File name:

Intel-Driver-and-Support-Assistant-Installer.exe

Full analysis: https://app.any.run/tasks/3810140c-854a-4ef8-8aba-3da3fb4962da
Verdict: Malicious activity
Analysis date: August 01, 2024, 21:28:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

85B706697C86D9FA7909C42CA60E7949

SHA1:

BC6EE7BF70438F4B4A2EFE6A03E7DAE7F5A9C536

SHA256:

DF5ED3253A7B9BBFCA7328EAC9A5BF6FF78B8E4084B7DF159EFEDE52BE8617A5

SSDEEP:

98304:ziwhXS+yjhOpRMD8vZjmedLG70CSeiTYETWN9KCLxHVFalqGTobVN0TiDiMjR2oj:NrrggvDe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • cmd.exe (PID: 7372)
    • Changes the autorun value in the registry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 7244)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • cmd.exe (PID: 7372)
    • Process drops legitimate windows executable

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
    • Reads security settings of Internet Explorer

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • esrv.exe (PID: 2152)
      • DSAServiceHelper.exe (PID: 7672)
    • Reads the date of Windows installation

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAServiceHelper.exe (PID: 7672)
    • Searches for installed software

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • dllhost.exe (PID: 6268)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • SurSvc.exe (PID: 6260)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
    • Checks Windows Trust Settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • SurSvc.exe (PID: 6260)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
    • Mutex name with non-standard characters

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 32)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 32)
    • Creates a software uninstall entry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Executes as Windows Service

      • DSAService.exe (PID: 5072)
      • VSSVC.exe (PID: 2212)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv_svc.exe (PID: 8120)
      • esrv_svc.exe (PID: 7256)
      • WmiApSrv.exe (PID: 7452)
    • Starts CMD.EXE for commands execution

      • msiexec.exe (PID: 6360)
      • cmd.exe (PID: 7244)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • wscript.exe (PID: 6344)
    • Process drops python dynamic module

      • msiexec.exe (PID: 32)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 32)
      • cmd.exe (PID: 7372)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 32)
    • Uses ICACLS.EXE to modify access control lists

      • msiexec.exe (PID: 6360)
    • Creates files in the driver directory

      • DSAService.exe (PID: 5072)
      • cmd.exe (PID: 7372)
    • Process drops SQLite DLL files

      • msiexec.exe (PID: 32)
    • Executing commands from a ".bat" file

      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • wscript.exe (PID: 6344)
    • Starts application with an unusual extension

      • cmd.exe (PID: 7244)
      • cmd.exe (PID: 7372)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 7244)
    • Creates or modifies Windows services

      • reg.exe (PID: 8160)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • SurSvc.exe (PID: 6260)
      • reg.exe (PID: 7780)
    • Application launched itself

      • cmd.exe (PID: 7244)
    • Loads Python modules

      • IntelSoftwareAssetManagerService.exe (PID: 7784)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7372)
      • cmd.exe (PID: 7244)
    • Executes application which crashes

      • SurSvc.exe (PID: 8016)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 7372)
      • esrv.exe (PID: 2152)
    • Runs WScript without displaying logo

      • wscript.exe (PID: 6344)
    • The process executes via Task Scheduler

      • wscript.exe (PID: 6344)
    • Reads the BIOS version

      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 6344)
    • The process checks if it is being run in the virtual environment

      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
    • Detected use of alternative data streams (AltDS)

      • esrv_svc.exe (PID: 8120)
  • INFO

    • Create files in a temporary directory

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
    • Checks supported languages

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • msiexec.exe (PID: 32)
      • msiexec.exe (PID: 4248)
      • DSAUpdateService.exe (PID: 5144)
      • msiexec.exe (PID: 7140)
      • msiexec.exe (PID: 6360)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 2464)
      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • chcp.com (PID: 7288)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • DSAArcDetect64.exe (PID: 7832)
      • DSATray.exe (PID: 8012)
      • SurSvc.exe (PID: 8016)
      • chcp.com (PID: 7404)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
      • esrv_svc.exe (PID: 7256)
      • DSATray.exe (PID: 7996)
      • DSAServiceHelper.exe (PID: 7672)
      • identity_helper.exe (PID: 5040)
      • identity_helper.exe (PID: 8520)
    • Reads the machine GUID from the registry

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 6260)
      • DSAArcDetect64.exe (PID: 7832)
      • DSATray.exe (PID: 8012)
      • SurSvc.exe (PID: 8016)
      • esrv_svc.exe (PID: 8120)
      • esrv.exe (PID: 2152)
      • task.exe (PID: 1044)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 7996)
    • Reads Environment values

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
      • identity_helper.exe (PID: 8520)
      • identity_helper.exe (PID: 5040)
    • Reads the computer name

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • BootstrapperUI_V2.exe (PID: 6504)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • msiexec.exe (PID: 4248)
      • msiexec.exe (PID: 7140)
      • DSAUpdateService.exe (PID: 5144)
      • msiexec.exe (PID: 6360)
      • msiexec.exe (PID: 2464)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 6764)
      • DSAArcDetect64.exe (PID: 7832)
      • esrv_svc.exe (PID: 8180)
      • esrv_svc.exe (PID: 6460)
      • SurSvc.exe (PID: 8016)
      • DSATray.exe (PID: 8012)
      • esrv_svc.exe (PID: 8120)
      • IntelSoftwareAssetManagerService.exe (PID: 7784)
      • esrv.exe (PID: 2152)
      • task.exe (PID: 1044)
      • esrv_svc.exe (PID: 7256)
      • DSATray.exe (PID: 7996)
      • DSAServiceHelper.exe (PID: 7672)
      • identity_helper.exe (PID: 5040)
      • identity_helper.exe (PID: 8520)
    • Disables trace logs

      • BootstrapperUI_V2.exe (PID: 6504)
      • DSAService.exe (PID: 5072)
      • DSAUpdateService.exe (PID: 5144)
      • SurSvc.exe (PID: 8016)
    • Creates files in the program directory

      • BootstrapperUI_V2.exe (PID: 6504)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 1108)
      • DSAService.exe (PID: 5072)
      • SurSvc.exe (PID: 6260)
      • cmd.exe (PID: 7244)
      • DSAUpdateService.exe (PID: 5144)
      • cmd.exe (PID: 7372)
      • DSAServiceHelper.exe (PID: 7672)
      • DSATray.exe (PID: 8012)
    • Checks proxy server information

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • BootstrapperUI_V2.exe (PID: 6504)
      • esrv.exe (PID: 2152)
    • Process checks computer location settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • DSAServiceHelper.exe (PID: 7672)
      • BootstrapperUI_V2.exe (PID: 6504)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 32)
    • Reads the software policy settings

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • DSAService.exe (PID: 5072)
      • SurSvc.exe (PID: 6260)
      • BootstrapperUI_V2.exe (PID: 6504)
      • SurSvc.exe (PID: 8016)
      • WerFault.exe (PID: 7572)
      • esrv_svc.exe (PID: 8120)
      • task.exe (PID: 1044)
      • esrv.exe (PID: 2152)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 32)
    • Creates files or folders in the user directory

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 6472)
      • msiexec.exe (PID: 32)
      • esrv.exe (PID: 2152)
    • Reads CPU info

      • SurSvc.exe (PID: 6764)
      • SurSvc.exe (PID: 6260)
      • SurSvc.exe (PID: 8016)
      • esrv_svc.exe (PID: 8120)
    • Application launched itself

      • msiexec.exe (PID: 32)
      • msedge.exe (PID: 5956)
      • msedge.exe (PID: 7052)
    • Dropped object may contain TOR URL's

      • msiexec.exe (PID: 32)
    • Reads product name

      • DSAService.exe (PID: 5072)
    • Reads the time zone

      • esrv_svc.exe (PID: 8120)
    • Reads Microsoft Office registry keys

      • DSAServiceHelper.exe (PID: 7672)
      • msedge.exe (PID: 5956)
      • msedge.exe (PID: 7052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:05 19:45:02+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.38
CodeSize: 483328
InitializedDataSize: 317440
UninitializedDataSize: -
EntryPoint: 0x517f0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 24.3.26.8
ProductVersionNumber: 24.3.26.8
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Intel
FileDescription: Intel® Driver & Support Assistant
FileVersion: 24.3.26.8
InternalName: burn
OriginalFileName: Intel-Driver-and-Support-Assistant-Installer.exe
ProductName: Intel® Driver & Support Assistant
ProductVersion: 24.3.26.8
LegalCopyright: Copyright © Intel Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
317
Monitored processes
173
Malicious processes
16
Suspicious processes
1

Behavior graph

Click at the process to see the details
start intel-driver-and-support-assistant-installer.exe bootstrapperui_v2.exe intel-driver-and-support-assistant-installer.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe dsaservice.exe msiexec.exe no specs msiexec.exe no specs dsaupdateservice.exe no specs msiexec.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs msiexec.exe no specs cmd.exe no specs conhost.exe no specs sursvc.exe no specs sursvc.exe cmd.exe no specs conhost.exe no specs chcp.com no specs choice.exe no specs choice.exe no specs reg.exe no specs find.exe no specs reg.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs esrv_svc.exe no specs esrv_svc.exe no specs reg.exe no specs schtasks.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs timeout.exe no specs timeout.exe no specs dsaarcdetect64.exe no specs conhost.exe no specs timeout.exe no specs sursvc.exe dsatray.exe no specs cmd.exe conhost.exe no specs chcp.com no specs werfault.exe choice.exe no specs choice.exe no specs timeout.exe no specs intelsoftwareassetmanagerservice.exe timeout.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs find.exe no specs sc.exe no specs esrv_svc.exe schtasks.exe no specs wscript.exe no specs cmd.exe no specs conhost.exe no specs task.exe no specs esrv.exe wmiapsrv.exe no specs sc.exe no specs esrv_svc.exe no specs dsaservicehelper.exe no specs dsatray.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
320"C:\WINDOWS\system32\cmd.exe" /c cd "C:\Program Files\Intel\SUR\QUEENCREEK\" && if exist SurSvc.exe (start /b /wait /d "C:\Program Files\Intel\SUR\QUEENCREEK\" SurSvc.exe /uninstall)C:\Windows\System32\cmd.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1044"C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.exe" C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.execmd.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
Intel(R) System Usage Report
Exit code:
0
Modules
Images
c:\program files\intel\sur\queencreek\x64\task.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1108"C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe" -q -burn.elevated BurnPipe.{0356C42E-0A40-49B4-BD28-5B34EEBF0AF6} {F364688D-E992-4D59-8F81-2DE12D529526} 6472C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe
Intel-Driver-and-Support-Assistant-Installer.exe
User:
admin
Company:
Intel
Integrity Level:
HIGH
Description:
Intel® Driver & Support Assistant
Exit code:
0
Version:
24.3.26.8
Modules
Images
c:\users\admin\appdata\local\temp\{ee535331-bc28-42ea-bada-79fbe8b5c963}\.be\intel-driver-and-support-assistant-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1128"CMD" /C RMDIR /S /Q "C:\Program Files\Intel\SUR\QUEENCREEK\Updater\" && RMDIR /S /Q "C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Intel\SUR\QUEENCREEK\Updater\"C:\Windows\SysWOW64\cmd.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
3
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1128"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2456 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1700"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4724 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1920"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a4,0x2bc,0x7fffca525fd8,0x7fffca525fe4,0x7fffca525ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2152"C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe" "--start" "--start_options_handle" "960"C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
task.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Intel(R) System Usage Report
Modules
Images
c:\program files\intel\sur\queencreek\x64\esrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2212C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
96 261
Read events
95 004
Write events
1 201
Delete events
56

Modification events

(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6504) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
Executable files
300
Suspicious files
357
Text files
166
Unknown types
27

Dropped files

PID
Process
Filename
Type
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ja\BootstrapperUI_V2.resources.dllexecutable
MD5:2C8B2E47BEBD546A8C053F8859D306D6
SHA256:7898FAF8BF359CF21E1074C83772421981D87E8D53A6AB69C3543064C4F3081E
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ko\BootstrapperUI_V2.resources.dllexecutable
MD5:C6C9EA1C041F6DD390A53A5714F559A5
SHA256:955D5C14BE38EB620B049D7F5B192F1D6E614320B17C1625D9F0CD7289AEFA04
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\es\BootstrapperUI_V2.resources.dllexecutable
MD5:B03A31232740D2E7497D86489F147638
SHA256:5846D91DC6949040BA6818EDC80F45B7DC875D09EC3FE56B49A7FDEFEEB3DEBA
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\fr\BootstrapperUI_V2.resources.dllexecutable
MD5:E462631050803B72DFCA3B49E91D1ACD
SHA256:C146DDB32FD877A17201A72A2AC7EBF9736F550B71A3C4581A3B701E1AA5DB78
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\BootstrapperUI_V2.exe.configxml
MD5:CB6048A33306DA8D4D32204388B83E94
SHA256:5C65F5D0BDD4B45FFF99C3AD3C3F319B9BA1824336D83463162ED5A02CBE3439
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\GalaSoft.MvvmLight.Extras.dllexecutable
MD5:D9C798E9A0E0EC3A09495D619E96C458
SHA256:8DE04C655729181216BD3F8B6FA75FB784D2CD555022873AC38FC1588592F00B
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\zh-CN\BootstrapperUI_V2.resources.dllexecutable
MD5:D7E708FEF39D4179CB518391091329F7
SHA256:59A850476D1A5A3EB7FE850B09F9B58F7D0DC257227CA1291E9FF228B5E09056
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\System.Windows.Interactivity.dllexecutable
MD5:1E0B056811644EDE66D7D987F65D3892
SHA256:0C2344883E6B5D93904D35DBF33EF1143D450C5C1B4EEC8723CB6223CACB01D8
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\WixToolset.BootstrapperApplicationApi.dllexecutable
MD5:482460EEA667E92015A4826FED6CFEBA
SHA256:AD1D088FB5E3DB65E9CC791496281AC7AED7C3EEEFDEF5DFAD7F2CD6B8940605
6472Intel-Driver-and-Support-Assistant-Installer.exeC:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\System.Runtime.CompilerServices.Unsafe.dllexecutable
MD5:68E08D325F042B2AC7E47F097B97F8E1
SHA256:802DD48A4E25A9627D40751BF1166C71243231DF9F60D646AA8AA1FE33D60665
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
153
DNS requests
143
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5976
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6928
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEQDevLVOPyKjTcl8PoK9arwe
unknown
whitelisted
8120
esrv_svc.exe
GET
200
172.64.149.23:80
http://crl.comodoca.com/AAACertificateServices.crl
unknown
whitelisted
32
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
whitelisted
5976
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6896
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6260
SurSvc.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
3140
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3848
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3140
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
2.23.209.182:443
www.bing.com
Akamai International B.V.
GB
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5976
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.74.206
whitelisted
www.bing.com
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.148
  • 2.23.209.130
  • 2.23.209.133
  • 2.23.209.177
  • 2.23.209.187
  • 2.23.209.176
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.68
  • 20.190.160.20
  • 20.190.160.17
  • 40.126.32.133
  • 40.126.32.136
  • 40.126.32.74
  • 20.190.160.22
whitelisted
client.wns.windows.com
  • 40.113.110.67
  • 40.113.103.199
whitelisted
th.bing.com
  • 2.23.209.133
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.179
  • 2.23.209.148
  • 2.23.209.130
  • 2.23.209.187
  • 2.23.209.176
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted

Threats

PID
Process
Class
Message
1128
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1128
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info