File name:

install.msix

Full analysis: https://app.any.run/tasks/4e0102c4-8794-45f1-b124-4f499bf0df67
Verdict: Malicious activity
Analysis date: February 13, 2024, 16:56:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=store
MD5:

CEB2FE7F4EB3574F86E0C1A36A7A637D

SHA1:

9C90FF28C5B167D5B697F205D301A3638478F5A9

SHA256:

AB24D02B7118446BE8D423F62276BA32FC52B5DAF5BFB3A38621256DC8FB1DD9

SSDEEP:

768:0++/XuflBoY9v4UCb1n3nbwarS9KtIcCi9bec8wp3l4uP7Q0rCzgpUE2:0++XOlBflCbh3bTtIcXbnp+WQgpUE2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3668)
      • ChromeSetupP4.exe (PID: 2124)
      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 4008)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3668)
      • G.exe (PID: 1876)
    • Reads the Internet Settings

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 2292)
    • Executable content was dropped or overwritten

      • ChromeSetupP4.exe (PID: 2124)
      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 4008)
    • Reads settings of System Certificates

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 2292)
    • Disables SEHOP

      • GoogleUpdate.exe (PID: 4008)
    • Creates/Modifies COM task schedule object

      • GoogleUpdate.exe (PID: 2692)
    • Executes as Windows Service

      • GoogleUpdate.exe (PID: 696)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3668)
    • Reads the machine GUID from the registry

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 4008)
      • GoogleUpdate.exe (PID: 2896)
      • GoogleUpdate.exe (PID: 696)
      • GoogleUpdate.exe (PID: 2292)
    • Reads the computer name

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 4008)
      • GoogleUpdate.exe (PID: 2648)
      • GoogleUpdate.exe (PID: 2692)
      • GoogleUpdate.exe (PID: 2292)
      • GoogleUpdate.exe (PID: 2896)
      • GoogleUpdate.exe (PID: 696)
    • Reads Environment values

      • G.exe (PID: 1876)
    • Reads the software policy settings

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 2292)
      • GoogleUpdate.exe (PID: 696)
    • Checks supported languages

      • G.exe (PID: 1876)
      • GoogleUpdate.exe (PID: 4008)
      • ChromeSetupP4.exe (PID: 2124)
      • GoogleUpdate.exe (PID: 2692)
      • GoogleUpdate.exe (PID: 2648)
      • GoogleUpdate.exe (PID: 2292)
      • GoogleUpdate.exe (PID: 2896)
      • GoogleUpdate.exe (PID: 696)
    • Creates files in the program directory

      • ChromeSetupP4.exe (PID: 2124)
      • GoogleUpdate.exe (PID: 4008)
      • GoogleUpdate.exe (PID: 2648)
      • GoogleUpdate.exe (PID: 2692)
      • GoogleUpdate.exe (PID: 2292)
      • GoogleUpdate.exe (PID: 2896)
      • GoogleUpdate.exe (PID: 696)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 45
ZipBitFlag: 0x0008
ZipCompression: None
ZipModifyDate: 2023:08:17 04:28:06
ZipCRC: 0xe987f85a
ZipCompressedSize: 532
ZipUncompressedSize: 532
ZipFileName: Assets/WindowsFormsApp2.exeSquare150x150Logo.scale-100.png
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe g.exe no specs g.exe chromesetupp4.exe googleupdate.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe no specs googleupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
696"C:\Program Files\Google\Update\GoogleUpdate.exe" /svcC:\Program Files\Google\Update\GoogleUpdate.exe
services.exe
User:
SYSTEM
Company:
Google Inc.
Integrity Level:
SYSTEM
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1876"C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Gооglе Uрdаtе
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3668.40984\g.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2124"C:\Windows\Temp\ChromeSetupP4.exe" C:\Windows\Temp\ChromeSetupP4.exe
G.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Update Setup
Exit code:
0
Version:
1.3.36.152
Modules
Images
c:\windows\temp\chromesetupp4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2292"C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNi4xNTIiIHNoZWxsX3ZlcnNpb249IjEuMy4zMy4yMyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9IntDNjYxRTAyNy00NDgxLTQwN0EtODlDQS00MkIxRjhDQzQxRjB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7OTAyOUJBNkYtNEYyQy00NTU0LUFFQjYtMjA5OEI1NUI0OTY2fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7NDMwRkQ0RDAtQjcyOS00RjYxLUFBMzQtOTE1MjY0ODE3OTlEfSIgdmVyc2lvbj0iMS4zLjM2LjMyIiBuZXh0dmVyc2lvbj0iMS4zLjM2LjE1MiIgbGFuZz0icnUiIGJyYW5kPSIiIGNsaWVudD0iIiBpaWQ9Ins0MUREOEQwOS0yOTQwLTlGRDAtOUU4OC1GRjUwMzU2RkZFQ0R9Ij48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjcwMyIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\Google\Update\GoogleUpdate.exe
GoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2648"C:\Program Files\Google\Update\GoogleUpdate.exe" /regsvcC:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2692"C:\Program Files\Google\Update\GoogleUpdate.exe" /regserverC:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2896"C:\Program Files\Google\Update\GoogleUpdate.exe" /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={41DD8D09-2940-9FD0-9E88-FF50356FFECD}&lang=ru&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=empty" /installsource taggedmi /sessionid "{C661E027-4481-407A-89CA-42B1F8CC41F0}"C:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3348"C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Gооglе Uрdаtе
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3668.40984\g.exe
c:\windows\system32\ntdll.dll
3668"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\install.msix.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4008"C:\Program Files\Google\Temp\GUM3062.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={41DD8D09-2940-9FD0-9E88-FF50356FFECD}&lang=ru&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=empty"C:\Program Files\Google\Temp\GUM3062.tmp\GoogleUpdate.exe
ChromeSetupP4.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.36.151
Modules
Images
c:\program files\google\temp\gum3062.tmp\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
16 736
Read events
15 310
Write events
1 290
Delete events
136

Modification events

(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\install.msix.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
138
Suspicious files
2
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\Assets\WindowsFormsApp2.exeSquare150x150Logo.scale-100.pngimage
MD5:A9F0D833D29A9195E6D5DC539A4DCA3B
SHA256:F3F304B7B13A445B18A2D69308C488DF29AF13B2F729D64626F8FD225AB67B4C
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\Assets\WindowsFormsApp2.exeSquare44x44Logo.scale-100.pngimage
MD5:F41A624D6B0DE8F13688B7C539E862A2
SHA256:A680D90930487BFEF541422718A30E77FA038D1A11434304354A9FB8769E78A5
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\AppxManifest.xmlxml
MD5:3B6AFBEBC6A9AC18B1843498FFFD3BFB
SHA256:DC7E16794E2F817F3C378201B8B686AFD5CB34E4B694DBA7525E2B0545E9CC16
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\AppxSignature.p7xbinary
MD5:56D3DECBA250A16DAC7AE3EA96D45D1A
SHA256:AAECCB6B4739827A17F8A072C058FC521EACD519E3F71766ACC74580D79B6FED
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\G.exeexecutable
MD5:6CA6141EF5305431CD1E36033B5EA4F0
SHA256:163D39CD5E2E3CD73690E1625854FEA824542C1989FA9430ACCA4C5A6F32A6B8
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\AppxMetadata\CodeIntegrity.catcat
MD5:693B99EF193B6455DAAB4732040276CD
SHA256:3114B490BD2126A134652557F4D4D0F3DFB2253E04E30ACBBD978D140F206613
2124ChromeSetupP4.exeC:\Program Files\Google\Temp\GUM3062.tmp\psmachine_64.dllexecutable
MD5:B005CCEAAEB80C98FC111F17F6900C4C
SHA256:42EE3C4F26D73887162A536F5D7C6670C57D1A9DF7EBFC3AC531FBC9D2957802
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3668.40984\[Content_Types].xmlxml
MD5:7AA98232BA237F4350C470169AC94AEA
SHA256:4038B4A93B0A91C03E675E10306FA522B74714491BD972A5DE48A1314567384C
2124ChromeSetupP4.exeC:\Program Files\Google\Temp\GUM3062.tmp\GoogleUpdateBroker.exeexecutable
MD5:9482267D8E065D5C3CFE30C69B41B30C
SHA256:23085B1BBB7D7B175EE9C4FC9DB4E7DD8981A3F5246CD864AB178C53C0612758
2124ChromeSetupP4.exeC:\Program Files\Google\Temp\GUM3062.tmp\goopdate.dllexecutable
MD5:85C58712E4EC9A730396F6A87F755144
SHA256:A249CFDB846F0DD407C14486C173163C4339EED5BE208A2A7BE12A0EF0E21A3D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
9
DNS requests
3
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/acihtkcueyye3ymoj2afvv7ulzxa_109.0.5414.120/109.0.5414.120_chrome_installer.exe
unknown
unknown
GET
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/acihtkcueyye3ymoj2afvv7ulzxa_109.0.5414.120/109.0.5414.120_chrome_installer.exe
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1876
G.exe
104.21.5.227:443
browsettings.com
CLOUDFLARENET
unknown
2292
GoogleUpdate.exe
142.250.186.35:443
update.googleapis.com
GOOGLE
US
whitelisted
696
GoogleUpdate.exe
142.250.186.35:443
update.googleapis.com
GOOGLE
US
whitelisted
1976
svchost.exe
239.255.255.250:1900
unknown
856
svchost.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
browsettings.com
  • 104.21.5.227
  • 172.67.133.240
unknown
update.googleapis.com
  • 142.250.186.35
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted

Threats

PID
Process
Class
Message
856
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
856
svchost.exe
Misc activity
ET INFO EXE - Served Attached HTTP
No debug info