| File name: | driver-hub-install__28.exe |
| Full analysis: | https://app.any.run/tasks/feaaff7f-17d1-40bb-965b-ef8cf5b8a3e4 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | January 16, 2026, 13:11:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections |
| MD5: | 4652AC4A0B4CF5E66B041491C1BDA467 |
| SHA1: | D42D90E731920BB3B57E994B894A054FD94834B7 |
| SHA256: | F2DBBB488279ACA7EF992D3F249E96F47963ABFD932BE33F3BE85E25A49213DC |
| SSDEEP: | 49152:j4q4V8sSgnwBW/UyeEd63YM+yaWDeS4O1K79rPgrJtKM1jX0kqs+NOIyI6fARfxs:j4Bh4c/DpSgrPukzpy7RwxW0lSB |
| .exe | | | UPX compressed Win32 Executable (64.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.6) |
| .exe | | | Win32 Executable (generic) (10.6) |
| .exe | | | Generic Win/DOS Executable (4.7) |
| .exe | | | DOS Executable Generic (4.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:07:12 09:37:20+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 913408 |
| InitializedDataSize: | 40960 |
| UninitializedDataSize: | 1908736 |
| EntryPoint: | 0x2b1360 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.6.1.0 |
| ProductVersionNumber: | 1.6.1.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileDescription: | DriverHub Installer |
| FileVersion: | 1.6.1.0 |
| InternalName: | DriverHub |
| LegalCopyright: | © ROSTPAY LTD. All rights reserved. |
| OriginalFileName: | DriverHubInstaller.exe |
| ProductName: | DriverHub |
| ProductVersion: | 1.6.1.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 972 | "C:\Users\admin\AppData\Local\Temp\driver-hub-install__28.exe" | C:\Users\admin\AppData\Local\Temp\driver-hub-install__28.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: DriverHub Installer Exit code: 3815968 Version: 1.6.1.0 Modules
| |||||||||||||||
| 1092 | C:\Windows\system32\svchost.exe -k NetworkService | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1364 | "C:\Users\admin\AppData\Local\Programs\ProxymaData\IndexingManager.exe" -s a.collo.net:4000 -p drvdef -path "C:\Users\admin\AppData\Local\Programs\ProxymaData\Data" | C:\Users\admin\AppData\Local\Programs\ProxymaData\IndexingManager.exe | PDClient.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Indexing manager Version: 1.4.0.0 Modules
| |||||||||||||||
| 1504 | "C:\Users\admin\AppData\Local\Programs\DriverHub\DriverHub.exe" | C:\Users\admin\AppData\Local\Programs\DriverHub\DriverHub.exe | — | DriverHub_.exe | |||||||||||
User: admin Company: ROSTPAY LTD Integrity Level: MEDIUM Description: DriverHub Exit code: 3221226540 Version: 1.5.2.1529 Modules
| |||||||||||||||
| 1556 | C:\Users\admin\AppData\Local\Programs\DriverHub\PDClient.exe init DriverHub /p=drvdef | C:\Users\admin\AppData\Local\Programs\DriverHub\PDClient.exe | — | DriverHub.exe | |||||||||||
User: admin Company: ProxymaData Integrity Level: HIGH Description: ProxymaData client Exit code: 0 Version: 2.1.0.0 Modules
| |||||||||||||||
| 1836 | "C:\Users\admin\AppData\Local\Programs\DriverHub\DriverHub.exe" | C:\Users\admin\AppData\Local\Programs\DriverHub\DriverHub.exe | DriverHub_.exe | ||||||||||||
User: admin Company: ROSTPAY LTD Integrity Level: HIGH Description: DriverHub Version: 1.5.2.1529 Modules
| |||||||||||||||
| 3916 | "C:\Users\admin\AppData\Local\Temp\DriverHub_.exe" | C:\Users\admin\AppData\Local\Temp\DriverHub_.exe | driver-hub-install__28.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Install DriverHub Exit code: 0 Version: 4.4.8.0 Modules
| |||||||||||||||
| 3932 | C:\Users\admin\AppData\Local\Programs\DriverHub\PDClient.exe start DriverHub | C:\Users\admin\AppData\Local\Programs\DriverHub\PDClient.exe | DriverHub.exe | ||||||||||||
User: admin Company: ProxymaData Integrity Level: HIGH Description: ProxymaData client Exit code: 1 Version: 2.1.0.0 Modules
| |||||||||||||||
| 4024 | "C:\Users\admin\AppData\Local\Programs\ProxymaData\PDClient.exe" control | C:\Users\admin\AppData\Local\Programs\ProxymaData\PDClient.exe | PDClient.exe | ||||||||||||
User: admin Company: ProxymaData Integrity Level: HIGH Description: ProxymaData client Version: 2.1.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1092) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\Intranet |
| Operation: | write | Name: | {4040CF00-1B3E-486A-B407-FA14C56B6FC0} |
Value: D4DA6D384E1D | |||
| (PID) Process: | (1092) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate |
| Operation: | write | Name: | DisallowedCertEncodedCtl |
Value: 308217CC06092A864886F70D010702A08217BD308217B9020101310F300D060960864801650304020105003082082806092B0601040182370A01A082081930820815300C060A2B0601040182370A031E043844006900730061006C006C006F0077006500640043006500720074005F004100750074006F005500700064006100740065005F0031000000020801DC1E14133124BF170D3235303930353033323034385A300E060A2B0601040182370A0B0F0500308207A03012041025FB7A5D86F72F5E67288F797305FE94301204106F2D4365C1021F5B8B63EF132BC3B36030120410AD11DBB76C9CF1AB9998CD842EC1767330120410DFBDD72F99C3B64A797E5AC96D59BE5630120410C668154BE95E16ADBC321ABC316E384A3012041037392E833DC605DD7B38244739939EE3301204103179FE4B5726D8DB2AAF3DF958C96B9730120410C35A97C80F687DC3C108C6A3339B6846301204102118A4C6F718CFC7D6D8788C5374D32930120410526A39C04D15862D427FD925AF033690301204103C36E168ABCC859663ED47A0C05AEE7930120410019E7D56D60DB9ADEC40B967B1BCBA9F3012041036CDE99AB8737F86287C583704C95E163012041026990A77587ED8640184C49366ACB07530120410F69D22AE1ED615B1B9E390E310BBBB3130120410EBE90AD101D3802B8A4C913CACEE6A57301204101E25F24EDFB0C0042DBB6FBD3C164FB8301204102CFBA29E2941BD68F66BC8AD30A8CFA03012041004521AE08FC7F2A38B2CF3F42CA2B2EF30120410037B37211FDF7843FAE49F1095C9CC7C30120410CD8489DC816F7B6DD409217B7AE811E130120410E1BECA3A5B9B93C076868AE67259616430120410F484AC6384E95A10561948EB864BCF7E30120410C524C00E47BB634806519EFB8221AC6E3012041022415E18812213E92C14628B2E9DB93330120410BD4FEF1BEC8B66D0E6D82F31A69F668D301204105F46C2674E6AD9447CF0B8B1A16817B530120410C8EA502805EA91ECF225309D7680DA2030120410D4A562946BDB33ACE0EEE29D99012A5530120410B10113A1514B2BC4998E48CFFC43D2B23012041075988004E80FEFDA282B71E4EB4C4A27301204102E58E949E04E426A2756285AA8D8A65430120410303D9607B02C6E6692538BFB51F6490030120410821C38E6EA4982C2B3E2152056BE265630120410545D7ED132EE81964E011713847A8028301204108BE7BAA03A30CA4960BFF906C42C43D830120410038C0D981EA50C9D0A855079A9DEEAD3301204107E275085CE505F7F2D213D15083D8A2D30120410BFA642C6B7910E24F0FA716F1CBE72463012041049111016CEA72C750AD05482594D0E423012041098AC3D9CB49E647345E122BDC640255730120410C0DD97864D9711F283AC34D64FFAB4A73012041073ED86E95001191A351904E3FD88BBD830120410BFD758A84D6931B6C6EDB5B4CBC4F26E30120410EADAC36AF68F2A5085F1166EA0150B523012041020E187126C369C3B9E297406AE82C0DD30120410E5A2B5AB5A97D360B3EE0ED412514A673012041004006A1CD54DD8DAD570B32D0564B4EB301204105619EEABEBEC8A27D6B501B25B4A373330120410162B191198B2FF7B3F31BEE50755C1533012041066E534F738D3F8FDFD54D8E461EBA4A930120410A70911C6616FCE36DC21E2FF5830448630120410469BFACC6EB0475A3B7EAC02072DF82830120410ECF53D5A1C360851F7818F943787B50730120410E0B6E0809EAF9BB42DC3AE6E8EF946D3301204104A780DE17A65BE7DB50E389EFCB0962330120410C9B425C2B40FE84F1AA8351FAF80D5EE30120410FEF4D13CA362F34BE529F60C275D715130120410D8BBA29124845A8D5D26DD2777FBC491301204101E972959F5DA1670643F4008F3182251301204104FB025C8E7C36B154D44C4A550E013303012041060F77D31881A33EF9C68D5DEED478F39301204103B83E4CDC8DD15708AA2D7B510230C68301204100E17D3B58B9405D6BA6E40D009D878E530120410C067869C2293E87712C6D008A7C44B97301204106C77D5B68DEE40FED751EEA2E2A949BC3012041082E75C3A1751CC2FA04A34D55F459FB13012041021BCDF70EE77A9E7A8A478B9DAA2A9D330120410B34857F6BEDE2A972A4557E40DF932D230120410BDFD0E91A258C0F3D642449414D7B0FB30120410437929BE2B9804CB1ABFCEDD569041443012041094429A96DF64F763F13D06C646FF68C93012041072AF7274D540D6CB3E7A3E69DC7663F73012041055EF82227F4B93EEF44AE57BDCD7AF0430120410EA632F67702D8BAE21897DC0568B7A273012041066E4D74B0FDF3359E42F194835745B5530120410B549FE5D205A57DD3756ED2B32D359BD301204107630BCFB87E7FC032CBCFF432276649F30120410966A334F1B89752B6E9B3D636EFBCD043012041062DAF46D4586D188049F9F23C0622C67301204107B3C70941C0DA531BA7F336B2A4AE04130120410A3F1B5889C142AFF8AC93B49DBFBCB18303204306E5BA5A2E61BD0D3831C2CAA33AE7CE5C95E92ABF0592FF8038CCDBC6B4BE61D3718D1308FE489209D2B283CE4BF8E2530320430E0204E0F7BA06E1F75608BE1BD6267C5E0B61364CC3B4E871F6210547D0BB836DA996DA1D5496B14B19B4B695EAF6A5730320430DC820CA48D97355F2802FD38413783C01D3C3B8D02AAD00709E66D5B5BEE7DB02184E6BA2571941F9525F8AB68E93C6D30320430A1A13D594D27718794367FF3DB7100403971F686857D11B811D0BE96BA0CC0756A2D3E64AECFE6AF08584488B6F96F3430320430E205022402A5A94315CB9D573BCEA9D112F159A55F0C9D26EA79E087B4AA27513E6048B0088EEC5E0FE60AC52DC53260303204304FC605C322F76F4D655179DB89629F3928C36D92B63F609BDD58294387986E121482541B3FC246AB9BFDC1D6E4FEF7A3A0820D1A30820605308203EDA003020102021333000000788BFC5B4B88F5EFF4000000000078300D06092A864886F70D01010B0500308181310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E312B3029060355040313224D6963726F736F6674204365727469666963617465204C6973742043412032303131301E170D3235303631393138313534315A170D3236303332383138313534315A308189310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E313330310603550403132A4D6963726F736F6674204365727469666963617465205472757374204C697374205075626C697368657230820122300D06092A864886F70D01010105000382010F003082010A0282010100CD2F48AA408CC1CD48476B46123D886CB7D3C0489CCCAB4F9D504C15F930A552D1A844F649BB2A465B32BC92ACD621B8A3BF23E4E80015FD474F5A2C604EDCD35DA3A1A16C5E5119034D457914A9BD99FFD9D72BA46E97E81BB83CB1A7CE3F22E94ED6B240D7F5D57E7CB3BD0CB990DACC92F4AD2186326199F9991009BF2F56BFBE39A8F74EE6B54283177BAD4105A04F8805D2D65ECE37E4440C07FFA322FCCE666511DE7BED3EBA8D3E568730871FCBB1522F5FD6826EB7504906EEFD3A232AE283490575857B69B0822F8DE010BA2078EA873A7F2C142E112B77734FB5D33267EEEA7B837CAA5D89DA0AC1263BDB13B62FF954914EB2B32100776DD066070203010001A382016A3082016630150603551D25040E300C060A2B0601040182370A0309301D0603551D0E041604142A229D011D74FA6A5048AEB5694FC3442237DBF230450603551D11043E303CA43A3038311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E311630140603550405130D3232393838372B353035323833301F0603551D2304183016801441F021C7EDC487FA8375FF0A0CDC2DECA86AAB5930590603551D1F04523050304EA04CA04A8648687474703A2F2F63726C2E6D6963726F736F66742E636F6D2F706B692F63726C2F70726F64756374732F4D69634365724C69734341323031315F323031312D30332D32392E63726C305D06082B060105050701010451304F304D06082B060105050730028641687474703A2F2F7777772E6D6963726F736F66742E636F6D2F706B692F63657274732F4D69634365724C69734341323031315F323031312D30332D32392E637274300C0603551D130101FF04023000300D06092A864886F70D01010B0500038202010045F46F7E1D92FAE7D5E849B81B5811EBA60A0A0A436B69AFA97F2B7BE14EF79522C4CFDFB73B81E794008F00EADDDD88311D3C47AC8557A15A24D314B670A3B37F0C4AFA0CA2B0E121D93170FB94E4AEAA064FAB4AF3FCC370EFECFB7D908213AFEAAC394BFB471C62D1AEDD5DCBA5966BBCE7F09D699D58CC5AEC5B87F686EE225C0C7BC2C0C824F4EE919682DA9203D3ACFEC71B65ADA7E0CAEC33695B83C9A1F07B28FF0D57587D20379B3A8EF585ED5DE6F815DA342FEE530BB8559ED59004117E2CC8D0A2AF737E64E5D0F2AC34F23B95B962C8AE6DFE774A24D5E02D8C136263367E18375205491479583CA67F5F5C86BF4FC28010846BBF9B52EDAAF55BCCD695F8D3F38B349D33BF20601CDFDA063A1C4BDF11D93466B66B84EBF169EFA7A143DBC52EED7EC911F4D7001F5ED3536229BA2ED38E7AB99F6D6889C6DA4EE6C3D9C1133ADB0E81858F18B579AFF75DFD3A5327ED2A5FDD020C901904C67228A94B577147C79CC474D1B3CBA9FE85E1098C1A4F94EA6E5E21A5E29E718D320E4BE05339A008A0F6AF379D42A6FA09E05AC235E4B37A9ACB434726A1D98C88B76AB85913369385EF7CD69ADDF5847802CD8B916C6DEC9844B17E1E546383FE38C6B2127A9DB8010D5AE3ECA954314173732EEF00293A1B15D913DAC5C9EB5BBC1AF0E9B231F99D7495AD05DA27439B1132AB743720A5CE74749A693546EA3082070D308204F5A003020102020A61116C92000000000007300D06092A864886F70D01010B0500308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F726974792032303130301E170D3131303332393138353833395A170D3236303332393139303833395A308181310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E312B3029060355040313224D6963726F736F6674204365727469666963617465204C697374204341203230313130820222300D06092A864886F70D01010105000382020F003082020A0282020100B8847A80FD4D27A7D2EF8236F153059DBE426D8E310847CBCDB3830A4B4E331A2E7CDD72818DCE90FC3C05CB2F3485388F3C1C686D6051524DACDA6D2B7EB37347ABD2DC95714A31815AA11FAB8226452D8CE88478BD20F00DC6F5AE26871E568E553C083032949422930BA5B0C65DE62D8139CDE9C7AEE8D8497149AB9174B84F8D2F47B33FD093835C021ADE4BB8B23C37E993EA725B98C7E3AC18E0E67E4AC1812CFD22147673E168DC2009C0F346CD2326C84522CAC7BC74FC89FF57E0CFBD8EB02BEF26D677AB1AF46741F15E0C71AA027F5EC082AA098BEC898841F5034269D91F45D9573E04964AD532B7D1612668C7C1B1A0E07A054EB56DC282E02EB6E7649F167D952A8632D021C85DF8CB05301EB902986CB3936BC88367215DD665982064DDCBBF479BFF18FAF190DEA778CD7B04867E278AB7959C26DDB196FC4FE040208368DDEC33F22AA007A7EB91FAAC0F514188F1C587414C8747629D58C09E7FBB127DDED39FFDC1C714BD7F98D0579BE1E36C57E1655FF0DC2B9CA154C2562A1564CBAA4EE4FDC3E87788FFDB0DAF909FD76881012F94E1AFC6E4C676DB75DADFD0124CF289366F48808158DD1709282B55AC9323E58E3165AD0D8E93D371A7811498E9ACAA0558EED74443306D1DC7BAC27FF548C4E5A08E558EB409C001C39D1D46F5FE46B53A008823B5F0CA41CD3B0DC6F6CA4004EA9BE588369F0203010001A382017C30820178301006092B06010401823715010403020100301D0603551D0E0416041441F021C7EDC487FA8375FF0A0CDC2DECA86AAB59301906092B0601040182371402040C1E0A00530075006200430041300B0603551D0F040403020186300F0603551D130101FF040530030101FF301F0603551D23041830168014D5F656CB8FE8A25C6268D13D94905BD7CE9A18C430560603551D1F044F304D304BA049A0478645687474703A2F2F63726C2E6D6963726F736F66742E636F6D2F706B692F63726C2F70726F64756374732F4D6963526F6F4365724175745F323031302D30362D32332E63726C305A06082B06010505070101044E304C304A06082B06010505073002863E687474703A2F2F7777772E6D6963726F736F66742E636F6D2F706B692F63657274732F4D6963526F6F4365724175745F323031302D30362D32332E63727430370603551D250430302E06082B06010505070303060A2B0601040182370A0301060A2B0601040182370A0309060A2B0601040182370A0313300D06092A864886F70D01010B0500038202010082F7A9A5B3BFE5C8594127340F629C41F0AB2B7DF9A7A8C8A80F5D43BEADF299F8FFFBF67950440C50EA42DB9D01E9A549792829133E40367416DB8F20CC8D2D5110DC2B41367CB6D040139B1C00374C816968B11A82963B6975C7E534D83EDC5A09ABD3BFA9AFC4086FE347C632EF25E90B0B551294EF871419D2E121DE37CFAEA6345D232904046D6DE71ADD443079741A8D8CC1F93EF9AD306BA3B46A7449395B372D0119EE0329DDAE4A2FF982AF481F149A9C3D253156EA3AA74DB7FD8B3FFEBF77368B55E5B31050EE54D4BF6BD82AF233782EBF31F93611EF300BF94C4383E35BA95C1D5BA67605B8F0754FE9B81F3644A67F66D04B0D18551E742E2727E52642836EBBA4EF7BF9E498BDD53B89D35892B8D1CD167F397E66250DDB8359BF571F9BD2E91B72275D6B33D1FEA2924C513DC6CC943A56FFEB10412EDD9253CD10F11D36EB041ADB35D991B699600FE00BAC670C44169C0247CBB74696490FDF03B10FAD0E12AD480536E12D3FBB5AE094D49792E93EE6EB2519CB33F1DF936090A6B90E56F628E942C71E105BA62E0FB9DBA964D78EE533D29D43824B6E3766B90D6757545A480EE38AFB1FED0A26BC0D34D20A4785612A23B1E0548A50145685C0FF2DF76999447D1AF44D7C180EE10707EE0966524A7A1A62A4E58BCF85A2868A7190B17DD611D3511EDA5CE7CCD6121076A8AE4F93B564C9BDEDDCFB3182025730820253020101308199308181310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E312B3029060355040313224D6963726F736F6674204365727469666963617465204C6973742043412032303131021333000000788BFC5B4B88F5EFF4000000000078300D06096086480165030402010500A0818F301806092A864886F70D010903310B06092B0601040182370A01302F06092A864886F70D01090431220420AD717861821FB744DEEE74835C5A8AC6FA38FC1CA4FE0B66865DC9EBB44558AF3042060A2B06010401823702010C31343032A0148012004D006900630072006F0073006F00660074A11A8018687474703A2F2F7777772E6D6963726F736F66742E636F6D300D06092A864886F70D0101010500048201006BC5015BB054BC0000B819475BE8ABC2033E7610EED6BE46B3741A261C7F6AA690F428E6410440D0A932F1C8B08E87D1E921E356051C96AE765452823A309E9027632F7FC04DEC88E082C35AB9752BC9104A28B68F682B164928CF7F84F1E0E85AA357D608DFFCF8216508FB9B1F62316E07F7FA913F6DD7AA029D0F737DCC18D8F058DB3CCF48410C11A607E4232341F609BA77A276924CBFFCF35DBC45F49AD6573F95E38CD493AF5C10E827362A6CAA5A945C833A767C0299766802249C30CB43ACA5564C557F4173A277E7AC2D180E92027DBBB98F1626DEEC5BB5F67B14A5DCF23E4E251E11F2A492C1F99F7AD309C70AE931FE622FBA6BBCA17EC410C0 | |||
| (PID) Process: | (1092) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate |
| Operation: | write | Name: | DisallowedCertLastSyncTime |
Value: A0F8AEB4E986DC01 | |||
| (PID) Process: | (972) driver-hub-install__28.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (972) driver-hub-install__28.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (972) driver-hub-install__28.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (972) driver-hub-install__28.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3916) DriverHub_.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: DriverHub_.exe | |||
| (PID) Process: | (3916) DriverHub_.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DriverHub__RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3916) DriverHub_.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DriverHub__RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1092 | svchost.exe | C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\TarEF54.tmp | binary | |
MD5:E4B65A98063D5A8B8BBAF332FFBF7EE8 | SHA256:400800C461437E5E304EC4A597ACC79436E522AFD0ACB7E32CC01FF26D3133DC | |||
| 972 | driver-hub-install__28.exe | C:\Users\admin\AppData\Local\Temp\DriverHub_.exe | binary | |
MD5:15E6EDFD0A0B018541EB6F9B66B77620 | SHA256:C444CB4D8C5286281B7FE3B77AE6571C7EE16DAFE394ADED585EF7D746E7204B | |||
| 1092 | svchost.exe | C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\CabEF53.tmp | compressed | |
MD5:5F036F91E86E30F749961506951D51EB | SHA256:0300E9DDB527990E8B59D06E9CCF3EC2BD92D3BBD0EF4FBA69D6336E4195E82D | |||
| 3916 | DriverHub_.exe | C:\Users\admin\AppData\Local\Programs\DriverHub\libEGL.dll | executable | |
MD5:E0E4011346A86083A0EC8EB01136D0BA | SHA256:411966CE4F8FEBB2FE3AB84B97ED9FB9062AB60C6211FC3B3E4A25A5EE607ECB | |||
| 972 | driver-hub-install__28.exe | C:\Users\admin\AppData\Local\Temp\_.txt | binary | |
MD5:8EBCBBC6AE03A3D6186B53742A835983 | SHA256:0EA77D7301F2D8E1D9FAD3610A06E8C3B59F4F82EEE909F459633DF252A08A1B | |||
| 3916 | DriverHub_.exe | C:\Users\admin\AppData\Local\Programs\DriverHub\Microsoft.Win32.TaskScheduler.dll | executable | |
MD5:0616EA42B68A8F5F2F01BCD985BDCBC7 | SHA256:EA27C65491119EEE5C8E87CE3D470783580DB8FC5BD141C496768D7D0CCE779A | |||
| 3916 | DriverHub_.exe | C:\Users\admin\AppData\Local\Programs\DriverHub\Credits.txt | text | |
MD5:12E055C9F638057EA5FA160F15B3B5A6 | SHA256:3F45CA9EF9B9BBD890B4C159703D92D906F1AAAE0CE57763F26B6A33377BAD5A | |||
| 3916 | DriverHub_.exe | C:\Users\admin\AppData\Local\Programs\DriverHub\Images\DriverHubLogo.png | image | |
MD5:451B153070269850DA133D4E493A1BD6 | SHA256:91D221FE4045038100274A1A32F8155C0195517C51A712B1F742A4F5BBB45E4B | |||
| 3916 | DriverHub_.exe | C:\Users\admin\AppData\Local\Programs\DriverHub\DriverHubUninstaller.exe | executable | |
MD5:1B06359502DBFAD35CE773CBBEE4BCE2 | SHA256:357526C2D0CA1A382AE650AC8384808E9B37A6981D0A5F574BA7B4419BFFAB7D | |||
| 3916 | DriverHub_.exe | C:\Users\admin\AppData\Local\Programs\DriverHub\libcurl.dll | executable | |
MD5:E5064ADFBC48E3FB81F09E7B8E78D49D | SHA256:4BFCAEE356CF1B99D3DBC03D42018FCFC29271C6A72B373343D24C45A7569489 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
972 | driver-hub-install__28.exe | HEAD | 301 | 188.130.153.33:443 | https://www.drvhub.net/app/download | RU | — | — | unknown |
972 | driver-hub-install__28.exe | HEAD | 302 | 188.130.153.33:443 | https://www.drvhub.net/products/free/download | RU | — | — | unknown |
972 | driver-hub-install__28.exe | HEAD | 200 | 188.130.153.32:443 | https://www.az-partners.net/apps/driver-hub/download?ap=28&driver-hub-install.exe | RU | — | — | unknown |
3916 | DriverHub_.exe | HEAD | 301 | 188.130.153.33:443 | https://drvhub.net/products/free/download | RU | — | — | unknown |
3916 | DriverHub_.exe | HEAD | 200 | 188.130.153.33:443 | https://www.drvhub.net/products/free/download | RU | — | — | unknown |
484 | lsass.exe | GET | 200 | 2.20.245.170:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7967cf888cb1c6c7 | NL | compressed | 4.87 Kb | unknown |
484 | lsass.exe | GET | 200 | 151.101.130.133:80 | http://ocsp.globalsign.com/gsgccr6alphasslca2023/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTYuQbxgZqJCf3D06HBxH57o5XEXgQUvQW384qTPHPLefoPhRKhd5YYkXQCDFlLKIswa%2F9W2fZzlA%3D%3D | US | binary | 1.42 Kb | whitelisted |
484 | lsass.exe | GET | 200 | 151.101.130.133:80 | http://ocsp2.globalsign.com/rootr6/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRi%2B7TJbHYn9EmJ9W03lecB7P%2BG7QQUrmwFo5MT4qLn4tcc1sfwf8hnU6ACEH8fLJAug9Djtvs77keLXoA%3D | US | binary | 1.65 Kb | unknown |
484 | lsass.exe | GET | 200 | 23.222.81.129:80 | http://x1.c.lencr.org/ | US | binary | 734 b | unknown |
484 | lsass.exe | GET | 200 | 104.18.21.213:80 | http://r12.c.lencr.org/79.crl | US | binary | 229 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
972 | driver-hub-install__28.exe | 188.130.153.33:443 | api.az-partners.net | ROSTPAY-AS | RU | whitelisted |
1092 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
484 | lsass.exe | 2.20.245.170:80 | ctldl.windowsupdate.com | AKAMAI-ASN1 | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
484 | lsass.exe | 151.101.130.133:80 | ocsp2.globalsign.com | FASTLY | US | whitelisted |
484 | lsass.exe | 23.222.81.129:80 | x1.c.lencr.org | AKAMAI-AS | US | whitelisted |
484 | lsass.exe | 104.18.21.213:80 | r12.c.lencr.org | CLOUDFLARENET | US | whitelisted |
972 | driver-hub-install__28.exe | 188.130.153.32:443 | api.az-partners.net | ROSTPAY-AS | RU | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
api.az-partners.net |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsp2.globalsign.com |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |
www.drvhub.net |
| unknown |
x1.c.lencr.org |
| whitelisted |
r12.c.lencr.org |
| whitelisted |
www.az-partners.net |
| malicious |
drvhub.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO PE EXE or DLL Windows file download HTTP |
— | — | Misc activity | ET INFO EXE - Served Attached HTTP |
Process | Message |
|---|---|
DriverHub.exe | qrc:/UpdateProgressDialog.qml:11:5: QML Connections: Implicitly defined onFoo properties in Connections are deprecated. Use this syntax instead: function onFoo(<arguments>) { ... }
|
DriverHub.exe | qrc:/main.qml:634:13: QML Connections: Implicitly defined onFoo properties in Connections are deprecated. Use this syntax instead: function onFoo(<arguments>) { ... }
|
DriverHub.exe | qrc:/main.qml:432:31: QML ItemDelegate: Binding loop detected for property "height"
|
DriverHub.exe | qml: State SCAN
|
DriverHub.exe | file:///C:/Users/admin/AppData/Local/Programs/DriverHub/QtQuick/Dialogs/DefaultFileDialog.qml:102:33: QML Settings: Failed to initialize QSettings instance. Status code is: 1
|
DriverHub.exe | file:///C:/Users/admin/AppData/Local/Programs/DriverHub/QtQuick/Dialogs/DefaultFileDialog.qml:102:33: QML Settings: The following application identifiers have not been set: QVector("organizationName", "organizationDomain")
|
DriverHub.exe | qrc:/SettingsPage.qml:50:9: QML MyCheckBox: Binding loop detected for property "width"
|
DriverHub.exe | qrc:/SettingsPage.qml:50:9: QML MyCheckBox: Binding loop detected for property "width"
|
DriverHub.exe | qrc:/SettingsPage.qml:50:9: QML MyCheckBox: Binding loop detected for property "width"
|
DriverHub.exe | qrc:/SettingsPage.qml:32:9: QML MyCheckBox: Binding loop detected for property "width"
|