driverfinder_frdlg14_setup.exe

DeskToolsSoft B.V.

The application driverfinder_frdlg14_setup.exe by DeskToolsSoft B.V has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. While running, it connects to the Internet address server-52-85-173-154.fra6.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
DeskToolsSoft B.V.  (signed and verified)

MD5:
3b36a5c3295be9971cdc7d3e227463c4

SHA-1:
a1e74b7931482063647f09dcace27ab0bfb5b4aa

SHA-256:
ae618edccca194181c1407a74320cbf396af9562c4ae3963b95455e35b300cdc

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 12:33:31 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DeskToolsSoft (L)
17.2.17.11

File size:
269.9 KB (276,416 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\exe\be34074825046dcedbd9be9a177c6051\driverfinder_frdlg14_setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
10/31/2016 1:00:00 AM

Valid to:
11/1/2019 12:59:59 AM

Subject:
CN=DeskToolsSoft B.V., O=DeskToolsSoft B.V., L=Assen, S=Drenthe, C=NL, SERIALNUMBER=01147451, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.1=Assen, OID.1.3.6.1.4.1.311.60.2.1.2=Drenthe, OID.1.3.6.1.4.1.311.60.2.1.3=NL

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
5A4A030677E97BFAB66B5B5006765B77

File PE Metadata
Compilation timestamp:
2/24/2012 8:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-192-203-59.fra50.r.cloudfront.net  (54.192.203.59:80)

TCP (HTTP):
Connects to server-54-230-95-140.fra2.r.cloudfront.net  (54.230.95.140:80)

TCP (HTTP):
Connects to server-54-230-95-107.fra2.r.cloudfront.net  (54.230.95.107:80)

TCP (HTTP):
Connects to server-54-192-203-162.fra50.r.cloudfront.net  (54.192.203.162:80)

TCP (HTTP):
Connects to server-54-192-14-234.ams1.r.cloudfront.net  (54.192.14.234:80)

TCP (HTTP):
Connects to server-54-192-130-156.ams50.r.cloudfront.net  (54.192.130.156:80)

TCP (HTTP):
Connects to server-52-85-173-7.fra6.r.cloudfront.net  (52.85.173.7:80)

TCP (HTTP):
Connects to server-54-239-132-35.sfo9.r.cloudfront.net  (54.239.132.35:80)

TCP (HTTP):
Connects to server-54-230-95-202.fra2.r.cloudfront.net  (54.230.95.202:80)

TCP (HTTP):
Connects to server-54-230-95-153.fra2.r.cloudfront.net  (54.230.95.153:80)

TCP (HTTP):
Connects to server-54-192-230-198.waw50.r.cloudfront.net  (54.192.230.198:80)

TCP (HTTP):
Connects to server-54-192-203-84.fra50.r.cloudfront.net  (54.192.203.84:80)

TCP (HTTP):
Connects to server-54-192-203-77.fra50.r.cloudfront.net  (54.192.203.77:80)

TCP (HTTP):
Connects to server-54-192-14-92.ams1.r.cloudfront.net  (54.192.14.92:80)

TCP (HTTP):
Connects to server-54-192-130-20.ams50.r.cloudfront.net  (54.192.130.20:80)

TCP (HTTP):
Connects to server-52-85-221-47.cdg50.r.cloudfront.net  (52.85.221.47:80)

TCP (HTTP):
Connects to server-52-85-173-81.fra6.r.cloudfront.net  (52.85.173.81:80)

TCP (HTTP):
Connects to server-52-85-173-60.fra6.r.cloudfront.net  (52.85.173.60:80)

TCP (HTTP):
Connects to server-52-85-173-38.fra6.r.cloudfront.net  (52.85.173.38:80)

TCP (HTTP):
Connects to server-52-85-173-252.fra6.r.cloudfront.net  (52.85.173.252:80)

Remove driverfinder_frdlg14_setup.exe - Powered by Reason Core Security