| File name: | GoogleCloudSDKInstaller.exe |
| Full analysis: | https://app.any.run/tasks/5b231662-c9cb-4df7-be7a-f3e091ded194 |
| Verdict: | Malicious activity |
| Analysis date: | October 23, 2023, 20:36:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | EA36404CA2394E5D93D1D11E34AE3327 |
| SHA1: | 5313A0C1B3CEAB74B5FB15BB2DDBEFF7CA2518C4 |
| SHA256: | 0055AB2C26082CA69DBF1CA8E92CE03869D9992B7A44DB9FF201F96D1999F8F4 |
| SSDEEP: | 3072:t8cFgUdOpDyTdcl4vN0HjHsGu03JXi+7YMa6oTWqE9G21BwIa1:tlTe4vS57zomZ+ |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:07:25 02:56:59+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24576 |
| InitializedDataSize: | 306176 |
| UninitializedDataSize: | 8192 |
| EntryPoint: | 0x310f |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3672 | "C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe" /UAC:1001CA /NCRC | C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe | GoogleCloudSDKInstaller.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3852 | "C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe" | C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3672) GoogleCloudSDKInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
| Operation: | write | Name: | PSModulePath |
Value: %SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\ | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3672 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\google-cloud-sdk.zip | — | |
MD5:— | SHA256:— | |||
| 3672 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\UAC.dll | executable | |
MD5:4814167AA1C7EC892E84907094646FAA | SHA256:32DD7269ABF5A0E5DB888E307D9DF313E87CEF4F1B597965A9D8E00934658822 | |||
| 3672 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\nsisdl.dll | executable | |
MD5:67A436C3D5BF33F894E65F37668E9657 | SHA256:58576947F44DFFF1B71B834F88F157674BE0ADE6C8C9032A3E8F658AAD4CF373 | |||
| 3852 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\System.dll | executable | |
MD5:2AE993A2FFEC0C137EB51C8832691BCB | SHA256:681382F3134DE5C6272A49DD13651C8C201B89C247B471191496E7335702FA59 | |||
| 3672 | GoogleCloudSDKInstaller.exe | C:\Program Files\Google\Cloud SDK\google-cloud-sdk\.install\bundled-python.snapshot.json | binary | |
MD5:8F1568A5FBA9C456A77E8A304868BFAD | SHA256:2E930A9F4079ABEC169EE7D3A2E413357F0CB202F30E38B5139B42B857FE1242 | |||
| 3852 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\modern-wizard.bmp | image | |
MD5:D03AE72AD4996166FB7E8B5E6B24E285 | SHA256:9D24BB8D3E5474208788FE809068FE0F2CA2AF19274F1BF2E36CDC2DFEFCBAF0 | |||
| 3672 | GoogleCloudSDKInstaller.exe | C:\Program Files\Google\Cloud SDK\google-cloud-sdk\.install\bundled-python-windows-x86.snapshot.json | binary | |
MD5:A3FE8324EE310A3B32055908ABE55DAF | SHA256:D7E613F9A12DFAFA71E177019BD6E131D5136F4F090E7850EE8CF2EA6E197D47 | |||
| 3672 | GoogleCloudSDKInstaller.exe | C:\Program Files\Google\Cloud SDK\google-cloud-sdk\.install\bundled-python3-windows-x86.snapshot.json | binary | |
MD5:C8BE8152BBEB2B2C90768E531F320213 | SHA256:AEFA16FC5DC60A61A3A91F5AC121074E89312F7F5D242F9AF90928D303EBBA6B | |||
| 3672 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\nsResize.dll | executable | |
MD5:AA849E7407CF349021812F62C001E097 | SHA256:29B0E5792679756A79D501E3A9B317971B08E876FAC1C2476180D0AE83B77BA5 | |||
| 3672 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\nsDialogs.dll | executable | |
MD5:13B6A88CF284D0F45619E76191E2B995 | SHA256:CB958E21C3935EF7697A2F14D64CAE0F9264C91A92D2DEEB821BA58852DAC911 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3672 | GoogleCloudSDKInstaller.exe | GET | — | 142.250.187.142:80 | http://dl.google.com/dl/cloudsdk/channels/rapid/google-cloud-sdk-windows-bundled-python.zip | unknown | — | — | unknown |
3672 | GoogleCloudSDKInstaller.exe | GET | 206 | 142.250.187.142:80 | http://dl.google.com/dl/cloudsdk/channels/rapid/google-cloud-sdk-windows-bundled-python.zip | unknown | binary | 42.4 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3672 | GoogleCloudSDKInstaller.exe | 142.250.187.142:80 | dl.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
dl.google.com |
| whitelisted |