File name:

driver-hub-install__28.exe

Full analysis: https://app.any.run/tasks/feaaff7f-17d1-40bb-965b-ef8cf5b8a3e4
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 16, 2026, 13:11:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
golang
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

4652AC4A0B4CF5E66B041491C1BDA467

SHA1:

D42D90E731920BB3B57E994B894A054FD94834B7

SHA256:

F2DBBB488279ACA7EF992D3F249E96F47963ABFD932BE33F3BE85E25A49213DC

SSDEEP:

49152:j4q4V8sSgnwBW/UyeEd63YM+yaWDeS4O1K79rPgrJtKM1jX0kqs+NOIyI6fARfxs:j4Bh4c/DpSgrPukzpy7RwxW0lSB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • driver-hub-install__28.exe (PID: 972)
    • Changes settings of System certificates

      • svchost.exe (PID: 1092)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • driver-hub-install__28.exe (PID: 972)
      • DriverHub_.exe (PID: 3916)
      • PDClient.exe (PID: 3932)
      • DriverHub.exe (PID: 1836)
    • Reads the Internet Settings

      • driver-hub-install__28.exe (PID: 972)
      • DriverHub_.exe (PID: 3916)
      • PDClient.exe (PID: 3932)
      • PDClient.exe (PID: 4024)
      • DriverHub.exe (PID: 1836)
    • Reads settings of System Certificates

      • DriverHub_.exe (PID: 3916)
      • DriverHub.exe (PID: 1836)
      • PDClient.exe (PID: 4024)
    • Executable content was dropped or overwritten

      • DriverHub_.exe (PID: 3916)
      • PDClient.exe (PID: 3932)
      • PDClient.exe (PID: 4024)
      • DriverHub.exe (PID: 1836)
    • The process drops C-runtime libraries

      • DriverHub_.exe (PID: 3916)
    • Searches for installed software

      • DriverHub_.exe (PID: 3916)
      • PDClient.exe (PID: 3932)
    • Process drops legitimate windows executable

      • DriverHub_.exe (PID: 3916)
      • DriverHub.exe (PID: 1836)
    • Starts itself from another location

      • PDClient.exe (PID: 3932)
    • Connects to unusual port

      • IndexingManager.exe (PID: 1364)
    • There is functionality for taking screenshot (YARA)

      • DriverHub.exe (PID: 1836)
  • INFO

    • The sample compiled with english language support

      • driver-hub-install__28.exe (PID: 972)
      • DriverHub_.exe (PID: 3916)
      • PDClient.exe (PID: 4024)
      • DriverHub.exe (PID: 1836)
    • Checks supported languages

      • driver-hub-install__28.exe (PID: 972)
      • DriverHub_.exe (PID: 3916)
      • DriverHub.exe (PID: 1836)
      • PDClient.exe (PID: 1556)
      • PDClient.exe (PID: 3932)
      • IndexingManager.exe (PID: 1364)
      • PDClient.exe (PID: 4024)
    • Reads the computer name

      • driver-hub-install__28.exe (PID: 972)
      • DriverHub_.exe (PID: 3916)
      • DriverHub.exe (PID: 1836)
      • PDClient.exe (PID: 3932)
      • PDClient.exe (PID: 1556)
      • PDClient.exe (PID: 4024)
      • IndexingManager.exe (PID: 1364)
    • Reads the machine GUID from the registry

      • DriverHub_.exe (PID: 3916)
      • DriverHub.exe (PID: 1836)
      • PDClient.exe (PID: 1556)
      • PDClient.exe (PID: 3932)
      • PDClient.exe (PID: 4024)
    • Create files in a temporary directory

      • driver-hub-install__28.exe (PID: 972)
    • Disables trace logs

      • DriverHub_.exe (PID: 3916)
      • PDClient.exe (PID: 4024)
    • Creates files or folders in the user directory

      • DriverHub_.exe (PID: 3916)
      • DriverHub.exe (PID: 1836)
      • PDClient.exe (PID: 1556)
      • PDClient.exe (PID: 3932)
      • PDClient.exe (PID: 4024)
      • IndexingManager.exe (PID: 1364)
    • Reads Environment values

      • DriverHub_.exe (PID: 3916)
      • PDClient.exe (PID: 4024)
    • The sample compiled with russian language support

      • DriverHub_.exe (PID: 3916)
    • Drops script file

      • DriverHub_.exe (PID: 3916)
      • DriverHub.exe (PID: 1836)
    • Creates a software uninstall entry

      • DriverHub_.exe (PID: 3916)
      • PDClient.exe (PID: 3932)
    • Application based on Golang

      • IndexingManager.exe (PID: 1364)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:07:12 09:37:20+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 913408
InitializedDataSize: 40960
UninitializedDataSize: 1908736
EntryPoint: 0x2b1360
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.6.1.0
ProductVersionNumber: 1.6.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: DriverHub Installer
FileVersion: 1.6.1.0
InternalName: DriverHub
LegalCopyright: © ROSTPAY LTD. All rights reserved.
OriginalFileName: DriverHubInstaller.exe
ProductName: DriverHub
ProductVersion: 1.6.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
9
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start driver-hub-install__28.exe driverhub_.exe driverhub.exe no specs driverhub.exe pdclient.exe no specs pdclient.exe pdclient.exe indexingmanager.exe svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
972"C:\Users\admin\AppData\Local\Temp\driver-hub-install__28.exe" C:\Users\admin\AppData\Local\Temp\driver-hub-install__28.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
DriverHub Installer
Exit code:
3815968
Version:
1.6.1.0
Modules
Images
c:\users\admin\appdata\local\temp\driver-hub-install__28.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1092C:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1364"C:\Users\admin\AppData\Local\Programs\ProxymaData\IndexingManager.exe" -s a.collo.net:4000 -p drvdef -path "C:\Users\admin\AppData\Local\Programs\ProxymaData\Data"C:\Users\admin\AppData\Local\Programs\ProxymaData\IndexingManager.exe
PDClient.exe
User:
admin
Integrity Level:
HIGH
Description:
Indexing manager
Version:
1.4.0.0
Modules
Images
c:\users\admin\appdata\local\programs\proxymadata\indexingmanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
1504"C:\Users\admin\AppData\Local\Programs\DriverHub\DriverHub.exe" C:\Users\admin\AppData\Local\Programs\DriverHub\DriverHub.exeDriverHub_.exe
User:
admin
Company:
ROSTPAY LTD
Integrity Level:
MEDIUM
Description:
DriverHub
Exit code:
3221226540
Version:
1.5.2.1529
Modules
Images
c:\users\admin\appdata\local\programs\driverhub\driverhub.exe
c:\windows\system32\ntdll.dll
1556C:\Users\admin\AppData\Local\Programs\DriverHub\PDClient.exe init DriverHub /p=drvdefC:\Users\admin\AppData\Local\Programs\DriverHub\PDClient.exeDriverHub.exe
User:
admin
Company:
ProxymaData
Integrity Level:
HIGH
Description:
ProxymaData client
Exit code:
0
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\programs\driverhub\pdclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1836"C:\Users\admin\AppData\Local\Programs\DriverHub\DriverHub.exe" C:\Users\admin\AppData\Local\Programs\DriverHub\DriverHub.exe
DriverHub_.exe
User:
admin
Company:
ROSTPAY LTD
Integrity Level:
HIGH
Description:
DriverHub
Version:
1.5.2.1529
Modules
Images
c:\users\admin\appdata\local\programs\driverhub\driverhub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\driverhub\pdinterface.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3916"C:\Users\admin\AppData\Local\Temp\DriverHub_.exe" C:\Users\admin\AppData\Local\Temp\DriverHub_.exe
driver-hub-install__28.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Install DriverHub
Exit code:
0
Version:
4.4.8.0
Modules
Images
c:\users\admin\appdata\local\temp\driverhub_.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3932C:\Users\admin\AppData\Local\Programs\DriverHub\PDClient.exe start DriverHubC:\Users\admin\AppData\Local\Programs\DriverHub\PDClient.exe
DriverHub.exe
User:
admin
Company:
ProxymaData
Integrity Level:
HIGH
Description:
ProxymaData client
Exit code:
1
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\programs\driverhub\pdclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4024"C:\Users\admin\AppData\Local\Programs\ProxymaData\PDClient.exe" controlC:\Users\admin\AppData\Local\Programs\ProxymaData\PDClient.exe
PDClient.exe
User:
admin
Company:
ProxymaData
Integrity Level:
HIGH
Description:
ProxymaData client
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\programs\proxymadata\pdclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
38 352
Read events
38 221
Write events
131
Delete events
0

Modification events

(PID) Process:(1092) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\Intranet
Operation:writeName:{4040CF00-1B3E-486A-B407-FA14C56B6FC0}
Value:
D4DA6D384E1D
(PID) Process:(1092) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
Operation:writeName:DisallowedCertEncodedCtl
Value:
308217CC06092A864886F70D010702A08217BD308217B9020101310F300D060960864801650304020105003082082806092B0601040182370A01A082081930820815300C060A2B0601040182370A031E043844006900730061006C006C006F0077006500640043006500720074005F004100750074006F005500700064006100740065005F0031000000020801DC1E14133124BF170D3235303930353033323034385A300E060A2B0601040182370A0B0F0500308207A03012041025FB7A5D86F72F5E67288F797305FE94301204106F2D4365C1021F5B8B63EF132BC3B36030120410AD11DBB76C9CF1AB9998CD842EC1767330120410DFBDD72F99C3B64A797E5AC96D59BE5630120410C668154BE95E16ADBC321ABC316E384A3012041037392E833DC605DD7B38244739939EE3301204103179FE4B5726D8DB2AAF3DF958C96B9730120410C35A97C80F687DC3C108C6A3339B6846301204102118A4C6F718CFC7D6D8788C5374D32930120410526A39C04D15862D427FD925AF033690301204103C36E168ABCC859663ED47A0C05AEE7930120410019E7D56D60DB9ADEC40B967B1BCBA9F3012041036CDE99AB8737F86287C583704C95E163012041026990A77587ED8640184C49366ACB07530120410F69D22AE1ED615B1B9E390E310BBBB3130120410EBE90AD101D3802B8A4C913CACEE6A57301204101E25F24EDFB0C0042DBB6FBD3C164FB8301204102CFBA29E2941BD68F66BC8AD30A8CFA03012041004521AE08FC7F2A38B2CF3F42CA2B2EF30120410037B37211FDF7843FAE49F1095C9CC7C30120410CD8489DC816F7B6DD409217B7AE811E130120410E1BECA3A5B9B93C076868AE67259616430120410F484AC6384E95A10561948EB864BCF7E30120410C524C00E47BB634806519EFB8221AC6E3012041022415E18812213E92C14628B2E9DB93330120410BD4FEF1BEC8B66D0E6D82F31A69F668D301204105F46C2674E6AD9447CF0B8B1A16817B530120410C8EA502805EA91ECF225309D7680DA2030120410D4A562946BDB33ACE0EEE29D99012A5530120410B10113A1514B2BC4998E48CFFC43D2B23012041075988004E80FEFDA282B71E4EB4C4A27301204102E58E949E04E426A2756285AA8D8A65430120410303D9607B02C6E6692538BFB51F6490030120410821C38E6EA4982C2B3E2152056BE265630120410545D7ED132EE81964E011713847A8028301204108BE7BAA03A30CA4960BFF906C42C43D830120410038C0D981EA50C9D0A855079A9DEEAD3301204107E275085CE505F7F2D213D15083D8A2D30120410BFA642C6B7910E24F0FA716F1CBE72463012041049111016CEA72C750AD05482594D0E423012041098AC3D9CB49E647345E122BDC640255730120410C0DD97864D9711F283AC34D64FFAB4A73012041073ED86E95001191A351904E3FD88BBD830120410BFD758A84D6931B6C6EDB5B4CBC4F26E30120410EADAC36AF68F2A5085F1166EA0150B523012041020E187126C369C3B9E297406AE82C0DD30120410E5A2B5AB5A97D360B3EE0ED412514A673012041004006A1CD54DD8DAD570B32D0564B4EB301204105619EEABEBEC8A27D6B501B25B4A373330120410162B191198B2FF7B3F31BEE50755C1533012041066E534F738D3F8FDFD54D8E461EBA4A930120410A70911C6616FCE36DC21E2FF5830448630120410469BFACC6EB0475A3B7EAC02072DF82830120410ECF53D5A1C360851F7818F943787B50730120410E0B6E0809EAF9BB42DC3AE6E8EF946D3301204104A780DE17A65BE7DB50E389EFCB0962330120410C9B425C2B40FE84F1AA8351FAF80D5EE30120410FEF4D13CA362F34BE529F60C275D715130120410D8BBA29124845A8D5D26DD2777FBC491301204101E972959F5DA1670643F4008F3182251301204104FB025C8E7C36B154D44C4A550E013303012041060F77D31881A33EF9C68D5DEED478F39301204103B83E4CDC8DD15708AA2D7B510230C68301204100E17D3B58B9405D6BA6E40D009D878E530120410C067869C2293E87712C6D008A7C44B97301204106C77D5B68DEE40FED751EEA2E2A949BC3012041082E75C3A1751CC2FA04A34D55F459FB13012041021BCDF70EE77A9E7A8A478B9DAA2A9D330120410B34857F6BEDE2A972A4557E40DF932D230120410BDFD0E91A258C0F3D642449414D7B0FB30120410437929BE2B9804CB1ABFCEDD569041443012041094429A96DF64F763F13D06C646FF68C93012041072AF7274D540D6CB3E7A3E69DC7663F73012041055EF82227F4B93EEF44AE57BDCD7AF0430120410EA632F67702D8BAE21897DC0568B7A273012041066E4D74B0FDF3359E42F194835745B5530120410B549FE5D205A57DD3756ED2B32D359BD301204107630BCFB87E7FC032CBCFF432276649F30120410966A334F1B89752B6E9B3D636EFBCD043012041062DAF46D4586D188049F9F23C0622C67301204107B3C70941C0DA531BA7F336B2A4AE04130120410A3F1B5889C142AFF8AC93B49DBFBCB18303204306E5BA5A2E61BD0D3831C2CAA33AE7CE5C95E92ABF0592FF8038CCDBC6B4BE61D3718D1308FE489209D2B283CE4BF8E2530320430E0204E0F7BA06E1F75608BE1BD6267C5E0B61364CC3B4E871F6210547D0BB836DA996DA1D5496B14B19B4B695EAF6A5730320430DC820CA48D97355F2802FD38413783C01D3C3B8D02AAD00709E66D5B5BEE7DB02184E6BA2571941F9525F8AB68E93C6D30320430A1A13D594D27718794367FF3DB7100403971F686857D11B811D0BE96BA0CC0756A2D3E64AECFE6AF08584488B6F96F3430320430E205022402A5A94315CB9D573BCEA9D112F159A55F0C9D26EA79E087B4AA27513E6048B0088EEC5E0FE60AC52DC53260303204304FC605C322F76F4D655179DB89629F3928C36D92B63F609BDD58294387986E121482541B3FC246AB9BFDC1D6E4FEF7A3A0820D1A30820605308203EDA003020102021333000000788BFC5B4B88F5EFF4000000000078300D06092A864886F70D01010B0500308181310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E312B3029060355040313224D6963726F736F6674204365727469666963617465204C6973742043412032303131301E170D3235303631393138313534315A170D3236303332383138313534315A308189310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E313330310603550403132A4D6963726F736F6674204365727469666963617465205472757374204C697374205075626C697368657230820122300D06092A864886F70D01010105000382010F003082010A0282010100CD2F48AA408CC1CD48476B46123D886CB7D3C0489CCCAB4F9D504C15F930A552D1A844F649BB2A465B32BC92ACD621B8A3BF23E4E80015FD474F5A2C604EDCD35DA3A1A16C5E5119034D457914A9BD99FFD9D72BA46E97E81BB83CB1A7CE3F22E94ED6B240D7F5D57E7CB3BD0CB990DACC92F4AD2186326199F9991009BF2F56BFBE39A8F74EE6B54283177BAD4105A04F8805D2D65ECE37E4440C07FFA322FCCE666511DE7BED3EBA8D3E568730871FCBB1522F5FD6826EB7504906EEFD3A232AE283490575857B69B0822F8DE010BA2078EA873A7F2C142E112B77734FB5D33267EEEA7B837CAA5D89DA0AC1263BDB13B62FF954914EB2B32100776DD066070203010001A382016A3082016630150603551D25040E300C060A2B0601040182370A0309301D0603551D0E041604142A229D011D74FA6A5048AEB5694FC3442237DBF230450603551D11043E303CA43A3038311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E311630140603550405130D3232393838372B353035323833301F0603551D2304183016801441F021C7EDC487FA8375FF0A0CDC2DECA86AAB5930590603551D1F04523050304EA04CA04A8648687474703A2F2F63726C2E6D6963726F736F66742E636F6D2F706B692F63726C2F70726F64756374732F4D69634365724C69734341323031315F323031312D30332D32392E63726C305D06082B060105050701010451304F304D06082B060105050730028641687474703A2F2F7777772E6D6963726F736F66742E636F6D2F706B692F63657274732F4D69634365724C69734341323031315F323031312D30332D32392E637274300C0603551D130101FF04023000300D06092A864886F70D01010B0500038202010045F46F7E1D92FAE7D5E849B81B5811EBA60A0A0A436B69AFA97F2B7BE14EF79522C4CFDFB73B81E794008F00EADDDD88311D3C47AC8557A15A24D314B670A3B37F0C4AFA0CA2B0E121D93170FB94E4AEAA064FAB4AF3FCC370EFECFB7D908213AFEAAC394BFB471C62D1AEDD5DCBA5966BBCE7F09D699D58CC5AEC5B87F686EE225C0C7BC2C0C824F4EE919682DA9203D3ACFEC71B65ADA7E0CAEC33695B83C9A1F07B28FF0D57587D20379B3A8EF585ED5DE6F815DA342FEE530BB8559ED59004117E2CC8D0A2AF737E64E5D0F2AC34F23B95B962C8AE6DFE774A24D5E02D8C136263367E18375205491479583CA67F5F5C86BF4FC28010846BBF9B52EDAAF55BCCD695F8D3F38B349D33BF20601CDFDA063A1C4BDF11D93466B66B84EBF169EFA7A143DBC52EED7EC911F4D7001F5ED3536229BA2ED38E7AB99F6D6889C6DA4EE6C3D9C1133ADB0E81858F18B579AFF75DFD3A5327ED2A5FDD020C901904C67228A94B577147C79CC474D1B3CBA9FE85E1098C1A4F94EA6E5E21A5E29E718D320E4BE05339A008A0F6AF379D42A6FA09E05AC235E4B37A9ACB434726A1D98C88B76AB85913369385EF7CD69ADDF5847802CD8B916C6DEC9844B17E1E546383FE38C6B2127A9DB8010D5AE3ECA954314173732EEF00293A1B15D913DAC5C9EB5BBC1AF0E9B231F99D7495AD05DA27439B1132AB743720A5CE74749A693546EA3082070D308204F5A003020102020A61116C92000000000007300D06092A864886F70D01010B0500308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F726974792032303130301E170D3131303332393138353833395A170D3236303332393139303833395A308181310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E312B3029060355040313224D6963726F736F6674204365727469666963617465204C697374204341203230313130820222300D06092A864886F70D01010105000382020F003082020A0282020100B8847A80FD4D27A7D2EF8236F153059DBE426D8E310847CBCDB3830A4B4E331A2E7CDD72818DCE90FC3C05CB2F3485388F3C1C686D6051524DACDA6D2B7EB37347ABD2DC95714A31815AA11FAB8226452D8CE88478BD20F00DC6F5AE26871E568E553C083032949422930BA5B0C65DE62D8139CDE9C7AEE8D8497149AB9174B84F8D2F47B33FD093835C021ADE4BB8B23C37E993EA725B98C7E3AC18E0E67E4AC1812CFD22147673E168DC2009C0F346CD2326C84522CAC7BC74FC89FF57E0CFBD8EB02BEF26D677AB1AF46741F15E0C71AA027F5EC082AA098BEC898841F5034269D91F45D9573E04964AD532B7D1612668C7C1B1A0E07A054EB56DC282E02EB6E7649F167D952A8632D021C85DF8CB05301EB902986CB3936BC88367215DD665982064DDCBBF479BFF18FAF190DEA778CD7B04867E278AB7959C26DDB196FC4FE040208368DDEC33F22AA007A7EB91FAAC0F514188F1C587414C8747629D58C09E7FBB127DDED39FFDC1C714BD7F98D0579BE1E36C57E1655FF0DC2B9CA154C2562A1564CBAA4EE4FDC3E87788FFDB0DAF909FD76881012F94E1AFC6E4C676DB75DADFD0124CF289366F48808158DD1709282B55AC9323E58E3165AD0D8E93D371A7811498E9ACAA0558EED74443306D1DC7BAC27FF548C4E5A08E558EB409C001C39D1D46F5FE46B53A008823B5F0CA41CD3B0DC6F6CA4004EA9BE588369F0203010001A382017C30820178301006092B06010401823715010403020100301D0603551D0E0416041441F021C7EDC487FA8375FF0A0CDC2DECA86AAB59301906092B0601040182371402040C1E0A00530075006200430041300B0603551D0F040403020186300F0603551D130101FF040530030101FF301F0603551D23041830168014D5F656CB8FE8A25C6268D13D94905BD7CE9A18C430560603551D1F044F304D304BA049A0478645687474703A2F2F63726C2E6D6963726F736F66742E636F6D2F706B692F63726C2F70726F64756374732F4D6963526F6F4365724175745F323031302D30362D32332E63726C305A06082B06010505070101044E304C304A06082B06010505073002863E687474703A2F2F7777772E6D6963726F736F66742E636F6D2F706B692F63657274732F4D6963526F6F4365724175745F323031302D30362D32332E63727430370603551D250430302E06082B06010505070303060A2B0601040182370A0301060A2B0601040182370A0309060A2B0601040182370A0313300D06092A864886F70D01010B0500038202010082F7A9A5B3BFE5C8594127340F629C41F0AB2B7DF9A7A8C8A80F5D43BEADF299F8FFFBF67950440C50EA42DB9D01E9A549792829133E40367416DB8F20CC8D2D5110DC2B41367CB6D040139B1C00374C816968B11A82963B6975C7E534D83EDC5A09ABD3BFA9AFC4086FE347C632EF25E90B0B551294EF871419D2E121DE37CFAEA6345D232904046D6DE71ADD443079741A8D8CC1F93EF9AD306BA3B46A7449395B372D0119EE0329DDAE4A2FF982AF481F149A9C3D253156EA3AA74DB7FD8B3FFEBF77368B55E5B31050EE54D4BF6BD82AF233782EBF31F93611EF300BF94C4383E35BA95C1D5BA67605B8F0754FE9B81F3644A67F66D04B0D18551E742E2727E52642836EBBA4EF7BF9E498BDD53B89D35892B8D1CD167F397E66250DDB8359BF571F9BD2E91B72275D6B33D1FEA2924C513DC6CC943A56FFEB10412EDD9253CD10F11D36EB041ADB35D991B699600FE00BAC670C44169C0247CBB74696490FDF03B10FAD0E12AD480536E12D3FBB5AE094D49792E93EE6EB2519CB33F1DF936090A6B90E56F628E942C71E105BA62E0FB9DBA964D78EE533D29D43824B6E3766B90D6757545A480EE38AFB1FED0A26BC0D34D20A4785612A23B1E0548A50145685C0FF2DF76999447D1AF44D7C180EE10707EE0966524A7A1A62A4E58BCF85A2868A7190B17DD611D3511EDA5CE7CCD6121076A8AE4F93B564C9BDEDDCFB3182025730820253020101308199308181310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E312B3029060355040313224D6963726F736F6674204365727469666963617465204C6973742043412032303131021333000000788BFC5B4B88F5EFF4000000000078300D06096086480165030402010500A0818F301806092A864886F70D010903310B06092B0601040182370A01302F06092A864886F70D01090431220420AD717861821FB744DEEE74835C5A8AC6FA38FC1CA4FE0B66865DC9EBB44558AF3042060A2B06010401823702010C31343032A0148012004D006900630072006F0073006F00660074A11A8018687474703A2F2F7777772E6D6963726F736F66742E636F6D300D06092A864886F70D0101010500048201006BC5015BB054BC0000B819475BE8ABC2033E7610EED6BE46B3741A261C7F6AA690F428E6410440D0A932F1C8B08E87D1E921E356051C96AE765452823A309E9027632F7FC04DEC88E082C35AB9752BC9104A28B68F682B164928CF7F84F1E0E85AA357D608DFFCF8216508FB9B1F62316E07F7FA913F6DD7AA029D0F737DCC18D8F058DB3CCF48410C11A607E4232341F609BA77A276924CBFFCF35DBC45F49AD6573F95E38CD493AF5C10E827362A6CAA5A945C833A767C0299766802249C30CB43ACA5564C557F4173A277E7AC2D180E92027DBBB98F1626DEEC5BB5F67B14A5DCF23E4E251E11F2A492C1F99F7AD309C70AE931FE622FBA6BBCA17EC410C0
(PID) Process:(1092) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
Operation:writeName:DisallowedCertLastSyncTime
Value:
A0F8AEB4E986DC01
(PID) Process:(972) driver-hub-install__28.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(972) driver-hub-install__28.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(972) driver-hub-install__28.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(972) driver-hub-install__28.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3916) DriverHub_.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
DriverHub_.exe
(PID) Process:(3916) DriverHub_.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DriverHub__RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3916) DriverHub_.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DriverHub__RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
62
Suspicious files
166
Text files
568
Unknown types
0

Dropped files

PID
Process
Filename
Type
1092svchost.exeC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\TarEF54.tmpbinary
MD5:E4B65A98063D5A8B8BBAF332FFBF7EE8
SHA256:400800C461437E5E304EC4A597ACC79436E522AFD0ACB7E32CC01FF26D3133DC
972driver-hub-install__28.exeC:\Users\admin\AppData\Local\Temp\DriverHub_.exebinary
MD5:15E6EDFD0A0B018541EB6F9B66B77620
SHA256:C444CB4D8C5286281B7FE3B77AE6571C7EE16DAFE394ADED585EF7D746E7204B
1092svchost.exeC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\CabEF53.tmpcompressed
MD5:5F036F91E86E30F749961506951D51EB
SHA256:0300E9DDB527990E8B59D06E9CCF3EC2BD92D3BBD0EF4FBA69D6336E4195E82D
3916DriverHub_.exeC:\Users\admin\AppData\Local\Programs\DriverHub\libEGL.dllexecutable
MD5:E0E4011346A86083A0EC8EB01136D0BA
SHA256:411966CE4F8FEBB2FE3AB84B97ED9FB9062AB60C6211FC3B3E4A25A5EE607ECB
972driver-hub-install__28.exeC:\Users\admin\AppData\Local\Temp\_.txtbinary
MD5:8EBCBBC6AE03A3D6186B53742A835983
SHA256:0EA77D7301F2D8E1D9FAD3610A06E8C3B59F4F82EEE909F459633DF252A08A1B
3916DriverHub_.exeC:\Users\admin\AppData\Local\Programs\DriverHub\Microsoft.Win32.TaskScheduler.dllexecutable
MD5:0616EA42B68A8F5F2F01BCD985BDCBC7
SHA256:EA27C65491119EEE5C8E87CE3D470783580DB8FC5BD141C496768D7D0CCE779A
3916DriverHub_.exeC:\Users\admin\AppData\Local\Programs\DriverHub\Credits.txttext
MD5:12E055C9F638057EA5FA160F15B3B5A6
SHA256:3F45CA9EF9B9BBD890B4C159703D92D906F1AAAE0CE57763F26B6A33377BAD5A
3916DriverHub_.exeC:\Users\admin\AppData\Local\Programs\DriverHub\Images\DriverHubLogo.pngimage
MD5:451B153070269850DA133D4E493A1BD6
SHA256:91D221FE4045038100274A1A32F8155C0195517C51A712B1F742A4F5BBB45E4B
3916DriverHub_.exeC:\Users\admin\AppData\Local\Programs\DriverHub\DriverHubUninstaller.exeexecutable
MD5:1B06359502DBFAD35CE773CBBEE4BCE2
SHA256:357526C2D0CA1A382AE650AC8384808E9B37A6981D0A5F574BA7B4419BFFAB7D
3916DriverHub_.exeC:\Users\admin\AppData\Local\Programs\DriverHub\libcurl.dllexecutable
MD5:E5064ADFBC48E3FB81F09E7B8E78D49D
SHA256:4BFCAEE356CF1B99D3DBC03D42018FCFC29271C6A72B373343D24C45A7569489
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
42
TCP/UDP connections
40
DNS requests
20
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
972
driver-hub-install__28.exe
HEAD
301
188.130.153.33:443
https://www.drvhub.net/app/download
RU
unknown
972
driver-hub-install__28.exe
HEAD
302
188.130.153.33:443
https://www.drvhub.net/products/free/download
RU
unknown
972
driver-hub-install__28.exe
HEAD
200
188.130.153.32:443
https://www.az-partners.net/apps/driver-hub/download?ap=28&driver-hub-install.exe
RU
unknown
3916
DriverHub_.exe
HEAD
301
188.130.153.33:443
https://drvhub.net/products/free/download
RU
unknown
3916
DriverHub_.exe
HEAD
200
188.130.153.33:443
https://www.drvhub.net/products/free/download
RU
unknown
484
lsass.exe
GET
200
2.20.245.170:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7967cf888cb1c6c7
NL
compressed
4.87 Kb
unknown
484
lsass.exe
GET
200
151.101.130.133:80
http://ocsp.globalsign.com/gsgccr6alphasslca2023/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTYuQbxgZqJCf3D06HBxH57o5XEXgQUvQW384qTPHPLefoPhRKhd5YYkXQCDFlLKIswa%2F9W2fZzlA%3D%3D
US
binary
1.42 Kb
whitelisted
484
lsass.exe
GET
200
151.101.130.133:80
http://ocsp2.globalsign.com/rootr6/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRi%2B7TJbHYn9EmJ9W03lecB7P%2BG7QQUrmwFo5MT4qLn4tcc1sfwf8hnU6ACEH8fLJAug9Djtvs77keLXoA%3D
US
binary
1.65 Kb
unknown
484
lsass.exe
GET
200
23.222.81.129:80
http://x1.c.lencr.org/
US
binary
734 b
unknown
484
lsass.exe
GET
200
104.18.21.213:80
http://r12.c.lencr.org/79.crl
US
binary
229 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
972
driver-hub-install__28.exe
188.130.153.33:443
api.az-partners.net
ROSTPAY-AS
RU
whitelisted
1092
svchost.exe
224.0.0.252:5355
whitelisted
484
lsass.exe
2.20.245.170:80
ctldl.windowsupdate.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
484
lsass.exe
151.101.130.133:80
ocsp2.globalsign.com
FASTLY
US
whitelisted
484
lsass.exe
23.222.81.129:80
x1.c.lencr.org
AKAMAI-AS
US
whitelisted
484
lsass.exe
104.18.21.213:80
r12.c.lencr.org
CLOUDFLARENET
US
whitelisted
972
driver-hub-install__28.exe
188.130.153.32:443
api.az-partners.net
ROSTPAY-AS
RU
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
api.az-partners.net
  • 188.130.153.33
  • 188.130.153.32
unknown
ctldl.windowsupdate.com
  • 2.20.245.170
  • 2.16.168.51
  • 2.16.168.38
  • 2.20.245.182
  • 2.16.168.54
whitelisted
ocsp2.globalsign.com
  • 151.101.130.133
  • 151.101.66.133
  • 151.101.194.133
  • 151.101.2.133
whitelisted
ocsp.globalsign.com
  • 151.101.130.133
  • 151.101.66.133
  • 151.101.194.133
  • 151.101.2.133
whitelisted
www.drvhub.net
  • 188.130.153.33
  • 188.130.153.32
unknown
x1.c.lencr.org
  • 23.222.81.129
whitelisted
r12.c.lencr.org
  • 104.18.21.213
  • 104.18.20.213
whitelisted
www.az-partners.net
  • 188.130.153.32
  • 188.130.153.33
malicious
drvhub.net
  • 188.130.153.33
  • 188.130.153.32
whitelisted

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
Misc activity
ET INFO EXE - Served Attached HTTP
Process
Message
DriverHub.exe
qrc:/UpdateProgressDialog.qml:11:5: QML Connections: Implicitly defined onFoo properties in Connections are deprecated. Use this syntax instead: function onFoo(<arguments>) { ... }
DriverHub.exe
qrc:/main.qml:634:13: QML Connections: Implicitly defined onFoo properties in Connections are deprecated. Use this syntax instead: function onFoo(<arguments>) { ... }
DriverHub.exe
qrc:/main.qml:432:31: QML ItemDelegate: Binding loop detected for property "height"
DriverHub.exe
qml: State SCAN
DriverHub.exe
file:///C:/Users/admin/AppData/Local/Programs/DriverHub/QtQuick/Dialogs/DefaultFileDialog.qml:102:33: QML Settings: Failed to initialize QSettings instance. Status code is: 1
DriverHub.exe
file:///C:/Users/admin/AppData/Local/Programs/DriverHub/QtQuick/Dialogs/DefaultFileDialog.qml:102:33: QML Settings: The following application identifiers have not been set: QVector("organizationName", "organizationDomain")
DriverHub.exe
qrc:/SettingsPage.qml:50:9: QML MyCheckBox: Binding loop detected for property "width"
DriverHub.exe
qrc:/SettingsPage.qml:50:9: QML MyCheckBox: Binding loop detected for property "width"
DriverHub.exe
qrc:/SettingsPage.qml:50:9: QML MyCheckBox: Binding loop detected for property "width"
DriverHub.exe
qrc:/SettingsPage.qml:32:9: QML MyCheckBox: Binding loop detected for property "width"