File name:

IDSAInstallerikgugkc4.exe

Full analysis: https://app.any.run/tasks/dc2e5f43-df24-4ea3-a045-25d8a1610f99
Verdict: Malicious activity
Analysis date: February 28, 2025, 00:09:20
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

E0F321774478AB9E04D5FA9FC5A3F129

SHA1:

3C8E43E60FB36A847970D2498DC39417AD655A64

SHA256:

EB0F64839742EDF69A72EA0C9C8106CD66EFF7DFE9BF2F8EDB6F789DE90DB9FE

SSDEEP:

98304:wiwhXS8ps612uYKmRDy+bdM/YUbkPr2vDSLoyb8bXOulT1SjBu7Ue7XuBIN0qkUN:keWVvFrZL95

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
    • Reads security settings of Internet Explorer

      • BootstrapperUI_V2.exe (PID: 496)
      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • ShellExperienceHost.exe (PID: 6652)
      • DSATray.exe (PID: 7488)
    • Searches for installed software

      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
      • dllhost.exe (PID: 7584)
    • Executes as Windows Service

      • VSSVC.exe (PID: 5332)
      • DSAService.exe (PID: 7524)
      • DSAUpdateService.exe (PID: 7528)
    • Checks Windows Trust Settings

      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • msiexec.exe (PID: 7872)
    • Process drops legitimate windows executable

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • msiexec.exe (PID: 7872)
    • Mutex name with non-standard characters

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
      • msiexec.exe (PID: 7872)
    • Creates a software uninstall entry

      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7872)
  • INFO

    • Create files in a temporary directory

      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
    • The sample compiled with english language support

      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
    • Checks supported languages

      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • BootstrapperUI_V2.exe (PID: 496)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
      • msiexec.exe (PID: 7872)
      • ShellExperienceHost.exe (PID: 6652)
      • DSAService.exe (PID: 7524)
      • DSAUpdateService.exe (PID: 7528)
      • DSAArcDetect64.exe (PID: 7224)
      • DSATray.exe (PID: 7488)
    • Reads the computer name

      • BootstrapperUI_V2.exe (PID: 496)
      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
      • msiexec.exe (PID: 7872)
      • ShellExperienceHost.exe (PID: 6652)
      • DSAUpdateService.exe (PID: 7528)
      • DSAArcDetect64.exe (PID: 7224)
      • DSATray.exe (PID: 7488)
      • DSAService.exe (PID: 7524)
    • Reads the machine GUID from the registry

      • BootstrapperUI_V2.exe (PID: 496)
      • Intel-Driver-and-Support-Assistant-Installer.exe (PID: 7708)
      • msiexec.exe (PID: 7872)
      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • DSAService.exe (PID: 7524)
      • DSATray.exe (PID: 7488)
    • Disables trace logs

      • BootstrapperUI_V2.exe (PID: 496)
      • DSAService.exe (PID: 7524)
    • Checks proxy server information

      • BootstrapperUI_V2.exe (PID: 496)
      • BackgroundTransferHost.exe (PID: 7768)
      • IDSAInstallerikgugkc4.exe (PID: 5008)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7552)
      • BackgroundTransferHost.exe (PID: 7768)
      • BackgroundTransferHost.exe (PID: 7408)
      • BackgroundTransferHost.exe (PID: 7928)
      • BackgroundTransferHost.exe (PID: 8148)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 7768)
      • IDSAInstallerikgugkc4.exe (PID: 5008)
      • msiexec.exe (PID: 7872)
      • BootstrapperUI_V2.exe (PID: 496)
      • DSAService.exe (PID: 7524)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 7768)
    • Creates files in the program directory

      • BootstrapperUI_V2.exe (PID: 496)
    • Process checks computer location settings

      • IDSAInstallerikgugkc4.exe (PID: 5008)
    • Manages system restore points

      • SrTasks.exe (PID: 7220)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7872)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7872)
    • Reads product name

      • DSAService.exe (PID: 7524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:05 19:45:02+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.38
CodeSize: 483328
InitializedDataSize: 317440
UninitializedDataSize: -
EntryPoint: 0x517f0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 25.1.9.6
ProductVersionNumber: 25.1.9.6
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Intel
FileDescription: Intel® Driver & Support Assistant
FileVersion: 25.1.9.6
InternalName: burn
OriginalFileName: Intel-Driver-and-Support-Assistant-Installer.exe
ProductName: Intel® Driver & Support Assistant
ProductVersion: 25.1.9.6
LegalCopyright: Copyright © Intel Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
21
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start idsainstallerikgugkc4.exe bootstrapperui_v2.exe sppextcomobj.exe no specs slui.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs intel-driver-and-support-assistant-installer.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs shellexperiencehost.exe no specs msiexec.exe dsaservice.exe dsaupdateservice.exe no specs dsaarcdetect64.exe no specs conhost.exe no specs dsatray.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\BootstrapperUI_V2.exe" -burn.ba.apiver 569705357157400576 -burn.ba.pipe BurnPipe.{3CFD3C14-CC60-4888-8847-9576F4FA01CC} {B4D21AE6-9DC1-4CC6-896F-E1665B79E32D}C:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\BootstrapperUI_V2.exe
IDSAInstallerikgugkc4.exe
User:
admin
Company:
Intel
Integrity Level:
MEDIUM
Description:
BootstrapperUI
Version:
25.1.9.6
Modules
Images
c:\users\admin\appdata\local\temp\{2be3b4c0-b69a-45fe-af15-fca938e358e4}\.ba\bootstrapperui_v2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1452"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4724C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5008"C:\Users\admin\AppData\Local\Temp\IDSAInstallerikgugkc4.exe" C:\Users\admin\AppData\Local\Temp\IDSAInstallerikgugkc4.exe
explorer.exe
User:
admin
Company:
Intel
Integrity Level:
MEDIUM
Description:
Intel® Driver & Support Assistant
Version:
25.1.9.6
Modules
Images
c:\users\admin\appdata\local\temp\idsainstallerikgugkc4.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5332C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6652"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wincorlib.dll
7220C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7224"C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe" json https://dsadata.intel.com/data/en "Dell"C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exeDSAService.exe
User:
SYSTEM
Company:
Intel
Integrity Level:
SYSTEM
Description:
Intel Arc Graphics detection
Exit code:
0
Version:
25.1.9.6
Modules
Images
c:\program files (x86)\intel\driver and support assistant\dsaarcdetect64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7408"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
19 863
Read events
19 318
Write events
510
Delete events
35

Modification events

(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(496) BootstrapperUI_V2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BootstrapperUI_V2_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
147
Suspicious files
60
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\de\BootstrapperUI_V2.resources.dllexecutable
MD5:A95685433782AF86EB7EC5282C4E2729
SHA256:F0CC48B31775344A584A49CAE70FA7A8A7155CFFE120C6EF483E9DC28A6F32FC
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\th\BootstrapperUI_V2.resources.dllexecutable
MD5:383734B6718F5825332165A5303ACDBC
SHA256:305B1EF928DF41313C090F8AEACD31D895131DDE2069FA09CB5F0597FECCE7DD
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\fr\BootstrapperUI_V2.resources.dllexecutable
MD5:BA9D4A6DB79DD8D5BD75E38B4F985B5B
SHA256:AA47ED3D11C513CFC5BD56644B38667FF32842A6DA2BF9687861115E1BF90440
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\vi\BootstrapperUI_V2.resources.dllexecutable
MD5:0B12ADA97DEAA557C43C439B20EDFFA3
SHA256:299FF5A2F2838B04532571B4A2087145C4AB24B8E35800A008C9FEF64F8B5939
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\zh-TW\BootstrapperUI_V2.resources.dllexecutable
MD5:BA7DCBB870FE7C432D603820847C8E6B
SHA256:1CBAF6AFAEDF9314EA5BAA5ECE05EAA264DFAB4FFC3723504581B085E81439B2
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\CommonServiceLocator.dllexecutable
MD5:0A8C9BF360F60C65735EC7027886496A
SHA256:270D9BC28BE2F0B7FBD25193F5C4F224E43E4033732B35EE6B940204E404C40A
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\BootstrapperUI_V2.exe.configxml
MD5:CB6048A33306DA8D4D32204388B83E94
SHA256:5C65F5D0BDD4B45FFF99C3AD3C3F319B9BA1824336D83463162ED5A02CBE3439
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\es\BootstrapperUI_V2.resources.dllexecutable
MD5:B7D83EA4F49F14D982AC0969975F3966
SHA256:B97F3E717C0213A464E1801618493916BEB63007D6A57C83A418EB7DC43426F9
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\id\BootstrapperUI_V2.resources.dllexecutable
MD5:076AFBC50DC5BF618724FD717946453B
SHA256:5F940C5C75660B3A8D93C3812DE585BADDB1DBB46096DFD2BECA3AEB4F58D887
5008IDSAInstallerikgugkc4.exeC:\Users\admin\AppData\Local\Temp\{2BE3B4C0-B69A-45FE-AF15-FCA938E358E4}\.ba\BootstrapperUI_V2.exeexecutable
MD5:AE292B0516F181B1C64AE36540EA6A9B
SHA256:D4A8C5CB0CEE17C8C46C657C4BC65F825F7142D526F5DB85FFB4C679598559D0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
39
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7768
BackgroundTransferHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7640
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7640
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5008
IDSAInstallerikgugkc4.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
5008
IDSAInstallerikgugkc4.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7872
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEAJ8OQEMp1rDOrXuDVQO%2BeU%3D
unknown
whitelisted
7872
msiexec.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
whitelisted
7872
msiexec.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEQDevLVOPyKjTcl8PoK9arwe
unknown
whitelisted
3968
WmiPrvSE.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
3968
WmiPrvSE.exe
GET
200
92.123.22.101:80
http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%20
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3008
backgroundTaskHost.exe
104.126.37.153:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2040
backgroundTaskHost.exe
20.103.156.88:443
fd.api.iris.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5048
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7768
BackgroundTransferHost.exe
104.126.37.153:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
google.com
  • 142.250.184.238
whitelisted
login.live.com
  • 20.190.160.65
  • 20.190.160.66
  • 20.190.160.4
  • 20.190.160.17
  • 40.126.32.136
  • 20.190.160.130
  • 40.126.32.140
  • 20.190.160.5
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
www.bing.com
  • 104.126.37.153
  • 104.126.37.155
  • 104.126.37.154
  • 104.126.37.162
  • 104.126.37.185
  • 104.126.37.160
  • 104.126.37.171
  • 104.126.37.139
  • 104.126.37.123
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 92.123.22.101
whitelisted

Threats

No threats detected
No debug info