File name:

Install iCUE.exe

Full analysis: https://app.any.run/tasks/e3c44657-70fa-4442-a178-8ef452446273
Verdict: Malicious activity
Analysis date: February 20, 2025, 02:53:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

56EA038E927A23EDF4E51CA3A80D932E

SHA1:

7B768DB2FF3FB6BEE30812E55F6666CD3747887A

SHA256:

EC9D3ED6C05A94DD3E551F6A170136A3E931F659C64BAC82885CD88A05D1656C

SSDEEP:

49152:YS0dCFL9jLFdfvxqQcGUT/IvfQ07V+WuNul+ehO3lUpjAg4RiDK/XjYYkSgGs+fq:YS0dCFJjLFdfvxqtGUzIvfgIK/sas

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Install iCUE.exe (PID: 6732)
    • Checks Windows Trust Settings

      • Install iCUE.exe (PID: 6732)
    • Executable content was dropped or overwritten

      • Install iCUE.exe (PID: 6732)
      • cuepkg.exe (PID: 7132)
    • Process drops legitimate windows executable

      • Install iCUE.exe (PID: 6732)
    • Uses TASKKILL.EXE to kill process

      • Install iCUE.exe (PID: 6732)
    • The process drops C-runtime libraries

      • Install iCUE.exe (PID: 6732)
  • INFO

    • Creates files in the program directory

      • Install iCUE.exe (PID: 6732)
      • cuepkg.exe (PID: 5992)
      • cuepkg.exe (PID: 2996)
      • cuepkg.exe (PID: 7132)
      • cuepkg.exe (PID: 2008)
    • Reads the software policy settings

      • Install iCUE.exe (PID: 6732)
    • Reads the computer name

      • Install iCUE.exe (PID: 6732)
      • cuepkg.exe (PID: 5992)
      • cuepkg.exe (PID: 2008)
      • cuepkg.exe (PID: 7132)
    • Checks supported languages

      • Install iCUE.exe (PID: 6732)
      • cuepkg.exe (PID: 5992)
      • cuepkg.exe (PID: 2996)
      • cuepkg.exe (PID: 2008)
      • cuepkg.exe (PID: 2548)
      • cuepkg.exe (PID: 7132)
    • Reads the machine GUID from the registry

      • Install iCUE.exe (PID: 6732)
      • cuepkg.exe (PID: 2996)
      • cuepkg.exe (PID: 7132)
      • cuepkg.exe (PID: 2008)
    • Checks proxy server information

      • Install iCUE.exe (PID: 6732)
      • cuepkg.exe (PID: 2008)
      • cuepkg.exe (PID: 7132)
    • Creates files or folders in the user directory

      • Install iCUE.exe (PID: 6732)
    • The sample compiled with english language support

      • Install iCUE.exe (PID: 6732)
      • cuepkg.exe (PID: 7132)
    • Create files in a temporary directory

      • cuepkg.exe (PID: 2008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:12:03 16:44:25+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.29
CodeSize: 1357824
InitializedDataSize: 2027008
UninitializedDataSize: -
EntryPoint: 0x10ae8c
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.15.8.0
ProductVersionNumber: 1.15.8.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: 1
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Corsair
FileDescription: Corsair iCUE Installer
FileVersion: 1.15.8
InternalName: Corsair iCUE Primary Installer
LegalCopyright: Corsair Memory, Inc. © 2023, All rights reserved
ProductName: Corsair iCUE
ProductVersion: 1.15.8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
24
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start install icue.exe taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs cuepkg.exe no specs conhost.exe no specs cuepkg.exe no specs conhost.exe no specs cuepkg.exe conhost.exe no specs cuepkg.exe no specs conhost.exe no specs cuepkg.exe conhost.exe no specs install icue.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1732\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1988\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execuepkg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2008"C:\ProgramData\Corsair\iCUE5 Initial Installer\manager\cuepkg.exe" --installdir="C:\ProgramData\Corsair\iCUE5 Initial Installer\packages" updateC:\ProgramData\Corsair\iCUE5 Initial Installer\manager\cuepkg.exe
Install iCUE.exe
User:
admin
Company:
Corsair Memory, Inc.
Integrity Level:
HIGH
Description:
iCUE Package Manager
Exit code:
0
Version:
1.31.3
Modules
Images
c:\programdata\corsair\icue5 initial installer\manager\cuepkg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2380taskkill /F /IM cuepkg.exe /TC:\Windows\System32\taskkill.exeInstall iCUE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2548"C:\ProgramData\Corsair\iCUE5 Initial Installer\manager\cuepkg.exe" --versionC:\ProgramData\Corsair\iCUE5 Initial Installer\manager\cuepkg.exeInstall iCUE.exe
User:
admin
Company:
Corsair Memory, Inc.
Integrity Level:
HIGH
Description:
iCUE Package Manager
Exit code:
0
Version:
1.31.3
Modules
Images
c:\programdata\corsair\icue5 initial installer\manager\cuepkg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\programdata\corsair\icue5 initial installer\manager\libcrypto-3-x64.dll
2612taskkill /F /IM cuepkg.exe /TC:\Windows\System32\taskkill.exeInstall iCUE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2996"C:\ProgramData\Corsair\iCUE5 Initial Installer\manager\cuepkg.exe" --installdir="C:\ProgramData\Corsair\iCUE5 Initial Installer\packages" set-config --global RepositoryUrl https://www3.corsair.com/software/CUE_V5/public/modules/windows/packagesC:\ProgramData\Corsair\iCUE5 Initial Installer\manager\cuepkg.exeInstall iCUE.exe
User:
admin
Company:
Corsair Memory, Inc.
Integrity Level:
HIGH
Description:
iCUE Package Manager
Exit code:
0
Version:
1.31.3
Modules
Images
c:\programdata\corsair\icue5 initial installer\manager\cuepkg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3732taskkill /F /IM cuepkg.exe /TC:\Windows\System32\taskkill.exeInstall iCUE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4392\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execuepkg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4816\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
6 273
Read events
6 268
Write events
5
Delete events
0

Modification events

(PID) Process:(6732) Install iCUE.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6732) Install iCUE.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6732) Install iCUE.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6732) Install iCUE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Corsair\iCUE5\Privacy
Operation:writeName:DataCollectionConsent
Value:
0
(PID) Process:(6732) Install iCUE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Corsair\iCUE5\Privacy
Operation:writeName:DataCollectionConsentTimestamp
Value:
Thu, 20 Feb 2025 02:54:00 +0000
Executable files
132
Suspicious files
38
Text files
446
Unknown types
0

Dropped files

PID
Process
Filename
Type
6732Install iCUE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:A14D6746B0F226002BF5D562D927B06B
SHA256:71D1A2DB700EC15B5228DE2C9E8FC54A873B50FA6054597D37891158E4BAF1D9
6732Install iCUE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
6732Install iCUE.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\terms-of-use[2].htmhtml
MD5:126629C1EC982103D4BCFAFE5964E677
SHA256:D2663F4E9FA30EEF594ACA122707C5FC683F01BDCE9975C3AD172DA8D69A3A1D
6732Install iCUE.exeC:\ProgramData\Corsair\iCUE5 Initial Installer\manager\cuepkg.zip.sha2text
MD5:1B061A28799684009189977F3FEB37D5
SHA256:BE1E3E1E57E2816E71FAEDCF0C6A80E9B0C476AD196CFD8015BD914C92DE5999
6732Install iCUE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:8BC723C9A222B66137400BD16B997FCE
SHA256:F7F4EACDE01AED882DB6F26CC664C8003891EC6229BF4F07230DF1BE7F54BCC4
6732Install iCUE.exeC:\ProgramData\Corsair\iCUE5 Initial Installer\manager\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:07EBE4D5CEF3301CCF07430F4C3E32D8
SHA256:8F8B79150E850ACC92FD6AAB614F6E3759BEA875134A62087D5DD65581E3001F
6732Install iCUE.exeC:\ProgramData\Corsair\iCUE5 Initial Installer\manager\api-ms-win-core-console-l1-2-0.dllexecutable
MD5:57193BFBCCEFE3D5DF8C1A0D27C4E8D4
SHA256:F5025E74DE2C1C6EA74E475B57771AC32205E6F1FA6A0390298BBE1F4049AC5D
6732Install iCUE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:A23148A9A508F01CF845278C6B147175
SHA256:AB7A5983FB7C650719A97BB9F9EC9789A9817C57F5DCDD1733B48184FA6B84D3
6732Install iCUE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:1CD59B665D0E553BC0A25F0D023466A4
SHA256:CA287883C99D97E4DE03F48094C3F1E8FFB81A0003F9C510CF9C3D212116CBAC
6732Install iCUE.exeC:\ProgramData\Corsair\iCUE5 Initial Installer\manager\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:557405C47613DE66B111D0E2B01F2FDB
SHA256:913EAAA7997A6AEE53574CFFB83F9C9C1700B1D8B46744A5E12D76A1E53376FD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
47
DNS requests
25
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6732
Install iCUE.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
6732
Install iCUE.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
6732
Install iCUE.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6192
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6732
Install iCUE.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
6192
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
104.126.37.139:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
184.30.18.9:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.184.206
whitelisted
www.bing.com
  • 104.126.37.139
  • 104.126.37.176
  • 104.126.37.154
  • 104.126.37.178
  • 104.126.37.185
  • 104.126.37.123
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.130
  • 40.126.32.68
  • 20.190.160.2
  • 40.126.32.140
  • 20.190.160.128
  • 20.190.160.20
  • 40.126.32.74
whitelisted
go.microsoft.com
  • 184.30.18.9
whitelisted
www3.corsair.com
  • 23.53.42.192
  • 23.53.42.163
whitelisted
www.corsair.com
  • 184.25.158.35
whitelisted

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] IP Geolocation and Threat Intelligence (api .ipregistr y.co)
No debug info