Intel-Driver-and-SupportInstaller_2.13.exe

First submission 2024-10-14 23:11:02 Last sumbission 2024-10-14 23:14:04

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 15895.12 KB (16276606 bytes)
Compile time: 2024-09-26 12:25:44
MD5: 7e68d4a24a9bc37425e889bcd46db8a8
SHA1: 53a6866b4d764c309b2fe087cd4262515e59225f
SHA256: 73c00ca06add32392782aa6ff491460c833bbe561faa40d37b8cc9e3bee1bc91
Import Hash : 872b8500f51b6bf18bf8a498f21ad1dd
Sections 5 .text .rdata .data .reloc .rsrc
Directories 6 import resource debug tls relocation security

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 20/77 VT report date: 2024-10-14 22:43:30
Malware Type 2 trojan dropper
Threat Type 2 pwsx strab

URLs, FQDN and IP indicators 2

URL Host (FQDN/IP) Date Added
hXXp://zoomcallers.com/en-gb/insider/Intel-Driver-and-SupportInstaller_2.13.exe VirusTotal Report zoomcallers.com VirusTotal Report 2024-10-14 23:14:07
hXXp://zoomcallers.com/en-gb/insider/Intel-Driver-and-SupportInstaller_2.12.exe VirusTotal Report zoomcallers.com VirusTotal Report 2024-10-14 23:11:02

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1020d 66560 8e7206d3610dd236e003bd874aff311b63ee4510 b8a3b8b6fa8271b26f1fd7ecc8dbd406
.rdata 0x12000 0x4652 18432 77838843e924333449404645236294412af368b1 e41b2fbc7eb86ec50cf13a1afdb4425f
.data 0x17000 0x6e0 1024 e19ba834ec058f29abb2ee5bfe4b1094e36f13b6 699886fcb61b5e96a44ce47ca2bdf23f
.reloc 0x18000 0x934 2560 6eeb61a69b7069339113a5f43207f392de31e55a 12e10a751af356099b4f4f1457c2c433
.rsrc 0x19000 0x56cec 355840 3802cc9ea25f32fcbe52c30a4c3e80e68512dc53 a13637b515a5d6570415e01450dffcc2

PE Resources 5

Name Language Sublanguage Offset Size Data
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x1e098 19260
RT_RCDATA LANG_NEUTRAL SUBLANG_DEFAULT 0x22bd4 314368
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x6f7d4 90
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_US 0x6f830 828
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x6fb6c 381

Meta infos 9

LegalCopyright: Copyright (c) 2024 HP Development Company, L.P.
InternalName: hpsoftpaqwrapper
FileVersion: 0.2.78.55519
CompanyName: HP Inc.
ProductVersion: 9.33.28.0
FileDescription: HP Support Assistant
Translation: 0x0409 0x04b0
OriginalFilename: hpsoftpaqwrapper.exe
ProductName: HP Support Assistant

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

File signature

MD5 SHA1 Block size Virtual Address
9435bae2869ea7ec555d724270a63184 bc1419dae946259e0ec7bc92822caf5b5b5aa068 11736 16264870

Strings analysis - File found

Registry
]a.ReG
Database
y[.Db
Audio
*A.wMA
Library
api-ms-win-core-registry-l1-1-0.dll
MSVCRT.dll
ADVAPI32.dll
bin\MSPDB140.DLL
mscoree.dll
ekernel32.dll
ntdll.dll
KERNEL32.dll

Strings analysis - Possible URLs found 17

http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
http://ocsp.digicert.com0\
http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
http://www.digicert.com/CPS0
http://ocsp.digicert.com0I
http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
http://ocsp.digicert.com0A
http://ocsp.digicert.com0C
http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0K
http://ocsp.digicert.com0X

Import functions

Name Latest seen MD5
Intel-Driver-and-SupportInstaller_SBNJHK78837fwef783SHJshbjhbj.exe 2024-10-14 23:13:03 1d8b00b46c0cdf5e9ac7535ac67cfbb4