File name:

Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE.7z

Full analysis: https://app.any.run/tasks/3f115eea-7ace-42cd-9059-3f0221760b49
Verdict: Malicious activity
Analysis date: July 14, 2023, 17:53:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

1BAE60A97D106DEE656280B07791CDE6

SHA1:

226FBA2E8E309936A1AEDDE1249F71340093F84A

SHA256:

3AF2E752EACC2E814D8667138611D341246B7A9BEEA922ECFD5B039A72D79822

SSDEEP:

98304:mqw8quT5u8EjY1SEKWfQqe57COh/t7kDlJRODglg:mqw8BQ8EMp+qe5mOhpClvc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 3760)
      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • miniunz.exe (PID: 3980)
      • miniunz.exe (PID: 3224)
      • Setup.exe (PID: 3288)
      • SetupSerialIO.exe (PID: 3760)
      • Setup.exe (PID: 1604)
      • SetupSerialIO.exe (PID: 1236)
    • Loads dropped or rewritten executable

      • miniunz.exe (PID: 3980)
      • miniunz.exe (PID: 3224)
      • Setup.exe (PID: 1604)
      • Setup.exe (PID: 3288)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Reads the Internet Settings

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • Setup.exe (PID: 1604)
      • Setup.exe (PID: 3288)
    • Reads Internet Explorer settings

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Executable content was dropped or overwritten

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • miniunz.exe (PID: 3980)
      • SetupSerialIO.exe (PID: 3760)
      • Setup.exe (PID: 1604)
      • miniunz.exe (PID: 3224)
      • SetupSerialIO.exe (PID: 1236)
      • Setup.exe (PID: 3288)
    • Drops a system driver (possible attempt to evade defenses)

      • miniunz.exe (PID: 3980)
      • miniunz.exe (PID: 3224)
    • Start notepad (likely ransomware note)

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3400)
    • The process checks LSA protection

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • Setup.exe (PID: 1604)
      • Setup.exe (PID: 3288)
    • Checks supported languages

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
      • miniunz.exe (PID: 3980)
      • Setup.exe (PID: 1604)
      • miniunz.exe (PID: 3224)
      • SetupSerialIO.exe (PID: 1236)
      • Setup.exe (PID: 3288)
      • SetupSerialIO.exe (PID: 3760)
    • Reads the machine GUID from the registry

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Reads the computer name

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Checks proxy server information

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Creates files in the program directory

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Creates files or folders in the user directory

      • Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE (PID: 2948)
    • Create files in a temporary directory

      • SetupSerialIO.exe (PID: 3760)
      • Setup.exe (PID: 1604)
      • SetupSerialIO.exe (PID: 1236)
      • Setup.exe (PID: 3288)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
10
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start drop and start winrar.exe intel-serial-io-driver_3mk53_win_30.100.2020.7_a06_04.exe no specs intel-serial-io-driver_3mk53_win_30.100.2020.7_a06_04.exe miniunz.exe setupserialio.exe setup.exe miniunz.exe setupserialio.exe setup.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1236"C:\ProgramData\Dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\SetupSerialIO.exe" /report "C:\ProgramData\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\DUPA237.tmp"C:\ProgramData\Dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\SetupSerialIO.exe
Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
Modules
Images
c:\programdata\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\setupserialio.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
1604C:\Users\admin\AppData\Local\Temp\IIF432D.tmp\setup.exe /report C:\ProgramData\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\DUP42EF.tmp C:\Users\admin\AppData\Local\Temp\IIF432D.tmp\Setup.exe
SetupSerialIO.exe
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
Modules
Images
c:\users\admin\appdata\local\temp\iif432d.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
2572"C:\Windows\system32\NOTEPAD.EXE" C:\ProgramData\Dell\UpdatePackage\Log\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.txtC:\Windows\System32\notepad.exeIntel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2948"C:\Users\admin\AppData\Local\Temp\Rar$EXb3400.21208\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXb3400.21208\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
WinRAR.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Dell Update Package: Intel Serial IO Driver, 30.100.2020.7, A06
Exit code:
0
Version:
004.008.007.000
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3400.21208\intel-serial-io-driver_3mk53_win_30.100.2020.7_a06_04.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
3224 -x C:\Users\admin\AppData\Local\Temp\RAR$EX~1.212\INTEL-~1.EXE -o -d c:\PROGRA~2\dell\drivers\A8CB65~1C:\ProgramData\Dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\miniunz.exe
Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\programdata\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\miniunz.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\programdata\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\zlibwapi.dll
3288C:\Users\admin\AppData\Local\Temp\IIFA284.tmp\setup.exe /report C:\ProgramData\dell\drivers\a8cb651b-2dce-41c3-8312-bd17ca7be14b\DUPA237.tmp C:\Users\admin\AppData\Local\Temp\IIFA284.tmp\Setup.exe
SetupSerialIO.exe
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
Modules
Images
c:\users\admin\appdata\local\temp\iifa284.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3400"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3760"C:\Users\admin\AppData\Local\Temp\Rar$EXb3400.21208\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXb3400.21208\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXEWinRAR.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
MEDIUM
Description:
Dell Update Package: Intel Serial IO Driver, 30.100.2020.7, A06
Exit code:
3221226540
Version:
004.008.007.000
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\rar$exb3400.21208\intel-serial-io-driver_3mk53_win_30.100.2020.7_a06_04.exe
3760"C:\ProgramData\Dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\SetupSerialIO.exe" /report "C:\ProgramData\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\DUP42EF.tmp"C:\ProgramData\Dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\SetupSerialIO.exe
Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
Modules
Images
c:\programdata\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\setupserialio.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3980 -x C:\Users\admin\AppData\Local\Temp\RAR$EX~1.212\INTEL-~1.EXE -o -d c:\PROGRA~2\dell\drivers\A567E8~1C:\ProgramData\Dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\miniunz.exe
Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\programdata\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\miniunz.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\programdata\dell\drivers\a567e8bb-0a71-4991-81c7-0a89b68bed7e\zlibwapi.dll
Total events
1 831
Read events
1 803
Write events
28
Delete events
0

Modification events

(PID) Process:(3400) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3400) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
127
Suspicious files
20
Text files
61
Unknown types
0

Dropped files

PID
Process
Filename
Type
2948Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXEC:\PROGRA~2\dell\drivers\A567E8~1\AppPackageInstaller.ps1text
MD5:0BD70E6BAA7A77114F1857223BDB36D5
SHA256:8F1CD2B9A6D733019F68244AADB5B7BA0557826E917277BF4A33251BFB14B4D3
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\ialpss2_gpio2_cnl.catbinary
MD5:8B4503E4786EE507C17FE95F4534FA8F
SHA256:8D2D1C37AF4F80F856D765E1332F6F75B31D08A40BC41A18F374487A7FAEFCBC
3400WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3400.21208\Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXEexecutable
MD5:2DE598E4B8AC407F34A558CC774E5573
SHA256:598253A99645FD51D95278719DEE8B0E89E5CD87D819E8887646E228AF6E9E2F
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\mup.xmlxml
MD5:DEA0325D86BDB9D60069243E6A17899B
SHA256:240BC1F0173A75E0B7FF2FB5BADB330937FEC8D5827F8C5DF5DB83A330EB77CD
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_GPIO2_CNL.sysexecutable
MD5:75FB2412D54AB939A349917905BB2A2E
SHA256:03B7F1F6BF593BB804A3604230002EBDB679C7A11BF2F7F34388D3F16CB2FF7E
2948Intel-Serial-IO-Driver_3MK53_WIN_30.100.2020.7_A06_04.EXEC:\PROGRA~2\dell\drivers\A567E8~1\miniunz.exeexecutable
MD5:5C3647BEB1347D6D4354C3124079945F
SHA256:3BFD2E6E373CD2214EC50127B4BF1261C39663775E85CBC35C16DE4FADA6DCAC
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_I2C_CNL.infbinary
MD5:57103D528555BDAB927F57CC409B3951
SHA256:D1F2CFBC8B8C90B36868AEF027EC497CE71B90687C81CC127DACE4B26023025B
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\ialpss2_i2c_cnl.catbinary
MD5:4024498F1C6CB11614560582178145AD
SHA256:8F9E291C8E758961873D9332E911CE1A830E3A342ED2725838AA1C8B5E236B82
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\ialpss2_spi_cnl.catbinary
MD5:961F9807FEAB77BFDF437DDBBA5A8345
SHA256:1FBFCA27170B985C757693893CB97F66B1E0EB1936EDD6C0A9D97A3742391421
3980miniunz.exeC:\PROGRA~2\dell\drivers\A567E8~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_SPI_CNL.sysexecutable
MD5:2D1BB7A9DB8993A1441043A79D15EBA5
SHA256:503BBB5153F588A919F17E991D67D1988445724B28F0154072FF63E96AEAE1E6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2640
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info