driverpack-online_1532797848.1469980068.exe

DriverPack

The application driverpack-online_1532797848.1469980068.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from download.drp.su.
Publisher:
DriverPack

Product:
DriverPack

Version:
1.0

MD5:
d9364de651b25e09fe6d34954970300d

SHA-1:
2cb0330423acd66f5f262a3e01279aabfd36182c

SHA-256:
7e2126d32cf05d4e1fd678f1eb6ac89a839e6cce3b2adc0429f8bba22c5ef736

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/21/2024 12:48:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DriverPack (L)
16.8.1.21

File size:
358.5 KB (367,096 bytes)

Product version:
1.0

Copyright:
Copyright © Kuzyakov Artur

Original file name:
DriverPack.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\driverpack-online_1532797848.1469980068.exe

File PE Metadata
Compilation timestamp:
4/3/2016 12:14:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:R5VP9Ge3+hoAvdeJBbmncZjOcVMPB9XQnjLg7omvYBGlbRx0MJFUzHxE:R5393whFOBb2cVMPB96g0slbL0MCa

Entry address:
0x1C35F

Entry point:
B4, 87, FF, C7, 4E, 86, C1, 86, E3, 81, EF, 49, 81, FD, E5, 8D, 3D, 9D, E3, D3, 60, F3, 83, E1, 00, 85, E8, 78, 0C, 69, C7, EF, 89, 8F, 3A, F6, C2, A7, F6, C7, 5B, 81, C9, 6C, FA, 00, 00, C6, C7, 0B, 81, E9, 7C, 0D, 00, 00, C7, C2, 98, 99, BC, D0, B7, 1E, F6, C5, 22, 86, C4, F7, C0, C8, C9, 89, 09, F6, C3, F1, B3, 6C, F2, E8, 58, 00, 00, 00, 3D, 88, 88, 00, 00, 78, 08, 0F, AF, DE, 28, EF, 0F, B7, DA, C7, C2, E8, 31, FD, BE, 86, D6, B0, 14, 18, D8, 0B, CB, 35, 34, 7A, F3, 2F, 81, D9, 5A, 86, B8, A8, BB, 06...
 
[+]

Entropy:
7.5585

Code size:
111.5 KB (114,176 bytes)

The file driverpack-online_1532797848.1469980068.exe has been seen being distributed by the following URL.

Remove driverpack-online_1532797848.1469980068.exe - Powered by Reason Core Security