File name:

BoseUpdaterInstaller_7.1.13.5238 (1).exe

Full analysis: https://app.any.run/tasks/2ac86515-482b-4fe8-b312-e78a20c542e2
Verdict: Malicious activity
Analysis date: July 19, 2024, 15:31:57
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

81F6218BCF4CB298C0BEECFC3E428D63

SHA1:

73F09DAC335DBCF5DB151726DBD15C96C0074A8E

SHA256:

423E7009C7F9F42166D27BECC780BF72C551E2075391CE98D80F46A5ABCA0373

SSDEEP:

98304:HlhwePBeox3ImKbttvReOWOn251c1nyRMwUtH8YS1RYCH1s7tjQEor62qK0WDMOa:i2Z9YoEEFayZ8H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
    • Executable content was dropped or overwritten

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
    • The process drops C-runtime libraries

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
    • Creates a software uninstall entry

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
  • INFO

    • Reads the computer name

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
      • BOSEUPDATER.EXE (PID: 6980)
    • Checks supported languages

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
      • BOSEUPDATER.EXE (PID: 6980)
    • Creates files in the program directory

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
    • Manual execution by a user

      • BOSEUPDATER.EXE (PID: 6980)
    • Create files in a temporary directory

      • BOSEUPDATER.EXE (PID: 6980)
    • UPX packer has been detected

      • BOSEUPDATER.EXE (PID: 6980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (43.5)
.exe | Win32 EXE Yoda's Crypter (42.7)
.exe | Win32 Executable (generic) (7.2)
.exe | Generic Win/DOS Executable (3.2)
.exe | DOS Executable Generic (3.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:05:15 15:32:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 9928704
InitializedDataSize: 45056
UninitializedDataSize: 17203200
EntryPoint: 0x19e0780
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 7.1.13.5238
ProductVersionNumber: 7.1.13.5238
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Bose Corporation
FileDescription: Bose® Device Updater
FileVersion: 7.1.13.5238
InternalName: BoseUpdaterInstaller.exe
LegalCopyright: � Bose Corporation 2024. All rights reserved.
OriginalFileName: BoseUpdaterInstaller.exe
ProductName: Bose Updater
ProductVersion: 7.1.13.5238
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start boseupdaterinstaller_7.1.13.5238 (1).exe THREAT boseupdater.exe no specs slui.exe no specs boseupdaterinstaller_7.1.13.5238 (1).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1032"C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5238 (1).exe" C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5238 (1).exeexplorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
MEDIUM
Description:
Bose® Device Updater
Exit code:
3221226540
Version:
7.1.13.5238
Modules
Images
c:\users\admin\downloads\boseupdaterinstaller_7.1.13.5238 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4372"C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5238 (1).exe" C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5238 (1).exe
explorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
HIGH
Description:
Bose® Device Updater
Exit code:
0
Version:
7.1.13.5238
Modules
Images
c:\users\admin\downloads\boseupdaterinstaller_7.1.13.5238 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4612C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6980"C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE" /initC:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE
explorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
MEDIUM
Description:
Bose® Device Updater
Version:
7.1.13.5238
Modules
Images
c:\program files (x86)\bose updater\boseupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
831
Read events
818
Write events
9
Delete events
4

Modification events

(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:delete keyName:(default)
Value:
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\btu
Operation:delete keyName:(default)
Value:
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\Bose Updater\uninstall.exe" /uninstall
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:DisplayName
Value:
Bose Updater
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:Publisher
Value:
Bose Corporation
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:DisplayVersion
Value:
7.1.13.5238
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE,0
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:NoModify
Value:
1
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:NoRepair
Value:
1
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\btu
Operation:writeName:URL Protocol
Value:
Executable files
19
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\QT5CORE.DLLexecutable
MD5:DB58C7E71AA35D2CC47B57828590F569
SHA256:4714F75569ABA7CEBD6B13466527B190ADC1999AEF5C8F1F73CB2472282FAF6C
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXEexecutable
MD5:7BD86AC7842694E9AA6577A8C2321351
SHA256:1E9A43954EC45C50D92CE69E34461B306277D826BE551E81CDF96B9617C29835
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\LIBGLESV2.DLLexecutable
MD5:D4A37250588E61E50AD7F9D129F0D37E
SHA256:785768F643F00CC013FBAB8D620F3C1D3ABEC8BBECA5942BA31834DEA269774B
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\LIBEGL.DLLexecutable
MD5:0469918FC1E19FC3F198CD14BE4E1E22
SHA256:5DD84A436F1BEE9FC1FDF6285DB21E4ACB52BB63CD86C53C23B440F021E03401
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\QT5GUI.DLLexecutable
MD5:5581175E339938F80CAFB164BE0DC4B0
SHA256:78BCA9C65600391EC4BB1FB0374169DB13E7517EBD154A11D244248B25A7D939
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\EULA.TXTtext
MD5:BD114633A1BF09AEB388E01A706818C5
SHA256:FBF67F036F4EFCDA531624D21D855784560E810EE545950637BCD1F0BE3F0B0A
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\MSVCP140.DLLexecutable
MD5:5FF1FCA37C466D6723EC67BE93B51442
SHA256:5136A49A682AC8D7F1CE71B211DE8688FCE42ED57210AF087A8E2DBC8A934062
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\PLATFORMS\QWINDOWS.DLLexecutable
MD5:8D82F89BCA48D7DE90C17AC37F754F16
SHA256:AC3A36B775AC8B9CD1E3C3A7AC9DD31E0CC0A12B84D5942E97D77DA20992D005
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\QT5NETWORK.DLLexecutable
MD5:78932F74452BD17566E2E4FDCD8368D6
SHA256:E94054F7F5EFEBDA73F2A075745B9391FF2AC1215B6BC55A6402BCC5AED880FF
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\QT5SERIALPORT.DLLexecutable
MD5:2E865BF5B0B2D297D272D5E8BF740235
SHA256:52C8BD89CD5B4543D5F393DA9B7B04601CD4811D62A8EEDEF6DB971A8FE2F298
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
33
DNS requests
14
Threats
5

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4716
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
192.168.100.255:137
whitelisted
5620
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7856
svchost.exe
4.209.32.67:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2760
svchost.exe
40.113.103.199:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5820
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7856
svchost.exe
4.209.33.156:443
licensing.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4716
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.160.14
  • 40.126.32.76
  • 40.126.32.74
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.136
  • 40.126.32.72
  • 20.190.160.20
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 172.217.23.110
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
licensing.mp.microsoft.com
  • 4.209.33.156
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
www.bing.com
  • 104.126.37.153
  • 104.126.37.139
  • 104.126.37.128
  • 104.126.37.179
  • 104.126.37.185
  • 104.126.37.186
  • 104.126.37.145
  • 104.126.37.146
  • 104.126.37.178
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Pages platform for frontend developers to collaborate and deploy websites (pages .dev)
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Domain chain identified as Phishing
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
No debug info