analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
download:

Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE

Full analysis: https://app.any.run/tasks/4d248c59-6963-4584-8339-132729e67369
Verdict: Malicious activity
Analysis date: July 27, 2022, 21:45:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9B62C902FB6C635170AC458A4783A84D

SHA1:

F8D39946775416F74A661A3480624ACEB73C4049

SHA256:

E0555444B90851DDB59554AB7EDB5C4FBAF026F0C979B6698A211DDBFA853DA7

SSDEEP:

196608:Rkat80el1xR4RzSmdtx2Tsw2E7cRGo8sOgZo0aH0HbhwmOZjwbZjTbtu2th:Q1xCRbhTb42/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE (PID: 3804)
      • miniunz.exe (PID: 3880)
      • SetupSerialIO.exe (PID: 2332)
      • setup.exe (PID: 1936)
    • Actions looks like stealing of personal data

      • SetupSerialIO.exe (PID: 2332)
    • Loads dropped or rewritten executable

      • setup.exe (PID: 1936)
      • miniunz.exe (PID: 3880)
    • Application was dropped or rewritten from another process

      • miniunz.exe (PID: 3880)
      • SetupSerialIO.exe (PID: 2332)
      • setup.exe (PID: 1936)
  • SUSPICIOUS

    • Checks supported languages

      • Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE (PID: 3804)
      • miniunz.exe (PID: 3880)
      • SetupSerialIO.exe (PID: 2332)
      • setup.exe (PID: 1936)
    • Reads the computer name

      • Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE (PID: 3804)
    • Creates files in the program directory

      • Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE (PID: 3804)
    • Executable content was dropped or overwritten

      • Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE (PID: 3804)
      • miniunz.exe (PID: 3880)
      • SetupSerialIO.exe (PID: 2332)
      • setup.exe (PID: 1936)
    • Reads Microsoft Outlook installation path

      • Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE (PID: 3804)
    • Reads internet explorer settings

      • Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE (PID: 3804)
    • Drops a file with a compile date too recent

      • Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE (PID: 3804)
      • miniunz.exe (PID: 3880)
      • SetupSerialIO.exe (PID: 2332)
      • setup.exe (PID: 1936)
  • INFO

    • Manual execution by user

      • msinfo32.exe (PID: 2532)
    • Reads the computer name

      • msinfo32.exe (PID: 2532)
    • Checks supported languages

      • msinfo32.exe (PID: 2532)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:07:29 07:14:55+02:00
PEType: PE32
LinkerVersion: 14
CodeSize: 5544960
InitializedDataSize: 3369984
UninitializedDataSize: -
EntryPoint: 0x1fb4a
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.8.9.106
ProductVersionNumber: 4.8.7.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Dell Inc.
FileDescription: Dell Update Package: Intel Serial IO Driver, 30.100.1943.2, A09
FileVersion: 004.008.007.000
InternalName: DUPFramework.exe
LegalCopyright: Copyright (C) Dell Inc. 2021. All rights reserved.
OriginalFileName: DUPFramework.exe
ProductName: Intel Serial IO Driver, 30.100.1943.2, A09
ProductVersion: 30.100.1943.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start intel-serial-io-driver_6cyp4_win_30.100.1943.2_a09_04.exe no specs intel-serial-io-driver_6cyp4_win_30.100.1943.2_a09_04.exe miniunz.exe setupserialio.exe setup.exe msinfo32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3180"C:\Users\admin\AppData\Local\Temp\Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE" C:\Users\admin\AppData\Local\Temp\Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEExplorer.EXE
User:
admin
Company:
Dell Inc.
Integrity Level:
MEDIUM
Description:
Dell Update Package: Intel Serial IO Driver, 30.100.1943.2, A09
Exit code:
3221226540
Version:
004.008.007.000
3804"C:\Users\admin\AppData\Local\Temp\Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE" C:\Users\admin\AppData\Local\Temp\Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE
Explorer.EXE
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Dell Update Package: Intel Serial IO Driver, 30.100.1943.2, A09
Exit code:
3
Version:
004.008.007.000
3880 -x C:\Users\admin\AppData\Local\Temp\INTEL-~1.EXE -o -d c:\PROGRA~2\dell\drivers\121990~1c:\PROGRA~2\dell\drivers\121990~1\miniunz.exe
Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
2332"C:\ProgramData\Dell\drivers\121990f1-1e2e-444e-83fb-20834060c85e\SetupSerialIO.exe" /report "C:\ProgramData\dell\drivers\121990f1-1e2e-444e-83fb-20834060c85e\DUP224F.tmp"C:\ProgramData\Dell\drivers\121990f1-1e2e-444e-83fb-20834060c85e\SetupSerialIO.exe
Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXE
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
1936C:\Users\admin\AppData\Local\Temp\IIF229D.tmp\setup.exe /report C:\ProgramData\dell\drivers\121990f1-1e2e-444e-83fb-20834060c85e\DUP224F.tmp C:\Users\admin\AppData\Local\Temp\IIF229D.tmp\setup.exe
SetupSerialIO.exe
User:
admin
Company:
Intel Corporation
Integrity Level:
HIGH
Description:
Intel(R) Serial IO installer
Exit code:
1603
Version:
3.0.2708.5
2532"C:\Windows\system32\msinfo32.exe" C:\Windows\system32\msinfo32.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
System Information
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
759
Read events
746
Write events
13
Delete events
0

Modification events

(PID) Process:(3804) Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3804) Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3804) Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3804) Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3804) Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3804) Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3804) Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3804) Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3804) Intel-Serial-IO-Driver_6CYP4_WIN_30.100.1943.2_A09_04.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
63
Suspicious files
2
Text files
31
Unknown types
8

Dropped files

PID
Process
Filename
Type
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\production\Windows10-x64\0\Drivers\WU\ialpss2_gpio2_skl.catcat
MD5:A27246F915D96DC2F2B29FD73E598501
SHA256:7FA70B333A0BDB5F3A11FFB5B6504C677E630A995E38CB391EF186A0A9C8AB91
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\mup.xmlxml
MD5:478386DE8D389F3946CFC37242E2D301
SHA256:DE809E763C1554DC17EDFF7B55DA0D29D5897F88E671BF707E15F2BB8D011B6F
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_GPIO2_SKL.inftxt
MD5:F4252CD5D9246A4C236C4C79689B94AD
SHA256:923F7998D205ACAF04A6DE3CAB899B68E01D7E6FE897A00120FD44E666BB3415
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_GPIO2.sysexecutable
MD5:27F9D764735B425E0039F9246A92E424
SHA256:7425056D914847FFD83657D561828D4D0C0DBBE7FA20E3BF0E71C925184DB50C
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\production\Windows10-x64\0\Drivers\WU\ialpss2_spi_skl.catcat
MD5:F8A6338CF784C77A3E42F98312FCAAD6
SHA256:435E8100BD451610F43B3B8D0D444DE92E0EA724F70859086C30EF0A340678FB
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\SetupSerialIO.exeexecutable
MD5:2681C9CE9860A261C74A2F451A32B7E9
SHA256:0761932DBC8961FA1D210B44ADCF77DE53C09B7ACD1F56BFED53CF59381EB3C5
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_SPI.sysexecutable
MD5:C87A953E7D707C10859D355132705ECF
SHA256:1E6F81720FAEC5A4A79136E78CF667EB03A361E4112399861C347AA381F8408D
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\production\Windows10-x64\0\Drivers\WU\iaLPSS2_I2C.sysexecutable
MD5:23024423C9EA2C2C1799B1D0672317E6
SHA256:363F4E9529BB0A7B1E442B07365824FD132566419E7E5EE2BF62B489725EFBD6
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\package.xmlbinary
MD5:B5F2198F56CFFCEF21141F53F9315850
SHA256:3C499CDDDAD8FF8634DDFEFD271371A59249BD92DB2E3DA3FAD6FB9FC3095A73
3880miniunz.exeC:\PROGRA~2\dell\drivers\121990~1\production\Windows10-x64\0\Drivers\WU\ialpss2_i2c_skl.catcat
MD5:F52F086D64B3E1DBC39963C71EE228FF
SHA256:0DED90E4209DC623268E4A318A39130B82D453FEAE11B7E8221DC3B27340D7DE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info