| File name: | goguardian-app-1.4.4.msi |
| Full analysis: | https://app.any.run/tasks/67117cef-aece-4103-9065-96375a8e1ab1 |
| Verdict: | Malicious activity |
| Analysis date: | December 03, 2023, 19:23:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {90E841FC-C0CB-4ABF-85A3-D827D5792B30}, Title: GoGuardian, Author: GoGuardian, Number of Words: 2, Last Saved Time/Date: Tue Nov 17 16:37:21 2020, Last Printed: Tue Nov 17 16:37:21 2020 |
| MD5: | 5CAD95004308F1C2843B31DC68BF3434 |
| SHA1: | 912D446CDA01EA8795A2A4D57B5DD344AA0074ED |
| SHA256: | 28CB8874444C50BD195E1255ED746F39E7A1FB30657212E8B04E321B671491E7 |
| SSDEEP: | 98304:zrXEXy+Sfjr1WRrgUfSOzeb0JUgKcdehtU1NLetI25uIj4TTHxqSbYIv4nHrRoW0:JX/n30F |
| .msi | | | Microsoft Windows Installer (90.2) |
|---|---|---|
| .msp | | | Windows Installer Patch (8.4) |
| .msi | | | Microsoft Installer (100) |
| CreateDate: | 1999:06:21 07:00:00 |
|---|---|
| Software: | Windows Installer |
| Security: | Password protected |
| CodePage: | Windows Latin 1 (Western European) |
| Template: | Intel;1033 |
| Pages: | 200 |
| RevisionNumber: | {90E841FC-C0CB-4ABF-85A3-D827D5792B30} |
| Title: | GoGuardian |
| Subject: | - |
| Author: | GoGuardian |
| Keywords: | - |
| Comments: | - |
| Words: | 2 |
| ModifyDate: | 2020:11:17 16:37:21 |
| LastPrinted: | 2020:11:17 16:37:21 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 272 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\System.Collections.dll | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 296 | "C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\goguardian_desktoplock.exe" | C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\goguardian_desktoplock.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: DesktopLock Exit code: 3762504530 Version: 1.4.4.2 Modules
| |||||||||||||||
| 732 | "C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\goguardian_desktoplock.exe" | C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\goguardian_desktoplock.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: DesktopLock Exit code: 0 Version: 1.4.4.2 Modules
| |||||||||||||||
| 952 | "C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\Chromium.Goguardian.GGWindowsHost.exe" | C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\Chromium.Goguardian.GGWindowsHost.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Chromium.Goguardian.GGWindowsHost Exit code: 3221225786 Version: 1.4.4.2 Modules
| |||||||||||||||
| 2136 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2644 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\goguardian-app-1.4.4.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2652 | "C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\Chromium.Goguardian.GGWindowsHost.exe" | C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\Chromium.Goguardian.GGWindowsHost.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Chromium.Goguardian.GGWindowsHost Exit code: 3221225786 Version: 1.4.4.2 Modules
| |||||||||||||||
| 2780 | C:\Windows\system32\MsiExec.exe -Embedding 81E9DFDC42A51B200386523146158C29 C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2972 | "C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\goguardian_desktoplock.exe" | C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\goguardian_desktoplock.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: DesktopLock Exit code: 3762504530 Version: 1.4.4.2 Modules
| |||||||||||||||
| 2988 | C:\Windows\system32\MsiExec.exe -Embedding CCD0B1D9F5B6324B1251E9F62793D753 | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2644) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3872) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 72 | |||
| (PID) Process: | (3872) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000008C62D6BA16B0D901C80700002C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Leave) |
Value: 400000000000000064514ABC16B0D901C80700002C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Enter) |
Value: 400000000000000064514ABC16B0D901C80700002C0A0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Leave) |
Value: 400000000000000034645DBC16B0D901C80700002C0A0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Leave) |
Value: 4000000000000000781D5ABD16B0D901C80700002C0A0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Leave) |
Value: 4000000000000000781D5ABD16B0D901C80700002C0A0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3872 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3872 | msiexec.exe | C:\Windows\Installer\MSI9426.tmp | executable | |
MD5:373E46A1E858B6A10432D589DE09732F | SHA256:0357B1185454D1A7D0C72DE5AF8E82A2185C0F1E52FB2D21B53E149D0A688041 | |||
| 3872 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:952BAACC6B9AFCA7D36AA5154CA70C35 | SHA256:67ACF5811D82645561FAA234369555D6AD08E7BB74D948B584F78D1793099260 | |||
| 3872 | msiexec.exe | C:\Windows\Installer\MSI9484.tmp | executable | |
MD5:373E46A1E858B6A10432D589DE09732F | SHA256:0357B1185454D1A7D0C72DE5AF8E82A2185C0F1E52FB2D21B53E149D0A688041 | |||
| 3872 | msiexec.exe | C:\Windows\Installer\MSI961C.tmp | binary | |
MD5:51CAE8A75F3812C48D06991B58055B6A | SHA256:0D7C96876CB0F54E940C6F81E053EE53E7FC2F8695D59D2A6176CB2350B72997 | |||
| 3872 | msiexec.exe | C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\System.Security.Principal.dll | executable | |
MD5:13D414FD8F0A2C9CD7DEEE51AA56E052 | SHA256:16A59E600C2A6EBF78D35077D79CEE86DF9AB76DE7B6780E631C531F24269A7D | |||
| 3872 | msiexec.exe | C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\System.Dynamic.Runtime.dll | executable | |
MD5:B87EFB9B3D1EC1081479F457B264E4A1 | SHA256:30DD071D011698C72F464D926E41C259CE69026B5FC6389E1B5C46FA38283B29 | |||
| 3872 | msiexec.exe | C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\Chromium.Goguardian.Utilities.dll | executable | |
MD5:EB8C6A1FDA4F4FBF78029AA8DB4A9CC1 | SHA256:81F9ACAB7B8E3DBE2A28DEA42250DA83017DAC73E9B30B608ED5A01B950E8D03 | |||
| 3872 | msiexec.exe | C:\Windows\Installer\2091e4.msi | executable | |
MD5:5CAD95004308F1C2843B31DC68BF3434 | SHA256:28CB8874444C50BD195E1255ED746F39E7A1FB30657212E8B04E321B671491E7 | |||
| 3872 | msiexec.exe | C:\Program Files\Win-GG-Chromeleon\GGWindowsHostSetup\System.Threading.Tasks.dll | executable | |
MD5:AD5752D60269C880C3E8C6E9A1A8AEAC | SHA256:F11CC147BEDFE5A1EE003A3305D3A9ACC0354C7F9C3ACB06D53F49A46E082B04 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Process | Message |
|---|---|
goguardian_desktoplock.exe | VirtualDesktop initialization error:
|
goguardian_desktoplock.exe | System.AggregateException: One or more errors occurred. ---> System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()
--- End of inner exception stack trace ---
at System.Threading.Tasks.Task.ThrowIfExceptional(Boolean includeTaskCanceledExceptions)
at System.Threading.Tasks.Task.Wait(Int32 millisecondsTimeout, CancellationToken cancellationToken)
at System.Threading.Tasks.Task.Wait()
at WindowsDesktop.VirtualDesktop.<GetIsSupported>g__Core|21_0()
---> (Inner Exception #0) System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()<---
|
goguardian_desktoplock.exe | System.AggregateException: One or more errors occurred. ---> System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()
--- End of inner exception stack trace ---
at System.Threading.Tasks.Task.ThrowIfExceptional(Boolean includeTaskCanceledExceptions)
at System.Threading.Tasks.Task.Wait(Int32 millisecondsTimeout, CancellationToken cancellationToken)
at System.Threading.Tasks.Task.Wait()
at WindowsDesktop.VirtualDesktop.<GetIsSupported>g__Core|21_0()
---> (Inner Exception #0) System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()<---
|
goguardian_desktoplock.exe | VirtualDesktop initialization error:
|
goguardian_desktoplock.exe | System.AggregateException: One or more errors occurred. ---> System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()
--- End of inner exception stack trace ---
at System.Threading.Tasks.Task.ThrowIfExceptional(Boolean includeTaskCanceledExceptions)
at System.Threading.Tasks.Task.Wait(Int32 millisecondsTimeout, CancellationToken cancellationToken)
at System.Threading.Tasks.Task.Wait()
at WindowsDesktop.VirtualDesktop.<GetIsSupported>g__Core|21_0()
---> (Inner Exception #0) System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()<---
|
goguardian_desktoplock.exe | VirtualDesktop initialization error:
|
goguardian_desktoplock.exe | System.AggregateException: One or more errors occurred. ---> System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()
--- End of inner exception stack trace ---
at System.Threading.Tasks.Task.ThrowIfExceptional(Boolean includeTaskCanceledExceptions)
at System.Threading.Tasks.Task.Wait(Int32 millisecondsTimeout, CancellationToken cancellationToken)
at System.Threading.Tasks.Task.Wait()
at WindowsDesktop.VirtualDesktop.<GetIsSupported>g__Core|21_0()
---> (Inner Exception #0) System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()<---
|
goguardian_desktoplock.exe | VirtualDesktop initialization error:
|
goguardian_desktoplock.exe | System.AggregateException: One or more errors occurred. ---> System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()
--- End of inner exception stack trace ---
at System.Threading.Tasks.Task.ThrowIfExceptional(Boolean includeTaskCanceledExceptions)
at System.Threading.Tasks.Task.Wait(Int32 millisecondsTimeout, CancellationToken cancellationToken)
at System.Threading.Tasks.Task.Wait()
at WindowsDesktop.VirtualDesktop.<GetIsSupported>g__Core|21_0()
---> (Inner Exception #0) System.Collections.Generic.KeyNotFoundException: The given key was not present in the dictionary.
at System.Collections.Generic.Dictionary`2.get_Item(TKey key)
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.CreateAssembly()
at WindowsDesktop.Interop.ComInterfaceAssemblyProvider.GetAssembly()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>g__Core|17_2()
at WindowsDesktop.VirtualDesktopProvider.<Initialize>b__17_0()
at System.Threading.Tasks.Task.InnerInvoke()
at System.Threading.Tasks.Task.Execute()<---
|
goguardian_desktoplock.exe | VirtualDesktop initialization error:
|