| File name: | install.msix |
| Full analysis: | https://app.any.run/tasks/4e0102c4-8794-45f1-b124-4f499bf0df67 |
| Verdict: | Malicious activity |
| Analysis date: | February 13, 2024, 16:56:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v4.5 to extract, compression method=store |
| MD5: | CEB2FE7F4EB3574F86E0C1A36A7A637D |
| SHA1: | 9C90FF28C5B167D5B697F205D301A3638478F5A9 |
| SHA256: | AB24D02B7118446BE8D423F62276BA32FC52B5DAF5BFB3A38621256DC8FB1DD9 |
| SSDEEP: | 768:0++/XuflBoY9v4UCb1n3nbwarS9KtIcCi9bec8wp3l4uP7Q0rCzgpUE2:0++XOlBflCbh3bTtIcXbnp+WQgpUE2 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 45 |
|---|---|
| ZipBitFlag: | 0x0008 |
| ZipCompression: | None |
| ZipModifyDate: | 2023:08:17 04:28:06 |
| ZipCRC: | 0xe987f85a |
| ZipCompressedSize: | 532 |
| ZipUncompressedSize: | 532 |
| ZipFileName: | Assets/WindowsFormsApp2.exeSquare150x150Logo.scale-100.png |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 696 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc | C:\Program Files\Google\Update\GoogleUpdate.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google Inc. Integrity Level: SYSTEM Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 1876 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Gооglе Uрdаtе Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2124 | "C:\Windows\Temp\ChromeSetupP4.exe" | C:\Windows\Temp\ChromeSetupP4.exe | G.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Update Setup Exit code: 0 Version: 1.3.36.152 Modules
| |||||||||||||||
| 2292 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNi4xNTIiIHNoZWxsX3ZlcnNpb249IjEuMy4zMy4yMyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9IntDNjYxRTAyNy00NDgxLTQwN0EtODlDQS00MkIxRjhDQzQxRjB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7OTAyOUJBNkYtNEYyQy00NTU0LUFFQjYtMjA5OEI1NUI0OTY2fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7NDMwRkQ0RDAtQjcyOS00RjYxLUFBMzQtOTE1MjY0ODE3OTlEfSIgdmVyc2lvbj0iMS4zLjM2LjMyIiBuZXh0dmVyc2lvbj0iMS4zLjM2LjE1MiIgbGFuZz0icnUiIGJyYW5kPSIiIGNsaWVudD0iIiBpaWQ9Ins0MUREOEQwOS0yOTQwLTlGRDAtOUU4OC1GRjUwMzU2RkZFQ0R9Ij48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjcwMyIvPjwvYXBwPjwvcmVxdWVzdD4 | C:\Program Files\Google\Update\GoogleUpdate.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 2648 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /regsvc | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 2692 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /regserver | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 2896 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={41DD8D09-2940-9FD0-9E88-FF50356FFECD}&lang=ru&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=empty" /installsource taggedmi /sessionid "{C661E027-4481-407A-89CA-42B1F8CC41F0}" | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 3348 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Gооglе Uрdаtе Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3668 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\install.msix.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 4008 | "C:\Program Files\Google\Temp\GUM3062.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={41DD8D09-2940-9FD0-9E88-FF50356FFECD}&lang=ru&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=empty" | C:\Program Files\Google\Temp\GUM3062.tmp\GoogleUpdate.exe | ChromeSetupP4.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.36.151 Modules
| |||||||||||||||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\install.msix.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3668 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\AppxBlockMap.xml | xml | |
MD5:A56A11AB21238352C74CB893856CCD51 | SHA256:5A9499DD9B928A95955AF95635F79FD21A061039BDC44A1B748F82AED91FD2F9 | |||
| 3668 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe | executable | |
MD5:6CA6141EF5305431CD1E36033B5EA4F0 | SHA256:163D39CD5E2E3CD73690E1625854FEA824542C1989FA9430ACCA4C5A6F32A6B8 | |||
| 3668 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\Assets\WindowsFormsApp2.exeSquare44x44Logo.scale-100.png | image | |
MD5:F41A624D6B0DE8F13688B7C539E862A2 | SHA256:A680D90930487BFEF541422718A30E77FA038D1A11434304354A9FB8769E78A5 | |||
| 3668 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\Assets\WindowsFormsApp2.exeSquare150x150Logo.scale-100.png | image | |
MD5:A9F0D833D29A9195E6D5DC539A4DCA3B | SHA256:F3F304B7B13A445B18A2D69308C488DF29AF13B2F729D64626F8FD225AB67B4C | |||
| 1876 | G.exe | C:\Windows\Temp\ChromeSetupP4.exe | executable | |
MD5:239FC7D5D087A1F242EAE91757C3B58F | SHA256:96972D6369B40DD098004A33AB22DACD6DAD8D494B2B24E6DD7DD2DE50BB588D | |||
| 3668 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\[Content_Types].xml | xml | |
MD5:7AA98232BA237F4350C470169AC94AEA | SHA256:4038B4A93B0A91C03E675E10306FA522B74714491BD972A5DE48A1314567384C | |||
| 3668 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\AppxMetadata\CodeIntegrity.cat | cat | |
MD5:693B99EF193B6455DAAB4732040276CD | SHA256:3114B490BD2126A134652557F4D4D0F3DFB2253E04E30ACBBD978D140F206613 | |||
| 2124 | ChromeSetupP4.exe | C:\Program Files\Google\Temp\GUM3062.tmp\GoogleUpdate.exe | executable | |
MD5:54A010C60BE10B65EEE5506720FCCABB | SHA256:9A4B728A0B652056CBD312DD917ADC08C72C89B6F666472F4E3D59A1B8039D89 | |||
| 3668 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\AppxSignature.p7x | binary | |
MD5:56D3DECBA250A16DAC7AE3EA96D45D1A | SHA256:AAECCB6B4739827A17F8A072C058FC521EACD519E3F71766ACC74580D79B6FED | |||
| 2124 | ChromeSetupP4.exe | C:\Program Files\Google\Temp\GUM3062.tmp\GoogleCrashHandler.exe | executable | |
MD5:381C22092074255A291F4C9946A5C28F | SHA256:C94DCB40543CB405474597C7E7C9D8EF558B1422797752625DB9CA4FAF53689C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/acihtkcueyye3ymoj2afvv7ulzxa_109.0.5414.120/109.0.5414.120_chrome_installer.exe | unknown | — | — | unknown |
— | — | GET | — | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/acihtkcueyye3ymoj2afvv7ulzxa_109.0.5414.120/109.0.5414.120_chrome_installer.exe | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1876 | G.exe | 104.21.5.227:443 | browsettings.com | CLOUDFLARENET | — | unknown |
2292 | GoogleUpdate.exe | 142.250.186.35:443 | update.googleapis.com | GOOGLE | US | whitelisted |
696 | GoogleUpdate.exe | 142.250.186.35:443 | update.googleapis.com | GOOGLE | US | whitelisted |
1976 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
856 | svchost.exe | 34.104.35.123:80 | edgedl.me.gvt1.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
browsettings.com |
| unknown |
update.googleapis.com |
| whitelisted |
edgedl.me.gvt1.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
856 | svchost.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
856 | svchost.exe | Misc activity | ET INFO EXE - Served Attached HTTP |