File name:

GoogleCloudSDKInstaller.exe

Full analysis: https://app.any.run/tasks/5b231662-c9cb-4df7-be7a-f3e091ded194
Verdict: Malicious activity
Analysis date: October 23, 2023, 20:36:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

EA36404CA2394E5D93D1D11E34AE3327

SHA1:

5313A0C1B3CEAB74B5FB15BB2DDBEFF7CA2518C4

SHA256:

0055AB2C26082CA69DBF1CA8E92CE03869D9992B7A44DB9FF201F96D1999F8F4

SSDEEP:

3072:t8cFgUdOpDyTdcl4vN0HjHsGu03JXi+7YMa6oTWqE9G21BwIa1:tlTe4vS57zomZ+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • GoogleCloudSDKInstaller.exe (PID: 3852)
      • GoogleCloudSDKInstaller.exe (PID: 3672)
    • Loads dropped or rewritten executable

      • GoogleCloudSDKInstaller.exe (PID: 3852)
      • GoogleCloudSDKInstaller.exe (PID: 3672)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • GoogleCloudSDKInstaller.exe (PID: 3852)
      • GoogleCloudSDKInstaller.exe (PID: 3672)
    • The process creates files with name similar to system file names

      • GoogleCloudSDKInstaller.exe (PID: 3852)
      • GoogleCloudSDKInstaller.exe (PID: 3672)
    • Application launched itself

      • GoogleCloudSDKInstaller.exe (PID: 3852)
    • Reads the Internet Settings

      • GoogleCloudSDKInstaller.exe (PID: 3672)
  • INFO

    • Checks supported languages

      • GoogleCloudSDKInstaller.exe (PID: 3852)
      • GoogleCloudSDKInstaller.exe (PID: 3672)
    • Reads the computer name

      • GoogleCloudSDKInstaller.exe (PID: 3852)
      • GoogleCloudSDKInstaller.exe (PID: 3672)
    • Create files in a temporary directory

      • GoogleCloudSDKInstaller.exe (PID: 3852)
      • GoogleCloudSDKInstaller.exe (PID: 3672)
    • Creates files in the program directory

      • GoogleCloudSDKInstaller.exe (PID: 3672)
    • Checks proxy server information

      • GoogleCloudSDKInstaller.exe (PID: 3672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:07:25 02:56:59+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 306176
UninitializedDataSize: 8192
EntryPoint: 0x310f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start googlecloudsdkinstaller.exe no specs googlecloudsdkinstaller.exe

Process information

PID
CMD
Path
Indicators
Parent process
3672"C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe" /UAC:1001CA /NCRC C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe
GoogleCloudSDKInstaller.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\googlecloudsdkinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
3852"C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe" C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
1 492
Read events
1 491
Write events
1
Delete events
0

Modification events

(PID) Process:(3672) GoogleCloudSDKInstaller.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment
Operation:writeName:PSModulePath
Value:
%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
Executable files
11
Suspicious files
99
Text files
3 507
Unknown types
0

Dropped files

PID
Process
Filename
Type
3672GoogleCloudSDKInstaller.exeC:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\google-cloud-sdk.zip
MD5:
SHA256:
3852GoogleCloudSDKInstaller.exeC:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\modern-header.bmpimage
MD5:82E29480F61BA33E80529FCBD7628248
SHA256:9D4F7B57ECE68B1405B424A23AF8E2180539BB747F44F01CE18D41C94FCC3AD1
3852GoogleCloudSDKInstaller.exeC:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\modern-wizard.bmpimage
MD5:D03AE72AD4996166FB7E8B5E6B24E285
SHA256:9D24BB8D3E5474208788FE809068FE0F2CA2AF19274F1BF2E36CDC2DFEFCBAF0
3852GoogleCloudSDKInstaller.exeC:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\System.dllexecutable
MD5:2AE993A2FFEC0C137EB51C8832691BCB
SHA256:681382F3134DE5C6272A49DD13651C8C201B89C247B471191496E7335702FA59
3672GoogleCloudSDKInstaller.exeC:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\modern-header.bmpimage
MD5:82E29480F61BA33E80529FCBD7628248
SHA256:9D4F7B57ECE68B1405B424A23AF8E2180539BB747F44F01CE18D41C94FCC3AD1
3672GoogleCloudSDKInstaller.exeC:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\modern-wizard.bmpimage
MD5:D03AE72AD4996166FB7E8B5E6B24E285
SHA256:9D24BB8D3E5474208788FE809068FE0F2CA2AF19274F1BF2E36CDC2DFEFCBAF0
3672GoogleCloudSDKInstaller.exeC:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\UAC.dllexecutable
MD5:4814167AA1C7EC892E84907094646FAA
SHA256:32DD7269ABF5A0E5DB888E307D9DF313E87CEF4F1B597965A9D8E00934658822
3852GoogleCloudSDKInstaller.exeC:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\nsResize.dllexecutable
MD5:AA849E7407CF349021812F62C001E097
SHA256:29B0E5792679756A79D501E3A9B317971B08E876FAC1C2476180D0AE83B77BA5
3852GoogleCloudSDKInstaller.exeC:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\nsDialogs.dllexecutable
MD5:13B6A88CF284D0F45619E76191E2B995
SHA256:CB958E21C3935EF7697A2F14D64CAE0F9264C91A92D2DEEB821BA58852DAC911
3672GoogleCloudSDKInstaller.exeC:\Program Files\Google\Cloud SDK\google-cloud-sdk\.install\bundled-python-windows-x86.manifesttext
MD5:A66C19D09E2B640AB87BD3EF70B861D8
SHA256:843FDFB285F107BDD7E6A15A4147C4FE0EED23E3CC45C89F82FE88CFF038F598
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
4
DNS requests
1
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3672
GoogleCloudSDKInstaller.exe
GET
142.250.187.142:80
http://dl.google.com/dl/cloudsdk/channels/rapid/google-cloud-sdk-windows-bundled-python.zip
unknown
unknown
3672
GoogleCloudSDKInstaller.exe
GET
206
142.250.187.142:80
http://dl.google.com/dl/cloudsdk/channels/rapid/google-cloud-sdk-windows-bundled-python.zip
unknown
binary
42.4 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3672
GoogleCloudSDKInstaller.exe
142.250.187.142:80
dl.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
dl.google.com
  • 142.250.187.142
whitelisted

Threats

Found threats are available for the paid subscriptions
4 ETPRO signatures available at the full report
No debug info