File name:

gg-install.exe

Full analysis: https://app.any.run/tasks/6607cfb7-1095-4f20-b4cd-ff7bc543cf00
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 24, 2025, 10:10:12
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

6589EABA3FD32E5C493A18440F4908CA

SHA1:

A9D045C659382237FB092E869ADF45A96ED5871F

SHA256:

F209ADFB0C5D9A6D78EB5916F72C2C8387A28CBFF7F826080913A26A62031D7D

SSDEEP:

12288:otIaZFm2UKq4j7L2Bz5vDYA/+9roQgIhNCIEL/+w:oCR2lqsL2Bz5vD/KroLIhobL/+w

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • gg-install.exe (PID: 4880)
      • ggInstaller.exe (PID: 4112)
      • ggshortcuticon.exe (PID: 1128)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • gg-install.exe (PID: 4880)
      • ggsetup41121031.exe (PID: 5416)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • ggsetup41121031.exe (PID: 5416)
    • Potential Corporate Privacy Violation

      • ggInstaller.exe (PID: 4112)
    • The process executes VB scripts

      • ggsetup41121031.exe (PID: 5416)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 3240)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 3240)
    • Process requests binary or script from the Internet

      • ggInstaller.exe (PID: 4112)
    • Get information on the list of running processes

      • cmd.exe (PID: 1628)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 1628)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 1628)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 3240)
    • Process drops legitimate windows executable

      • ggsetup41121031.exe (PID: 5416)
    • The process drops C-runtime libraries

      • ggsetup41121031.exe (PID: 5416)
  • INFO

    • Create files in a temporary directory

      • gg-install.exe (PID: 4880)
      • ggInstaller.exe (PID: 4112)
      • ggsetup41121031.exe (PID: 5416)
    • The sample compiled with english language support

      • gg-install.exe (PID: 4880)
      • ggsetup41121031.exe (PID: 5416)
    • Checks supported languages

      • gg-install.exe (PID: 4880)
      • ggshortcuticon.exe (PID: 1128)
    • Creates files or folders in the user directory

      • ggsetup41121031.exe (PID: 5416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:04:10 12:19:38+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 26624
InitializedDataSize: 475136
UninitializedDataSize: 16896
EntryPoint: 0x3415
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
23
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start gg-install.exe gginstaller.exe sppextcomobj.exe no specs slui.exe no specs ggsetup41121031.exe wscript.exe no specs cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs ggshortcuticon.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1128"C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\ggshortcuticon.exe" -i "C:\Users\admin\Desktop" "C:\Users\admin\Favorites" "C:\Users\admin\Links"C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\ggshortcuticon.exeggsetup41121031.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsg4526.tmp\ggshortcuticon.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1628C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\killgg.bat" 5416"C:\Windows\SysWOW64\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2656TASKLIST /FI "PID ne 5416" /FI "IMAGENAME eq gg.exe" C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3240wscript "C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\silent.vbs" "C:\Users\admin\AppData\Local\Temp\nsg4526.tmp\killgg.bat" 5416C:\Windows\SysWOW64\wscript.exeggsetup41121031.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\syswow64\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4000tasklist /FI "PID ne 5416" /FI "IMAGENAME eq gghub.exe" C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
4112"C:\Users\admin\AppData\Local\Temp\nsqB74D.tmp\ggInstaller.exe" "C:\Users\admin\AppData\Local\Temp\nsvB76D.tmp"C:\Users\admin\AppData\Local\Temp\nsqB74D.tmp\ggInstaller.exe
gg-install.exe
User:
admin
Company:
GG Network S.A.
Integrity Level:
MEDIUM
Description:
GG installer
Exit code:
0
Version:
2.1.2.0
Modules
Images
c:\users\admin\appdata\local\temp\nsqb74d.tmp\gginstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4880"C:\Users\admin\AppData\Local\Temp\gg-install.exe" C:\Users\admin\AppData\Local\Temp\gg-install.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\gg-install.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5216FINDSTR gg.exe C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\user32.dll
5392\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5416"C:\Users\admin\AppData\Local\Temp\ggsetup41121031.exe" -launcher=downloader -installOpenFm=noC:\Users\admin\AppData\Local\Temp\ggsetup41121031.exe
gg-install.exe
User:
admin
Company:
England Sp. z o.o.
Integrity Level:
MEDIUM
Description:
GG - instalator
Version:
12.4.112.12203
Modules
Images
c:\users\admin\appdata\local\temp\ggsetup41121031.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
3 668
Read events
3 641
Write events
22
Delete events
5

Modification events

(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(4112) ggInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\GG\Setup
Operation:writeName:InstallPath
Value:
C:\Users\admin\AppData\Local\GG\Application
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GG
Operation:writeName:DisplayName
Value:
GG
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GG
Operation:writeName:DisplayVersion
Value:
12
(PID) Process:(5416) ggsetup41121031.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GG
Operation:writeName:Publisher
Value:
England Sp. z o.o.
Executable files
45
Suspicious files
26
Text files
34
Unknown types
0

Dropped files

PID
Process
Filename
Type
4112ggInstaller.exeC:\Users\admin\AppData\Local\Temp\ggsetup41121031.tmp
MD5:
SHA256:
4880gg-install.exeC:\Users\admin\AppData\Local\Temp\ggsetup41121031.exe
MD5:
SHA256:
4880gg-install.exeC:\Users\admin\AppData\Local\Temp\nsqB74D.tmp\ggInstaller.exeexecutable
MD5:CA63C2932EB9D73875A47EE297801F1D
SHA256:0016C3186284983CB210F32A8D461D0A9332ED3DD43345A3706DEA732C944B64
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\1_7.bmpimage
MD5:3B790AD314A6DDF614B34362554AC398
SHA256:13E2898D1AC7ABA78D087213C6111DFD5A9575E89F8A94386C692BC320FBD215
4112ggInstaller.exeC:\Users\admin\AppData\Local\Temp\nsvB76D.tmptext
MD5:42E0B1948A8749A2714A51D68B9A978E
SHA256:E0996281856ABCE065BCBE9F424066F79E972773B5AC5DB2C93D27236994CAFD
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\1_10.bmpimage
MD5:151A5D82B009EF1F447F812A8944677E
SHA256:C59701EE30CC720C3A667FCACC432A44EDFA58EAB5F0F5162BBC68CF3AF8CF52
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\2_1.bmpimage
MD5:7C32F8C985C2792C3F1EC34D0E653190
SHA256:1C4FB5EF7824C5ECD6A63522DEEE0B3385B910DD8881061B2BCCF7FB268A056E
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\killgg.battext
MD5:1781CF9AF139F801EADB09BDC02020BF
SHA256:33126F722A01EF1DB6916B2BE7DEC381BB4462E81FC0C0FAA290A97A199D021F
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\ggshortcuticon.exeexecutable
MD5:71CCB16AB9561B7350C3A46A50CF68A0
SHA256:9CDE19F7D26ECCC9C89185E79AD66EAB572664B6C7752DF9B148786FF9942F3C
5416ggsetup41121031.exeC:\Users\admin\AppData\Local\Temp\nsg4526.tmp\3_finish_pl.inibinary
MD5:25CD5315CFCC9B51A2D6E25606F5942D
SHA256:C2556703D44A818AF9245257C413FBBABA686491B87E6EB8C71D50F4FB523EBF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
43
DNS requests
16
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4112
ggInstaller.exe
GET
302
54.38.193.40:80
http://im-updates.gg.pl/downloader/installer-metadata/windows
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4112
ggInstaller.exe
GET
302
54.38.193.40:80
http://im-updates.gg.pl/downloader/installer-metadata/windows
unknown
whitelisted
7224
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4112
ggInstaller.exe
GET
200
212.91.26.251:80
http://hit.gg.pl/GG-Downloader/evt/download-started?id=Qtknc2noToRAUShacilb9GqJpXHqZ6jC&branding=GG
unknown
whitelisted
4112
ggInstaller.exe
GET
200
54.38.193.40:80
http://im-updates.gg.pl/metadata/projectName,phoenix/version,latest/channel,release/distribution,standard/platform,WINNT_x86-msvc/locale,pl/ggsetup.exe
unknown
whitelisted
4112
ggInstaller.exe
GET
206
54.38.193.40:80
http://im-updates.gg.pl/phoenix/app/release/12.4.112.12203/standard/WINNT_x86-msvc/pl/ggsetup.exe
unknown
whitelisted
4112
ggInstaller.exe
GET
206
54.38.193.40:80
http://im-updates.gg.pl/phoenix/app/release/12.4.112.12203/standard/WINNT_x86-msvc/pl/ggsetup.exe
unknown
whitelisted
4112
ggInstaller.exe
GET
206
54.38.193.40:80
http://im-updates.gg.pl/phoenix/app/release/12.4.112.12203/standard/WINNT_x86-msvc/pl/ggsetup.exe
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
20.197.71.89:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
3304
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
client.wns.windows.com
  • 20.197.71.89
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.128
  • 40.126.32.134
  • 20.190.160.5
  • 40.126.32.138
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
im-updates.gg.pl
  • 54.38.193.40
whitelisted
hit.gg.pl
  • 212.91.26.251
  • 212.91.26.250
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted

Threats

PID
Process
Class
Message
4112
ggInstaller.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
No debug info