driverpack-online_996461655.1470304795.exe

DriverPack

The application driverpack-online_996461655.1470304795.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from download.drp.su.
Publisher:
DriverPack

Product:
DriverPack

Version:
1.0

MD5:
6cfb0ff4786fda36c51238793fab6d1d

SHA-1:
dbe7552094870bcb9fdf2b1abbe5907de9dd3db4

SHA-256:
a9058d706c337201ebec4472b3bea58347844f6de18aa50f4ca64ecb5ec02180

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 8:28:50 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DriverPack (M)
16.8.8.6

File size:
350.5 KB (358,904 bytes)

Product version:
1.0

Copyright:
Copyright © Kuzyakov Artur

Original file name:
DriverPack.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\driverpack-online_996461655.1470304795.exe

File PE Metadata
Compilation timestamp:
4/3/2016 3:44:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:l5VP9Ge3+hoAvdeJBbgncZjOcVd+Uo7ilnWhFqmvYBGlbRx0MJFUzHxE:l5393whFOBbQcVIZ7qnWhFqslbL0MCa

Entry address:
0x1C35F

Entry point:
81, FA, 71, E0, 00, 00, 75, 06, 1A, D1, 1A, E2, B7, C7, 47, 80, C9, 05, B7, AC, 89, FD, 0F, AF, FB, B4, 11, 51, 8B, D9, C6, C7, 7C, 85, FB, E8, 3F, 00, 00, 00, 42, C6, C6, E1, 78, 08, FE, C1, F7, C0, 9D, A3, F9, 89, 42, 1D, AF, 76, 52, 34, BE, DF, A2, 00, 00, 87, C0, FF, C5, 81, F6, C7, 91, 00, 00, 41, 13, D7, 81, EE, 2C, 0A, 00, 00, F7, C5, F1, 8B, 35, 19, 25, A4, C8, 52, 83, 33, DE, 8D, 3D, 16, 4E, F9, 54, 81, F9, C1, E6, 00, 00, 70, 04, 8A, E2, FE, CC, EB, 06, 89, F6, 85, DD, 31, F5, B0, D0, C6, C5, EE...
 
[+]

Entropy:
7.5968

Code size:
111.5 KB (114,176 bytes)

The file driverpack-online_996461655.1470304795.exe has been seen being distributed by the following URL.

Remove driverpack-online_996461655.1470304795.exe - Powered by Reason Core Security