| File name: | SupportAssistInstaller.exe |
| Full analysis: | https://app.any.run/tasks/2c30997d-e4cf-42d3-a267-6bc092422a20 |
| Verdict: | Malicious activity |
| Analysis date: | July 25, 2019, 17:36:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | 27187B033E6B3F46F1BD8B69BE02859F |
| SHA1: | 78529BF2258021D54E0F763DF917329567E24D91 |
| SHA256: | AD37B80D9CC8796B79E313C01BF2C244FA7EA8EAA96C09BD2841944E4FECE2F8 |
| SSDEEP: | 6144:qdKpsv8oSl2u8GRXmg/Sb+26axbYJrRV7xIXt08YEchiYOZODuFLOnQN67uYBBMb:yKLoSl2qJq9xbsRVFUKX8SuFCKJY1g8Y |
| .exe | | | UPX compressed Win32 Executable (39.3) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (38.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.5) |
| .exe | | | Win32 Executable (generic) (6.5) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:11:18 17:27:32+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 45056 |
| InitializedDataSize: | 8192 |
| UninitializedDataSize: | 90112 |
| EntryPoint: | 0x21420 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 9.20.0.0 |
| ProductVersionNumber: | 9.20.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Dell Inc. |
| FileDescription: | SupportAssist Installer |
| FileVersion: | 2.2.0.0 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Copyright © 2018 Dell Inc. or its subsidiaries. All Rights Reserved. |
| OriginalFileName: | 7zS.sfx.exe |
| ProductName: | SupportAssist |
| ProductVersion: | 2.2.0.0 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 18-Nov-2010 16:27:32 |
| Detected languages: |
|
| CompanyName: | Dell Inc. |
| FileDescription: | SupportAssist Installer |
| FileVersion: | 2.2.0.0 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Copyright © 2018 Dell Inc. or its subsidiaries. All Rights Reserved. |
| OriginalFilename: | 7zS.sfx.exe |
| ProductName: | SupportAssist |
| ProductVersion: | 2.2.0.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 3 |
| Time date stamp: | 18-Nov-2010 16:27:32 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
UPX0 | 0x00001000 | 0x00016000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
UPX1 | 0x00017000 | 0x0000B000 | 0x0000B000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.97532 |
.rsrc | 0x00022000 | 0x00002000 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.76821 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.01524 | 1949 | UNKNOWN | UNKNOWN | RT_MANIFEST |
2 | 3.18403 | 296 | UNKNOWN | English - United States | RT_ICON |
5 | 5.62352 | 52 | UNKNOWN | English - United States | RT_STRING |
500 | 6.95547 | 184 | UNKNOWN | English - United States | RT_DIALOG |
KERNEL32.DLL |
MSVCRT.dll |
OLEAUT32.dll |
SHELL32.dll |
USER32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 544 | "SCHTASKS.exe" /Create /XML C:\Windows\TEMP\AutoUpdateScheduler.xml /TN "Dell SupportAssistAgent AutoUpdate" | C:\Windows\system32\SCHTASKS.exe | — | SupportAssistAgent.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 796 | "SupportAssistDownloadManager.exe" https://downloads.dell.com/serviceability/Catalog/SupportAssistx86-3.2.2.119.msp "C:\Windows\TEMP\SupportAssistAgent\LauncherAutoUpdate\SupportAssistx86-3.2.2.119.msp" | C:\Windows\TEMP\SupportAssistAgent\Installer\SupportAssistDownloadManager.exe | SupportAssistInstaller.exe | ||||||||||||
User: admin Company: Dell Inc. Integrity Level: HIGH Description: DownloadManager Exit code: 0 Version: 3.1.0.0 Modules
| |||||||||||||||
| 804 | C:\Windows\system32\MsiExec.exe -Embedding 1C121565AD276E5E49D0862929A0B724 M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 884 | "C:\Windows\TEMP\SupportAssistAgent\Installer\SupportAssistInstaller.exe" noargument | C:\Windows\TEMP\SupportAssistAgent\Installer\SupportAssistInstaller.exe | SupportAssistInstaller.exe | ||||||||||||
User: admin Company: Dell Inc. Integrity Level: HIGH Description: SupportAssistInstaller Exit code: 0 Version: 3.1.0.142 Modules
| |||||||||||||||
| 920 | C:\Windows\system32\MsiExec.exe -Embedding E1C4A54D2EC1FC995185DF274296B671 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1672 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1884 | "SupportAssistDownloadManager.exe" https://downloads.dell.com/serviceability/Catalog/SupportAssistx86-3.2.2.119.msi "C:\Windows\TEMP\SupportAssistAgent\LauncherAutoUpdate\SupportAssistx86-3.2.2.119.msi" | C:\Windows\TEMP\SupportAssistAgent\Installer\SupportAssistDownloadManager.exe | SupportAssistInstaller.exe | ||||||||||||
User: admin Company: Dell Inc. Integrity Level: HIGH Description: DownloadManager Exit code: 0 Version: 3.1.0.0 Modules
| |||||||||||||||
| 1896 | "C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe" | C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe | services.exe | ||||||||||||
User: SYSTEM Company: Dell Inc. Integrity Level: SYSTEM Description: Service Exit code: 0 Version: 3.2.2.119 Modules
| |||||||||||||||
| 2168 | "msiexec.exe" /i C:\Windows\TEMP\SupportAssistAgent\LauncherAutoUpdate\SupportAssistx86-3.2.2.119.msi /qn REBOOT=ReallySuppress /norestart | C:\Windows\system32\msiexec.exe | — | SupportAssistInstaller.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2464 | .\SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\SupportAssistInstaller.exe | SupportAssistInstaller.exe | ||||||||||||
User: admin Company: Dell Inc. Integrity Level: MEDIUM Description: SupportAssistInstaller Exit code: 0 Version: 3.1.0.142 Modules
| |||||||||||||||
| (PID) Process: | (2464) SupportAssistInstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2464) SupportAssistInstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2464) SupportAssistInstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: SupportAssistInstaller.exe | |||
| (PID) Process: | (884) SupportAssistInstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (884) SupportAssistInstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (884) SupportAssistInstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: SupportAssistInstaller.exe | |||
| (PID) Process: | (3968) SupportAssistDownloadManager.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application |
| Operation: | write | Name: | AutoBackupLogFiles |
Value: 0 | |||
| (PID) Process: | (3968) SupportAssistDownloadManager.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\SupportAssistAgent |
| Operation: | write | Name: | EventMessageFile |
Value: C:\Windows\Microsoft.NET\Framework\v4.0.30319\EventLogMessages.dll | |||
| (PID) Process: | (3968) SupportAssistDownloadManager.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SupportAssistDownloadManager_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3968) SupportAssistDownloadManager.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SupportAssistDownloadManager_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\Resources\New-Dell-Logo-White.png | image | |
MD5:18AE7C444367FB4BF43E20DCD4F721F0 | SHA256:C3B07610D159518DFBF0087BD3AD60193B2814D391D5F960538397422EC2FCF7 | |||
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\SupportAssistInstaller.exe.config | xml | |
MD5:8E38AB4400A26B4476B12DDC818B3938 | SHA256:136C95A49587F46687ED52625F194D17EEE974D267028EC0237DAD89D9C763AA | |||
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\Resources\Alienware-Logo-head-while.png | image | |
MD5:BC4CD5C98535966A9853443D32C886D1 | SHA256:9B1734C28917520C3CC492602997FDA7AC3320520A8F2E9BCBEA6F8CDEBE0206 | |||
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\Microsoft.Deployment.Compression.Cab.dll | executable | |
MD5:A8A1C773013848C13E8A61FFF539A9F8 | SHA256:34576A410DC632C5F60AC6476E66EA88A4271ECD7AE1C878D079DD78E50CF7C1 | |||
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\SupportAssistInstaller.exe | executable | |
MD5:E2711C6F88A76558149C397CCE6E800A | SHA256:59580F7BA427E465DEB5F606EC25ECBE7977AD126BD85082A53C8A88296E1B59 | |||
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\SupportAssistDownloadManager.exe | executable | |
MD5:7857F6D351B958DEE84369D627797191 | SHA256:30EA52D707D396360EB01B93F89DB1716C1D6799EEF2FD349C29554795B9CB01 | |||
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\log4net.dll | executable | |
MD5:D035DFB88B97167074272C955369D181 | SHA256:C72E3851D0793E2FF6CE3EEC73F6C71AAB895450C0295C6A20CB0987FBEDE0A1 | |||
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\Microsoft.Practices.Unity.dll | executable | |
MD5:87AA4850BF57F6AF6A9A7610DB2CD793 | SHA256:AF079CB2A1B853F6FF993DDBBAD0ADCD9D80F704DBB94C8586564372C23EB330 | |||
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\Resources\greenTick_28x28.png | image | |
MD5:7910E3985D12331C628B93037DE44E43 | SHA256:92403FBB74777EA753908726D2548F3D08CE242AA61AFE0DCD19CBB0325DCB2F | |||
| 3412 | SupportAssistInstaller.exe | C:\Users\admin\AppData\Local\Temp\7zSF03C.tmp\de-DE\SupportAssistInstaller.resources.dll | executable | |
MD5:2E9739314B471CDB105093CA18C4112A | SHA256:23AC2B3621FE216F2CF0F45729C67E274232BE2A735A2BD456455E4F916A33DC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
884 | SupportAssistInstaller.exe | GET | 200 | 23.37.43.27:80 | http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D | NL | der | 1.71 Kb | whitelisted |
884 | SupportAssistInstaller.exe | GET | 200 | 93.184.220.29:80 | http://sv.symcb.com/sv.crt | US | der | 1.34 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3968 | SupportAssistDownloadManager.exe | 2.18.232.9:443 | downloads.dell.com | Akamai International B.V. | — | whitelisted |
884 | SupportAssistInstaller.exe | 93.184.220.29:80 | sv.symcb.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
884 | SupportAssistInstaller.exe | 23.37.43.27:80 | s2.symcb.com | Akamai Technologies, Inc. | NL | whitelisted |
1884 | SupportAssistDownloadManager.exe | 2.18.232.9:443 | downloads.dell.com | Akamai International B.V. | — | whitelisted |
3692 | SupportAssistDownloadManager.exe | 2.18.232.9:443 | downloads.dell.com | Akamai International B.V. | — | whitelisted |
1896 | SupportAssistAgent.exe | 104.111.214.12:443 | afcs.dell.com | Akamai International B.V. | NL | whitelisted |
796 | SupportAssistDownloadManager.exe | 2.18.232.9:443 | downloads.dell.com | Akamai International B.V. | — | whitelisted |
1896 | SupportAssistAgent.exe | 2.18.232.9:443 | downloads.dell.com | Akamai International B.V. | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
downloads.dell.com |
| whitelisted |
sv.symcb.com |
| whitelisted |
s2.symcb.com |
| whitelisted |
sv.symcd.com |
| shared |
afcs.dell.com |
| whitelisted |
Process | Message |
|---|---|
SupportAssistInstaller.exe | log4net:ERROR Could not create Appender [CustomizedFileAppender] of type [Dell.Services.SupportAssist.Logger.CustomizedFileAppender, Logger]. Reported error follows.
|
SupportAssistInstaller.exe | System.IO.FileNotFoundException: Could not load file or assembly 'Logger' or one of its dependencies. The system cannot find the file specified.
File name: 'Logger'
at System.RuntimeTypeHandle.GetTypeByName(String name, Boolean throwOnError, Boolean ignoreCase, Boolean reflectionOnly, StackCrawlMarkHandle stackMark, IntPtr pPrivHostBinder, Boolean loadTypeFromPartialName, ObjectHandleOnStack type)
at System.RuntimeTypeHandle.GetTypeByName(String name, Boolean throwOnError, Boolean ignoreCase, Boolean reflectionOnly, StackCrawlMark& stackMark, IntPtr pPrivHostBinder, Boolean loadTypeFromPartialName)
at System.RuntimeType.GetType(String typeName, Boolean throwOnError, Boolean ignoreCase, Boolean reflectionOnly, StackCrawlMark& stackMark)
at System.Type.GetType(String typeName, Boolean throwOnError, Boolean ignoreCase)
at log4net.Util.SystemInfo.GetTypeFromString(Assembly relativeAssembly, String typeName, Boolean throwOnError, Boolean ignoreCase)
at log4net.Util.SystemInfo.GetTypeFromString(String typeName, Boolean throwOnError, Boolean ignoreCase)
at log4net.Repository.Hierarchy.XmlHierarchyConfigurator.ParseAppender(XmlElement appenderElement)
WRN: Assembly binding logging is turned OFF.
To enable assembly bind failure logging, set the registry value [HKLM\Software\Microsoft\Fusion!EnableLog] (DWORD) to 1.
Note: There is some performance penalty associated with assembly bind failure logging.
To turn this feature off, remove the registry value [HKLM\Software\Microsoft\Fusion!EnableLog].
|
SupportAssistInstaller.exe | log4net:ERROR Appender named [CustomizedFileAppender] not found.
|
SupportAssistInstaller.exe | log4net:ERROR Could not create Appender [CustomizedFileAppender] of type [Dell.Services.SupportAssist.Logger.CustomizedFileAppender, Logger]. Reported error follows.
|
SupportAssistInstaller.exe | log4net:ERROR Appender named [CustomizedFileAppender] not found.
|
SupportAssistInstaller.exe | log4net:ERROR Appender named [CustomizedFileAppender] not found.
|
SupportAssistInstaller.exe | log4net:ERROR Could not create Appender [CustomizedFileAppender] of type [Dell.Services.SupportAssist.Logger.CustomizedFileAppender, Logger]. Reported error follows.
|
SupportAssistInstaller.exe | System.IO.FileNotFoundException: Could not load file or assembly 'Logger' or one of its dependencies. The system cannot find the file specified.
File name: 'Logger'
at System.RuntimeTypeHandle.GetTypeByName(String name, Boolean throwOnError, Boolean ignoreCase, Boolean reflectionOnly, StackCrawlMarkHandle stackMark, IntPtr pPrivHostBinder, Boolean loadTypeFromPartialName, ObjectHandleOnStack type)
at System.RuntimeTypeHandle.GetTypeByName(String name, Boolean throwOnError, Boolean ignoreCase, Boolean reflectionOnly, StackCrawlMark& stackMark, IntPtr pPrivHostBinder, Boolean loadTypeFromPartialName)
at System.RuntimeType.GetType(String typeName, Boolean throwOnError, Boolean ignoreCase, Boolean reflectionOnly, StackCrawlMark& stackMark)
at System.Type.GetType(String typeName, Boolean throwOnError, Boolean ignoreCase)
at log4net.Util.SystemInfo.GetTypeFromString(Assembly relativeAssembly, String typeName, Boolean throwOnError, Boolean ignoreCase)
at log4net.Util.SystemInfo.GetTypeFromString(String typeName, Boolean throwOnError, Boolean ignoreCase)
at log4net.Repository.Hierarchy.XmlHierarchyConfigurator.ParseAppender(XmlElement appenderElement)
WRN: Assembly binding logging is turned OFF.
To enable assembly bind failure logging, set the registry value [HKLM\Software\Microsoft\Fusion!EnableLog] (DWORD) to 1.
Note: There is some performance penalty associated with assembly bind failure logging.
To turn this feature off, remove the registry value [HKLM\Software\Microsoft\Fusion!EnableLog].
|
SupportAssistInstaller.exe | log4net:ERROR Appender named [CustomizedFileAppender] not found.
|
SupportAssistInstaller.exe | log4net:ERROR Could not create Appender [CustomizedFileAppender] of type [Dell.Services.SupportAssist.Logger.CustomizedFileAppender, Logger]. Reported error follows.
|