File name:

Intel-Driver-and-Support-Assistant-Installer.exe

Full analysis: https://app.any.run/tasks/3810140c-854a-4ef8-8aba-3da3fb4962da
Verdict: Malicious activity
Analysis date: August 01, 2024, 21:28:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

85B706697C86D9FA7909C42CA60E7949

SHA1:

BC6EE7BF70438F4B4A2EFE6A03E7DAE7F5A9C536

SHA256:

DF5ED3253A7B9BBFCA7328EAC9A5BF6FF78B8E4084B7DF159EFEDE52BE8617A5

SSDEEP:

98304:ziwhXS+yjhOpRMD8vZjmedLG70CSeiTYETWN9KCLxHVFalqGTobVN0TiDiMjR2oj:NrrggvDe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 32)
      • cmd.exe (PID: 7372)
    • Changes the autorun value in the registry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 7244)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • cmd.exe (PID: 7372)
    • Reads security settings of Internet Explorer

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • esrv.exe (PID: 2152)
      • DSAServiceHelper.exe (PID: 7672)
    • Searches for installed software

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • dllhost.exe (PID: 6268)
      • SurSvc.exe (PID: 6260)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
    • Reads the date of Windows installation

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAServiceHelper.exe (PID: 7672)
    • Process drops legitimate windows executable

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2212)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv_svc.exe (PID: 8120)
      • esrv_svc.exe (PID: 7256)
      • WmiApSrv.exe (PID: 7452)
    • Creates a software uninstall entry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Checks Windows Trust Settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • SurSvc.exe (PID: 6260)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
    • Mutex name with non-standard characters

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 32)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 32)
    • Starts CMD.EXE for commands execution

      • msiexec.exe (PID: 6360)
      • SurSvc.exe (PID: 6260)
      • cmd.exe (PID: 7244)
      • SurSvc.exe (PID: 8016)
      • wscript.exe (PID: 6344)
    • Process drops python dynamic module

      • msiexec.exe (PID: 32)
    • Process drops SQLite DLL files

      • msiexec.exe (PID: 32)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 32)
      • cmd.exe (PID: 7372)
    • Creates files in the driver directory

      • DSAService.exe (PID: 5072)
      • cmd.exe (PID: 7372)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 32)
    • Uses ICACLS.EXE to modify access control lists

      • msiexec.exe (PID: 6360)
    • Executing commands from a ".bat" file

      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • wscript.exe (PID: 6344)
    • Starts application with an unusual extension

      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 7372)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 7244)
    • Creates or modifies Windows services

      • reg.exe (PID: 8160)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • reg.exe (PID: 7780)
      • SurSvc.exe (PID: 6260)
    • Application launched itself

      • cmd.exe (PID: 7244)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 7372)
    • Executes application which crashes

      • SurSvc.exe (PID: 8016)
    • Loads Python modules

      • IntelSoftwareAssetManagerService.exe (PID: 7784)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 7372)
      • esrv.exe (PID: 2152)
    • The process executes via Task Scheduler

      • wscript.exe (PID: 6344)
    • Runs WScript without displaying logo

      • wscript.exe (PID: 6344)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 6344)
    • Reads the BIOS version

      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
    • The process checks if it is being run in the virtual environment

      • esrv.exe (PID: 2152)
      • esrv_svc.exe (PID: 8120)
    • Detected use of alternative data streams (AltDS)

      • esrv_svc.exe (PID: 8120)
  • INFO

    • Checks supported languages

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 4248)
      • msiexec.exe (PID: 7140)
      • msiexec.exe (PID: 6360)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • msiexec.exe (PID: 2464)
      • chcp.com (PID: 7288)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • DSAArcDetect64.exe (PID: 7832)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • chcp.com (PID: 7404)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
      • esrv_svc.exe (PID: 7256)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 7996)
      • identity_helper.exe (PID: 8520)
      • identity_helper.exe (PID: 5040)
    • Reads the computer name

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 4248)
      • msiexec.exe (PID: 7140)
      • msiexec.exe (PID: 6360)
      • DSAUpdateService.exe (PID: 5144)
      • msiexec.exe (PID: 2464)
      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • DSAArcDetect64.exe (PID: 7832)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
      • esrv_svc.exe (PID: 7256)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 7996)
      • identity_helper.exe (PID: 8520)
      • identity_helper.exe (PID: 5040)
    • Disables trace logs

      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
    • Process checks computer location settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAServiceHelper.exe (PID: 7672)
    • Reads Environment values

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • BootstrapperUI_V2.exe (PID: 6504)
      • SurSvc.exe (PID: 8016)
      • identity_helper.exe (PID: 5040)
      • identity_helper.exe (PID: 8520)
    • Creates files in the program directory

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 6260)
      • cmd.exe (PID: 7244)
      • DSATray.exe (PID: 8012)
      • cmd.exe (PID: 7372)
      • DSAServiceHelper.exe (PID: 7672)
    • Checks proxy server information

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • esrv.exe (PID: 2152)
    • Reads the machine GUID from the registry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • BootstrapperUI_V2.exe (PID: 6504)
      • SurSvc.exe (PID: 6260)
      • DSAArcDetect64.exe (PID: 7832)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 7996)
    • Reads the software policy settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • WerFault.exe (PID: 7572)
      • BootstrapperUI_V2.exe (PID: 6504)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
    • Create files in a temporary directory

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 32)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • esrv.exe (PID: 2152)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 32)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 32)
    • Application launched itself

      • msiexec.exe (PID: 32)
      • msedge.exe (PID: 7052)
      • msedge.exe (PID: 5956)
    • Reads CPU info

      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • esrv_svc.exe (PID: 8120)
    • Dropped object may contain TOR URL's

      • msiexec.exe (PID: 32)
    • Reads product name

      • DSAService.exe (PID: 5072)
    • Reads the time zone

      • esrv_svc.exe (PID: 8120)
    • Reads Microsoft Office registry keys

      • DSAServiceHelper.exe (PID: 7672)
      • msedge.exe (PID: 5956)
      • msedge.exe (PID: 7052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:05 19:45:02+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.38
CodeSize: 483328
InitializedDataSize: 317440
UninitializedDataSize: -
EntryPoint: 0x517f0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 24.3.26.8
ProductVersionNumber: 24.3.26.8
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Intel
FileDescription: Intel® Driver & Support Assistant
FileVersion: 24.3.26.8
InternalName: burn
OriginalFileName: Intel-Driver-and-Support-Assistant-Installer.exe
ProductName: Intel® Driver & Support Assistant
ProductVersion: 24.3.26.8
LegalCopyright: Copyright © Intel Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
317
Monitored processes
173
Malicious processes
16
Suspicious processes
1

Behavior graph

Click at the process to see the details
start intel-driver-and-support-assistant-installer.exe bootstrapperui_v2.exe intel-driver-and-support-assistant-installer.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe dsaservice.exe msiexec.exe no specs msiexec.exe no specs dsaupdateservice.exe no specs msiexec.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs msiexec.exe no specs cmd.exe no specs conhost.exe no specs sursvc.exe no specs sursvc.exe cmd.exe no specs conhost.exe no specs chcp.com no specs choice.exe no specs choice.exe no specs reg.exe no specs find.exe no specs reg.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs esrv_svc.exe no specs esrv_svc.exe no specs reg.exe no specs schtasks.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs timeout.exe no specs timeout.exe no specs dsaarcdetect64.exe no specs conhost.exe no specs timeout.exe no specs sursvc.exe dsatray.exe no specs cmd.exe conhost.exe no specs chcp.com no specs werfault.exe choice.exe no specs choice.exe no specs timeout.exe no specs intelsoftwareassetmanagerservice.exe timeout.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs esrv_svc.exe schtasks.exe no specs wscript.exe no specs cmd.exe no specs conhost.exe no specs task.exe no specs esrv.exe wmiapsrv.exe no specs sc.exe no specs esrv_svc.exe no specs dsaservicehelper.exe no specs dsatray.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
320"C:\WINDOWS\system32\cmd.exe" /c cd "C:\Program Files\Intel\SUR\QUEENCREEK\" && if exist SurSvc.exe (start /b /wait /d "C:\Program Files\Intel\SUR\QUEENCREEK\" SurSvc.exe /uninstall)C:\Windows\System32\cmd.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1044"C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.exe" C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.execmd.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
Intel(R) System Usage Report
Exit code:
0
Modules
Images
c:\program files\intel\sur\queencreek\x64\task.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1108"C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe" -q -burn.elevated BurnPipe.{0356C42E-0A40-49B4-BD28-5B34EEBF0AF6} {F364688D-E992-4D59-8F81-2DE12D529526} 6472C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe
Intel-Driver-and-Support-Assistant-Installer.exe
User:
admin
Company:
Intel
Integrity Level:
HIGH
Description:
Intel® Driver & Support Assistant
Exit code:
0
Version:
24.3.26.8
Modules
Images
c:\users\admin\appdata\local\temp\{ee535331-bc28-42ea-bada-79fbe8b5c963}\.be\intel-driver-and-support-assistant-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1128"CMD" /C RMDIR /S /Q "C:\Program Files\Intel\SUR\QUEENCREEK\Updater\" && RMDIR /S /Q "C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Intel\SUR\QUEENCREEK\Updater\"C:\Windows\SysWOW64\cmd.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
3
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1128"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2456 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1700"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4724 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1920"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a4,0x2bc,0x7fffca525fd8,0x7fffca525fe4,0x7fffca525ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2152"C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe" "--start" "--start_options_handle" "960"C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
task.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Intel(R) System Usage Report
Modules
Images
c:\program files\intel\sur\queencreek\x64\esrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2212C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
96 261
Read events
95 004
Write events
1 201
Delete events
56

Modification events

(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
Executable files
300
Suspicious files
357
Text files
166
Unknown types
27

Dropped files

PID
Process
Filename
Type
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\vi\BootstrapperUI_V2.resources.dllexecutable
MD5:7A6478D5960E5042C5A89F481E67D8DD
SHA256:E1CF09DCBA99488FC93A8A935ADE30F3ED682783EAE209CD9BA2BBAC73D0DB2C
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\es\BootstrapperUI_V2.resources.dllexecutable
MD5:B03A31232740D2E7497D86489F147638
SHA256:5846D91DC6949040BA6818EDC80F45B7DC875D09EC3FE56B49A7FDEFEEB3DEBA
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\id\BootstrapperUI_V2.resources.dllexecutable
MD5:F6CCDE24E714364CE7288FE7CED0A3B8
SHA256:E8AE1E7D3A237ADA0D95A8C739A11570F52AE956242B910DB59BDF226DF75DBF
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\fr\BootstrapperUI_V2.resources.dllexecutable
MD5:E462631050803B72DFCA3B49E91D1ACD
SHA256:C146DDB32FD877A17201A72A2AC7EBF9736F550B71A3C4581A3B701E1AA5DB78
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ko\BootstrapperUI_V2.resources.dllexecutable
MD5:C6C9EA1C041F6DD390A53A5714F559A5
SHA256:955D5C14BE38EB620B049D7F5B192F1D6E614320B17C1625D9F0CD7289AEFA04
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ja\BootstrapperUI_V2.resources.dllexecutable
MD5:2C8B2E47BEBD546A8C053F8859D306D6
SHA256:7898FAF8BF359CF21E1074C83772421981D87E8D53A6AB69C3543064C4F3081E
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\pt-BR\BootstrapperUI_V2.resources.dllexecutable
MD5:8865827C673F6B9033DAAD970F229F8F
SHA256:9D2D05A46F5B3F04057CF0DD65FCA11624A51EE88A4A1EB23CE6A760DCAC2275
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\de\BootstrapperUI_V2.resources.dllexecutable
MD5:E20749FC2A2A24F4499A6E622CF263EF
SHA256:1E24731DC7BD4FE61C7C37B082F3B00108F047EE24B4596CFD570B52B0C2D3AA
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\System.Memory.dllexecutable
MD5:3BD7EF8CA6646B99ACBE2B503DE835C1
SHA256:07F2F987794F31652B8649884BC310007C0EC06F97D9F186375D9A737178FAAA
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\GalaSoft.MvvmLight.Extras.dllexecutable
MD5:D9C798E9A0E0EC3A09495D619E96C458
SHA256:8DE04C655729181216BD3F8B6FA75FB784D2CD555022873AC38FC1588592F00B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
153
DNS requests
143
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5976
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6896
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5976
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6928
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6472
Intel-Driver-and-Support-Assistant-Installer.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6472
Intel-Driver-and-Support-Assistant-Installer.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D
unknown
whitelisted
6472
Intel-Driver-and-Support-Assistant-Installer.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEDW%2BdGOMs%2BneKAVwt5eAs2c%3D
unknown
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEAJ8OQEMp1rDOrXuDVQO%2BeU%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
3140
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3848
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3140
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
2.23.209.182:443
www.bing.com
Akamai International B.V.
GB
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5976
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.74.206
whitelisted
www.bing.com
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.148
  • 2.23.209.130
  • 2.23.209.133
  • 2.23.209.177
  • 2.23.209.187
  • 2.23.209.176
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.68
  • 20.190.160.20
  • 20.190.160.17
  • 40.126.32.133
  • 40.126.32.136
  • 40.126.32.74
  • 20.190.160.22
whitelisted
client.wns.windows.com
  • 40.113.110.67
  • 40.113.103.199
whitelisted
th.bing.com
  • 2.23.209.133
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.148
  • 2.23.209.130
  • 2.23.209.187
  • 2.23.209.176
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted

Threats

PID
Process
Class
Message
1128
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1128
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info