| File name: | GoogleEarthProSetup.exe |
| Full analysis: | https://app.any.run/tasks/21a53c88-de11-4d32-b797-5ae9b1d3a60c |
| Verdict: | Malicious activity |
| Analysis date: | September 11, 2024, 14:09:55 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 772972045415EA5D68A7059E119F2DCA |
| SHA1: | 0BE10CCEA0A4AE91A158DF5CDB7F1C82D27B79C4 |
| SHA256: | 8AF135448A7974E4A9DDE39B407941DD388974B424D59F32B5250F17F340A120 |
| SSDEEP: | 98304:BLEkbQIdDJR5kgCF7BWlL1OStuEKrfs65Q3HWg+4BKZBdXR5R+OwAHDExhfnsZH0:Bf |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:08:26 03:02:15+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 2866176 |
| InitializedDataSize: | 6031360 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x14f370 |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 130.0.6679.0 |
| ProductVersionNumber: | 130.0.6679.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Installer |
| FileVersion: | 130.0.6679.0 |
| InternalName: | Google Installer(x86) |
| LegalCopyright: | Copyright 2024 Google LLC. All rights reserved. |
| OriginalFileName: | UpdaterSetup.exe |
| ProductName: | Google Installer |
| ProductVersion: | 130.0.6679.0 |
| CompanyShortName: | |
| ProductShortName: | GoogleUpdater |
| LastChange: | 76ef045d11ea7b79d11f381d30e93459f1eb5017-refs/branch-heads/6679@{#1} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1168 | "C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe" --system --windows-service --service=update-internal | C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Exit code: 0 Version: 130.0.6679.0 Modules
| |||||||||||||||
| 2268 | "C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe" --system --windows-service --service=update | C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Version: 130.0.6679.0 Modules
| |||||||||||||||
| 2456 | "C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping2268_399348120\googleearth-win-pro-7.3.6.9796-x64.exe" REBOOT=ReallySuppress OMAHA=1 ALLUSERS=1 REINSTALLMODE=emus | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping2268_399348120\googleearth-win-pro-7.3.6.9796-x64.exe | — | updater.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Modules
| |||||||||||||||
| 4252 | "C:\WINDOWS\SystemTemp\Google4688_483904574\bin\updater.exe" --install=appguid={65E60E95-0DE9-43FF-9F3F-4F7D2DFF04B5}&iid={65E60E95-0DE9-43FF-9F3F-4F7D2DFF04B5}&lang=pt&browser=4&usagestats=1&appname=Google%20Earth%20Pro&needsadmin=True&brand=GGGE --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevated | C:\Windows\SystemTemp\Google4688_483904574\bin\updater.exe | GoogleEarthProSetup.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Updater Version: 130.0.6679.0 Modules
| |||||||||||||||
| 4688 | "C:\Users\admin\AppData\Local\Temp\GoogleEarthProSetup.exe" --install=appguid={65E60E95-0DE9-43FF-9F3F-4F7D2DFF04B5}&iid={65E60E95-0DE9-43FF-9F3F-4F7D2DFF04B5}&lang=pt&browser=4&usagestats=1&appname=Google%20Earth%20Pro&needsadmin=True&brand=GGGE --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevated | C:\Users\admin\AppData\Local\Temp\GoogleEarthProSetup.exe | GoogleEarthProSetup.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer Version: 130.0.6679.0 Modules
| |||||||||||||||
| 5072 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5524 | C:\WINDOWS\SystemTemp\Google4688_483904574\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=130.0.6679.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2ac,0x2b0,0x2b4,0x288,0x2b8,0x112a6cc,0x112a6d8,0x112a6e4 | C:\Windows\SystemTemp\Google4688_483904574\bin\updater.exe | — | updater.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Updater Version: 130.0.6679.0 Modules
| |||||||||||||||
| 6176 | "C:\Users\admin\AppData\Local\Temp\GoogleEarthProSetup.exe" | C:\Users\admin\AppData\Local\Temp\GoogleEarthProSetup.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Installer Version: 130.0.6679.0 Modules
| |||||||||||||||
| 6884 | "C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=130.0.6679.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x57a6cc,0x57a6d8,0x57a6e4 | C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Version: 130.0.6679.0 Modules
| |||||||||||||||
| 7104 | "C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=130.0.6679.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a0,0x2a4,0x2a8,0x27c,0x2ac,0x57a6cc,0x57a6d8,0x57a6e4 | C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Exit code: 0 Version: 130.0.6679.0 Modules
| |||||||||||||||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 130.0.6679.0 | |||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 130.0.6679.0 | |||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{53A53FE9-0D1A-5CE1-A982-92ECA1CB48BC} |
| Operation: | write | Name: | AppID |
Value: {53A53FE9-0D1A-5CE1-A982-92ECA1CB48BC} | |||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{53A53FE9-0D1A-5CE1-A982-92ECA1CB48BC} |
| Operation: | write | Name: | LocalService |
Value: GoogleUpdaterInternalService130.0.6679.0 | |||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{53A53FE9-0D1A-5CE1-A982-92ECA1CB48BC} |
| Operation: | write | Name: | ServiceParameters |
Value: --com-service | |||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{DC738913-8AA7-5CF3-912D-45FB81D79BCB}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DC738913-8AA7-5CF3-912D-45FB81D79BCB}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (4252) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{0125FBD6-CB11-5A7E-828A-0845F90C7D4E}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4688 | GoogleEarthProSetup.exe | C:\Windows\SystemTemp\Google4688_961277760\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 4252 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\Crashpad\settings.dat | binary | |
MD5:74310C13389832CD652DE181A96E7133 | SHA256:464C68E2E218337CE2268FB416895A6884B96AE23202D303291E15309AC89083 | |||
| 4252 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\uninstall.cmd | text | |
MD5:FBC297EE9060D4256192E4EDB98CAD1B | SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044 | |||
| 4252 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 | binary | |
MD5:492F71E80AED562BCF65C2669BD9AE2E | SHA256:A6FB2CD31F0D0D8B22C669E299E196516FE04FA6F91EF7794B61BD97B784A1D9 | |||
| 1168 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json | binary | |
MD5:296119A02E6E84CB49E0555D32FDF277 | SHA256:A7F79F3F4B026E34699FE64251FA03B1E855A4874141F9B3DED3C8927FFD79D0 | |||
| 1168 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\283a73e4-4095-4cf4-8ec2-f0daa9ff5b81.tmp | binary | |
MD5:296119A02E6E84CB49E0555D32FDF277 | SHA256:A7F79F3F4B026E34699FE64251FA03B1E855A4874141F9B3DED3C8927FFD79D0 | |||
| 2268 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_2268_1008967375\-65e60e95-0de9-43ff-9f3f-4f7d2dff04b5-_7.3.6.9796_all_adwtpv4uh6jq3ijahrkhnrvwxqnq.crx3 | — | |
MD5:— | SHA256:— | |||
| 2268 | updater.exe | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping2268_399348120\googleearth-win-pro-7.3.6.9796-x64.exe | — | |
MD5:— | SHA256:— | |||
| 4252 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json | binary | |
MD5:C88C3AD52765A523B2B598BF2C5A9216 | SHA256:E450A8D057F11BB4CD98343448B3FD8A70B0F22BD7EB6B84B6FB03731B36FC32 | |||
| 1168 | updater.exe | C:\Windows\SystemTemp\Google1168_1453509086\scoped_dir1168_726980164\GoogleUpdate.exe | executable | |
MD5:3AA2C853D6BC7AF7F2F9B8A934943EFD | SHA256:07034876B9EC0B59432B96FEDB7E10E332440159F9802FAAD5F5B99F01885F6B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
2268 | updater.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/Earth/acetybbjzi5bh3qhtqu3h4j2thlq_7.3.6.9796/-65e60e95-0de9-43ff-9f3f-4f7d2dff04b5-_7.3.6.9796_all_adwtpv4uh6jq3ijahrkhnrvwxqnq.crx3 | unknown | — | — | whitelisted |
4252 | updater.exe | GET | 200 | 142.250.185.131:80 | http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEEY%2BBbWicZDJCutGRyts3so%3D | unknown | — | — | whitelisted |
4252 | updater.exe | GET | 200 | 142.250.184.227:80 | http://c.pki.goog/r/r1.crl | unknown | — | — | whitelisted |
4252 | updater.exe | GET | 200 | 172.217.18.99:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | whitelisted |
3652 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
320 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
320 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6516 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
3260 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2268 | updater.exe | 216.58.206.67:443 | update.googleapis.com | GOOGLE | US | whitelisted |
4252 | updater.exe | 142.250.186.46:443 | dl.google.com | GOOGLE | US | whitelisted |
2268 | updater.exe | 34.104.35.123:80 | edgedl.me.gvt1.com | GOOGLE | US | whitelisted |
4252 | updater.exe | 172.217.18.99:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
edgedl.me.gvt1.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |