File name:

BoseUpdaterInstaller_7.1.13.5238 (1).exe

Full analysis: https://app.any.run/tasks/2ac86515-482b-4fe8-b312-e78a20c542e2
Verdict: Malicious activity
Analysis date: July 19, 2024, 15:31:57
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

81F6218BCF4CB298C0BEECFC3E428D63

SHA1:

73F09DAC335DBCF5DB151726DBD15C96C0074A8E

SHA256:

423E7009C7F9F42166D27BECC780BF72C551E2075391CE98D80F46A5ABCA0373

SSDEEP:

98304:HlhwePBeox3ImKbttvReOWOn251c1nyRMwUtH8YS1RYCH1s7tjQEor62qK0WDMOa:i2Z9YoEEFayZ8H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
    • The process drops C-runtime libraries

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
    • Creates a software uninstall entry

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
    • Executable content was dropped or overwritten

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
  • INFO

    • Checks supported languages

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
      • BOSEUPDATER.EXE (PID: 6980)
    • Reads the computer name

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
      • BOSEUPDATER.EXE (PID: 6980)
    • Creates files in the program directory

      • BoseUpdaterInstaller_7.1.13.5238 (1).exe (PID: 4372)
    • UPX packer has been detected

      • BOSEUPDATER.EXE (PID: 6980)
    • Create files in a temporary directory

      • BOSEUPDATER.EXE (PID: 6980)
    • Manual execution by a user

      • BOSEUPDATER.EXE (PID: 6980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (43.5)
.exe | Win32 EXE Yoda's Crypter (42.7)
.exe | Win32 Executable (generic) (7.2)
.exe | Generic Win/DOS Executable (3.2)
.exe | DOS Executable Generic (3.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:05:15 15:32:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 9928704
InitializedDataSize: 45056
UninitializedDataSize: 17203200
EntryPoint: 0x19e0780
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 7.1.13.5238
ProductVersionNumber: 7.1.13.5238
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Bose Corporation
FileDescription: Bose® Device Updater
FileVersion: 7.1.13.5238
InternalName: BoseUpdaterInstaller.exe
LegalCopyright: � Bose Corporation 2024. All rights reserved.
OriginalFileName: BoseUpdaterInstaller.exe
ProductName: Bose Updater
ProductVersion: 7.1.13.5238
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start boseupdaterinstaller_7.1.13.5238 (1).exe THREAT boseupdater.exe no specs slui.exe no specs boseupdaterinstaller_7.1.13.5238 (1).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1032"C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5238 (1).exe" C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5238 (1).exeexplorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
MEDIUM
Description:
Bose® Device Updater
Exit code:
3221226540
Version:
7.1.13.5238
Modules
Images
c:\users\admin\downloads\boseupdaterinstaller_7.1.13.5238 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4372"C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5238 (1).exe" C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5238 (1).exe
explorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
HIGH
Description:
Bose® Device Updater
Exit code:
0
Version:
7.1.13.5238
Modules
Images
c:\users\admin\downloads\boseupdaterinstaller_7.1.13.5238 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4612C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6980"C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE" /initC:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE
explorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
MEDIUM
Description:
Bose® Device Updater
Version:
7.1.13.5238
Modules
Images
c:\program files (x86)\bose updater\boseupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
831
Read events
818
Write events
9
Delete events
4

Modification events

(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:delete keyName:(default)
Value:
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\btu
Operation:delete keyName:(default)
Value:
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\Bose Updater\uninstall.exe" /uninstall
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:DisplayName
Value:
Bose Updater
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:Publisher
Value:
Bose Corporation
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:DisplayVersion
Value:
7.1.13.5238
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE,0
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:NoModify
Value:
1
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:writeName:NoRepair
Value:
1
(PID) Process:(4372) BoseUpdaterInstaller_7.1.13.5238 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\btu
Operation:writeName:URL Protocol
Value:
Executable files
19
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\AWS-CPP-SDK-CORE.DLLexecutable
MD5:FAB66E1C94590B55E377665F26AC31B5
SHA256:8CD3EF7B0183FB255841C4DFDA31413126006DA28CE672BEEAAC21F421D2F154
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\LIBGLESV2.DLLexecutable
MD5:D4A37250588E61E50AD7F9D129F0D37E
SHA256:785768F643F00CC013FBAB8D620F3C1D3ABEC8BBECA5942BA31834DEA269774B
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\CONCRT140.DLLexecutable
MD5:35628D71CF20D4F8AAFB0ABA8DF14B70
SHA256:B2C8A0FBCD4C2EB9BC1AAB03F8FDB2D72D78573A54F3E83D44C95246C4F2D168
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\LIBEAY32.DLLexecutable
MD5:A236287C42F921D109475D47E9DCAC2B
SHA256:63AA600A7C914C2D59280069169CC93E750E42C9A1146E238C9128E073D578FD
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\EULA.TXTtext
MD5:BD114633A1BF09AEB388E01A706818C5
SHA256:FBF67F036F4EFCDA531624D21D855784560E810EE545950637BCD1F0BE3F0B0A
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\AWS-CPP-SDK-S3.DLLexecutable
MD5:B64E1DB05C2E794C8DB0CE9127C10EA0
SHA256:F21BCD19F480E3B39D550667E2F18BC15B6F4F46336BAF3CCD587FB4C45212CF
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\QT5WIDGETS.DLLexecutable
MD5:4E44578216ABF3654056015EF4C8A9C3
SHA256:91BB41088F847FB73641FA556EDA6D67BACB67560B8ABF6EA1F0C885390004F8
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\PLATFORMS\QWINDOWS.DLLexecutable
MD5:8D82F89BCA48D7DE90C17AC37F754F16
SHA256:AC3A36B775AC8B9CD1E3C3A7AC9DD31E0CC0A12B84D5942E97D77DA20992D005
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\SSLEAY32.DLLexecutable
MD5:EE856A00410ECED8CC609936D01F954E
SHA256:B6192300D3C1476EF3C25A368D055AA401035E78F9F6DBE5F93C84D36EF1FA62
4372BoseUpdaterInstaller_7.1.13.5238 (1).exeC:\Program Files (x86)\Bose Updater\QT5XML.DLLexecutable
MD5:D6CE2679999CE4EBA077310850897268
SHA256:C6CFF6AF4BAB546CA2AC2D6E7FD999899A411D8A861C125E6BD36778817C0428
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
33
DNS requests
14
Threats
5

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4716
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
192.168.100.255:137
whitelisted
5620
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7856
svchost.exe
4.209.32.67:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2760
svchost.exe
40.113.103.199:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5820
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7856
svchost.exe
4.209.33.156:443
licensing.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4716
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.160.14
  • 40.126.32.76
  • 40.126.32.74
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.136
  • 40.126.32.72
  • 20.190.160.20
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 172.217.23.110
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
licensing.mp.microsoft.com
  • 4.209.33.156
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
www.bing.com
  • 104.126.37.153
  • 104.126.37.139
  • 104.126.37.128
  • 104.126.37.179
  • 104.126.37.185
  • 104.126.37.186
  • 104.126.37.145
  • 104.126.37.146
  • 104.126.37.178
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Pages platform for frontend developers to collaborate and deploy websites (pages .dev)
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Domain chain identified as Phishing
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
No debug info