InstallDriver.EXE

InstallDriver Application

This is a self-extracting archive and installer. The file has been seen being downloaded from doc-0o-1c-docs.googleusercontent.com and multiple other hosts.
Product:
InstallDriver Application

Description:
InstallDriver MFC Application

Version:
1, 0, 0, 1

MD5:
66519e67c90c3f2b86ee443e3b41415f

SHA-1:
a09a2fbf06fefe6dfd85fc4c69008ade42b432c9

SHA-256:
958d60178914ac74e36c4218279eec2b18760bab0ab97e7fed18005a691a4ba6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:29:12 PM UTC  (a few moments ago)

File size:
622 KB (636,928 bytes)

Product version:
1, 10, 32, 0

Copyright:
Copyright (C) 2005

Original file name:
InstallDriver.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\driver\installdriver.exe

File PE Metadata
Compilation timestamp:
8/11/2010 3:28:00 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:byfUVjJQKXxXjjAZkU5UUXiy8Xtd9AsyG5/tAp3fLO6EwgbA6:byU82bU/Xiy8ZFAp3fLOH

Entry address:
0x48FF2

Entry point:
E8, 37, EC, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 40, 24, 49, 00, E8, 98, 3A, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, D0, BC, 49, 00, 77, 22, 6A, 04, E8, 3A, EE, 00, 00, 59, 83, 65, FC, 00, 56, E8, 9C, FB, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, A4, 3A, 00, 00, C3, 6A, 04, E8, 1D, ED, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 83, 3D, 9C, B9, 49, 00, 00, 75, 18, E8, 6D, E1, 00, 00, 6A, 1E, E8, 95, DF, 00, 00, 68, FF, 00, 00, 00, E8, 3C, 03, 00, 00, 59, 59, A1...
 
[+]

Code size:
480 KB (491,520 bytes)

The file InstallDriver.EXE has been seen being distributed by the following 16 URLs.

https://doc-0o-1c-docs.googleusercontent.com/docs/securesc/947tkpchk4ed8smqiopd2t746n5emani/uq3kc7dnt00tqnb7aaposg57rq0kdj89/1482890400000/09475735845195895700/.../0B4huyVgvdssGQXU4WXlxNWMzNUk?e=download

https://doc-04-2s-docs.googleusercontent.com/docs/securesc/lj87rjfju85t6qp5d3kjvuuu9qcqjnhq/e189avb1iqqtfbhpobf494nm3q4o1iot/1482091200000/09475735845195895700/.../0B4huyVgvdssGQXU4WXlxNWMzNUk?e=download

https://doc-0g-5s-docs.googleusercontent.com/docs/securesc/4cog7m9nru7a5m9i9gerdam5lgfu03hl/6d23i4nvjgg1hc1vc4fv05ahqtg7m9ai/1472781600000/05019473353936302415/.../0B_NPobQbXPpncmhNMjZIa1FJQ3M?e=download

https://doc-10-c8-docs.googleusercontent.com/docs/securesc/3vc5nqss1su6ve1nge0v0brb99gaaiqf/ql878c3cd6gfpifj14sf2g5gd669q7uu/1478275200000/09475735845195895700/.../0B4huyVgvdssGQXU4WXlxNWMzNUk?e=download

https://mega.nz/temporary/.../3YoFRSAb

https://mega.nz/persistent/.../SZBynJgR

https://docviewer.yandex.ua/source?id=7iab-dca6y9ocxiwsnjonn03v3ln0lkshxgs5pytwlzddnp55e80fgqujv6egwe0e9mkw7ar7e3xg2ro0650vdsys7878btb7zhx4nt&archive-path=//Driver/.../9DyyO6tOw==&name=Driver.rar&uid=111065055

ftp://202.166.217.21:5656/TELETALK SOFTWARE/TOOLS/DRIVERS/DRIVERS/.../InstallDriver.exe

temp:InstallDriver.exe

Scan InstallDriver.EXE - Powered by Reason Core Security