update160401.exe

DriverMax

Innovative Solutions Grup SRL

The application update160401.exe, “DriverMax Setup ” by Innovative Solutions Grup SRL has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.softonic.com and multiple other hosts.
Publisher:
Innovative Solutions   (signed by Innovative Solutions Grup SRL)

Product:
DriverMax

Description:
DriverMax Setup

MD5:
d03edd8d4bde47170f4e44479bf45d1e

SHA-1:
7b8f56419d15ef911f7ede6a2baa90d1d336a128

SHA-256:
7e4cd4d0dda935814c3f6030318a9df96e11ff517fe783029a5ee960b78dd982

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 7:29:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DriverMax.Innovati.Installer.Meta (L)
16.6.16.18

File size:
5.1 MB (5,330,480 bytes)

Product version:
8.21.0.438

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\update160401.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/18/2015 9:00:00 PM

Valid to:
5/17/2016 8:59:59 PM

Subject:
CN=Innovative Solutions Grup SRL, O=Innovative Solutions Grup SRL, L=Bucharest, S=Bucharest, C=RO

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6CCC9ABD5046DE5246F5CD620FC3DEBB

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:UJBVmdtVvxLAOfVj5zuCua684aRRslyEr9Ajvb+4mqGW5:OmdTvxP/puRy8GDatW5

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file update160401.exe has been seen being distributed by the following 18 URLs.

http://www.softonic.com/sads/tracker.php?ev=c&co=CL&sid=656b0b36a3d7af9402da97e87a32fe15&upv=f26954448947b79deb84af6f115f9eaa&z=results&sk=0&abp=1&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA81C42AA7B2AB56E85BF65B1AFD3DBC46443DC8D945CB35570014CA05C7E4B88441D2064A37958843E5605E0454F6462673964A961AC18511FA354B06982645768F68D1EB1FD5654BCE3EE899FC819430FD6459235B8E4497746E9C68596DD23A8B638C8B2F2BB608E933C0E8A8DB91E98A537E4DB4AD36BA883F2DA13DF353A28738277BA7BA300D6688E00BFC0E7E86&h=CE40A73CA4F69753C30E2A60673864D54A7127B0E610A1F9C8AAB85C1B31A634&directdownload=1&f=55238&d=http://www.drivermax.es/.../drivermax.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&sid=2ff5c905e466655fbaa354224544289f&upv=ac177c78c8abdec4ba8982236e4ad4a7&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA81C42AA7B2AB56E85BF65B1AFD3DBC46443DC8D945CB35570014CA05C7E4B88441D2064A37958843E5605E0454F6462673964A961AC18511FA354B0698264576D13F40BF2B9AAE53222869BF992AADEE85715FFBBB0831C40F882D61E0B26E35465035C1CE6B8E3D50AEBE3CE646C816594D39176E4642289E8EF7E1E87AEFCD3AE885C36AB5E2B69BF11E42E018D178&h=A51809949C32F46E41797BAC523F4FBB9E581042851A74FC3FF0F921B52A19CB&directdownload=1&f=55238&d=http://www.drivermax.es/.../drivermax.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=PE&sid=8b196c1f23269dab927db2c70bc7a220&upv=fe70709b841d9cdb06b654c5382193cf&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA81C42AA7B2AB56E85BF65B1AFD3DBC46443DC8D945CB35570014CA05C7E4B884CB51FA99C7F7AFC9332A79EE8F429B79151CB31D99B559C0D7FA2888F9513545745AF7AEDB9AE65941689E4C7391E4E975337FE024789CEAF0BD4AE5A9FC459300EC3B8AE085D442313E83676639FAF1E998DCF6E34B53EFB88A0C7308F73BF49F751D6845D05BCFBF64F09DA7DB7B6D&h=90A82308DD38906E732EA5DD24BDAAD4848CDA175AD7A27573B948AED3436C8E&directdownload=1&f=55238&d=http://www.drivermax.es/.../drivermax.exe

http://drivermax.softonic.com/descargar

http://www.softonic.com.br/sads/tracker.php?ev=c&co=PT&sid=f9a9e031454568a2fd0094af661a9937&upv=c4da3be44a365fce54b163b9cab84718&z=pp_warning&sk=1651&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAB9D0A325A0C66CC51714148938FC8A64E16CCEC8B21B2D40363C77D42C03A73863636E7F68366836A44EBBBAFDEED562D8E39D3E5FCE70E349FDCFE0A1D1825A195908AE36230148DD450B4B4DE83E72E8FC061A4C14BBD7098E05CD218A85B6CD48C9A0A45CD69126E9333B9505DAFD2122AA44A82C8FCAA71B413617FA6C657B372FC496D7DF22C30E0D68F658700BAB6E20DF2EAB8FCA2302583F232EACD4&h=729FC8481055EB063157242132032ACF0CAAD18709C97AD3E474B5AE0B8742F0&directdownload=1&f=55238&d=http://www.drivermax.com.br/.../drivermax.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=AR&sid=255a0e5fbd5bcaf69d29baf6d2ebde5b&upv=dfe3d98e8e7e657aa035dc809241e65e&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA81C42AA7B2AB56E85BF65B1AFD3DBC46443DC8D945CB35570014CA05C7E4B88441D2064A37958843E5605E0454F6462673964A961AC18511FA354B069826457615579566F5964E66895849487893D4C9252DDC3E130ED5F9A978D14341832F7A110D1DF06925A638127D936787FDAEAE107F04C811FD5AAEF1C894D08471AC702898DEB2ED2DFACB2F626AE3ECECEC7A&h=4FF39FF2BB534808D3A7B3E0DDAEAF9F6516075DC7E8B3790D0CFC2306F92E62&directdownload=1&f=55238&d=http://www.drivermax.es/.../drivermax.exe

Remove update160401.exe - Powered by Reason Core Security