File name:

install.msix

Full analysis: https://app.any.run/tasks/4e0102c4-8794-45f1-b124-4f499bf0df67
Verdict: Malicious activity
Analysis date: February 13, 2024, 16:56:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=store
MD5:

CEB2FE7F4EB3574F86E0C1A36A7A637D

SHA1:

9C90FF28C5B167D5B697F205D301A3638478F5A9

SHA256:

AB24D02B7118446BE8D423F62276BA32FC52B5DAF5BFB3A38621256DC8FB1DD9

SSDEEP:

768:0++/XuflBoY9v4UCb1n3nbwarS9KtIcCi9bec8wp3l4uP7Q0rCzgpUE2:0++XOlBflCbh3bTtIcXbnp+WQgpUE2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3668)
      • G.exe (PID: 1876)
      • ChromeSetupP4.exe (PID: 2124)
      • GoogleUpdate.exe (PID: 4008)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 2292)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3668)
      • G.exe (PID: 1876)
    • Executable content was dropped or overwritten

      • G.exe (PID: 1876)
      • ChromeSetupP4.exe (PID: 2124)
      • GoogleUpdate.exe (PID: 4008)
    • Reads the Internet Settings

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 2292)
    • Disables SEHOP

      • GoogleUpdate.exe (PID: 4008)
    • Creates/Modifies COM task schedule object

      • GoogleUpdate.exe (PID: 2692)
    • Executes as Windows Service

      • GoogleUpdate.exe (PID: 696)
  • INFO

    • Checks supported languages

      • G.exe (PID: 1876)
      • ChromeSetupP4.exe (PID: 2124)
      • GoogleUpdate.exe (PID: 4008)
      • GoogleUpdate.exe (PID: 2896)
      • GoogleUpdate.exe (PID: 2648)
      • GoogleUpdate.exe (PID: 2692)
      • GoogleUpdate.exe (PID: 2292)
      • GoogleUpdate.exe (PID: 696)
    • Reads the computer name

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 4008)
      • GoogleUpdate.exe (PID: 2896)
      • GoogleUpdate.exe (PID: 2648)
      • GoogleUpdate.exe (PID: 2692)
      • GoogleUpdate.exe (PID: 2292)
      • GoogleUpdate.exe (PID: 696)
    • Reads the software policy settings

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 696)
      • GoogleUpdate.exe (PID: 2292)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3668)
    • Reads the machine GUID from the registry

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 4008)
      • GoogleUpdate.exe (PID: 2896)
      • GoogleUpdate.exe (PID: 2292)
      • GoogleUpdate.exe (PID: 696)
    • Reads Environment values

      • G.exe (PID: 1876)
    • Creates files in the program directory

      • ChromeSetupP4.exe (PID: 2124)
      • GoogleUpdate.exe (PID: 4008)
      • GoogleUpdate.exe (PID: 2648)
      • GoogleUpdate.exe (PID: 2692)
      • GoogleUpdate.exe (PID: 2292)
      • GoogleUpdate.exe (PID: 2896)
      • GoogleUpdate.exe (PID: 696)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 45
ZipBitFlag: 0x0008
ZipCompression: None
ZipModifyDate: 2023:08:17 04:28:06
ZipCRC: 0xe987f85a
ZipCompressedSize: 532
ZipUncompressedSize: 532
ZipFileName: Assets/WindowsFormsApp2.exeSquare150x150Logo.scale-100.png
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe g.exe no specs g.exe chromesetupp4.exe googleupdate.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe no specs googleupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
696"C:\Program Files\Google\Update\GoogleUpdate.exe" /svcC:\Program Files\Google\Update\GoogleUpdate.exe
services.exe
User:
SYSTEM
Company:
Google Inc.
Integrity Level:
SYSTEM
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1876"C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Gооglе Uрdаtе
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3668.40984\g.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2124"C:\Windows\Temp\ChromeSetupP4.exe" C:\Windows\Temp\ChromeSetupP4.exe
G.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Update Setup
Exit code:
0
Version:
1.3.36.152
Modules
Images
c:\windows\temp\chromesetupp4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2292"C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNi4xNTIiIHNoZWxsX3ZlcnNpb249IjEuMy4zMy4yMyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9IntDNjYxRTAyNy00NDgxLTQwN0EtODlDQS00MkIxRjhDQzQxRjB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7OTAyOUJBNkYtNEYyQy00NTU0LUFFQjYtMjA5OEI1NUI0OTY2fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7NDMwRkQ0RDAtQjcyOS00RjYxLUFBMzQtOTE1MjY0ODE3OTlEfSIgdmVyc2lvbj0iMS4zLjM2LjMyIiBuZXh0dmVyc2lvbj0iMS4zLjM2LjE1MiIgbGFuZz0icnUiIGJyYW5kPSIiIGNsaWVudD0iIiBpaWQ9Ins0MUREOEQwOS0yOTQwLTlGRDAtOUU4OC1GRjUwMzU2RkZFQ0R9Ij48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjcwMyIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\Google\Update\GoogleUpdate.exe
GoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2648"C:\Program Files\Google\Update\GoogleUpdate.exe" /regsvcC:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2692"C:\Program Files\Google\Update\GoogleUpdate.exe" /regserverC:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2896"C:\Program Files\Google\Update\GoogleUpdate.exe" /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={41DD8D09-2940-9FD0-9E88-FF50356FFECD}&lang=ru&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=empty" /installsource taggedmi /sessionid "{C661E027-4481-407A-89CA-42B1F8CC41F0}"C:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3348"C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Gооglе Uрdаtе
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3668.40984\g.exe
c:\windows\system32\ntdll.dll
3668"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\install.msix.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4008"C:\Program Files\Google\Temp\GUM3062.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={41DD8D09-2940-9FD0-9E88-FF50356FFECD}&lang=ru&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=empty"C:\Program Files\Google\Temp\GUM3062.tmp\GoogleUpdate.exe
ChromeSetupP4.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.36.151
Modules
Images
c:\program files\google\temp\gum3062.tmp\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
16 736
Read events
15 310
Write events
1 290
Delete events
136

Modification events

(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\install.msix.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
138
Suspicious files
2
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\AppxBlockMap.xmlxml
MD5:A56A11AB21238352C74CB893856CCD51
SHA256:5A9499DD9B928A95955AF95635F79FD21A061039BDC44A1B748F82AED91FD2F9
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exeexecutable
MD5:6CA6141EF5305431CD1E36033B5EA4F0
SHA256:163D39CD5E2E3CD73690E1625854FEA824542C1989FA9430ACCA4C5A6F32A6B8
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\Assets\WindowsFormsApp2.exeSquare44x44Logo.scale-100.pngimage
MD5:F41A624D6B0DE8F13688B7C539E862A2
SHA256:A680D90930487BFEF541422718A30E77FA038D1A11434304354A9FB8769E78A5
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\Assets\WindowsFormsApp2.exeSquare150x150Logo.scale-100.pngimage
MD5:A9F0D833D29A9195E6D5DC539A4DCA3B
SHA256:F3F304B7B13A445B18A2D69308C488DF29AF13B2F729D64626F8FD225AB67B4C
1876G.exeC:\Windows\Temp\ChromeSetupP4.exeexecutable
MD5:239FC7D5D087A1F242EAE91757C3B58F
SHA256:96972D6369B40DD098004A33AB22DACD6DAD8D494B2B24E6DD7DD2DE50BB588D
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\[Content_Types].xmlxml
MD5:7AA98232BA237F4350C470169AC94AEA
SHA256:4038B4A93B0A91C03E675E10306FA522B74714491BD972A5DE48A1314567384C
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\AppxMetadata\CodeIntegrity.catcat
MD5:693B99EF193B6455DAAB4732040276CD
SHA256:3114B490BD2126A134652557F4D4D0F3DFB2253E04E30ACBBD978D140F206613
2124ChromeSetupP4.exeC:\Program Files\Google\Temp\GUM3062.tmp\GoogleUpdate.exeexecutable
MD5:54A010C60BE10B65EEE5506720FCCABB
SHA256:9A4B728A0B652056CBD312DD917ADC08C72C89B6F666472F4E3D59A1B8039D89
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\AppxSignature.p7xbinary
MD5:56D3DECBA250A16DAC7AE3EA96D45D1A
SHA256:AAECCB6B4739827A17F8A072C058FC521EACD519E3F71766ACC74580D79B6FED
2124ChromeSetupP4.exeC:\Program Files\Google\Temp\GUM3062.tmp\GoogleCrashHandler.exeexecutable
MD5:381C22092074255A291F4C9946A5C28F
SHA256:C94DCB40543CB405474597C7E7C9D8EF558B1422797752625DB9CA4FAF53689C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
9
DNS requests
3
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/acihtkcueyye3ymoj2afvv7ulzxa_109.0.5414.120/109.0.5414.120_chrome_installer.exe
unknown
unknown
GET
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/acihtkcueyye3ymoj2afvv7ulzxa_109.0.5414.120/109.0.5414.120_chrome_installer.exe
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1876
G.exe
104.21.5.227:443
browsettings.com
CLOUDFLARENET
unknown
2292
GoogleUpdate.exe
142.250.186.35:443
update.googleapis.com
GOOGLE
US
whitelisted
696
GoogleUpdate.exe
142.250.186.35:443
update.googleapis.com
GOOGLE
US
whitelisted
1976
svchost.exe
239.255.255.250:1900
unknown
856
svchost.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
browsettings.com
  • 104.21.5.227
  • 172.67.133.240
unknown
update.googleapis.com
  • 142.250.186.35
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted

Threats

PID
Process
Class
Message
856
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
856
svchost.exe
Misc activity
ET INFO EXE - Served Attached HTTP
No debug info