| File name: | Intel-Driver-and-Support-Assistant-Installer.exe |
| Full analysis: | https://app.any.run/tasks/3810140c-854a-4ef8-8aba-3da3fb4962da |
| Verdict: | Malicious activity |
| Analysis date: | August 01, 2024, 21:28:15 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 85B706697C86D9FA7909C42CA60E7949 |
| SHA1: | BC6EE7BF70438F4B4A2EFE6A03E7DAE7F5A9C536 |
| SHA256: | DF5ED3253A7B9BBFCA7328EAC9A5BF6FF78B8E4084B7DF159EFEDE52BE8617A5 |
| SSDEEP: | 98304:ziwhXS+yjhOpRMD8vZjmedLG70CSeiTYETWN9KCLxHVFalqGTobVN0TiDiMjR2oj:NrrggvDe |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:04:05 19:45:02+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit, Removable run from swap, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 14.38 |
| CodeSize: | 483328 |
| InitializedDataSize: | 317440 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x517f0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 24.3.26.8 |
| ProductVersionNumber: | 24.3.26.8 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| CompanyName: | Intel |
| FileDescription: | Intel® Driver & Support Assistant |
| FileVersion: | 24.3.26.8 |
| InternalName: | burn |
| OriginalFileName: | Intel-Driver-and-Support-Assistant-Installer.exe |
| ProductName: | Intel® Driver & Support Assistant |
| ProductVersion: | 24.3.26.8 |
| LegalCopyright: | Copyright © Intel Corporation. All rights reserved. |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 32 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 320 | "C:\WINDOWS\system32\cmd.exe" /c cd "C:\Program Files\Intel\SUR\QUEENCREEK\" && if exist SurSvc.exe (start /b /wait /d "C:\Program Files\Intel\SUR\QUEENCREEK\" SurSvc.exe /uninstall) | C:\Windows\System32\cmd.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1044 | "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.exe" | C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.exe | — | cmd.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: Intel(R) System Usage Report Exit code: 0 Modules
| |||||||||||||||
| 1108 | "C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe" -q -burn.elevated BurnPipe.{0356C42E-0A40-49B4-BD28-5B34EEBF0AF6} {F364688D-E992-4D59-8F81-2DE12D529526} 6472 | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.be\Intel-Driver-and-Support-Assistant-Installer.exe | Intel-Driver-and-Support-Assistant-Installer.exe | ||||||||||||
User: admin Company: Intel Integrity Level: HIGH Description: Intel® Driver & Support Assistant Exit code: 0 Version: 24.3.26.8 Modules
| |||||||||||||||
| 1128 | "CMD" /C RMDIR /S /Q "C:\Program Files\Intel\SUR\QUEENCREEK\Updater\" && RMDIR /S /Q "C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Intel\SUR\QUEENCREEK\Updater\" | C:\Windows\SysWOW64\cmd.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 3 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1128 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2456 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1700 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4724 --field-trial-handle=2320,i,14090253114551167275,5846454218178151140,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1920 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a4,0x2bc,0x7fffca525fd8,0x7fffca525fe4,0x7fffca525ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2152 | "C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe" "--start" "--start_options_handle" "960" | C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe | task.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Intel(R) System Usage Report Modules
| |||||||||||||||
| 2212 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (6504) BootstrapperUI_V2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\vi\BootstrapperUI_V2.resources.dll | executable | |
MD5:7A6478D5960E5042C5A89F481E67D8DD | SHA256:E1CF09DCBA99488FC93A8A935ADE30F3ED682783EAE209CD9BA2BBAC73D0DB2C | |||
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\es\BootstrapperUI_V2.resources.dll | executable | |
MD5:B03A31232740D2E7497D86489F147638 | SHA256:5846D91DC6949040BA6818EDC80F45B7DC875D09EC3FE56B49A7FDEFEEB3DEBA | |||
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\id\BootstrapperUI_V2.resources.dll | executable | |
MD5:F6CCDE24E714364CE7288FE7CED0A3B8 | SHA256:E8AE1E7D3A237ADA0D95A8C739A11570F52AE956242B910DB59BDF226DF75DBF | |||
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\fr\BootstrapperUI_V2.resources.dll | executable | |
MD5:E462631050803B72DFCA3B49E91D1ACD | SHA256:C146DDB32FD877A17201A72A2AC7EBF9736F550B71A3C4581A3B701E1AA5DB78 | |||
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ko\BootstrapperUI_V2.resources.dll | executable | |
MD5:C6C9EA1C041F6DD390A53A5714F559A5 | SHA256:955D5C14BE38EB620B049D7F5B192F1D6E614320B17C1625D9F0CD7289AEFA04 | |||
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\ja\BootstrapperUI_V2.resources.dll | executable | |
MD5:2C8B2E47BEBD546A8C053F8859D306D6 | SHA256:7898FAF8BF359CF21E1074C83772421981D87E8D53A6AB69C3543064C4F3081E | |||
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\pt-BR\BootstrapperUI_V2.resources.dll | executable | |
MD5:8865827C673F6B9033DAAD970F229F8F | SHA256:9D2D05A46F5B3F04057CF0DD65FCA11624A51EE88A4A1EB23CE6A760DCAC2275 | |||
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\de\BootstrapperUI_V2.resources.dll | executable | |
MD5:E20749FC2A2A24F4499A6E622CF263EF | SHA256:1E24731DC7BD4FE61C7C37B082F3B00108F047EE24B4596CFD570B52B0C2D3AA | |||
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\System.Memory.dll | executable | |
MD5:3BD7EF8CA6646B99ACBE2B503DE835C1 | SHA256:07F2F987794F31652B8649884BC310007C0EC06F97D9F186375D9A737178FAAA | |||
| 6472 | Intel-Driver-and-Support-Assistant-Installer.exe | C:\Users\admin\AppData\Local\Temp\{EE535331-BC28-42EA-BADA-79FBE8B5C963}\.ba\GalaSoft.MvvmLight.Extras.dll | executable | |
MD5:D9C798E9A0E0EC3A09495D619E96C458 | SHA256:8DE04C655729181216BD3F8B6FA75FB784D2CD555022873AC38FC1588592F00B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5976 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6896 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5976 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6928 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6472 | Intel-Driver-and-Support-Assistant-Installer.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6472 | Intel-Driver-and-Support-Assistant-Installer.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D | unknown | — | — | whitelisted |
6472 | Intel-Driver-and-Support-Assistant-Installer.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEDW%2BdGOMs%2BneKAVwt5eAs2c%3D | unknown | — | — | whitelisted |
32 | msiexec.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D | unknown | — | — | whitelisted |
32 | msiexec.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEAJ8OQEMp1rDOrXuDVQO%2BeU%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3140 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3848 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3140 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5336 | SearchApp.exe | 2.23.209.182:443 | www.bing.com | Akamai International B.V. | GB | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
5976 | svchost.exe | 40.126.32.134:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
th.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1128 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
1128 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |