File name:

gg-install.exe

Full analysis: https://app.any.run/tasks/6607cfb7-1095-4f20-b4cd-ff7bc543cf00
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 24, 2025, 10:10:12
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

6589EABA3FD32E5C493A18440F4908CA

SHA1:

A9D045C659382237FB092E869ADF45A96ED5871F

SHA256:

F209ADFB0C5D9A6D78EB5916F72C2C8387A28CBFF7F826080913A26A62031D7D

SSDEEP:

12288:otIaZFm2UKq4j7L2Bz5vDYA/+9roQgIhNCIEL/+w:oCR2lqsL2Bz5vD/KroLIhobL/+w

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • gg-install.exe (PID: 4880)
      • ggInstaller.exe (PID: 4112)
      • ggshortcuticon.exe (PID: 1128)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • gg-install.exe (PID: 4880)
      • ggsetup41121031.exe (PID: 5416)
    • Potential Corporate Privacy Violation

      • ggInstaller.exe (PID: 4112)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • ggsetup41121031.exe (PID: 5416)
    • Process requests binary or script from the Internet

      • ggInstaller.exe (PID: 4112)
    • The process executes VB scripts

      • ggsetup41121031.exe (PID: 5416)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 3240)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 3240)
    • Get information on the list of running processes

      • cmd.exe (PID: 1628)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 1628)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 3240)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 1628)
    • Process drops legitimate windows executable

      • ggsetup41121031.exe (PID: 5416)
    • The process drops C-runtime libraries

      • ggsetup41121031.exe (PID: 5416)
  • INFO

    • Create files in a temporary directory

      • gg-install.exe (PID: 4880)
      • ggInstaller.exe (PID: 4112)
      • ggsetup41121031.exe (PID: 5416)
    • Checks supported languages

      • gg-install.exe (PID: 4880)
      • ggshortcuticon.exe (PID: 1128)
    • The sample compiled with english language support

      • gg-install.exe (PID: 4880)
      • ggsetup41121031.exe (PID: 5416)
    • Creates files or folders in the user directory

      • ggsetup41121031.exe (PID: 5416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:04:10 12:19:38+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 26624
InitializedDataSize: 475136
UninitializedDataSize: 16896
EntryPoint: 0x3415
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
23
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start gg-install.exe gginstaller.exe sppextcomobj.exe no specs slui.exe no specs ggsetup41121031.exe wscript.exe no specs cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs ggshortcuticon.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1128"C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\ggshortcuticon.exe" -i "C:\Users\admin\Desktop" "C:\Users\admin\Favorites" "C:\Users\admin\Links"C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\ggshortcuticon.exeggsetup41121031.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsg4526.tmp\ggshortcuticon.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1628C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\killgg.bat" 5416"C:\Windows\SysWOW64\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2656TASKLIST /FI "PID ne 5416" /FI "IMAGENAME eq gg.exe" C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3240wscript "C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\silent.vbs" "C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\killgg.bat" 5416C:\Windows\SysWOW64\wscript.exeggsetup41121031.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\syswow64\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4000tasklist /FI "PID ne 5416" /FI "IMAGENAME eq gghub.exe" C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
4112"C:\Users\admin\AppData\Local\Temp\nsqB74D.tmp\ggInstaller.exe" "C:\Users\admin\AppData\Local\Temp\nsvB76D.tmp"C:\Users\admin\AppData\Local\Temp\nsqB74D.tmp\ggInstaller.exe
gg-install.exe
User:
admin
Company:
GG Network S.A.
Integrity Level:
MEDIUM
Description:
GG installer
Exit code:
0
Version:
2.1.2.0
Modules
Images
c:\users\admin\appdata\local\temp\nsqb74d.tmp\gginstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4880"C:\Users\admin\AppData\Local\Temp\gg-install.exe" C:\Users\admin\AppData\Local\Temp\gg-install.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\gg-install.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5216FINDSTR gg.exe C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\user32.dll
5392\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5416"C:\Users\admin\AppData\Local\Temp\ggsetup41121031.exe" -launcher=downloader -installOpenFm=noC:\Users\admin\AppData\Local\Temp\ggsetup41121031.exe
gg-install.exe
User:
admin
Company:
England Sp. z o.o.
Integrity Level:
MEDIUM
Description:
GG - instalator
Version:
12.4.112.12203
Modules
Images
c:\users\admin\appdata\local\temp\ggsetup41121031.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
3 668
Read events
3 641
Write events
22
Delete events
5

Modification events

(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\GG\Setup
Operation:writeName:InstallPath
Value:
C:\Users\admin\AppData\Local\GG\Application
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GG
Operation:writeName:DisplayName
Value:
GG
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GG
Operation:writeName:DisplayVersion
Value:
12
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GG
Operation:writeName:Publisher
Value:
England Sp. z o.o.
Executable files
45
Suspicious files
26
Text files
34
Unknown types
0

Dropped files

PID
Process
Filename
Type
4112ggInstaller.exeC:\Users\admin\AppData\Local\Temp\ggsetup41121031.tmp
MD5:
SHA256:
4880gg-install.exeC:\Users\admin\AppData\Local\Temp\ggsetup41121031.exe
MD5:
SHA256:
4880gg-install.exeC:\Users\admin\AppData\Local\Temp\nsqB74D.tmp\ggInstaller.exeexecutable
MD5:CA63C2932EB9D73875A47EE297801F1D
SHA256:0016C3186284983CB210F32A8D461D0A9332ED3DD43345A3706DEA732C944B64
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\ggshortcuticon.exeexecutable
MD5:71CCB16AB9561B7350C3A46A50CF68A0
SHA256:9CDE19F7D26ECCC9C89185E79AD66EAB572664B6C7752DF9B148786FF9942F3C
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\silent.vbstext
MD5:80D8C1695BE1595671C45178274E69A1
SHA256:B0C186103A4E25B23035987ACA9B78CAAC0232A118F87C3F06420F2E1BF7BB70
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\silent2.vbstext
MD5:6E546DBE70C4B192F571BA915931A3AB
SHA256:4DB12C85B8A0665C63327F24F2F513D0E083254FE5CF85A9EEF2A81E9040C3E9
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\CloseGG.dllexecutable
MD5:A9CC082B1CE61790BEEFAE954175F1CB
SHA256:EB415325BBEE0726637DB45272E3600319384597A98327E67C515A6DA537024D
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\2_1.bmpimage
MD5:7C32F8C985C2792C3F1EC34D0E653190
SHA256:1C4FB5EF7824C5ECD6A63522DEEE0B3385B910DD8881061B2BCCF7FB268A056E
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\GG\Application\application.initext
MD5:8CE31F831736435B5F85DD576CA3EEE7
SHA256:BE8A23DB02C9CE33CF2CBEDB990AF791A87B7B67104A2A5A1F1825AABE63C48C
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\System.dllexecutable
MD5:959EA64598B9A3E494C00E8FA793BE7E
SHA256:03CD57AB00236C753E7DDEEE8EE1C10839ACE7C426769982365531042E1F6F8B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
43
DNS requests
16
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7224
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4112
ggInstaller.exe
GET
302
54.38.193.40:80
http://im-updates.gg.pl/downloader/installer-metadata/windows
unknown
whitelisted
4112
ggInstaller.exe
GET
206
54.38.193.40:80
http://im-updates.gg.pl/phoenix/app/release/12.4.112.12203/standard/WINNT_x86-msvc/pl/ggsetup.exe
unknown
whitelisted
4112
ggInstaller.exe
GET
200
212.91.26.251:80
http://hit.gg.pl/GG-Downloader/evt/download-started?id=Qtknc2noToRAUShacilb9GqJpXHqZ6jC&branding=GG
unknown
whitelisted
4112
ggInstaller.exe
GET
302
54.38.193.40:80
http://im-updates.gg.pl/downloader/installer-metadata/windows
unknown
whitelisted
4112
ggInstaller.exe
GET
200
54.38.193.40:80
http://im-updates.gg.pl/metadata/projectName,phoenix/version,latest/channel,release/distribution,standard/platform,WINNT_x86-msvc/locale,pl/ggsetup.exe
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4112
ggInstaller.exe
GET
206
54.38.193.40:80
http://im-updates.gg.pl/phoenix/app/release/12.4.112.12203/standard/WINNT_x86-msvc/pl/ggsetup.exe
unknown
whitelisted
4112
ggInstaller.exe
GET
206
54.38.193.40:80
http://im-updates.gg.pl/phoenix/app/release/12.4.112.12203/standard/WINNT_x86-msvc/pl/ggsetup.exe
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
20.197.71.89:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
3304
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
client.wns.windows.com
  • 20.197.71.89
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.128
  • 40.126.32.134
  • 20.190.160.5
  • 40.126.32.138
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
im-updates.gg.pl
  • 54.38.193.40
whitelisted
hit.gg.pl
  • 212.91.26.251
  • 212.91.26.250
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted

Threats

PID
Process
Class
Message
4112
ggInstaller.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
No debug info