DriverPack

カテゴリ: アドウェアと不要なアプリケーション(PUA)保護提供の開始日時:2018 11 02 17:01:43 (GMT)
種類: Unspecified PUA最終更新日時:2019 9 16 21:55:24 (GMT)

Download Sophos Virus Removal Tool (無償) のダウンロード - 他社製ウイルス対策製品が検出できなかったマルウェアを検出

Examples of DriverPack include:

Example 1

File Information

Size
3.7M
SHA-1
49176be396eacb75999fc3ceb3bbabe648ec6574
MD5
e6fbebbe80e7ed1d4d7ef6db5f022b90
CRC-32
367adde0
File type
Windows executable
First seen
2017-04-30

Runtime Analysis

Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su\update-test2
    https
    0x00000001
  • HKCU\Software\drpsu
    computerId
    468023953.2033716126
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su\update
    https
    0x00000001
  • HKCR\.js
    Content Type
    application/javascript
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING
    mshta.exe
    0x00000001
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Styles
    MaxScriptStatements
    0xffffffff
  • HKLM\SOFTWARE\drpsu
    computerId
    468023953.2033716126
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX
    mshta.exe
    0x00000001
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_NINPUT_LEGACYMODE
    mshta.exe
    0x00000000
  • HKCU\Software\Microsoft\Internet Explorer\Styles
    MaxScriptStatements
    0xffffffff
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    Administrative Tools
    c:\Documents and Settings\test user\Start Menu\Programs\Administrative Tools
Processes Created
  • c:\docume~1\support\locals~1\temp\7zipsfx.000\bin\tools\driverpack-wget.exe
  • c:\docume~1\support\locals~1\temp\7zipsfx.000\driverpack.exe
  • c:\windows\system32\cmd.exe
  • c:\windows\system32\mshta.exe
  • c:\windows\system32\reg.exe
  • c:\windows\system32\wscript.exe
HTTP Requests
  • http://download.drp.su/DriverPack-17-Online-autoinstall.exe
  • http://update.drp.su/nano/
  • http://www.google-analytics.com/collect
DNS Requests
  • download.drp.su
  • mc.yandex.ru
  • update.drp.su
  • www.google-analytics.com

Example 2

File Information

Size
2.3M
SHA-1
5716395c8034e8d4e92fa88d3b61dde0903d533c
MD5
c8de36d5998e2aa5917ffb640162e608
CRC-32
b17d3550
File type
Windows executable
First seen
2017-07-27

Runtime Analysis

Registry Keys Created
  • HKCR\.js
    Content Type
    application/javascript
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_NINPUT_LEGACYMODE
    mshta.exe
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su\update
    https
    0x00000001
  • HKCU\Software\drpsu
    computerId
    487667701.9904124883
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING
    mshta.exe
    0x00000001
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su\update-test2
    https
    0x00000001
  • HKCU\Software\Microsoft\Internet Explorer\Styles
    MaxScriptStatements
    0xffffffff
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX
    mshta.exe
    0x00000001
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Styles
    MaxScriptStatements
    0xffffffff
  • HKLM\SOFTWARE\drpsu
    computerId
    487667701.9904124883
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    Administrative Tools
    c:\Documents and Settings\test user\Start Menu\Programs\Administrative Tools
Processes Created
  • c:\docume~1\support\locals~1\temp\7zipsfx.000\bin\tools\driverpack-wget.exe
  • c:\docume~1\support\locals~1\temp\7zipsfx.000\driverpack.exe
  • c:\windows\system32\cmd.exe
  • c:\windows\system32\mshta.exe
  • c:\windows\system32\reg.exe
  • c:\windows\system32\wscript.exe
HTTP Requests
  • http://download.drp.su/DriverPack-17-Online-autoinstall.exe
  • http://update.drp.su/nano/
  • http://www.google-analytics.com/collect
DNS Requests
  • download.drp.su
  • mc.yandex.ru
  • update.drp.su
  • www.google-analytics.com

Example 3

File Information

Size
2.7M
SHA-1
5ef068208e7b14f110f877b2ac3d324e4b73dfa1
MD5
635056b6850e2c470704daf8b4fac4a4
CRC-32
7f0ec2f5
File type
Windows executable
First seen
2017-07-25

Runtime Analysis

Registry Keys Created
  • HKCU\Software\drpsu
    computerId
    468973336.3411220916
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su\update
    https
    0x00000001
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_NINPUT_LEGACYMODE
    mshta.exe
    0x00000000
  • HKCR\.js
    Content Type
    application/javascript
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING
    mshta.exe
    0x00000001
  • HKLM\SOFTWARE\drpsu
    computerId
    468973336.3411220916
  • HKCU\Software\Microsoft\Internet Explorer\Styles
    MaxScriptStatements
    0xffffffff
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Styles
    MaxScriptStatements
    0xffffffff
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su\update-test2
    https
    0x00000001
  • HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX
    mshta.exe
    0x00000001
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    Administrative Tools
    c:\Documents and Settings\test user\Start Menu\Programs\Administrative Tools
Processes Created
  • c:\docume~1\support\locals~1\temp\7zipsfx.000\bin\tools\driverpack-wget.exe
  • c:\docume~1\support\locals~1\temp\7zipsfx.000\driverpack.exe
  • c:\windows\system32\cmd.exe
  • c:\windows\system32\mshta.exe
  • c:\windows\system32\reg.exe
  • c:\windows\system32\wscript.exe
HTTP Requests
  • http://download.drp.su/DriverPack-17-Online-autoinstall.exe
  • http://update.drp.su/nano/
  • http://www.google-analytics.com/collect
DNS Requests
  • download.drp.su
  • mc.yandex.ru
  • update.drp.su
  • www.google-analytics.com

download 無償評価版の試用
無償評価版のダウンロード