File name:

Intel-Driver-and-Support-Assistant-Installer.exe

Full analysis: https://app.any.run/tasks/3810140c-854a-4ef8-8aba-3da3fb4962da
Verdict: Malicious activity
Analysis date: August 01, 2024, 21:28:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

85B706697C86D9FA7909C42CA60E7949

SHA1:

BC6EE7BF70438F4B4A2EFE6A03E7DAE7F5A9C536

SHA256:

DF5ED3253A7B9BBFCA7328EAC9A5BF6FF78B8E4084B7DF159EFEDE52BE8617A5

SSDEEP:

98304:ziwhXS+yjhOpRMD8vZjmedLG70CSeiTYETWN9KCLxHVFalqGTobVN0TiDiMjR2oj:NrrggvDe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • cmd.exe (PID: 7372)
    • Changes the autorun value in the registry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 7244)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • cmd.exe (PID: 7372)
    • Process drops legitimate windows executable

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
    • Reads security settings of Internet Explorer

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • esrv.exe (PID: 2152)
      • DSAServiceHelper.exe (PID: 7672)
    • Searches for installed software

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • dllhost.exe (PID: 6268)
      • SurSvc.exe (PID: 6260)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2212)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv_svc.exe (PID: 8120)
      • esrv_svc.exe (PID: 7256)
      • WmiApSrv.exe (PID: 7452)
    • Checks Windows Trust Settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • SurSvc.exe (PID: 6260)
      • task.exe (PID: 1044)
      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
    • Creates a software uninstall entry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Mutex name with non-standard characters

      • msiexec.exe (PID: 32)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 32)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 32)
    • Process drops python dynamic module

      • msiexec.exe (PID: 32)
    • Starts CMD.EXE for commands execution

      • msiexec.exe (PID: 6360)
      • SurSvc.exe (PID: 6260)
      • cmd.exe (PID: 7244)
      • SurSvc.exe (PID: 8016)
      • wscript.exe (PID: 6344)
    • Reads the date of Windows installation

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAServiceHelper.exe (PID: 7672)
    • Creates files in the driver directory

      • DSAService.exe (PID: 5072)
      • cmd.exe (PID: 7372)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 32)
      • cmd.exe (PID: 7372)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 32)
    • Uses ICACLS.EXE to modify access control lists

      • msiexec.exe (PID: 6360)
    • Process drops SQLite DLL files

      • msiexec.exe (PID: 32)
    • Starts application with an unusual extension

      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 7372)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 7244)
    • Executing commands from a ".bat" file

      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • wscript.exe (PID: 6344)
    • Creates or modifies Windows services

      • reg.exe (PID: 8160)
      • reg.exe (PID: 7780)
      • esrv_svc.exe (PID: 8180)
      • SurSvc.exe (PID: 6260)
      • esrv_svc.exe (PID: 6460)
    • Application launched itself

      • cmd.exe (PID: 7244)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 7372)
    • Executes application which crashes

      • SurSvc.exe (PID: 8016)
    • Loads Python modules

      • IntelSoftwareAssetManagerService.exe (PID: 7784)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 7372)
      • esrv.exe (PID: 2152)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 6344)
    • Reads the BIOS version

      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
    • The process checks if it is being run in the virtual environment

      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
    • The process executes via Task Scheduler

      • wscript.exe (PID: 6344)
    • Runs WScript without displaying logo

      • wscript.exe (PID: 6344)
    • Detected use of alternative data streams (AltDS)

      • esrv_svc.exe (PID: 8120)
  • INFO

    • Checks supported languages

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 4248)
      • msiexec.exe (PID: 7140)
      • DSAUpdateService.exe (PID: 5144)
      • msiexec.exe (PID: 6360)
      • msiexec.exe (PID: 2464)
      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • chcp.com (PID: 7288)
      • esrv_svc.exe (PID: 8180)
      • SurSvc.exe (PID: 8016)
      • esrv_svc.exe (PID: 6460)
      • DSAArcDetect64.exe (PID: 7832)
      • DSATray.exe (PID: 8012)
      • chcp.com (PID: 7404)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
      • esrv_svc.exe (PID: 7256)
      • DSAServiceHelper.exe (PID: 7672)
      • identity_helper.exe (PID: 8520)
      • identity_helper.exe (PID: 5040)
      • DSATray.exe (PID: 7996)
    • Create files in a temporary directory

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Reads the computer name

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 4248)
      • msiexec.exe (PID: 7140)
      • msiexec.exe (PID: 6360)
      • DSAUpdateService.exe (PID: 5144)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • SurSvc.exe (PID: 6260)
      • msiexec.exe (PID: 2464)
      • SurSvc.exe (PID: 6764)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • DSAArcDetect64.exe (PID: 7832)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
      • esrv_svc.exe (PID: 7256)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 7996)
      • identity_helper.exe (PID: 5040)
      • identity_helper.exe (PID: 8520)
    • Reads the machine GUID from the registry

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 6260)
      • DSAArcDetect64.exe (PID: 7832)
      • DSATray.exe (PID: 8012)
      • SurSvc.exe (PID: 8016)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 7996)
    • Reads Environment values

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
      • identity_helper.exe (PID: 8520)
      • identity_helper.exe (PID: 5040)
    • Disables trace logs

      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
    • Checks proxy server information

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • esrv.exe (PID: 2152)
    • Creates files in the program directory

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • DSAService.exe (PID: 5072)
      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 6260)
      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 7372)
      • DSATray.exe (PID: 8012)
      • DSAServiceHelper.exe (PID: 7672)
    • Reads the software policy settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • SurSvc.exe (PID: 8016)
      • SurSvc.exe (PID: 6260)
      • WerFault.exe (PID: 7572)
      • BootstrapperUI_V2.exe (PID: 6504)
      • task.exe (PID: 1044)
      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 32)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • esrv.exe (PID: 2152)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 32)
    • Application launched itself

      • msiexec.exe (PID: 32)
      • msedge.exe (PID: 7052)
      • msedge.exe (PID: 5956)
    • Process checks computer location settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAServiceHelper.exe (PID: 7672)
    • Dropped object may contain TOR URL's

      • msiexec.exe (PID: 32)
    • Reads CPU info

      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • esrv_svc.exe (PID: 8120)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 32)
    • Reads product name

      • DSAService.exe (PID: 5072)
    • Reads the time zone

      • esrv_svc.exe (PID: 8120)
    • Reads Microsoft Office registry keys

      • DSAServiceHelper.exe (PID: 7672)
      • msedge.exe (PID: 5956)
      • msedge.exe (PID: 7052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:05 19:45:02+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.38
CodeSize: 483328
InitializedDataSize: 317440
UninitializedDataSize: -
EntryPoint: 0x517f0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 24.3.26.8
ProductVersionNumber: 24.3.26.8
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Intel
FileDescription: Intel® Driver & Support Assistant
FileVersion: 24.3.26.8
InternalName: burn
OriginalFileName: Intel-Driver-and-Support-Assistant-Installer.exe
ProductName: Intel® Driver & Support Assistant
ProductVersion: 24.3.26.8
LegalCopyright: Copyright © Intel Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
317
Monitored processes
173
Malicious processes
16
Suspicious processes
1

Behavior graph

Click at the process to see the details
start intel-driver-and-support-assistant-installer.exe bootstrapperui_v2.exe intel-driver-and-support-assistant-installer.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe dsaservice.exe msiexec.exe no specs msiexec.exe no specs dsaupdateservice.exe no specs msiexec.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs msiexec.exe no specs cmd.exe no specs conhost.exe no specs sursvc.exe no specs sursvc.exe cmd.exe no specs conhost.exe no specs chcp.com no specs choice.exe no specs choice.exe no specs reg.exe no specs find.exe no specs reg.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs esrv_svc.exe no specs esrv_svc.exe no specs reg.exe no specs schtasks.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs timeout.exe no specs timeout.exe no specs dsaarcdetect64.exe no specs conhost.exe no specs timeout.exe no specs sursvc.exe dsatray.exe no specs cmd.exe conhost.exe no specs chcp.com no specs werfault.exe choice.exe no specs choice.exe no specs timeout.exe no specs intelsoftwareassetmanagerservice.exe timeout.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs esrv_svc.exe schtasks.exe no specs wscript.exe no specs cmd.exe no specs conhost.exe no specs task.exe no specs esrv.exe wmiapsrv.exe no specs sc.exe no specs esrv_svc.exe no specs dsaservicehelper.exe no specs dsatray.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
320"C:\WINDOWS\system32\cmd.exe" /c cd "C:\Program Files\Intel\SUR\QUEENCREEK\" && if exist SurSvc.exe (start /b /wait /d "C:\Program Files\Intel\SUR\QUEENCREEK\" SurSvc.exe /uninstall)C:\Windows\System32\cmd.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1044"C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.exe" C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.execmd.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
Intel(R) System Usage Report
Exit code:
0
Modules
Images
c:\program files\intel\sur\queencreek\x64\task.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1108"C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe" -q -burn.elevated BurnPipe.{0356C42E-0A40-49B4-BD28-5B34EEBF0AF6} {F364688D-E992-4D59-8F81-2DE12D529526} 6472C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe
Intel-Driver-and-Support-Assistant-Installer.exe
User:
admin
Company:
Intel
Integrity Level:
HIGH
Description:
Intel® Driver & Support Assistant
Exit code:
0
Version:
24.3.26.8
Modules
Images
c:\users\admin\appdata\local\temp\{ee535331-bc28-42ea-bada-79fbe8b5c963}\.be\intel-driver-and-support-assistant-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1128"CMD" /C RMDIR /S /Q "C:\Program Files\Intel\SUR\QUEENCREEK\Updater\" && RMDIR /S /Q "C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Intel\SUR\QUEENCREEK\Updater\"C:\Windows\SysWOW64\cmd.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
3
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1128"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2456 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1700"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4724 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1920"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a4,0x2bc,0x7fffca525fd8,0x7fffca525fe4,0x7fffca525ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2152"C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe" "--start" "--start_options_handle" "960"C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
task.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Intel(R) System Usage Report
Modules
Images
c:\program files\intel\sur\queencreek\x64\esrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2212C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
96 261
Read events
95 004
Write events
1 201
Delete events
56

Modification events

(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
Executable files
300
Suspicious files
357
Text files
166
Unknown types
27

Dropped files

PID
Process
Filename
Type
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\id\BootstrapperUI_V2.resources.dllexecutable
MD5:F6CCDE24E714364CE7288FE7CED0A3B8
SHA256:E8AE1E7D3A237ADA0D95A8C739A11570F52AE956242B910DB59BDF226DF75DBF
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\th\BootstrapperUI_V2.resources.dllexecutable
MD5:594CB4312A7FD15E6D72AF5AA6913BE6
SHA256:534962BEA045D9CA8A8135BBA8EF025FC3A4CF5343A47E249A86688D8B83A865
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ja\BootstrapperUI_V2.resources.dllexecutable
MD5:2C8B2E47BEBD546A8C053F8859D306D6
SHA256:7898FAF8BF359CF21E1074C83772421981D87E8D53A6AB69C3543064C4F3081E
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\vi\BootstrapperUI_V2.resources.dllexecutable
MD5:7A6478D5960E5042C5A89F481E67D8DD
SHA256:E1CF09DCBA99488FC93A8A935ADE30F3ED682783EAE209CD9BA2BBAC73D0DB2C
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\de\BootstrapperUI_V2.resources.dllexecutable
MD5:E20749FC2A2A24F4499A6E622CF263EF
SHA256:1E24731DC7BD4FE61C7C37B082F3B00108F047EE24B4596CFD570B52B0C2D3AA
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\System.Memory.dllexecutable
MD5:3BD7EF8CA6646B99ACBE2B503DE835C1
SHA256:07F2F987794F31652B8649884BC310007C0EC06F97D9F186375D9A737178FAAA
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\zh-TW\BootstrapperUI_V2.resources.dllexecutable
MD5:E40528D73249E402E5DCED08FA7248A7
SHA256:F0B63C48476F47B40C55E59627A44DC4E59A638AB223C8C870B8718FF7590482
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ko\BootstrapperUI_V2.resources.dllexecutable
MD5:C6C9EA1C041F6DD390A53A5714F559A5
SHA256:955D5C14BE38EB620B049D7F5B192F1D6E614320B17C1625D9F0CD7289AEFA04
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\CommonServiceLocator.dllexecutable
MD5:D67456ECFC98E1ACDEDD700DC59E9AC1
SHA256:67E4CA4E34390B6884BF2A2CAF9F1C0EE35F55BBA36F8B34E7B0EF9B3421484D
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\pt-BR\BootstrapperUI_V2.resources.dllexecutable
MD5:8865827C673F6B9033DAAD970F229F8F
SHA256:9D2D05A46F5B3F04057CF0DD65FCA11624A51EE88A4A1EB23CE6A760DCAC2275
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
153
DNS requests
143
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5976
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6896
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5976
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6928
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6472
Intel-Driver-and-Support-Assistant-Installer.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6472
Intel-Driver-and-Support-Assistant-Installer.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D
unknown
whitelisted
6472
Intel-Driver-and-Support-Assistant-Installer.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEDW%2BdGOMs%2BneKAVwt5eAs2c%3D
unknown
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEAJ8OQEMp1rDOrXuDVQO%2BeU%3D
unknown
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
3140
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3848
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3140
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
2.23.209.182:443
www.bing.com
Akamai International B.V.
GB
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5976
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.74.206
whitelisted
www.bing.com
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.148
  • 2.23.209.130
  • 2.23.209.133
  • 2.23.209.177
  • 2.23.209.187
  • 2.23.209.176
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.68
  • 20.190.160.20
  • 20.190.160.17
  • 40.126.32.133
  • 40.126.32.136
  • 40.126.32.74
  • 20.190.160.22
whitelisted
client.wns.windows.com
  • 40.113.110.67
  • 40.113.103.199
whitelisted
th.bing.com
  • 2.23.209.133
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.148
  • 2.23.209.130
  • 2.23.209.187
  • 2.23.209.176
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted

Threats

PID
Process
Class
Message
1128
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1128
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info