URL:

https://dl.google.com/earth/client/GE7/release_7_1_8/googleearth-win-pro-7.1.8.3036.exe

Full analysis: https://app.any.run/tasks/2ce42b60-d838-4996-afe6-b84711604abd
Verdict: Malicious activity
Analysis date: November 08, 2023, 01:01:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
SHA1:

81FC90FC22000CE24428F3A3498A8241B0A4F14D

SHA256:

1C634A8CA9B521DEBD8A870EB5F83BBCD04EA8632876A1D862796AEEE2AF22B2

SSDEEP:

3:N8Rt3um1ALjAylrv+RSvLUMCLN:2/+mKf1rmRSv7I

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 3676)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 3676)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3676)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 3676)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 3676)
    • Reads the Internet Settings

      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
    • Reads settings of System Certificates

      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 3400)
      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
    • Application launched itself

      • iexplore.exe (PID: 3152)
      • msiexec.exe (PID: 3676)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3400)
      • googleearth-win-pro-7.1.8.3036.exe (PID: 4060)
      • msiexec.exe (PID: 3676)
      • msiexec.exe (PID: 3588)
      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3400)
      • googleearth-win-pro-7.1.8.3036.exe (PID: 4060)
      • msiexec.exe (PID: 3676)
      • msiexec.exe (PID: 3588)
      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
    • Create files in a temporary directory

      • googleearth-win-pro-7.1.8.3036.exe (PID: 4060)
      • msiexec.exe (PID: 3676)
      • googleearth.exe (PID: 2136)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 3152)
      • iexplore.exe (PID: 3156)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3152)
    • Reads the machine GUID from the registry

      • googleearth-win-pro-7.1.8.3036.exe (PID: 4060)
      • wmpnscfg.exe (PID: 3400)
      • msiexec.exe (PID: 3676)
      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
      • msiexec.exe (PID: 3588)
    • Reads Environment values

      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
    • Process checks computer location settings

      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
    • Checks proxy server information

      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
    • Creates files or folders in the user directory

      • googleearth.exe (PID: 2368)
      • googleearth.exe (PID: 2136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs googleearth-win-pro-7.1.8.3036.exe no specs googleearth-win-pro-7.1.8.3036.exe msiexec.exe no specs msiexec.exe no specs googleearth.exe googleearth.exe

Process information

PID
CMD
Path
Indicators
Parent process
2136"C:\Program Files\Google\Google Earth Pro\client\googleearth.exe" C:\Program Files\Google\Google Earth Pro\client\googleearth.exe
explorer.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Google Earth
Exit code:
0
Version:
7.1.8.3036
Modules
Images
c:\program files\google\google earth pro\client\googleearth.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\google earth pro\client\qtcore4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2368"C:\Program Files\Google\Google Earth Pro\client\googleearth.exe" C:\Program Files\Google\Google Earth Pro\client\googleearth.exe
explorer.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Google Earth
Exit code:
4294967295
Version:
7.1.8.3036
Modules
Images
c:\program files\google\google earth pro\client\googleearth.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\google earth pro\client\qtcore4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3152"C:\Program Files\Internet Explorer\iexplore.exe" "https://dl.google.com/earth/client/GE7/release_7_1_8/googleearth-win-pro-7.1.8.3036.exe"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3156"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3152 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3400"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3588C:\Windows\system32\MsiExec.exe -Embedding D029F5335F71525176BBC4A761BA8CE9C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3676C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3756"C:\Users\admin\Downloads\googleearth-win-pro-7.1.8.3036.exe" C:\Users\admin\Downloads\googleearth-win-pro-7.1.8.3036.exeiexplore.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\googleearth-win-pro-7.1.8.3036.exe
c:\windows\system32\ntdll.dll
4060"C:\Users\admin\Downloads\googleearth-win-pro-7.1.8.3036.exe" C:\Users\admin\Downloads\googleearth-win-pro-7.1.8.3036.exe
iexplore.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\googleearth-win-pro-7.1.8.3036.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
29 732
Read events
29 595
Write events
120
Delete events
17

Modification events

(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
43
Suspicious files
272
Text files
120
Unknown types
0

Dropped files

PID
Process
Filename
Type
4060googleearth-win-pro-7.1.8.3036.exeC:\Users\admin\AppData\Local\Temp\GoogleEarth-Pro.msi
MD5:
SHA256:
3676msiexec.exeC:\Windows\Installer\172422.msi
MD5:
SHA256:
3156iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:421F616F58AC0B9FECF7F33AF2921D0B
SHA256:D126DDC991B163A5CC0C69BB6BFD5B1FC49F14754FECCA8137FA21B646658F02
3156iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:74BF9E0776239A87440163A0119050A4
SHA256:6AAF0FEE94EC555BBFA09A8637E42FBFE6635095A697358B478402374EFDB7B5
3152iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{6750817F-7DD2-11EE-A826-12A9866C77DE}.datbinary
MD5:D88A8F4420EC789D5A302D3656909C85
SHA256:61C011A4C19F5C62903D996C80C6FA55FE8A2F788D6F3486E1D6D2A92F5C7D16
3156iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAbinary
MD5:AC89A852C2AAA3D389B2D2DD312AD367
SHA256:0B720E19270C672F9B6E0EC40B468AC49376807DE08A814573FE038779534F45
3156iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F2DDCD2B5F37625B82E81F4976CEE400_11314361DFE3E655E02EC2E7F9346EC1binary
MD5:98E3712EAF9A6804F520F60753B8AA8C
SHA256:B91BE14FA8CC74ADBD45DAAD0DEA1A57ED3AFC69180554345056B22FB3F3F99C
3156iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F2DDCD2B5F37625B82E81F4976CEE400_11314361DFE3E655E02EC2E7F9346EC1binary
MD5:A47C30311376800166A3EFB5F56F91B1
SHA256:E442BB172FCB7D7833F11FD73B241CFF63015B7EACE0ED8A4A429679475B5CBF
3156iexplore.exeC:\Users\admin\Downloads\googleearth-win-pro-7.1.8.3036.exe.th27sxy.partialexecutable
MD5:A8AE99ADCAB84F84DBCB5F1EA68F48D1
SHA256:247CC2B9E4454EA05B24697418E53DFBB90B50594C09D7AB32CDB8CBB764E12D
3152iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\VersionManager\verE60F.tmpxml
MD5:CBD0581678FA40F0EDCBC7C59E0CAD10
SHA256:159BD4343F344A08F6AF3B716B6FA679859C1BD1D7030D26FF5EF0255B86E1D9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
56
DNS requests
18
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2136
googleearth.exe
GET
301
142.250.185.225:80
http://earth.googleusercontent.com/earth/pro/viewport?l=r
unknown
unknown
2136
googleearth.exe
GET
301
142.250.185.225:80
http://earth.googleusercontent.com/earth/pro/viewport?l=lb
unknown
unknown
2136
googleearth.exe
GET
301
142.250.185.225:80
http://earth.googleusercontent.com/earth/pro/viewport?l=p
unknown
unknown
2136
googleearth.exe
GET
301
142.250.185.225:80
http://earth.googleusercontent.com/earth/pro/viewport?l=b
unknown
unknown
2136
googleearth.exe
GET
301
142.250.185.225:80
http://earth.googleusercontent.com/earth/pro/viewport?l=tra
unknown
unknown
3156
iexplore.exe
GET
200
8.241.9.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?95cc7fa7a6c3a3dc
unknown
compressed
4.66 Kb
unknown
3156
iexplore.exe
GET
200
8.241.9.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5cdd097ce74b12a6
unknown
compressed
4.66 Kb
unknown
3156
iexplore.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3156
iexplore.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2136
googleearth.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCWHS2CBFHxhQl5wQbli4WB
unknown
binary
472 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3156
iexplore.exe
8.241.9.126:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3156
iexplore.exe
172.217.18.3:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3152
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
3152
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2368
googleearth.exe
172.217.18.14:443
kh.google.com
GOOGLE
US
whitelisted
2368
googleearth.exe
172.217.18.3:80
ocsp.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 8.241.9.126
  • 8.248.139.254
  • 67.26.137.254
  • 8.253.95.120
  • 8.253.95.249
whitelisted
ocsp.pki.goog
  • 172.217.18.3
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
kh.google.com
  • 172.217.18.14
whitelisted
support.google.com
  • 172.217.16.142
whitelisted
www.google-analytics.com
  • 142.250.186.174
whitelisted
www.googletagmanager.com
  • 172.217.23.104
whitelisted
www.gstatic.com
  • 172.217.18.3
whitelisted

Threats

Found threats are available for the paid subscriptions
5 ETPRO signatures available at the full report
Process
Message
googleearth.exe
Intrinsic Alchemy v3.9 Beta-1123 (Dynamic/Production) Built by <unknown> on Wed Nov 23 00:00:00 2016
googleearth.exe
INFO: Using OpenGL ES 2.0 Context.
googleearth.exe
Intrinsic Alchemy v3.9 Beta-1123 (Dynamic/Production) Built by <unknown> on Wed Nov 23 00:00:00 2016
googleearth.exe
INFO: Using OpenGL Context.
googleearth.exe
undefined:0: ReferenceError: Can't find variable: requestAnimationFrame
googleearth.exe
undefined:0: TypeError: 'undefined' is not a function
googleearth.exe
undefined:0: TypeError: 'undefined' is not a function
googleearth.exe
undefined:0: TypeError: 'undefined' is not a function
googleearth.exe
undefined:0: TypeError: 'undefined' is not an object
googleearth.exe
undefined:0: TypeError: 'undefined' is not a function