| URL: | http://d2gjpou01t97is.cloudfront.net/11tl5w7)ci6pk/Baixaki_google-earth_3923644003.exe |
| Full analysis: | https://app.any.run/tasks/737c94f2-d5b4-4dd4-b6c2-ccfa90182c02 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | April 22, 2019, 10:05:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 012EF6CE159ECCB6EA2B7676A63EDFC3 |
| SHA1: | 14A063E25F836257D267A9A0B683296543484A05 |
| SHA256: | 7F4C323E4BFD9FF50CE6B8DBD0598A2E26F9D3338FBAEBEFC9F81477C6AFA7C8 |
| SSDEEP: | 3:N1KaXkU6/p1+l/0sRJyMGM/EEM6EsBRo4RzaN:CaXK1nwJyMGUHMkR2N |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 684 | C:\Windows\system32\svchost.exe -k RPCSS | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1180 | "C:\Program Files\GUM1BBC.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={65E60E95-0DE9-43FF-9F3F-4F7D2DFF04B5}&iid={353D0CE3-03E2-8C9A-948D-2771C5105893}&lang=undefined&browser=4&usagestats=1&appname=Google%20Earth%20Pro&needsadmin=True&brand=GGGE" | C:\Program Files\GUM1BBC.tmp\GoogleUpdate.exe | Baixaki_google-earth.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.34.7 Modules
| |||||||||||||||
| 1492 | "C:\Users\admin\Downloads\Baixaki_google-earth.exe" | C:\Users\admin\Downloads\Baixaki_google-earth.exe | Baixaki_google-earth_3923644003[1].exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Update Setup Exit code: 0 Version: 1.3.34.7 Modules
| |||||||||||||||
| 1688 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /ondemand | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdateOnDemand.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 1704 | "C:\Program Files\Google\Update\Install\{05FEADB9-33C1-4FFE-A760-00CFA4C220C3}\googleearth-win-pro-7.3.2.5776-x86.exe" REBOOT=ReallySuppress OMAHA=1 OMAHA_AUTO_LAUNCH=1 ALLUSERS=1 REINSTALLMODE=emus | C:\Program Files\Google\Update\Install\{05FEADB9-33C1-4FFE-A760-00CFA4C220C3}\googleearth-win-pro-7.3.2.5776-x86.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1720 | C:\Windows\System32\regsvr32.exe /s "C:\Program Files\Google\Google Earth Pro\client\earthps64.dll" | C:\Windows\System32\regsvr32.exe | googleearth.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft(C) Register Server Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1724 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3368.20.1270167439\1735098727" -childID 3 -isForBrowser -prefsHandle 7476 -prefMapHandle 3512 -prefsLen 5824 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3368 "\\.\pipe\gecko-crash-server-pipe.3368" 7492 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 65.0.2 Modules
| |||||||||||||||
| 1916 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3368.6.757646012\776151320" -childID 1 -isForBrowser -prefsHandle 1540 -prefMapHandle 1644 -prefsLen 1 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3368 "\\.\pipe\gecko-crash-server-pipe.3368" 1600 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 65.0.2 Modules
| |||||||||||||||
| 2040 | "C:\Program Files\Google\Google Earth Pro\client\googleearth.exe" /RegServer | C:\Program Files\Google\Google Earth Pro\client\googleearth.exe | — | msiexec.exe | |||||||||||
User: admin Company: Google Integrity Level: HIGH Description: Google Earth Exit code: 0 Version: 7.3.2.5776 Modules
| |||||||||||||||
| 2120 | "C:\Program Files\Google\Update\1.3.34.7\GoogleCrashHandler.exe" | C:\Program Files\Google\Update\1.3.34.7\GoogleCrashHandler.exe | — | GoogleUpdate.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Crash Handler Exit code: 0 Version: 1.3.34.7 Modules
| |||||||||||||||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {27E0A925-64E6-11E9-A09E-5254004A04AF} |
Value: 0 | |||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Type |
Value: 4 | |||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Count |
Value: 1 | |||
| (PID) Process: | (2304) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Time |
Value: E3070400010016000A0005001E001100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2304 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFECD0A264B0368DBB.TMP | — | |
MD5:— | SHA256:— | |||
| 2304 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 2304 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 2304 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF2F76C9F610616F3C.TMP | — | |
MD5:— | SHA256:— | |||
| 2304 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{27E0A925-64E6-11E9-A09E-5254004A04AF}.dat | — | |
MD5:— | SHA256:— | |||
| 2420 | Baixaki_google-earth_3923644003[1].exe | C:\Users\admin\AppData\Local\Temp\000EAF47.log | — | |
MD5:— | SHA256:— | |||
| 2304 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{27E0A926-64E6-11E9-A09E-5254004A04AF}.dat | binary | |
MD5:— | SHA256:— | |||
| 3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat | dat | |
MD5:— | SHA256:— | |||
| 3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat | dat | |
MD5:— | SHA256:— | |||
| 3960 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\JavaDeployReg.log | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3960 | iexplore.exe | GET | 200 | 143.204.208.17:80 | http://d2gjpou01t97is.cloudfront.net/11tl5w7)ci6pk/Baixaki_google-earth_3923644003.exe | US | executable | 2.05 Mb | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | POST | 200 | 52.214.73.247:80 | http://www4.gellnatotgehele.com/ | IE | — | — | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | GET | 200 | 46.166.187.59:80 | http://img.gellnatotgehele.com/img/Rowabobeso/bg_custom_TB.png | NL | image | 11.7 Kb | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | POST | 200 | 52.214.73.247:80 | http://www4.gellnatotgehele.com/ | IE | — | — | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | POST | 200 | 52.209.116.64:80 | http://gw.gellnatotgehele.com/ | IE | text | 1.96 Kb | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | POST | 200 | 52.214.73.247:80 | http://www4.gellnatotgehele.com/ | IE | — | — | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | GET | 200 | 46.166.187.59:80 | http://img.gellnatotgehele.com/img/Tavasat/15Feb17/v2/EN.png | NL | image | 43.9 Kb | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | POST | 200 | 52.214.73.247:80 | http://www4.gellnatotgehele.com/ | IE | — | — | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | POST | 200 | 52.214.73.247:80 | http://www4.gellnatotgehele.com/ | IE | — | — | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | POST | 200 | 52.214.73.247:80 | http://www4.gellnatotgehele.com/ | IE | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3960 | iexplore.exe | 143.204.208.17:80 | d2gjpou01t97is.cloudfront.net | — | US | suspicious |
2304 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2420 | Baixaki_google-earth_3923644003[1].exe | 52.214.73.247:80 | www4.gellnatotgehele.com | Amazon.com, Inc. | IE | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | 52.209.116.64:80 | gw.gellnatotgehele.com | Amazon.com, Inc. | IE | whitelisted |
2420 | Baixaki_google-earth_3923644003[1].exe | 52.31.245.195:80 | api.gellnatotgehele.com | Amazon.com, Inc. | IE | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | 151.80.204.60:443 | img.ibxk.com.br | OVH SAS | FR | unknown |
2420 | Baixaki_google-earth_3923644003[1].exe | 46.166.187.59:80 | img.gellnatotgehele.com | NForce Entertainment B.V. | NL | malicious |
2420 | Baixaki_google-earth_3923644003[1].exe | 172.217.22.14:443 | dl.google.com | Google Inc. | US | whitelisted |
3368 | firefox.exe | 151.80.204.60:80 | img.ibxk.com.br | OVH SAS | FR | unknown |
3368 | firefox.exe | 52.10.42.204:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
d2gjpou01t97is.cloudfront.net |
| malicious |
www.bing.com |
| whitelisted |
www4.gellnatotgehele.com |
| malicious |
gw.gellnatotgehele.com |
| malicious |
api.gellnatotgehele.com |
| malicious |
img.ibxk.com.br |
| suspicious |
img.gellnatotgehele.com |
| malicious |
dl.google.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
www.baixaki.com.br |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
3960 | iexplore.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3960 | iexplore.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2420 | Baixaki_google-earth_3923644003[1].exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2 |
2420 | Baixaki_google-earth_3923644003[1].exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1 |
2420 | Baixaki_google-earth_3923644003[1].exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M3 |
2420 | Baixaki_google-earth_3923644003[1].exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M4 |
— | — | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
googleearth.exe | INFO: Using OpenGL Context.
|
googleearth.exe | libpng warning: iCCP: known incorrect sRGB profile
|
googleearth.exe | QWindowsContext::windowsProc: No Qt Window found for event 0x83 (WM_NCCALCSIZE), hwnd=0x0x1024a.
|
googleearth.exe | QWindowsContext::windowsProc: No Qt Window found for event 0x5 (WM_SIZE), hwnd=0x0x1024a.
|
googleearth.exe | QWindowsContext::windowsProc: No Qt Window found for event 0x3 (WM_MOVE), hwnd=0x0x1024a.
|