analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://cdn.drivereasy.com/DriverEasy_Setup.exe

Full analysis: https://app.any.run/tasks/0302cf8e-adc8-4744-baa3-a333436d891a
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 20, 2019, 20:02:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

6433638EA14183781009F89701196DA8

SHA1:

B794C4832FA9516D74512522365DF0E33AE70C76

SHA256:

9FF344B571121D6D06E6EC59A3ACF2D201E0B445B2555EDF36DF8FD2D2F44B87

SSDEEP:

3:N1KdBLdzX5yTJWkA:CXdzcTUkA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • DriverEasy_Setup[1].exe (PID: 2636)
      • DriverEasy_Setup[1].exe (PID: 1664)
      • Easeware.ConfigLanguageFromSetup.exe (PID: 1332)
      • Easeware.CheckScheduledScan.exe (PID: 3420)
    • Downloads executable files from the Internet

      • iexplore.exe (PID: 1708)
    • Loads the Task Scheduler DLL interface

      • Easeware.CheckScheduledScan.exe (PID: 3420)
    • Loads dropped or rewritten executable

      • Easeware.ConfigLanguageFromSetup.exe (PID: 1332)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 900)
      • iexplore.exe (PID: 1708)
      • DriverEasy_Setup[1].exe (PID: 1664)
      • DriverEasy_Setup[1].exe (PID: 2636)
      • DriverEasy_Setup[1].tmp (PID: 3680)
    • Reads Windows owner or organization settings

      • DriverEasy_Setup[1].tmp (PID: 3680)
    • Reads the Windows organization settings

      • DriverEasy_Setup[1].tmp (PID: 3680)
    • Creates files in the user directory

      • Easeware.ConfigLanguageFromSetup.exe (PID: 1332)
    • Creates files in the Windows directory

      • Easeware.CheckScheduledScan.exe (PID: 3420)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 900)
      • iexplore.exe (PID: 1708)
    • Creates files in the user directory

      • iexplore.exe (PID: 1708)
    • Application launched itself

      • iexplore.exe (PID: 900)
    • Changes internet zones settings

      • iexplore.exe (PID: 900)
    • Application was dropped or rewritten from another process

      • DriverEasy_Setup[1].tmp (PID: 3680)
      • DriverEasy_Setup[1].tmp (PID: 3252)
    • Creates a software uninstall entry

      • DriverEasy_Setup[1].tmp (PID: 3680)
    • Loads dropped or rewritten executable

      • DriverEasy_Setup[1].tmp (PID: 3680)
    • Creates files in the program directory

      • DriverEasy_Setup[1].tmp (PID: 3680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
2
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe drivereasy_setup[1].exe drivereasy_setup[1].tmp no specs drivereasy_setup[1].exe drivereasy_setup[1].tmp easeware.checkscheduledscan.exe no specs easeware.configlanguagefromsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
900"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
1708"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:900 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
1664"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\DriverEasy_Setup[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\DriverEasy_Setup[1].exe
iexplore.exe
User:
admin
Company:
Easeware
Integrity Level:
MEDIUM
Description:
Driver Easy Setup
Version:
5.6.10.59951
3252"C:\Users\admin\AppData\Local\Temp\is-FCGVQ.tmp\DriverEasy_Setup[1].tmp" /SL5="$402B8,3620027,397824,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\DriverEasy_Setup[1].exe" C:\Users\admin\AppData\Local\Temp\is-FCGVQ.tmp\DriverEasy_Setup[1].tmpDriverEasy_Setup[1].exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
2636"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\DriverEasy_Setup[1].exe" /SPAWNWND=$6017E /NOTIFYWND=$402B8 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\DriverEasy_Setup[1].exe
DriverEasy_Setup[1].tmp
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
Driver Easy Setup
Version:
5.6.10.59951
3680"C:\Users\admin\AppData\Local\Temp\is-CAGKQ.tmp\DriverEasy_Setup[1].tmp" /SL5="$70114,3620027,397824,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\DriverEasy_Setup[1].exe" /SPAWNWND=$6017E /NOTIFYWND=$402B8 C:\Users\admin\AppData\Local\Temp\is-CAGKQ.tmp\DriverEasy_Setup[1].tmp
DriverEasy_Setup[1].exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
3420"C:\Program Files\Easeware\DriverEasy\Easeware.CheckScheduledScan.exe" -create "Driver Easy Scheduled Scan" "C:\Program Files\Easeware\DriverEasy\DriverEasy.exe"C:\Program Files\Easeware\DriverEasy\Easeware.CheckScheduledScan.exeDriverEasy_Setup[1].tmp
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
Easeware.CheckScheduledScan
Exit code:
0
Version:
1.0.1.0
1332"C:\Program Files\Easeware\DriverEasy\Easeware.ConfigLanguageFromSetup.exe" DriverEasy enC:\Program Files\Easeware\DriverEasy\Easeware.ConfigLanguageFromSetup.exeDriverEasy_Setup[1].tmp
User:
admin
Company:
Easeware
Integrity Level:
HIGH
Description:
Easeware.ConfigLanguageFromSetup
Exit code:
0
Version:
1.0.4.0
Total events
1 261
Read events
1 167
Write events
0
Delete events
0

Modification events

No data
Executable files
19
Suspicious files
3
Text files
41
Unknown types
9

Dropped files

PID
Process
Filename
Type
900iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF883BA915B10D018B.TMP
MD5:
SHA256:
1708iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:4E5711A3C3210D8611D1585588F83E9E
SHA256:C85109F5A75AEF9DC860D1643708C0A0C93D14C057F4C43286FEECA00B63A032
900iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019052020190521\index.datdat
MD5:07089B03BAE0B58A93C4A36CCB46E0E3
SHA256:CA21595594B6F162BBD55183A488881ECEF038F311A3F0BA5487000A4219F619
900iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{4A19DAA2-7B3A-11E9-B63D-5254004A04AF}.datbinary
MD5:52EC1103F8CB44F7DD6E4D3270E9D23E
SHA256:DE11EF64F2C8083C01143BBF3E5A0C25B5E6DDCDD551F77B4DAD7249F4E27980
1708iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\JavaDeployReg.logtext
MD5:A9E9B5372FAC20CC83AE3B919548CD5E
SHA256:2B8EE695FE9C6CC6D9E3628A91A3C71038257E21377AE0CE1BBD592FEA42FEC0
2636DriverEasy_Setup[1].exeC:\Users\admin\AppData\Local\Temp\is-CAGKQ.tmp\DriverEasy_Setup[1].tmpexecutable
MD5:06AAC6F9C8928B62FC13F1D8AF9EFBF4
SHA256:A1DB1CF8A166B35777EA1CD9C5DA9F8DC4C949E59D53F08C0407606928EA9B54
1664DriverEasy_Setup[1].exeC:\Users\admin\AppData\Local\Temp\is-FCGVQ.tmp\DriverEasy_Setup[1].tmpexecutable
MD5:06AAC6F9C8928B62FC13F1D8AF9EFBF4
SHA256:A1DB1CF8A166B35777EA1CD9C5DA9F8DC4C949E59D53F08C0407606928EA9B54
1708iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:DA038EA41B3962677845648569CF7E6B
SHA256:EA39C23D3B4A98DD6CBA9DBB7B3AAB736F1A858137F453A058BD42B4455B3A26
900iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BK9VRVP7\DriverEasy_Setup[1].exe:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
1708iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019052020190521\index.datdat
MD5:E413E86A52DBBA8B4390FBF01D9B5F78
SHA256:0C177912F5939B2D989609011C0822131C64406943F2D66E6841F1619B128D10
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
4
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1708
iexplore.exe
GET
200
2.16.106.187:80
http://cdn.drivereasy.com/DriverEasy_Setup.exe
unknown
executable
3.94 Mb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
900
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
900
iexplore.exe
13.107.21.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
1708
iexplore.exe
2.16.106.201:80
cdn.drivereasy.com
Akamai International B.V.
whitelisted
1708
iexplore.exe
2.16.106.187:80
cdn.drivereasy.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
cdn.drivereasy.com
  • 2.16.106.201
  • 2.16.106.187
suspicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

PID
Process
Class
Message
1708
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info