File name: | GoogleCloudSDKInstaller.exe |
Full analysis: | https://app.any.run/tasks/5b231662-c9cb-4df7-be7a-f3e091ded194 |
Verdict: | Malicious activity |
Analysis date: | October 23, 2023, 20:36:56 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
MD5: | EA36404CA2394E5D93D1D11E34AE3327 |
SHA1: | 5313A0C1B3CEAB74B5FB15BB2DDBEFF7CA2518C4 |
SHA256: | 0055AB2C26082CA69DBF1CA8E92CE03869D9992B7A44DB9FF201F96D1999F8F4 |
SSDEEP: | 3072:t8cFgUdOpDyTdcl4vN0HjHsGu03JXi+7YMa6oTWqE9G21BwIa1:tlTe4vS57zomZ+ |
.exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (14.2) |
.exe | | | Win32 Executable (generic) (9.7) |
.exe | | | Generic Win/DOS Executable (4.3) |
.exe | | | DOS Executable Generic (4.3) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2016:07:25 02:56:59+02:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 24576 |
InitializedDataSize: | 306176 |
UninitializedDataSize: | 8192 |
EntryPoint: | 0x310f |
OSVersion: | 4 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3672 | "C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe" /UAC:1001CA /NCRC | C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe | GoogleCloudSDKInstaller.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
3852 | "C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe" | C:\Users\admin\AppData\Local\Temp\GoogleCloudSDKInstaller.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
|
(PID) Process: | (3672) GoogleCloudSDKInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
Operation: | write | Name: | PSModulePath |
Value: %SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\ |
PID | Process | Filename | Type | |
---|---|---|---|---|
3672 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\google-cloud-sdk.zip | — | |
MD5:— | SHA256:— | |||
3852 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\modern-header.bmp | image | |
MD5:82E29480F61BA33E80529FCBD7628248 | SHA256:9D4F7B57ECE68B1405B424A23AF8E2180539BB747F44F01CE18D41C94FCC3AD1 | |||
3852 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\modern-wizard.bmp | image | |
MD5:D03AE72AD4996166FB7E8B5E6B24E285 | SHA256:9D24BB8D3E5474208788FE809068FE0F2CA2AF19274F1BF2E36CDC2DFEFCBAF0 | |||
3852 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\System.dll | executable | |
MD5:2AE993A2FFEC0C137EB51C8832691BCB | SHA256:681382F3134DE5C6272A49DD13651C8C201B89C247B471191496E7335702FA59 | |||
3672 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\modern-header.bmp | image | |
MD5:82E29480F61BA33E80529FCBD7628248 | SHA256:9D4F7B57ECE68B1405B424A23AF8E2180539BB747F44F01CE18D41C94FCC3AD1 | |||
3672 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\modern-wizard.bmp | image | |
MD5:D03AE72AD4996166FB7E8B5E6B24E285 | SHA256:9D24BB8D3E5474208788FE809068FE0F2CA2AF19274F1BF2E36CDC2DFEFCBAF0 | |||
3672 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiFA8B.tmp\UAC.dll | executable | |
MD5:4814167AA1C7EC892E84907094646FAA | SHA256:32DD7269ABF5A0E5DB888E307D9DF313E87CEF4F1B597965A9D8E00934658822 | |||
3852 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\nsResize.dll | executable | |
MD5:AA849E7407CF349021812F62C001E097 | SHA256:29B0E5792679756A79D501E3A9B317971B08E876FAC1C2476180D0AE83B77BA5 | |||
3852 | GoogleCloudSDKInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsiC63D.tmp\nsDialogs.dll | executable | |
MD5:13B6A88CF284D0F45619E76191E2B995 | SHA256:CB958E21C3935EF7697A2F14D64CAE0F9264C91A92D2DEEB821BA58852DAC911 | |||
3672 | GoogleCloudSDKInstaller.exe | C:\Program Files\Google\Cloud SDK\google-cloud-sdk\.install\bundled-python-windows-x86.manifest | text | |
MD5:A66C19D09E2B640AB87BD3EF70B861D8 | SHA256:843FDFB285F107BDD7E6A15A4147C4FE0EED23E3CC45C89F82FE88CFF038F598 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3672 | GoogleCloudSDKInstaller.exe | GET | — | 142.250.187.142:80 | http://dl.google.com/dl/cloudsdk/channels/rapid/google-cloud-sdk-windows-bundled-python.zip | unknown | — | — | unknown |
3672 | GoogleCloudSDKInstaller.exe | GET | 206 | 142.250.187.142:80 | http://dl.google.com/dl/cloudsdk/channels/rapid/google-cloud-sdk-windows-bundled-python.zip | unknown | binary | 42.4 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3672 | GoogleCloudSDKInstaller.exe | 142.250.187.142:80 | dl.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
dl.google.com |
| whitelisted |