File name: | Google Gemini AI official version v1.msi |
Full analysis: | https://app.any.run/tasks/515f5fa4-fdf8-4a11-b8b7-1753efcfdb8a |
Verdict: | Malicious activity |
Analysis date: | December 13, 2023, 12:53:27 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
Indicators: | |
MIME: | application/x-msi |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {63A3D0ED-51F2-428B-9409-676AC8A9CA77}, Title: Install, Author: Install, Comments: Bringing the benefits of AI to everyone, Number of Words: 2, Last Saved Time/Date: Wed Dec 13 01:08:12 2023, Last Printed: Wed Dec 13 01:08:12 2023 |
MD5: | 8E6F7A85D032D7F68C0D2111981F1BAF |
SHA1: | EAF1ED37133849BD6DF26C06E6AC5584A32EAB64 |
SHA256: | 83E571AE288CE7B75AFFA0031D7388C86BE268F93442215A0F9DE8F84FABD278 |
SSDEEP: | 49152:IvipiRM4wMOa0mZ+UsZoJ5RxgKVQIvHe3wqnDA1/69RTuj1OA0mnybauVuu99GQP:riRM4wmUUs+J5RxV6901iXm8A0mnIjuC |
.msi | | | Microsoft Windows Installer (90.2) |
---|---|---|
.msp | | | Windows Installer Patch (8.4) |
.msi | | | Microsoft Installer (100) |
CreateDate: | 1999:06:21 07:00:00 |
---|---|
Software: | Windows Installer |
Security: | Password protected |
CodePage: | Windows Latin 1 (Western European) |
Template: | Intel;1033 |
Pages: | 200 |
RevisionNumber: | {63A3D0ED-51F2-428B-9409-676AC8A9CA77} |
Title: | Install |
Subject: | - |
Author: | Install |
Keywords: | - |
Comments: | Bringing the benefits of AI to everyone |
Words: | 2 |
ModifyDate: | 2023:12:13 01:08:12 |
LastPrinted: | 2023:12:13 01:08:12 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1392 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1420 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1328 --field-trial-handle=1396,i,1678145793698562453,518584701932014582,131072 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1452 | "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2088 --field-trial-handle=1072,i,3131559018797910565,2823570634067214174,131072 /prefetch:1 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
1560 | "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --load-extension="C:\Program Files (x86)\Google\Install\nmmhkkegccagdldgiimedpic" --new-window https://deepmind.google/technologies/gemini/#introduction | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | powershell.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
1612 | "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1112 --field-trial-handle=1072,i,3131559018797910565,2823570634067214174,131072 /prefetch:2 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
1680 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --load-extension="C:\Program Files (x86)\Google\Install\nmmhkkegccagdldgiimedpic" --new-window https://deepmind.google/technologies/gemini/#introduction | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1716 | powershell -ExecutionPolicy Bypass -File "C:\Program Files (x86)\Google\Install\nmmhkkegccagdldgiimedpic/ru.ps1" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
1772 | C:\Windows\syswow64\MsiExec.exe -Embedding 49A38E315EFC22D4C1E9518CBBEC195C C | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1828 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2060 | "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xcc,0xd0,0xd4,0xa0,0xd8,0x7fef4fc6b58,0x7fef4fc6b68,0x7fef4fc6b78 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
|
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4800000000000000C42CD6BE4EB0D9014C0F0000380F0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppCreate (Enter) |
Value: 4800000000000000C42CD6BE4EB0D9014C0F0000380F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
Operation: | write | Name: | LastIndex |
Value: 66 | |||
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 480000000000000080A00ABF4EB0D9014C0F0000380F0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppGatherWriterMetadata (Leave) |
Value: 4800000000000000A4CA79C04EB0D9014C0F0000380F0000D30700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppAddInterestingComponents (Enter) |
Value: 4800000000000000A4CA79C04EB0D9014C0F0000380F0000D40700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppAddInterestingComponents (Leave) |
Value: 4800000000000000CE3F8FC04EB0D9014C0F0000380F0000D40700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppCreate (Leave) |
Value: 48000000000000000CAEE5C24EB0D9014C0F0000380F0000D00700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
Operation: | write | Name: | SrCreateRp (Leave) |
Value: 48000000000000006610E8C24EB0D9014C0F0000380F0000D50700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore |
Operation: | write | Name: | FirstRun |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1828 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
1828 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{5b5e79d6-9a9e-4bd0-a432-d500b542a9d4}_OnDiskSnapshotProp | binary | |
MD5:EBAF8F3A47CE49638A4C09F1ADD10FA4 | SHA256:B02C732B0D96932B6ED237202E505D775AD45730D71231B79AC3B08077836626 | |||
1828 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:EBAF8F3A47CE49638A4C09F1ADD10FA4 | SHA256:B02C732B0D96932B6ED237202E505D775AD45730D71231B79AC3B08077836626 | |||
1828 | msiexec.exe | C:\Windows\Installer\MSIF4BB.tmp | executable | |
MD5:B77A2A2768B9CC78A71BBFFB9812B978 | SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0 | |||
1828 | msiexec.exe | C:\Windows\Installer\MSIF529.tmp | executable | |
MD5:B77A2A2768B9CC78A71BBFFB9812B978 | SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0 | |||
2932 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIBD11.tmp | executable | |
MD5:B77A2A2768B9CC78A71BBFFB9812B978 | SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0 | |||
1772 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\CFGBD7E.tmp | xml | |
MD5:68675E0D405C8C76102802FA624EB895 | SHA256:B839CDD1C3F55651CD4D0E54A679BCE5AC60ED7618A7B74BFC8EF8CA311E53ED | |||
1828 | msiexec.exe | C:\Windows\Installer\22f392.msi | executable | |
MD5:8E6F7A85D032D7F68C0D2111981F1BAF | SHA256:83E571AE288CE7B75AFFA0031D7388C86BE268F93442215A0F9DE8F84FABD278 | |||
1828 | msiexec.exe | C:\Program Files (x86)\Google\Install\System.Deployment.dll | executable | |
MD5:A3866C0523804E20005AB9CCDC1DC8B8 | SHA256:D1F155CBC36C0032382A39DEDAAB9D3CEB681ECE6DCFA988E34A3116B7CC5549 | |||
1828 | msiexec.exe | C:\Windows\Installer\MSIF5B7.tmp | binary | |
MD5:9116160A8BFEE7570A775010D65C85B3 | SHA256:EA302EAD6DA6C52D78DD36A6ECA556296DF42D05325969ADA531E9F0C10A1423 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1560 | chrome.exe | 239.255.255.250:1900 | — | — | — | unknown |
2300 | chrome.exe | 216.58.206.42:443 | www.googleapis.com | GOOGLE | US | unknown |
2300 | chrome.exe | 108.177.15.84:443 | accounts.google.com | GOOGLE | US | unknown |
2300 | chrome.exe | 142.250.186.35:443 | clientservices.googleapis.com | GOOGLE | US | unknown |
2300 | chrome.exe | 216.239.38.21:443 | deepmind.google | GOOGLE | US | unknown |
1680 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
www.googleapis.com |
| unknown |
accounts.google.com |
| unknown |
clientservices.googleapis.com |
| unknown |
deepmind.google |
| unknown |
fonts.googleapis.com |
| unknown |
www.gstatic.com |
| unknown |
edge.microsoft.com |
| unknown |
config.edge.skype.com |
| unknown |
nav-edge.smartscreen.microsoft.com |
| unknown |
data-edge.smartscreen.microsoft.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net) |