Windows Analysis Report
https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda_12.4.0_551.61_windows.exe

Overview

General Information

Sample URL: https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda_12.4.0_551.61_windows.exe
Analysis ID: 1419160
Infos:

Detection

Score: 24
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Drops large PE files
Abnormal high CPU Usage
Drops PE files
Found dropped PE file which has not been started or loaded
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Usage Of Web Request Commands And Cmdlets
Tries to load missing DLLs
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Source: Binary string: C:\dvs\p4\build\sw\dev\cm\pfw\dev_a\cm\SFX\Output\Win32\7zSfxMod.pdbh source: cuda_12.4.0_551.61_windows.exe, 0000000C.00000000.6027366330.000000000049E000.00000002.00000001.01000000.00000004.sdmp
Source: Binary string: C:\dvs\p4\build\sw\dev\cm\pfw\dev_a\cm\SFX\Output\Win32\7zSfxMod.pdb source: cuda_12.4.0_551.61_windows.exe, 0000000C.00000000.6027366330.000000000049E000.00000002.00000001.01000000.00000004.sdmp
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras\CUPTI\doc Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras\CUPTI Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras\CUPTI\doc\html Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras\CUPTI\doc\html\api Jump to behavior
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://aia.entrust.net/ts1-chain256.cer01
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/2048ca.crl0
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/ts1ca.crl0
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: CUDAToolkit.nvi.12.dr String found in binary or memory: http://docs.nvidia.com/cuda/cuda-installation-guide-microsoft-windows/index.html#system-requirements
Source: is_trivially_relocatable.h.12.dr String found in binary or memory: http://eel.is/c
Source: EULA.txt.12.dr String found in binary or memory: http://impact.crhc.illinois.edu
Source: EULA.txt.12.dr String found in binary or memory: http://llvm.org
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net02
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net03
Source: EULA.txt.12.dr String found in binary or memory: http://openai.com)
Source: unique.h.12.dr, tabulate.h1.12.dr, swap_ranges.h.12.dr, device_synchronize.cuh.12.dr, namespace.h.12.dr, complex.h0.12.dr, unique.h1.12.dr, assign_value.h.12.dr, memory_resource.h0.12.dr, compiler.h.12.dr, scatter.h.12.dr, ccosh.h.12.dr, copy.h2.12.dr, reduce.h.12.dr, uninitialized_fill.h0.12.dr, partition.inl.12.dr, unique.inl.12.dr, execution_policy.h1.12.dr, fill_construct_range.inl.12.dr, sequence.h1.12.dr, transform_scan.h.12.dr String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: EULA.txt.12.dr String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com/CPS0
Source: EULA.txt.12.dr String found in binary or memory: http://www.eclipse.org.
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.entrust.net/rpa03
Source: EULA.txt.12.dr String found in binary or memory: http://www.gnu.org/licenses/gpl.txt
Source: FindTBB.cmake.12.dr String found in binary or memory: http://www.ogre3d.org/
Source: EULA.txt.12.dr String found in binary or memory: http://www.opensource.org/licenses/bsd-license.php)
Source: FindTBB.cmake.12.dr String found in binary or memory: https://cmake.org/cmake/help/latest/variable/MSVC_VERSION.html
Source: wget.exe, 00000002.00000002.5704491020.0000000000D38000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda
Source: wget.exe, 00000002.00000002.5704258359.0000000000B90000.00000004.00000020.00020000.00000000.sdmp, cmdline.out.0.dr String found in binary or memory: https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda_12.4.0_551.61_window
Source: EULA.txt.12.dr String found in binary or memory: https://developer.nvidia.com.
Source: cupti_result.h.12.dr String found in binary or memory: https://developer.nvidia.com/CUPTI_ERROR_INSUFFICIENT_PRIVILEGES
Source: cupti_result.h.12.dr String found in binary or memory: https://developer.nvidia.com/ERR_NVCMPGPU
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://developer.nvidia.com/blog/updating-the-cuda-linux-gpg-repository-key/.
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://developer.nvidia.com/cuda-gpus.
Source: DOCS.12.dr String found in binary or memory: https://docs.nvidia.com/cuda
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cuda-c-best-practices-guide/index.html#cuda-compatibility-and-upgrades.
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cuda-c-programming-guide/index.html#stream-ordered-querying-memory-supp
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cuda-installation-guide-linux/index.html#open-gpu-kernel-modules
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cuda-installation-guide-linux/index.html#package-manager-metas
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cuda-installation-guide-microsoft-windows/index.html#install-cuda-softw
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cuda-math-api/index.html
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cuda-math-api/index.html.
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cuda-toolkit-release-notes/index.html.
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cusparse/index.html#cusparse-generic-function-spmm-op.
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/cusparse/index.html#cusparse-logging.
Source: driver_types.h.12.dr, cuda_runtime_api.h.12.dr String found in binary or memory: https://docs.nvidia.com/cuda/gpudirect-rdma
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://docs.nvidia.com/deploy/cuda-compatibility/index.html
Source: count.h1.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/algorithm/count
Source: sort.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/algorithm/is_sorted
Source: reverse.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/algorithm/reverse
Source: reverse.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/algorithm/reverse_copy
Source: sort.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/algorithm/sort
Source: sort.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/algorithm/stable_sort
Source: unique.h1.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/algorithm/unique
Source: unique.h1.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/algorithm/unique_copy
Source: count.h1.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/concepts/equality_comparable
Source: count.h1.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/concepts/predicate
Source: sort.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/concepts/strict_weak_order
Source: vector.h0.12.dr, vector.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/container/vector
Source: advance.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/iterator/advance
Source: reverse.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/iterator/bidirectional_iterator
Source: sort.h0.12.dr, tabulate.h0.12.dr, uninitialized_fill.h1.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/iterator/forward_iterator
Source: count.h1.12.dr, advance.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/iterator/input_iterator
Source: advance.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/iterator/next
Source: unique.h1.12.dr, shuffle.h.12.dr, reverse.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/iterator/output_iterator
Source: advance.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/iterator/prev
Source: sort.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/iterator/random_access_iterator
Source: integer_sequence.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/language/constant_expression#Integral_constant_expression
Source: uninitialized_fill.h1.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/memory/uninitialized_fill
Source: advance.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/named_req/BidirectionalIterator
Source: unique.h1.12.dr, is_operator_less_or_greater_function_object.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/named_req/BinaryPredicate
Source: is_trivially_relocatable.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/named_req/BinaryTypeTrait
Source: is_contiguous_iterator.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/named_req/ContiguousIterator
Source: advance.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/named_req/InputIterator
Source: sort.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/named_req/LessThanComparable
Source: sort.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/named_req/RandomAccessIterator
Source: is_contiguous_iterator.h.12.dr, is_operator_less_or_greater_function_object.h.12.dr, is_trivially_relocatable.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/named_req/UnaryTypeTrait
Source: is_trivially_relocatable.h.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/string/byte/memcpy
Source: integer_sequence.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/types/size_t
Source: tabulate.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/utility/functional/unary_function
Source: integer_sequence.h0.12.dr String found in binary or memory: https://en.cppreference.com/w/cpp/utility/integer_sequence
Source: __access_property.12.dr String found in binary or memory: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=61414
Source: README.txt.12.dr String found in binary or memory: https://github.com/microsoft/Detours
Source: EULA.txt.12.dr String found in binary or memory: https://github.com/nvidia/cuda-samples
Source: EULA.txt.12.dr String found in binary or memory: https://github.com/openai/openai-gemm/blob/master/LICENSE
Source: thrust-config.cmake.12.dr String found in binary or memory: https://gitlab.kitware.com/cmake/cmake/-/issues/20670
Source: atomic_nvrtc.h.12.dr, xlocale.h0.12.dr, optional.12.dr, is_union.h.12.dr, cmp.h.12.dr, in_place.h.12.dr, thread.12.dr, __config_site.in.12.dr, cstdbool.12.dr, is_valid_expansion.h.12.dr, complex.h.12.dr, csetjmp.12.dr, chrono.h.12.dr, swap_ranges.h2.12.dr, boolean_testable.h.12.dr, set0.12.dr, stdexcept.12.dr, is_reference_wrapper.h.12.dr, list.12.dr, limits0.12.dr, forward_list.12.dr String found in binary or memory: https://llvm.org/LICENSE.txt
Source: is_trivially_relocatable.h.12.dr String found in binary or memory: https://wg21.link/P1144
Source: is_trivially_relocatable.h.12.dr String found in binary or memory: https://wg21.link/P1144R0#wording-inheritance
Source: wget.exe, 00000002.00000003.5099081030.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.5099081030.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.entrust.net/rpa0
Source: CUDA_Toolkit_Release_Notes.txt.12.dr String found in binary or memory: https://www.nvidia.com/drivers.

System Summary

barindex
Source: C:\Windows\SysWOW64\wget.exe File dump: cuda_12.4.0_551.61_windows.exe.2.dr 3190723024 Jump to dropped file
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Process Stats: CPU usage > 49%
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: thumbcache.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Section loaded: explorerframe.dll Jump to behavior
Source: classification engine Classification label: sus24.win@5/1027@0/1
Source: C:\Windows\SysWOW64\cmd.exe File created: C:\Users\user\Desktop\cmdline.out Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\c:*users*user*appdata*local*temp*cuda
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6916:120:WilError_03
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File created: C:\Users\user\AppData\Local\Temp\cuda Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda_12.4.0_551.61_windows.exe" > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda_12.4.0_551.61_windows.exe"
Source: unknown Process created: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe "C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda_12.4.0_551.61_windows.exe" Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File written: C:\Users\user\AppData\Local\Temp\cuda\GFExperience.NvStreamSrv\SteamLauncher\NVIDIA.SteamLauncher.ini Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: Binary string: C:\dvs\p4\build\sw\dev\cm\pfw\dev_a\cm\SFX\Output\Win32\7zSfxMod.pdbh source: cuda_12.4.0_551.61_windows.exe, 0000000C.00000000.6027366330.000000000049E000.00000002.00000001.01000000.00000004.sdmp
Source: Binary string: C:\dvs\p4\build\sw\dev\cm\pfw\dev_a\cm\SFX\Output\Win32\7zSfxMod.pdb source: cuda_12.4.0_551.61_windows.exe, 0000000C.00000000.6027366330.000000000049E000.00000002.00000001.01000000.00000004.sdmp
Source: C:\Windows\SysWOW64\wget.exe File created: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Jump to dropped file
Source: C:\Windows\SysWOW64\wget.exe Dropped PE file which has not been started: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe Jump to dropped file
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras\CUPTI\doc Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras\CUPTI Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras\CUPTI\doc\html Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti Jump to behavior
Source: C:\Users\user\Desktop\download\cuda_12.4.0_551.61_windows.exe File opened: C:\Users\user\AppData\Local\Temp\cuda\cuda_cupti\cupti\extras\CUPTI\doc\html\api Jump to behavior
Source: wget.exe, 00000002.00000002.5704491020.0000000000D38000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: unknown Process created: C:\Windows\SysWOW64\cmd.exe c:\windows\system32\cmd.exe /c wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda_12.4.0_551.61_windows.exe" > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda_12.4.0_551.61_windows.exe"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "https://developer.download.nvidia.com/compute/cuda/12.4.0/local_installers/cuda_12.4.0_551.61_windows.exe" Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Queries volume information: C:\Users\user\Desktop\download VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs