File name:

Intel-Driver-and-Support-Assistant-Installer.exe

Full analysis: https://app.any.run/tasks/3810140c-854a-4ef8-8aba-3da3fb4962da
Verdict: Malicious activity
Analysis date: August 01, 2024, 21:28:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

85B706697C86D9FA7909C42CA60E7949

SHA1:

BC6EE7BF70438F4B4A2EFE6A03E7DAE7F5A9C536

SHA256:

DF5ED3253A7B9BBFCA7328EAC9A5BF6FF78B8E4084B7DF159EFEDE52BE8617A5

SSDEEP:

98304:ziwhXS+yjhOpRMD8vZjmedLG70CSeiTYETWN9KCLxHVFalqGTobVN0TiDiMjR2oj:NrrggvDe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 32)
      • cmd.exe (PID: 7372)
    • Changes the autorun value in the registry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 7244)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • cmd.exe (PID: 7372)
    • Process drops legitimate windows executable

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
    • Reads security settings of Internet Explorer

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • SurSvc.exe (PID: 6260)
      • DSATray.exe (PID: 8012)
      • SurSvc.exe (PID: 8016)
      • esrv.exe (PID: 2152)
      • DSAServiceHelper.exe (PID: 7672)
    • Searches for installed software

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • dllhost.exe (PID: 6268)
      • SurSvc.exe (PID: 6260)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
    • Reads the date of Windows installation

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAServiceHelper.exe (PID: 7672)
    • Creates a software uninstall entry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2212)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv_svc.exe (PID: 8120)
      • WmiApSrv.exe (PID: 7452)
      • esrv_svc.exe (PID: 7256)
    • Checks Windows Trust Settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • SurSvc.exe (PID: 6260)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
    • Mutex name with non-standard characters

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 32)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 32)
    • Starts CMD.EXE for commands execution

      • msiexec.exe (PID: 6360)
      • SurSvc.exe (PID: 6260)
      • cmd.exe (PID: 7244)
      • SurSvc.exe (PID: 8016)
      • wscript.exe (PID: 6344)
    • Process drops python dynamic module

      • msiexec.exe (PID: 32)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 32)
      • cmd.exe (PID: 7372)
    • Process drops SQLite DLL files

      • msiexec.exe (PID: 32)
    • Uses ICACLS.EXE to modify access control lists

      • msiexec.exe (PID: 6360)
    • Creates files in the driver directory

      • DSAService.exe (PID: 5072)
      • cmd.exe (PID: 7372)
    • Executing commands from a ".bat" file

      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • wscript.exe (PID: 6344)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 32)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 7244)
    • Starts application with an unusual extension

      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 7372)
    • Creates or modifies Windows services

      • reg.exe (PID: 8160)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • reg.exe (PID: 7780)
      • SurSvc.exe (PID: 6260)
    • Application launched itself

      • cmd.exe (PID: 7244)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 7372)
    • Executes application which crashes

      • SurSvc.exe (PID: 8016)
    • Loads Python modules

      • IntelSoftwareAssetManagerService.exe (PID: 7784)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 7372)
      • esrv.exe (PID: 2152)
    • Runs WScript without displaying logo

      • wscript.exe (PID: 6344)
    • The process executes via Task Scheduler

      • wscript.exe (PID: 6344)
    • Reads the BIOS version

      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 6344)
    • The process checks if it is being run in the virtual environment

      • esrv.exe (PID: 2152)
      • esrv_svc.exe (PID: 8120)
    • Detected use of alternative data streams (AltDS)

      • esrv_svc.exe (PID: 8120)
  • INFO

    • Checks supported languages

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 7140)
      • DSAUpdateService.exe (PID: 5144)
      • msiexec.exe (PID: 6360)
      • msiexec.exe (PID: 4248)
      • msiexec.exe (PID: 2464)
      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • chcp.com (PID: 7288)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • DSAArcDetect64.exe (PID: 7832)
      • SurSvc.exe (PID: 8016)
      • chcp.com (PID: 7404)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
      • esrv_svc.exe (PID: 7256)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 7996)
      • identity_helper.exe (PID: 8520)
      • DSATray.exe (PID: 8012)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • identity_helper.exe (PID: 5040)
    • Reads the computer name

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 4248)
      • msiexec.exe (PID: 7140)
      • DSAUpdateService.exe (PID: 5144)
      • msiexec.exe (PID: 6360)
      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • msiexec.exe (PID: 2464)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • DSAArcDetect64.exe (PID: 7832)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • esrv_svc.exe (PID: 8120)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
      • esrv_svc.exe (PID: 7256)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 7996)
      • identity_helper.exe (PID: 8520)
      • identity_helper.exe (PID: 5040)
    • Create files in a temporary directory

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Reads the machine GUID from the registry

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • SurSvc.exe (PID: 6260)
      • DSAArcDetect64.exe (PID: 7832)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
      • task.exe (PID: 1044)
      • DSATray.exe (PID: 7996)
      • DSAServiceHelper.exe (PID: 7672)
    • Disables trace logs

      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
    • Reads Environment values

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
      • identity_helper.exe (PID: 8520)
      • identity_helper.exe (PID: 5040)
    • Checks proxy server information

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • esrv.exe (PID: 2152)
    • Creates files in the program directory

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 6260)
      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 7372)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 8012)
    • Process checks computer location settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAServiceHelper.exe (PID: 7672)
    • Creates files or folders in the user directory

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • esrv.exe (PID: 2152)
    • Reads the software policy settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • BootstrapperUI_V2.exe (PID: 6504)
      • WerFault.exe (PID: 7572)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 32)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 32)
    • Application launched itself

      • msiexec.exe (PID: 32)
      • msedge.exe (PID: 5956)
      • msedge.exe (PID: 7052)
    • Dropped object may contain TOR URL's

      • msiexec.exe (PID: 32)
    • Reads CPU info

      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • esrv_svc.exe (PID: 8120)
    • Reads product name

      • DSAService.exe (PID: 5072)
    • Reads the time zone

      • esrv_svc.exe (PID: 8120)
    • Reads Microsoft Office registry keys

      • DSAServiceHelper.exe (PID: 7672)
      • msedge.exe (PID: 5956)
      • msedge.exe (PID: 7052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:05 19:45:02+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.38
CodeSize: 483328
InitializedDataSize: 317440
UninitializedDataSize: -
EntryPoint: 0x517f0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 24.3.26.8
ProductVersionNumber: 24.3.26.8
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Intel
FileDescription: Intel® Driver & Support Assistant
FileVersion: 24.3.26.8
InternalName: burn
OriginalFileName: Intel-Driver-and-Support-Assistant-Installer.exe
ProductName: Intel® Driver & Support Assistant
ProductVersion: 24.3.26.8
LegalCopyright: Copyright © Intel Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
317
Monitored processes
173
Malicious processes
16
Suspicious processes
1

Behavior graph

Click at the process to see the details
start intel-driver-and-support-assistant-installer.exe bootstrapperui_v2.exe intel-driver-and-support-assistant-installer.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe dsaservice.exe msiexec.exe no specs msiexec.exe no specs dsaupdateservice.exe no specs msiexec.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs msiexec.exe no specs cmd.exe no specs conhost.exe no specs sursvc.exe no specs sursvc.exe cmd.exe no specs conhost.exe no specs chcp.com no specs choice.exe no specs choice.exe no specs reg.exe no specs find.exe no specs reg.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs esrv_svc.exe no specs esrv_svc.exe no specs reg.exe no specs schtasks.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs timeout.exe no specs timeout.exe no specs dsaarcdetect64.exe no specs conhost.exe no specs timeout.exe no specs sursvc.exe dsatray.exe no specs cmd.exe conhost.exe no specs chcp.com no specs werfault.exe choice.exe no specs choice.exe no specs timeout.exe no specs intelsoftwareassetmanagerservice.exe timeout.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs esrv_svc.exe schtasks.exe no specs wscript.exe no specs cmd.exe no specs conhost.exe no specs task.exe no specs esrv.exe wmiapsrv.exe no specs sc.exe no specs esrv_svc.exe no specs dsaservicehelper.exe no specs dsatray.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
320"C:\WINDOWS\system32\cmd.exe" /c cd "C:\Program Files\Intel\SUR\QUEENCREEK\" && if exist SurSvc.exe (start /b /wait /d "C:\Program Files\Intel\SUR\QUEENCREEK\" SurSvc.exe /uninstall)C:\Windows\System32\cmd.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1044"C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.exe" C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.execmd.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
Intel(R) System Usage Report
Exit code:
0
Modules
Images
c:\program files\intel\sur\queencreek\x64\task.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1108"C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe" -q -burn.elevated BurnPipe.{0356C42E-0A40-49B4-BD28-5B34EEBF0AF6} {F364688D-E992-4D59-8F81-2DE12D529526} 6472C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe
Intel-Driver-and-Support-Assistant-Installer.exe
User:
admin
Company:
Intel
Integrity Level:
HIGH
Description:
Intel® Driver & Support Assistant
Exit code:
0
Version:
24.3.26.8
Modules
Images
c:\users\admin\appdata\local\temp\{ee535331-bc28-42ea-bada-79fbe8b5c963}\.be\intel-driver-and-support-assistant-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1128"CMD" /C RMDIR /S /Q "C:\Program Files\Intel\SUR\QUEENCREEK\Updater\" && RMDIR /S /Q "C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Intel\SUR\QUEENCREEK\Updater\"C:\Windows\SysWOW64\cmd.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
3
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1128"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2456 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1700"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4724 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1920"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a4,0x2bc,0x7fffca525fd8,0x7fffca525fe4,0x7fffca525ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2152"C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe" "--start" "--start_options_handle" "960"C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
task.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Intel(R) System Usage Report
Modules
Images
c:\program files\intel\sur\queencreek\x64\esrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2212C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
96 261
Read events
95 004
Write events
1 201
Delete events
56

Modification events

(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
Executable files
300
Suspicious files
357
Text files
166
Unknown types
27

Dropped files

PID
Process
Filename
Type
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ko\BootstrapperUI_V2.resources.dllexecutable
MD5:C6C9EA1C041F6DD390A53A5714F559A5
SHA256:955D5C14BE38EB620B049D7F5B192F1D6E614320B17C1625D9F0CD7289AEFA04
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\pt-BR\BootstrapperUI_V2.resources.dllexecutable
MD5:8865827C673F6B9033DAAD970F229F8F
SHA256:9D2D05A46F5B3F04057CF0DD65FCA11624A51EE88A4A1EB23CE6A760DCAC2275
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\id\BootstrapperUI_V2.resources.dllexecutable
MD5:F6CCDE24E714364CE7288FE7CED0A3B8
SHA256:E8AE1E7D3A237ADA0D95A8C739A11570F52AE956242B910DB59BDF226DF75DBF
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ja\BootstrapperUI_V2.resources.dllexecutable
MD5:2C8B2E47BEBD546A8C053F8859D306D6
SHA256:7898FAF8BF359CF21E1074C83772421981D87E8D53A6AB69C3543064C4F3081E
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\th\BootstrapperUI_V2.resources.dllexecutable
MD5:594CB4312A7FD15E6D72AF5AA6913BE6
SHA256:534962BEA045D9CA8A8135BBA8EF025FC3A4CF5343A47E249A86688D8B83A865
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\vi\BootstrapperUI_V2.resources.dllexecutable
MD5:7A6478D5960E5042C5A89F481E67D8DD
SHA256:E1CF09DCBA99488FC93A8A935ADE30F3ED682783EAE209CD9BA2BBAC73D0DB2C
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\fr\BootstrapperUI_V2.resources.dllexecutable
MD5:E462631050803B72DFCA3B49E91D1ACD
SHA256:C146DDB32FD877A17201A72A2AC7EBF9736F550B71A3C4581A3B701E1AA5DB78
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\GalaSoft.MvvmLight.Platform.dllexecutable
MD5:819EABE09308AD05341152E61925B33F
SHA256:A5E126E6879F7326F621A5D08B2552C0D54B6A44D23FEC997058A1A6C78B174D
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\es\BootstrapperUI_V2.resources.dllexecutable
MD5:B03A31232740D2E7497D86489F147638
SHA256:5846D91DC6949040BA6818EDC80F45B7DC875D09EC3FE56B49A7FDEFEEB3DEBA
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\CommonServiceLocator.dllexecutable
MD5:D67456ECFC98E1ACDEDD700DC59E9AC1
SHA256:67E4CA4E34390B6884BF2A2CAF9F1C0EE35F55BBA36F8B34E7B0EF9B3421484D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
153
DNS requests
143
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6472
Intel-Driver-and-Support-Assistant-Installer.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
6472
Intel-Driver-and-Support-Assistant-Installer.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D
unknown
binary
1.42 Kb
whitelisted
6472
Intel-Driver-and-Support-Assistant-Installer.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEDW%2BdGOMs%2BneKAVwt5eAs2c%3D
unknown
binary
979 b
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEAJ8OQEMp1rDOrXuDVQO%2BeU%3D
unknown
binary
2.18 Kb
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
binary
765 b
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
binary
1.42 Kb
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEQDevLVOPyKjTcl8PoK9arwe
unknown
binary
638 b
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
5976
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
8120
esrv_svc.exe
GET
200
172.64.149.23:80
http://crl.comodoca.com/AAACertificateServices.crl
US
binary
607 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
3140
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3848
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3140
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
2.23.209.182:443
www.bing.com
Akamai International B.V.
GB
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5976
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.74.206
whitelisted
www.bing.com
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.148
  • 2.23.209.130
  • 2.23.209.133
  • 2.23.209.177
  • 2.23.209.187
  • 2.23.209.176
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.68
  • 20.190.160.20
  • 20.190.160.17
  • 40.126.32.133
  • 40.126.32.136
  • 40.126.32.74
  • 20.190.160.22
whitelisted
client.wns.windows.com
  • 40.113.110.67
  • 40.113.103.199
whitelisted
th.bing.com
  • 2.23.209.133
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.148
  • 2.23.209.130
  • 2.23.209.187
  • 2.23.209.176
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted

Threats

PID
Process
Class
Message
1128
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1128
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info