File name:

google-books-downloader-2-7.exe

Full analysis: https://app.any.run/tasks/9ceed648-053a-4f96-a293-48fed4513140
Verdict: Malicious activity
Analysis date: September 15, 2022, 18:27:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1D12AE93C91A9EF8744E5649CC679ADF

SHA1:

FB829B2912F222DEAE66F0DF88B4873435A876D3

SHA256:

C1BA877F3B101557ED18F03E19DACADEA435F29C83A769D94448ED0A4B50907A

SSDEEP:

12288:CQiGYyOw5ZuiRvc28WoYzDA8GAVxL4PsRftxw1xERl7q3C8pJth:CQi1yTvy2MCZGSacftixOl7uh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • google-books-downloader-2-7.exe (PID: 3076)
      • google-books-downloader-2-7.exe (PID: 3896)
      • google-books-downloader-2-7.tmp (PID: 3992)
  • SUSPICIOUS

    • Checks supported languages

      • google-books-downloader-2-7.exe (PID: 3076)
      • google-books-downloader-2-7.tmp (PID: 3316)
      • google-books-downloader-2-7.exe (PID: 3896)
      • google-books-downloader-2-7.tmp (PID: 3992)
    • Reads the computer name

      • google-books-downloader-2-7.tmp (PID: 3316)
      • google-books-downloader-2-7.tmp (PID: 3992)
    • Drops a file with a compile date too recent

      • google-books-downloader-2-7.exe (PID: 3076)
      • google-books-downloader-2-7.exe (PID: 3896)
      • google-books-downloader-2-7.tmp (PID: 3992)
    • Executable content was dropped or overwritten

      • google-books-downloader-2-7.exe (PID: 3076)
      • google-books-downloader-2-7.exe (PID: 3896)
      • google-books-downloader-2-7.tmp (PID: 3992)
    • Reads the Windows organization settings

      • google-books-downloader-2-7.tmp (PID: 3992)
    • Reads Windows owner or organization settings

      • google-books-downloader-2-7.tmp (PID: 3992)
  • INFO

    • Application was dropped or rewritten from another process

      • google-books-downloader-2-7.tmp (PID: 3316)
      • google-books-downloader-2-7.tmp (PID: 3992)
    • Loads dropped or rewritten executable

      • google-books-downloader-2-7.tmp (PID: 3992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (71.1)
.exe | Win32 Executable Delphi generic (9.1)
.scr | Windows screen saver (8.4)
.dll | Win32 Dynamic Link Library (generic) (4.2)
.exe | Win32 Executable (generic) (2.9)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 1992-Jun-19 22:22:17
Detected languages:
  • Dutch - Netherlands
  • English - United States
Comments: This installation was built with Inno Setup.
CompanyName: GBOOKSDOWNLOADER.COM
FileDescription: Google Books Downloader Setup
FileVersion: -
LegalCopyright: -
ProductName: Google Books Downloader
ProductVersion: 2.7

DOS Header

e_magic: MZ
e_cblp: 80
e_cp: 2
e_crlc: -
e_cparhdr: 4
e_minalloc: 15
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: 26
e_oemid: -
e_oeminfo: -
e_lfanew: 256

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 8
TimeDateStamp: 1992-Jun-19 22:22:17
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_BYTES_REVERSED_HI
  • IMAGE_FILE_BYTES_REVERSED_LO
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
CODE
4096
40240
40448
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.63177
DATA
45056
592
1024
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.75182
BSS
49152
3724
0
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.idata
53248
2384
2560
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.43073
.tls
57344
8
0
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rdata
61440
24
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED
0.204488
.reloc
65536
2244
0
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED
.rsrc
69632
11264
11264
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED
4.50813

Resources

Title
Entropy
Size
Codepage
Language
Type
1
3.25755
296
UNKNOWN
Dutch - Netherlands
RT_ICON
2
3.47151
1384
UNKNOWN
Dutch - Netherlands
RT_ICON
3
3.91708
744
UNKNOWN
Dutch - Netherlands
RT_ICON
4
3.91366
2216
UNKNOWN
Dutch - Netherlands
RT_ICON
4089
3.21823
754
UNKNOWN
UNKNOWN
RT_STRING
4090
3.31515
780
UNKNOWN
UNKNOWN
RT_STRING
4091
3.25024
718
UNKNOWN
UNKNOWN
RT_STRING
4093
2.86149
104
UNKNOWN
UNKNOWN
RT_STRING
4094
3.20731
180
UNKNOWN
UNKNOWN
RT_STRING
4095
3.04592
174
UNKNOWN
UNKNOWN
RT_STRING

Imports

advapi32.dll
advapi32.dll (#2)
comctl32.dll
kernel32.dll
kernel32.dll (#2)
oleaut32.dll
user32.dll
user32.dll (#2)
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start google-books-downloader-2-7.exe google-books-downloader-2-7.tmp no specs google-books-downloader-2-7.exe google-books-downloader-2-7.tmp

Process information

PID
CMD
Path
Indicators
Parent process
3076"C:\Users\admin\AppData\Local\Temp\google-books-downloader-2-7.exe" C:\Users\admin\AppData\Local\Temp\google-books-downloader-2-7.exe
Explorer.EXE
User:
admin
Company:
GBOOKSDOWNLOADER.COM
Integrity Level:
MEDIUM
Description:
Google Books Downloader Setup
Exit code:
1
Version:
Modules
Images
c:\users\admin\appdata\local\temp\google-books-downloader-2-7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3316"C:\Users\admin\AppData\Local\Temp\is-BHM4Q.tmp\google-books-downloader-2-7.tmp" /SL5="$3012C,410236,56832,C:\Users\admin\AppData\Local\Temp\google-books-downloader-2-7.exe" C:\Users\admin\AppData\Local\Temp\is-BHM4Q.tmp\google-books-downloader-2-7.tmpgoogle-books-downloader-2-7.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-bhm4q.tmp\google-books-downloader-2-7.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3896"C:\Users\admin\AppData\Local\Temp\google-books-downloader-2-7.exe" /SPAWNWND=$20130 /NOTIFYWND=$3012C C:\Users\admin\AppData\Local\Temp\google-books-downloader-2-7.exe
google-books-downloader-2-7.tmp
User:
admin
Company:
GBOOKSDOWNLOADER.COM
Integrity Level:
HIGH
Description:
Google Books Downloader Setup
Exit code:
1
Version:
Modules
Images
c:\users\admin\appdata\local\temp\google-books-downloader-2-7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3992"C:\Users\admin\AppData\Local\Temp\is-QTNGP.tmp\google-books-downloader-2-7.tmp" /SL5="$30138,410236,56832,C:\Users\admin\AppData\Local\Temp\google-books-downloader-2-7.exe" /SPAWNWND=$20130 /NOTIFYWND=$3012C C:\Users\admin\AppData\Local\Temp\is-QTNGP.tmp\google-books-downloader-2-7.tmp
google-books-downloader-2-7.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qtngp.tmp\google-books-downloader-2-7.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
932
Read events
925
Write events
3
Delete events
4

Modification events

(PID) Process:(3992) google-books-downloader-2-7.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
980F0000669E36D730C9D801
(PID) Process:(3992) google-books-downloader-2-7.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
1EC0719C9862EB61A76F202F0B56895B28C731FB6E9D55BD21535BD11397E8A5
(PID) Process:(3992) google-books-downloader-2-7.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3992) google-books-downloader-2-7.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3992) google-books-downloader-2-7.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
1EC0719C9862EB61A76F202F0B56895B28C731FB6E9D55BD21535BD11397E8A5
(PID) Process:(3992) google-books-downloader-2-7.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
980F0000669E36D730C9D801
(PID) Process:(3992) google-books-downloader-2-7.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
3
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3076google-books-downloader-2-7.exeC:\Users\admin\AppData\Local\Temp\is-BHM4Q.tmp\google-books-downloader-2-7.tmpexecutable
MD5:A2C4D52C66B4B399FACADB8CC8386745
SHA256:6C0465CE64C07E729C399A338705941D77727C7D089430957DF3E91A416E9D2A
3896google-books-downloader-2-7.exeC:\Users\admin\AppData\Local\Temp\is-QTNGP.tmp\google-books-downloader-2-7.tmpexecutable
MD5:A2C4D52C66B4B399FACADB8CC8386745
SHA256:6C0465CE64C07E729C399A338705941D77727C7D089430957DF3E91A416E9D2A
3992google-books-downloader-2-7.tmpC:\Users\admin\AppData\Local\Temp\is-A87SK.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3992
google-books-downloader-2-7.tmp
GET
200
66.115.166.233:80
http://www.gbooksdownloader.com/version.php
US
html
1.35 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.2:53
whitelisted
3992
google-books-downloader-2-7.tmp
66.115.166.233:80
www.gbooksdownloader.com
NationalNet, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
www.microsoft.com
whitelisted
www.gbooksdownloader.com
  • 66.115.166.233
unknown

Threats

No threats detected
No debug info