| File name: | Auslogics_Driver_Updater_v1.26.0.exe |
| Full analysis: | https://app.any.run/tasks/8bf97ed6-4d6c-45f8-988a-6b787d49b9e4 |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2024, 20:24:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 500133750866AD5A0B9CE3BB639DCBD5 |
| SHA1: | 1E9CD82A1ED78796D38356299E5CD2821CEF9C14 |
| SHA256: | B9A0DFE4A7E9E20D7E6191FF9C2DCBCF321D70E66F45C0E3FFAC3CBC29AA75EA |
| SSDEEP: | 98304:2tx6iT2RjOd3uk+6yC+0nb7bTWY4IV1aMyhc+PL/7mj2wkeg+0y/E/TUW0GLsv8L:ouN1mWSiQY+dG6+GFskOr++QEl |
| .exe | | | Inno Setup installer (81.5) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10.5) |
| .exe | | | Win32 Executable (generic) (3.3) |
| .exe | | | Win16/32 Executable Delphi generic (1.5) |
| .exe | | | Generic Win/DOS Executable (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:10:02 05:04:04+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 86016 |
| InitializedDataSize: | 109056 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x16478 |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.26.0.0 |
| ProductVersionNumber: | 1.26.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Auslogics Labs Pty Ltd. (RePack by Dodakaedr) |
| FileDescription: | Auslogics Driver Updater |
| FileVersion: | 1.26.0.0 |
| LegalCopyright: | |
| ProductName: | Auslogics Driver Updater |
| ProductVersion: | 1.26.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1036 | DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{5ea7d9c3-7d11-3304-1253-211b33776f36}\cpu.inf" "0" "6baea0d2f" "000004D4" "WinSta0\Default" "0000060C" "208" "c:\users\admin\appdata\local\temp\9c70126b-78f9-46ed-b013-eb52c096414e\5d56e097f0885d94fc6cc9ce693f304b" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 3758096959 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1636 | DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{3fd8e824-b3d7-74c6-4eaa-ef54cf84083b}\cpu.inf" "0" "6e4f9fd47" "000005E0" "WinSta0\Default" "000004D4" "208" "c:\users\admin\appdata\local\temp\6d32d2e1-a97d-4c13-b0c1-fe7a62cc08bf\421eaac2f006ec1cb9dc61cf77f0d1f1" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 3758096959 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2072 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2160 | "C:\Users\admin\AppData\Local\Temp\Auslogics_Driver_Updater_v1.26.0.exe" | C:\Users\admin\AppData\Local\Temp\Auslogics_Driver_Updater_v1.26.0.exe | — | explorer.exe | |||||||||||
User: admin Company: Auslogics Labs Pty Ltd. (RePack by Dodakaedr) Integrity Level: MEDIUM Description: Auslogics Driver Updater Exit code: 3221226540 Version: 1.26.0.0 Modules
| |||||||||||||||
| 2320 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2404 | C:\Users\admin\AppData\Local\Temp\6D32D2E1-A97D-4C13-B0C1-FE7A62CC08BF\DPINST32.EXE | C:\Users\admin\AppData\Local\Temp\6D32D2E1-A97D-4C13-B0C1-FE7A62CC08BF\DPINST32.EXE | DriverUpdater.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 2147549184 Version: 2.1 Modules
| |||||||||||||||
| 2636 | "C:\Program Files\Auslogics\Driver Updater\DriverUpdater.exe" | C:\Program Files\Auslogics\Driver Updater\DriverUpdater.exe | Auslogics_Driver_Updater_v1.26.0.tmp | ||||||||||||
User: admin Company: Auslogics Integrity Level: HIGH Description: Driver Updater Exit code: 0 Version: 1.26.0.0 Modules
| |||||||||||||||
| 2852 | "C:\Users\admin\AppData\Local\Temp\Auslogics_Driver_Updater_v1.26.0.exe" | C:\Users\admin\AppData\Local\Temp\Auslogics_Driver_Updater_v1.26.0.exe | explorer.exe | ||||||||||||
User: admin Company: Auslogics Labs Pty Ltd. (RePack by Dodakaedr) Integrity Level: HIGH Description: Auslogics Driver Updater Exit code: 0 Version: 1.26.0.0 Modules
| |||||||||||||||
| 2956 | DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{10cf5d1a-ebb9-5d17-05ea-700a9705ca33}\mshdc.inf" "0" "6ed70c233" "0000060C" "WinSta0\Default" "000003F8" "208" "c:\users\admin\appdata\local\temp\3a4e438a-12b3-4f04-91e5-428d5bdbdec4\e718cd850583163909a865eba69d088a" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 3758096959 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2964 | "C:\Users\admin\AppData\Local\Temp\is-PIPBN.tmp\Auslogics_Driver_Updater_v1.26.0.tmp" /SL5="$F0170,14265316,196096,C:\Users\admin\AppData\Local\Temp\Auslogics_Driver_Updater_v1.26.0.exe" | C:\Users\admin\AppData\Local\Temp\is-PIPBN.tmp\Auslogics_Driver_Updater_v1.26.0.tmp | Auslogics_Driver_Updater_v1.26.0.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 940B00006264F5245F5CDA01 | |||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: B8075BB68B85B30D2629F4FD4B55FC17269CF450E6793081DABF61066B38C99B | |||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\Auslogics\Driver Updater\ActionCenterHelper.dll | |||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 701CF5997D411C72B2515960B05AB3F81BFBEA6B4EA2E98631116599E5D0E2CD | |||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics\Driver Updater\1.x\Settings |
| Operation: | write | Name: | General.IsRegistered |
Value: 1 | |||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics\Driver Updater\1.x\Settings |
| Operation: | write | Name: | General.Language |
Value: RUS | |||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics\Driver Updater\1.x\Settings |
| Operation: | write | Name: | App.Application.SendInfo |
Value: 0 | |||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics\Driver Updater\1.x\Settings |
| Operation: | write | Name: | App.Application.AutostartEnable |
Value: 0 | |||
| (PID) Process: | (2964) Auslogics_Driver_Updater_v1.26.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics\Driver Updater\1.x\Settings |
| Operation: | write | Name: | Application.IsFirstRun |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2964 | Auslogics_Driver_Updater_v1.26.0.tmp | C:\Users\admin\AppData\Local\Temp\is-7QGU3.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 2964 | Auslogics_Driver_Updater_v1.26.0.tmp | C:\Users\admin\AppData\Local\Temp\is-7QGU3.tmp\eng.jpg | image | |
MD5:4AD999118697C0735EED9B5437E2DDD9 | SHA256:EE6D8D45A073FF7C69012CF34B1FA4DAFED071E709F64143D57A42BE5BB6E7F4 | |||
| 2964 | Auslogics_Driver_Updater_v1.26.0.tmp | C:\Users\admin\AppData\Local\Temp\is-7QGU3.tmp\iswin7logo.dll | executable | |
MD5:7363A2A5949C9F613CDE458B89DEECB5 | SHA256:196390762F6393024E0C5D33B037D497C5A8CFDD6C406719C05B0081D7E45CB5 | |||
| 2964 | Auslogics_Driver_Updater_v1.26.0.tmp | C:\Users\admin\AppData\Local\Temp\is-7QGU3.tmp\Installer net.png | image | |
MD5:1C5BFE3B17AE62449E5F9E42B762F33B | SHA256:567A2D3CEA865F672B63E6FF44FC7091173A79FA840C9D20286ECD5429029823 | |||
| 2964 | Auslogics_Driver_Updater_v1.26.0.tmp | C:\Users\admin\AppData\Local\Temp\is-7QGU3.tmp\icon.png | image | |
MD5:056DF69E2101DD1B0370B4021E17818F | SHA256:F6B3BB237018BC9F0845CC8693638CD375F6B9E9CE57B3723E5A078F50D04012 | |||
| 2964 | Auslogics_Driver_Updater_v1.26.0.tmp | C:\Users\admin\AppData\Local\Temp\is-7QGU3.tmp\botva2.dll | executable | |
MD5:EF899FA243C07B7B82B3A45F6EC36771 | SHA256:DA7D0368712EE419952EB2640A65A7F24E39FB7872442ED4D2EE847EC4CFDE77 | |||
| 2852 | Auslogics_Driver_Updater_v1.26.0.exe | C:\Users\admin\AppData\Local\Temp\is-PIPBN.tmp\Auslogics_Driver_Updater_v1.26.0.tmp | executable | |
MD5:36A104C924469DB12D4741A397D39181 | SHA256:4F35E3A48E3BDAD3A7CEB88C2FF257F77484FD6DB03C686877CF44A2E2B2095D | |||
| 2964 | Auslogics_Driver_Updater_v1.26.0.tmp | C:\Program Files\Auslogics\Driver Updater\is-0E9U9.tmp | executable | |
MD5:134440801ED952214A66D40E33128A92 | SHA256:0CD832F8BF3F2306C9CC7879FE507B49426CDAF32D850B1045D835DC84C74150 | |||
| 2964 | Auslogics_Driver_Updater_v1.26.0.tmp | C:\Users\admin\AppData\Local\Temp\is-7QGU3.tmp\stac.png | image | |
MD5:EAEC12CF0E741D23CBF1A100E7DEE23E | SHA256:B38E0315691ADF47090665EC21AEE0C0CB5014246CFE0EDF0C1F1FF36C45D2AC | |||
| 2964 | Auslogics_Driver_Updater_v1.26.0.tmp | C:\Users\admin\AppData\Local\Temp\is-7QGU3.tmp\Portable.png | image | |
MD5:89475A0F65E50EE9C484967EBC348AB7 | SHA256:5F9CA566D37E1F25D19BBF5F885862808CB6B3D1A4DBCCA5AF812A58AE6FEDF9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
488 | lsass.exe | GET | 304 | 87.248.204.0:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?144111b1a3e00b48 | unknown | — | — | unknown |
488 | lsass.exe | GET | 200 | 18.173.185.228:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | unknown | binary | 1.49 Kb | unknown |
488 | lsass.exe | GET | 200 | 18.173.185.228:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D | unknown | binary | 1.37 Kb | unknown |
488 | lsass.exe | GET | 200 | 18.66.183.220:80 | http://ocsp.r2m03.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQqHI%2BsdmapawQncL1rpCEZZ8gTSAQUVdkYX9IczAHhWLS%2Bq9lVQgHXLgICEA%2BHrpGtSM2fvOAqp0nhJVM%3D | unknown | binary | 471 b | unknown |
488 | lsass.exe | GET | 200 | 108.138.34.63:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | unknown | binary | 2.02 Kb | unknown |
2636 | DriverUpdater.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAsllCLO2YEqFaBOmVKKDvo%3D | unknown | binary | 471 b | unknown |
2636 | DriverUpdater.exe | GET | 200 | 192.229.221.95:80 | http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJiUKgT2m88fZ4nxc1Lu6M%2FjvkagQUDNtsgkkPSmcKuBTuesRIUojrVjgCEAdpVDZkciT8g1iEeh8ZYO0%3D | unknown | binary | 471 b | unknown |
1080 | svchost.exe | GET | 200 | 87.248.204.0:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0754c686571bd23f | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2636 | DriverUpdater.exe | 44.241.182.253:443 | auslgics.com | AMAZON-02 | US | unknown |
488 | lsass.exe | 87.248.204.0:80 | ctldl.windowsupdate.com | LLNW | US | unknown |
488 | lsass.exe | 108.138.34.63:80 | o.ss2.us | AMAZON-02 | US | unknown |
488 | lsass.exe | 18.173.185.228:80 | ocsp.rootg2.amazontrust.com | — | US | unknown |
488 | lsass.exe | 18.66.183.220:80 | ocsp.r2m03.amazontrust.com | AMAZON-02 | US | unknown |
2636 | DriverUpdater.exe | 51.81.185.149:443 | du.auslogics.com | OVH SAS | US | unknown |
2636 | DriverUpdater.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
auslgics.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.r2m03.amazontrust.com |
| unknown |
du.auslogics.com |
| unknown |
ocsp.digicert.com |
| whitelisted |
status.rapidssl.com |
| shared |
du-static.auslogics.com |
| unknown |