File name:

Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE.7z

Full analysis: https://app.any.run/tasks/3f115eea-7ace-42cd-9059-3f0221760b49
Verdict: Malicious activity
Analysis date: July 14, 2023, 17:53:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

1BAE60A97D106DEE656280B07791CDE6

SHA1:

226FBA2E8E309936A1AEDDE1249F71340093F84A

SHA256:

3AF2E752EACC2E814D8667138611D341246B7A9BEEA922ECFD5B039A72D79822

SSDEEP:

98304:mqw8quT5u8EjY1SEKWfQqe57COh/t7kDlJRODglg:mqw8BQ8EMp+qe5mOhpClvc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 3760)
      • miniunz.exe (PID: 3980)
      • SetupSerialIO.exe (PID: 3760)
      • Setup.exe (PID: 1604)
      • SetupSerialIO.exe (PID: 1236)
      • miniunz.exe (PID: 3224)
      • Setup.exe (PID: 3288)
    • Loads dropped or rewritten executable

      • miniunz.exe (PID: 3980)
      • Setup.exe (PID: 1604)
      • miniunz.exe (PID: 3224)
      • Setup.exe (PID: 3288)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • Setup.exe (PID: 1604)
      • Setup.exe (PID: 3288)
    • Reads Microsoft Outlook installation path

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Reads Internet Explorer settings

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Executable content was dropped or overwritten

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • miniunz.exe (PID: 3980)
      • SetupSerialIO.exe (PID: 3760)
      • Setup.exe (PID: 1604)
      • miniunz.exe (PID: 3224)
      • Setup.exe (PID: 3288)
      • SetupSerialIO.exe (PID: 1236)
    • Drops a system driver (possible attempt to evade defenses)

      • miniunz.exe (PID: 3980)
      • miniunz.exe (PID: 3224)
    • Start notepad (likely ransomware note)

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3400)
    • Checks supported languages

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • miniunz.exe (PID: 3980)
      • SetupSerialIO.exe (PID: 3760)
      • Setup.exe (PID: 1604)
      • miniunz.exe (PID: 3224)
      • SetupSerialIO.exe (PID: 1236)
      • Setup.exe (PID: 3288)
    • Reads the machine GUID from the registry

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • The process checks LSA protection

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • Setup.exe (PID: 1604)
      • Setup.exe (PID: 3288)
    • Reads the computer name

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Creates files in the program directory

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Checks proxy server information

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Creates files or folders in the user directory

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Create files in a temporary directory

      • SetupSerialIO.exe (PID: 3760)
      • Setup.exe (PID: 1604)
      • Setup.exe (PID: 3288)
      • SetupSerialIO.exe (PID: 1236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
10
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start drop and start winrar.exe intel-serial-io-driver_3mk53_win_30.100.2020.7_a06_04.exe no specs intel-serial-io-driver_3mk53_win_30.100.2020.7_a06_04.exe miniunz.exe setupserialio.exe setup.exe miniunz.exe setupserialio.exe setup.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1236"C:\ProgramData\Dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\SetupSerialIO.exe" /report "C:\ProgramData\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\DUPA237.tmp"C:\ProgramData\Dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\SetupSerialIO.exe
Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
Modules
Images
c:\programdata\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\setupserialio.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
1604C:\Users\admin\AppData\Local\Temp\IIF432D.tmp\setup.exe /report C:\ProgramData\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\DUP42EF.tmp C:\Users\admin\AppData\Local\Temp\IIF432D.tmp\Setup.exe
SetupSerialIO.exe
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
Modules
Images
c:\users\admin\appdata\local\temp\iif432d.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
2572"C:\Windows\system32\NOTEPAD.EXE" C:\ProgramData\Dell\UpdatePackage\Log\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.txtC:\Windows\System32\notepad.exeIntel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2948"C:\Users\admin\AppData\Local\Temp\Rar$EXb3400.21208\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXb3400.21208\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
WinRAR.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Dell Update Package: Intel Serial IO Driver, 30.100.2020.7, A06
Exit code:
0
Version:
004.008.007.000
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3400.21208\intel-serial-io-driver_3mk53_win_30.100.2020.7_a06_04.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
3224 -x C:\Users\admin\AppData\Local\Temp\RAR$EX~1.212\INTEL-~1.EXE -o -d c:\PROGRA~2\dell\drivers\A8CB65~1C:\ProgramData\Dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\miniunz.exe
Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\programdata\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\miniunz.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\programdata\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\zlibwapi.dll
3288C:\Users\admin\AppData\Local\Temp\IIFA284.tmp\setup.exe /report C:\ProgramData\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\DUPA237.tmp C:\Users\admin\AppData\Local\Temp\IIFA284.tmp\Setup.exe
SetupSerialIO.exe
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
Modules
Images
c:\users\admin\appdata\local\temp\iifa284.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3400"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3760"C:\Users\admin\AppData\Local\Temp\Rar$EXb3400.21208\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXb3400.21208\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXEWinRAR.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
MEDIUM
Description:
Dell Update Package: Intel Serial IO Driver, 30.100.2020.7, A06
Exit code:
3221226540
Version:
004.008.007.000
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\rar$exb3400.21208\intel-serial-io-driver_3mk53_win_30.100.2020.7_a06_04.exe
3760"C:\ProgramData\Dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\SetupSerialIO.exe" /report "C:\ProgramData\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\DUP42EF.tmp"C:\ProgramData\Dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\SetupSerialIO.exe
Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
Modules
Images
c:\programdata\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\setupserialio.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3980 -x C:\Users\admin\AppData\Local\Temp\RAR$EX~1.212\INTEL-~1.EXE -o -d c:\PROGRA~2\dell\drivers\A567E8~1C:\ProgramData\Dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\miniunz.exe
Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\programdata\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\miniunz.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\programdata\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\zlibwapi.dll
Total events
1 831
Read events
1 803
Write events
28
Delete events
0

Modification events

(PID) Process:(3400) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
127
Suspicious files
20
Text files
61
Unknown types
0

Dropped files

PID
Process
Filename
Type
2948Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXEC:\PROGRA~2\dell\drivers\A567E8~1\AppPackageInstaller.ps1text
MD5:0BD70E6BAA7A77114F1857223BDB36D5
SHA256:8F1CD2B9A6D733019F68244AADB5B7BA0557826E917277BF4A33251BFB14B4D3
2948Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXEC:\PROGRA~2\dell\drivers\A567E8~1\AppPackageRollBack.ps1text
MD5:6B06DDD5B01A03CC74C8E1ABBFF1568A
SHA256:18EF204AC8DD572AE3967AEC77317CA265E454E1A849F5FFC505CA4607BDC1DB
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\ialpss2_i2c_cnl.catbinary
MD5:4024498F1C6CB11614560582178145AD
SHA256:8F9E291C8E758961873D9332E911CE1A830E3A342ED2725838AA1C8B5E236B82
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_I2C_CNL.infbinary
MD5:57103D528555BDAB927F57CC409B3951
SHA256:D1F2CFBC8B8C90B36868AEF027EC497CE71B90687C81CC127DACE4B26023025B
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_GPIO2_CNL.sysexecutable
MD5:75FB2412D54AB939A349917905BB2A2E
SHA256:03B7F1F6BF593BB804A3604230002EBDB679C7A11BF2F7F34388D3F16CB2FF7E
2948Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXEC:\PROGRA~2\dell\drivers\A567E8~1\zlibwapi.dllexecutable
MD5:8C4F11E9EE6E80AA7824CF42FC128038
SHA256:1794B9AE1A7C67BD92E9820A441E81A0A1804B953D34C1F58227551F76D695A2
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\ialpss2_spi_cnl.catbinary
MD5:961F9807FEAB77BFDF437DDBBA5A8345
SHA256:1FBFCA27170B985C757693893CB97F66B1E0EB1936EDD6C0A9D97A3742391421
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_SPI_CNL.sysexecutable
MD5:2D1BB7A9DB8993A1441043A79D15EBA5
SHA256:503BBB5153F588A919F17E991D67D1988445724B28F0154072FF63E96AEAE1E6
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_SPI_CNL.infbinary
MD5:73EA39E0F81992EBD0293D55115AA244
SHA256:30EC7E2CE6F53D282A7BFA531840776F416C5A20DAD58A4C66432B04236597B3
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\SetupSerialIO.exeexecutable
MD5:5FEA60421A39BCEAC3B41B8701642DA5
SHA256:B341A5EE154E35DD991EEF0414E1894C2DC0DC8F0D9DEA3EBE43800F55722121
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2640
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info