternalName: | Driver Installer |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| OriginalFileName: | Driver Installer |
| ProductName: | Driver Installer |
| ProductVersion: | 2.1.0.2 |
| Comments: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1080 | "Taskkill.exe" /IM innostp.exe /F | C:\Windows\SysWOW64\taskkill.exe | — | tmp-drivermax13945590.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1164 | "C:\Users\admin\AppData\Local\Temp\NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe" | C:\Users\admin\AppData\Local\Temp\NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | — | explorer.exe | |||||||||||
User: admin Company: Innovative Solutions Integrity Level: MEDIUM Description: Driver Installer Exit code: 3221226540 Version: 2.1.0.2 Modules
| |||||||||||||||
| 1244 | "Taskkill.exe" /IM innostp.exe /F | C:\Windows\SysWOW64\taskkill.exe | — | tmp-drivermax13945590.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1492 | "Taskkill.exe" /IM stop_dmx.exe /F | C:\Windows\SysWOW64\taskkill.exe | — | tmp-drivermax13945590.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1492 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1940 | "C:\Program Files (x86)\Innovative Solutions\DriverMax\stop_dmx.exe" /STOP | C:\Program Files (x86)\Innovative Solutions\DriverMax\stop_dmx.exe | — | tmp-drivermax13945590.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1952 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2040 | "Taskkill.exe" /IM stop_dmx.exe /F | C:\Windows\SysWOW64\taskkill.exe | — | tmp-drivermax13945590.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2144 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2248 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6504) NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Innovative Solutions\Analytics |
| Operation: | write | Name: | cid |
Value: 9878DF11-04CA-4DAE-87A0-5FB4695CA081 | |||
| (PID) Process: | (6280) tmp-drivermax13945590.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Innovative Solutions\DriverMax |
| Operation: | write | Name: | Affiliate |
Value: Inno | |||
| (PID) Process: | (6280) tmp-drivermax13945590.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6280) tmp-drivermax13945590.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6280) tmp-drivermax13945590.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6280) tmp-drivermax13945590.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Innovative Solutions\DriverMax |
| Operation: | write | Name: | fc |
Value: DE | |||
| (PID) Process: | (6280) tmp-drivermax13945590.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Innovative Solutions\DriverMax |
| Operation: | write | Name: | lc |
Value: DE | |||
| (PID) Process: | (6280) tmp-drivermax13945590.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | delete value | Name: | DriverMax |
Value: | |||
| (PID) Process: | (6280) tmp-drivermax13945590.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Innovative Solutions\DriverMax |
| Operation: | delete value | Name: | chkAgentEnabledCheck |
Value: | |||
| (PID) Process: | (6280) tmp-drivermax13945590.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Innovative Solutions\DriverMax |
| Operation: | write | Name: | chkAgentEnabledCheck |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6280 | tmp-drivermax13945590.tmp | C:\Program Files (x86)\Innovative Solutions\DriverMax\unins000.exe | executable | |
MD5:DDA56268C2B003EA0ECF68982E950F9E | SHA256:61E4D3ED79FD304D8D8E9588A4E4ACDD9193FE44955A3E1CF3BF60A2B8351138 | |||
| 6280 | tmp-drivermax13945590.tmp | C:\Users\admin\AppData\Local\Temp\is-JFAF8.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 6504 | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | C:\Users\admin\AppData\Local\Temp\tmp-drivermax13945590.exe | executable | |
MD5:B666EA6DA4E501E90A2AD8183DC60BD5 | SHA256:A2AE414849DDAE1056007CEDAF204905F45437080438BCE81A8BB091490F46A7 | |||
| 6280 | tmp-drivermax13945590.tmp | C:\Users\admin\AppData\Local\Temp\is-JFAF8.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 6280 | tmp-drivermax13945590.tmp | C:\Users\admin\AppData\Local\Temp\is-JFAF8.tmp\folder-images-icon.bmp | image | |
MD5:D393253B0477CCE0D1E2F6E96E1339E9 | SHA256:171092952FE01BACAFEEA6B4C7CF90AF0CA98EB251834F9B9E3E702DC878FA61 | |||
| 6280 | tmp-drivermax13945590.tmp | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\json[1].json | binary | |
MD5:D1A5029DF0761FB16204E5BA90D018D8 | SHA256:41259873978FF2081F6A4BC067C40E9AD974F897A493085A4311DF5EE3A7447F | |||
| 6280 | tmp-drivermax13945590.tmp | C:\Users\admin\AppData\Local\Temp\is-JFAF8.tmp\analytics_v2.dll | executable | |
MD5:F39F747376FE925CFC727F99ACAFE682 | SHA256:C41DE2A1F0F9BFF8FB51D84E6E09FFBE48BCA58CEC4421E36B7F7EE383911E35 | |||
| 6280 | tmp-drivermax13945590.tmp | C:\Program Files (x86)\Innovative Solutions\DriverMax\Readme\is-R08RS.tmp | text | |
MD5:EE7204BC2FE947E020945431E7BB0696 | SHA256:560FABF6D58F78AE92E34D9D2BEDA7EFF07DC4260DB948E60382641FDFA3A43F | |||
| 6280 | tmp-drivermax13945590.tmp | C:\Program Files (x86)\Innovative Solutions\DriverMax\Readme\license.rtf | text | |
MD5:EE7204BC2FE947E020945431E7BB0696 | SHA256:560FABF6D58F78AE92E34D9D2BEDA7EFF07DC4260DB948E60382641FDFA3A43F | |||
| 6504 | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | C:\Users\admin\AppData\Local\Temp\tmp-drivermax13945590.exe.part | executable | |
MD5:B666EA6DA4E501E90A2AD8183DC60BD5 | SHA256:A2AE414849DDAE1056007CEDAF204905F45437080438BCE81A8BB091490F46A7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6504 | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | POST | 200 | 168.119.201.56:80 | http://user.drivermax.com/driver-download/hdwl.php | unknown | — | — | unknown |
6504 | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | GET | 206 | 168.119.201.56:80 | http://small.drivermax.com/soft/dmx/drivermax.exe | unknown | — | — | whitelisted |
6232 | drivermax.exe | GET | 200 | 34.117.59.81:80 | http://ipinfo.io/json | unknown | — | — | whitelisted |
6280 | tmp-drivermax13945590.tmp | GET | 200 | 34.117.59.81:80 | http://ipinfo.io/json | unknown | — | — | whitelisted |
6232 | drivermax.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDA5ml5aITsG9Y8TP4w%3D%3D | unknown | — | — | whitelisted |
6232 | drivermax.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6504 | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | POST | 200 | 142.250.185.110:80 | http://www.google-analytics.com/collect | unknown | — | — | unknown |
6504 | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | POST | 200 | 142.250.185.110:80 | http://www.google-analytics.com/collect | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1692 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6504 | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | 168.119.201.56:80 | user.drivermax.com | Hetzner Online GmbH | UA | whitelisted |
2988 | svchost.exe | 40.126.31.73:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2988 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6504 | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | 142.250.185.110:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
user.drivermax.com |
| whitelisted |
small.drivermax.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
ipinfo.io |
| shared |
ocsp.globalsign.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6504 | NET-Atheros-Atheros-L2-Fast-Ethernet-10-100Base-T-Controller.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2256 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io) |
6280 | tmp-drivermax13945590.tmp | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ipinfo.io |
6280 | tmp-drivermax13945590.tmp | Misc activity | ET ADWARE_PUP Drivermax Utility Checkin Activity |
6280 | tmp-drivermax13945590.tmp | Device Retrieving External IP Address Detected | ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io) |
2256 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io) |
6232 | drivermax.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ipinfo.io |
6356 | drivermax.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ipinfo.io |