Intel-Driver-and-SupportInstaller_SBNJHK78837fwef783SHJshbjhbj.exe

First submission 2024-10-14 23:12:04 Last sumbission 2024-10-14 23:13:03

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 16011.42 KB (16395695 bytes)
Compile time: 2024-09-26 12:25:44
MD5: 1d8b00b46c0cdf5e9ac7535ac67cfbb4
SHA1: 7c2c97f229e56903fa5955b56cbf650b3ec9daa3
SHA256: dea0246d7c1d52e9360bffd41f848619ae58bf2bac38050b5dcf741938375aeb
Import Hash : 872b8500f51b6bf18bf8a498f21ad1dd
Sections 5 .text .rdata .data .reloc .rsrc
Directories 6 import resource debug tls relocation security

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 23/77 VT report date: 2024-10-14 20:51:25
Malware Type 2 trojan dropper
Threat Type 2 pwsx strab

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://zoomcallers.com/en-gb/insider/Intel-DriverSupport_SBNJHK788372hJHSBh2323.exe VirusTotal Report zoomcallers.com VirusTotal Report 2024-10-14 23:12:04

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1020d 66560 8e7206d3610dd236e003bd874aff311b63ee4510 b8a3b8b6fa8271b26f1fd7ecc8dbd406
.rdata 0x12000 0x4652 18432 77838843e924333449404645236294412af368b1 e41b2fbc7eb86ec50cf13a1afdb4425f
.data 0x17000 0x6e0 1024 e19ba834ec058f29abb2ee5bfe4b1094e36f13b6 699886fcb61b5e96a44ce47ca2bdf23f
.reloc 0x18000 0x934 2560 6eeb61a69b7069339113a5f43207f392de31e55a 12e10a751af356099b4f4f1457c2c433
.rsrc 0x19000 0x73cec 474624 fa8353c26b16c6c3eeb772697132335191b2e24a 5f2385e31f1ea1770884770c5caaa6ef

PE Resources 5

Name Language Sublanguage Offset Size Data
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x1e098 19260
RT_RCDATA LANG_NEUTRAL SUBLANG_DEFAULT 0x22bd4 433152
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x8c7d4 90
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_US 0x8c830 828
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x8cb6c 381

Meta infos 9

LegalCopyright: Copyright (c) 2024 HP Development Company, L.P.
InternalName: hpsoftpaqwrapper
FileVersion: 0.2.78.55519
CompanyName: HP Inc.
ProductVersion: 9.33.28.0
FileDescription: HP Support Assistant
Translation: 0x0409 0x04b0
OriginalFilename: hpsoftpaqwrapper.exe
ProductName: HP Support Assistant

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

File signature

MD5 SHA1 Block size Virtual Address
9435bae2869ea7ec555d724270a63184 bc1419dae946259e0ec7bc92822caf5b5b5aa068 11736 16383959

Strings analysis - File found

Autocad
k.dwg
Database
Iy].DB
g.DB
Ik.DB
Library
api-ms-win-core-registry-l1-1-0.dll
MSVCRT.dll
ADVAPI32.dll
bin\MSPDB140.DLL
mscoree.dll
ekernel32.dll
KERNEL32.dll
ntdll.dll

Strings analysis - Possible URLs found 17

http://ocsp.digicert.com0X
http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
http://www.digicert.com/CPS0
http://ocsp.digicert.com0I
http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
http://ocsp.digicert.com0A
http://ocsp.digicert.com0C
http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
http://ocsp.digicert.com0\
http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0K
http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S

Import functions

Name Latest seen MD5
Intel-Driver-and-SupportInstaller_2.13.exe 2024-10-14 23:14:04 7e68d4a24a9bc37425e889bcd46db8a8