File name:

GoogleCrashHandler.exe

Full analysis: https://app.any.run/tasks/28b1db1c-711c-4b46-9fac-472d9869a5e8
Verdict: Malicious activity
Threats:

Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.

Analysis date: December 10, 2023, 11:23:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
miner
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C39CFF08202CC032A0BF46F63E57AEB8

SHA1:

40B1CE37E962EBD8847771DBE37725EDAE981B7E

SHA256:

4DE6E6C9C7BC0BE888EDD0B0CCA866CBEE745D6DF2C0F34D762055CEF879A0CC

SSDEEP:

98304:WtiJNVYv1LeKIC0swEZXzMqYwplC31NecfyLg1v6ivGlBUVcdb3pPGN5aCfMs/FG:yTvx6B2KDeP/RYOLa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • GoogleCrashHandler.exe (PID: 2832)
    • MINER has been detected (SURICATA)

      • dIlhost.exe (PID: 924)
    • Connects to the CnC server

      • dIlhost.exe (PID: 924)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • GoogleCrashHandler.exe (PID: 2832)
    • Starts CMD.EXE for commands execution

      • GoogleCrashHandler.exe (PID: 2832)
    • Executing commands from a ".bat" file

      • GoogleCrashHandler.exe (PID: 2832)
    • Starts application with an unusual extension

      • cmd.exe (PID: 1828)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 1828)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 1828)
    • Get information on the list of running processes

      • cmd.exe (PID: 1828)
    • Connects to unusual port

      • dIlhost.exe (PID: 924)
  • INFO

    • Checks supported languages

      • GoogleCrashHandler.exe (PID: 2832)
      • chcp.com (PID: 2512)
      • dIlhost.exe (PID: 924)
    • Create files in a temporary directory

      • GoogleCrashHandler.exe (PID: 2832)
      • dIlhost.exe (PID: 924)
    • Reads the computer name

      • GoogleCrashHandler.exe (PID: 2832)
      • dIlhost.exe (PID: 924)
    • The executable file from the user directory is run by the CMD process

      • dIlhost.exe (PID: 924)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (38.3)
.exe | Win32 Executable (generic) (26.2)
.exe | Win16/32 Executable Delphi generic (12)
.exe | Generic Win/DOS Executable (11.6)
.exe | DOS Executable Generic (11.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:11:16 23:57:03+01:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 35840
InitializedDataSize: 15872
UninitializedDataSize: -
EntryPoint: 0x3948f8
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.3.36.351
ProductVersionNumber: 1.3.36.351
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Crash Handler
FileVersion: 1.3.36.351
InternalName: Google Update
LegalCopyright: Copyright 2018 Google LLC
OriginalFileName: GoogleUpdate.exe
ProductName: Google Update
ProductVersion: 1.3.36.351
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start googlecrashhandler.exe no specs cmd.exe no specs chcp.com no specs tasklist.exe no specs findstr.exe no specs timeout.exe no specs findstr.exe no specs tasklist.exe no specs #MINER dilhost.exe

Process information

PID
CMD
Path
Indicators
Parent process
924"C:\Users\admin\AppData\Local\Temp\dIlhost.exe"C:\Users\admin\AppData\Local\Temp\dIlhost.exe
cmd.exe
User:
admin
Company:
Topaz OFD
Integrity Level:
MEDIUM
Description:
Topaz OFD - Protection Module
Exit code:
0
Version:
2.11.0.201
Modules
Images
c:\users\admin\appdata\local\temp\dilhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
972TASKLIST C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1772FINDSTR /I "dIlhost.exe"C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1776FINDSTR /I "dIlhost.exe"C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1828cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\2832LRL3.bat" "C:\Users\admin\AppData\Local\Temp\GoogleCrashHandler.exe" "C:\Windows\SysWOW64\cmd.exeGoogleCrashHandler.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2512chcp 1252C:\Windows\SysWOW64\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2800TIMEOUT /T 10C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2832"C:\Users\admin\AppData\Local\Temp\GoogleCrashHandler.exe" C:\Users\admin\AppData\Local\Temp\GoogleCrashHandler.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Crash Handler
Exit code:
0
Version:
1.3.36.351
Modules
Images
c:\users\admin\appdata\local\temp\googlecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2852TASKLIST C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
446
Read events
446
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2832GoogleCrashHandler.exeC:\Users\admin\AppData\Local\Temp\2832LRL3.battext
MD5:A7D9990A5FC2E39186BEA134B458684C
SHA256:6A7F7E123295347C52E532855E2BCAAA1CE488BEC82D55A79B743135444977D8
2832GoogleCrashHandler.exeC:\users\admin\appdata\local\temp\dIlhost.exeexecutable
MD5:FD1E0D2F028D7BCC2F090A8F40715703
SHA256:34D97DF13F6FFF6C38081CBF9FC250DDD75C258B8E0744630287E0947BA86431
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
1956
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:138
unknown
324
svchost.exe
224.0.0.252:5355
unknown
924
dIlhost.exe
199.247.0.216:10128
gulf.moneroocean.stream
AS-CHOOPA
DE
unknown

DNS requests

Domain
IP
Reputation
gulf.moneroocean.stream
  • 199.247.0.216
  • 51.75.64.249
unknown

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY Cryptocurrency Miner Checkin
No debug info