| File name: | Intel-Driver-and-Support-Assistant-Installer.exe |
| Full analysis: | https://app.any.run/tasks/2ac1e4a6-da0b-411f-85de-6827bdafcfa4 |
| Verdict: | Malicious activity |
| Analysis date: | June 25, 2024, 19:57:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 75174C136C15EB50C81EBFCB7B768D6A |
| SHA1: | 8A7F7844AD78F1A1B6B3B1E07D06B8ADA09A2B53 |
| SHA256: | 6682E936C0914AD87DD6699E8A7F22FAE9BB255E4393930281C86972665DD369 |
| SSDEEP: | 49152:YYiVOXT863HShwxaSffCunW6OcURY5D8vAkOd2z5HNmedf/ptG72T/CSOZr:biwhXSPyjhOpRMD8vZjmedLG70CSe |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:04:05 19:45:02+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit, Removable run from swap, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 14.38 |
| CodeSize: | 483328 |
| InitializedDataSize: | 317440 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x517f0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 24.3.26.8 |
| ProductVersionNumber: | 24.3.26.8 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| CompanyName: | Intel |
| FileDescription: | Intel® Driver & Support Assistant |
| FileVersion: | 24.3.26.8 |
| InternalName: | burn |
| OriginalFileName: | Intel-Driver-and-Support-Assistant-Installer.exe |
| ProductName: | Intel® Driver & Support Assistant |
| ProductVersion: | 24.3.26.8 |
| LegalCopyright: | Copyright © Intel Corporation. All rights reserved. |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3392 | "C:\Users\admin\AppData\Local\Temp\Intel-Driver-and-Support-Assistant-Installer.exe" | C:\Users\admin\AppData\Local\Temp\Intel-Driver-and-Support-Assistant-Installer.exe | explorer.exe | ||||||||||||
User: admin Company: Intel Integrity Level: MEDIUM Description: Intel® Driver & Support Assistant Version: 24.3.26.8 Modules
| |||||||||||||||
| 3700 | "C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\BootstrapperUI_V2.exe" -burn.ba.apiver 569705357157400576 -burn.ba.pipe BurnPipe.{78042054-7B80-4271-B3D4-EDB7138353EA} {8032D56C-2978-499E-8592-4BC5F3E7B194} | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\BootstrapperUI_V2.exe | — | Intel-Driver-and-Support-Assistant-Installer.exe | |||||||||||
User: admin Company: Intel Integrity Level: MEDIUM Description: BootstrapperUI Version: 24.3.26.8 Modules
| |||||||||||||||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (3700) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\de\BootstrapperUI_V2.resources.dll | executable | |
MD5:E20749FC2A2A24F4499A6E622CF263EF | SHA256:1E24731DC7BD4FE61C7C37B082F3B00108F047EE24B4596CFD570B52B0C2D3AA | |||
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\ko\BootstrapperUI_V2.resources.dll | executable | |
MD5:C6C9EA1C041F6DD390A53A5714F559A5 | SHA256:955D5C14BE38EB620B049D7F5B192F1D6E614320B17C1625D9F0CD7289AEFA04 | |||
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\id\BootstrapperUI_V2.resources.dll | executable | |
MD5:F6CCDE24E714364CE7288FE7CED0A3B8 | SHA256:E8AE1E7D3A237ADA0D95A8C739A11570F52AE956242B910DB59BDF226DF75DBF | |||
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\BootstrapperUI_V2.exe | executable | |
MD5:7FCF8606160DEC95FBDB53701908ED01 | SHA256:D1124234641940BE68AC2AF4BCDDB2D0FF6C4C44E982A33608E9BA692B6E854A | |||
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\fr\BootstrapperUI_V2.resources.dll | executable | |
MD5:E462631050803B72DFCA3B49E91D1ACD | SHA256:C146DDB32FD877A17201A72A2AC7EBF9736F550B71A3C4581A3B701E1AA5DB78 | |||
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\GalaSoft.MvvmLight.Platform.dll | executable | |
MD5:819EABE09308AD05341152E61925B33F | SHA256:A5E126E6879F7326F621A5D08B2552C0D54B6A44D23FEC997058A1A6C78B174D | |||
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\ja\BootstrapperUI_V2.resources.dll | executable | |
MD5:2C8B2E47BEBD546A8C053F8859D306D6 | SHA256:7898FAF8BF359CF21E1074C83772421981D87E8D53A6AB69C3543064C4F3081E | |||
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\System.Buffers.dll | executable | |
MD5:6868FC142B679D8EBEEF2AC3A6CFCED5 | SHA256:962B2711D5792B2B265C6E5BE74745B122BF24584803614CEAB7F44F6EC9D5CA | |||
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\zh-CN\BootstrapperUI_V2.resources.dll | executable | |
MD5:D7E708FEF39D4179CB518391091329F7 | SHA256:59A850476D1A5A3EB7FE850B09F9B58F7D0DC257227CA1291E9FF228B5E09056 | |||
| 3392 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{C232CBC7-682E-41B8-8DDE-48B4433FB196}\.ba\zh-TW\BootstrapperUI_V2.resources.dll | executable | |
MD5:E40528D73249E402E5DCED08FA7248A7 | SHA256:F0B63C48476F47B40C55E59627A44DC4E59A638AB223C8C870B8718FF7590482 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1372 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33 | unknown | — | — | unknown |
1372 | svchost.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
1372 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
1060 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbe613066ac7852b | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1372 | svchost.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1372 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1372 | svchost.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
1372 | svchost.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
1372 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
1060 | svchost.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
dns.msftncsi.com |
| shared |
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |