File name:

BoseUpdaterInstaller_7.1.13.5180.exe

Full analysis: https://app.any.run/tasks/f7d97d2b-b9ae-495c-a70c-89e346b0521f
Verdict: Malicious activity
Analysis date: January 10, 2024, 20:05:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

5777989AC8B0ABEA98FC0283B8444BAF

SHA1:

CE3C0ED63EAA56710837FA4A96A60538E00740A4

SHA256:

80DB9CB21EC42475E64EF74580BE038266BEF359FEA24E8171691C01CAEA408D

SSDEEP:

98304:pGU9C2mZrWXAjVSBDVlEDk0HYfGER/vpfFF/3d3+uWddPVGLHdQ9hLtPSfH4yBzW:YXDGrxO/7+SDwg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
      • BOSEUPDATER.EXE (PID: 1040)
    • Reads settings of System Certificates

      • BOSEUPDATER.EXE (PID: 1040)
  • INFO

    • Checks supported languages

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2420)
      • BOSEUPDATER.EXE (PID: 1040)
      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
      • BOSEUPDATER.EXE (PID: 1556)
      • BOSEUPDATER.EXE (PID: 2660)
    • Drops the executable file immediately after the start

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2420)
      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
    • Creates files in the program directory

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2420)
      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
    • Reads the computer name

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2420)
      • BOSEUPDATER.EXE (PID: 1040)
      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
      • BOSEUPDATER.EXE (PID: 2660)
    • Process drops legitimate windows executable

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2420)
      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
    • Reads the machine GUID from the registry

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2420)
      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
      • BOSEUPDATER.EXE (PID: 1040)
    • Manual execution by a user

      • BOSEUPDATER.EXE (PID: 1040)
      • explorer.exe (PID: 1496)
      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 188)
      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
      • BOSEUPDATER.EXE (PID: 2660)
    • Create files in a temporary directory

      • BOSEUPDATER.EXE (PID: 1040)
    • The process drops C-runtime libraries

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2420)
      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
    • Checks proxy server information

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
    • Creates files or folders in the user directory

      • BoseUpdaterInstaller_7.1.13.5180.exe (PID: 2564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (43.5)
.exe | Win32 EXE Yoda's Crypter (42.7)
.exe | Win32 Executable (generic) (7.2)
.exe | Generic Win/DOS Executable (3.2)
.exe | DOS Executable Generic (3.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:09 16:25:28+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 9928704
InitializedDataSize: 45056
UninitializedDataSize: 17203200
EntryPoint: 0x19dff80
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 7.1.13.5180
ProductVersionNumber: 7.1.13.5180
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Bose Corporation
FileDescription: Bose® Device Updater
FileVersion: 7.1.13.5180
InternalName: BoseUpdaterInstaller.exe
LegalCopyright: � Bose Corporation 2024. All rights reserved.
OriginalFileName: BoseUpdaterInstaller.exe
ProductName: Bose Updater
ProductVersion: 7.1.13.5180
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start boseupdaterinstaller_7.1.13.5180.exe boseupdater.exe explorer.exe no specs boseupdaterinstaller_7.1.13.5180.exe no specs boseupdaterinstaller_7.1.13.5180.exe boseupdater.exe boseupdater.exe boseupdaterinstaller_7.1.13.5180.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5180.exe" C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5180.exeexplorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
MEDIUM
Description:
Bose® Device Updater
Exit code:
3221226540
Version:
7.1.13.5180
Modules
Images
c:\users\admin\downloads\boseupdaterinstaller_7.1.13.5180.exe
c:\windows\system32\ntdll.dll
188"C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5180.exe" C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5180.exeexplorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
MEDIUM
Description:
Bose® Device Updater
Exit code:
3221226540
Version:
7.1.13.5180
Modules
Images
c:\users\admin\downloads\boseupdaterinstaller_7.1.13.5180.exe
c:\windows\system32\ntdll.dll
1040"C:\Program Files\Bose Updater\BOSEUPDATER.EXE" /initC:\Program Files\Bose Updater\BOSEUPDATER.EXE
explorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
MEDIUM
Description:
Bose® Device Updater
Exit code:
0
Version:
7.1.13.5180
Modules
Images
c:\program files\bose updater\boseupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
1496"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1556"C:\Program Files\Bose Updater\BoseUpdater.exe" /uninstallC:\Program Files\Bose Updater\BOSEUPDATER.EXE
BoseUpdaterInstaller_7.1.13.5180.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
HIGH
Description:
Bose® Device Updater
Exit code:
0
Version:
7.1.13.5180
Modules
Images
c:\program files\bose updater\boseupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
2420"C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5180.exe" C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5180.exe
explorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
HIGH
Description:
Bose® Device Updater
Exit code:
0
Version:
7.1.13.5180
Modules
Images
c:\users\admin\downloads\boseupdaterinstaller_7.1.13.5180.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\ole32.dll
2564"C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5180.exe" C:\Users\admin\Downloads\BoseUpdaterInstaller_7.1.13.5180.exe
explorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
HIGH
Description:
Bose® Device Updater
Exit code:
0
Version:
7.1.13.5180
Modules
Images
c:\users\admin\downloads\boseupdaterinstaller_7.1.13.5180.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\ole32.dll
2660"C:\Program Files\Bose Updater\BOSEUPDATER.EXE" /initC:\Program Files\Bose Updater\BOSEUPDATER.EXE
explorer.exe
User:
admin
Company:
Bose Corporation
Integrity Level:
MEDIUM
Description:
Bose® Device Updater
Exit code:
0
Version:
7.1.13.5180
Modules
Images
c:\program files\bose updater\boseupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
Total events
2 310
Read events
2 289
Write events
12
Delete events
9

Modification events

(PID) Process:(2420) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bose Updater
Operation:delete keyName:(default)
Value:
(PID) Process:(2420) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\btu
Operation:delete keyName:(default)
Value:
(PID) Process:(2564) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2564) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2564) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2564) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2564) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2564) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2564) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2564) BoseUpdaterInstaller_7.1.13.5180.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
38
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\AWS-CPP-SDK-CORE.DLLexecutable
MD5:FAB66E1C94590B55E377665F26AC31B5
SHA256:8CD3EF7B0183FB255841C4DFDA31413126006DA28CE672BEEAAC21F421D2F154
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\BOSEUPDATER.EXEexecutable
MD5:9774E3C5B4CC4B24937DF016AFD7BB81
SHA256:462BF66587320DB3BFD22F2431FD829E5BFBC1D407C3ECA60346475472EF4EE9
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\AWS-CPP-SDK-S3.DLLexecutable
MD5:B64E1DB05C2E794C8DB0CE9127C10EA0
SHA256:F21BCD19F480E3B39D550667E2F18BC15B6F4F46336BAF3CCD587FB4C45212CF
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\LIBEAY32.DLLexecutable
MD5:A236287C42F921D109475D47E9DCAC2B
SHA256:63AA600A7C914C2D59280069169CC93E750E42C9A1146E238C9128E073D578FD
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\QT5CORE.DLLexecutable
MD5:DB58C7E71AA35D2CC47B57828590F569
SHA256:4714F75569ABA7CEBD6B13466527B190ADC1999AEF5C8F1F73CB2472282FAF6C
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\QT5NETWORK.DLLexecutable
MD5:78932F74452BD17566E2E4FDCD8368D6
SHA256:E94054F7F5EFEBDA73F2A075745B9391FF2AC1215B6BC55A6402BCC5AED880FF
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\LIBEGL.DLLexecutable
MD5:0469918FC1E19FC3F198CD14BE4E1E22
SHA256:5DD84A436F1BEE9FC1FDF6285DB21E4ACB52BB63CD86C53C23B440F021E03401
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\QT5WIDGETS.DLLexecutable
MD5:4E44578216ABF3654056015EF4C8A9C3
SHA256:91BB41088F847FB73641FA556EDA6D67BACB67560B8ABF6EA1F0C885390004F8
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\MSVCP140.DLLexecutable
MD5:5FF1FCA37C466D6723EC67BE93B51442
SHA256:5136A49A682AC8D7F1CE71B211DE8688FCE42ED57210AF087A8E2DBC8A934062
2420BoseUpdaterInstaller_7.1.13.5180.exeC:\Program Files\Bose Updater\QT5SERIALPORT.DLLexecutable
MD5:2E865BF5B0B2D297D272D5E8BF740235
SHA256:52C8BD89CD5B4543D5F393DA9B7B04601CD4811D62A8EEDEF6DB971A8FE2F298
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1040
BOSEUPDATER.EXE
99.84.88.12:443
worldwide.bose.com
AMAZON-02
US
unknown
1040
BOSEUPDATER.EXE
3.5.17.140:443
bose-downloads.s3.amazonaws.com
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
worldwide.bose.com
  • 99.84.88.12
  • 99.84.88.102
  • 99.84.88.129
  • 99.84.88.46
unknown
bose-downloads.s3.amazonaws.com
  • 3.5.17.140
  • 52.217.96.36
  • 52.217.105.60
  • 52.216.133.163
  • 52.216.57.57
  • 54.231.172.169
  • 52.217.168.49
  • 52.217.171.241
unknown

Threats

No threats detected
Process
Message
BOSEUPDATER.EXE
"Bose Updater startup ver 7.1.13.5180"
BOSEUPDATER.EXE
"Starting web server"
BOSEUPDATER.EXE
"Loaded locale: en, suffix: en, result = true"
BOSEUPDATER.EXE
"Loading translations"
BOSEUPDATER.EXE
"Creating notification icon"
BOSEUPDATER.EXE
"Tray available: 1"
BOSEUPDATER.EXE
"Listening now"
BOSEUPDATER.EXE
"Loading settings"
BOSEUPDATER.EXE
"Loaded icon: 1 :/images/favicon.png"
BOSEUPDATER.EXE
"Token missing for request GET /updater/exitProcess HTTP/1.1\r"