| File name: | googleupdatesetup (2).zip |
| Full analysis: | https://app.any.run/tasks/a888a513-b26c-4d07-a52c-879486082447 |
| Verdict: | Malicious activity |
| Analysis date: | December 28, 2023, 11:00:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 261EAE3405B2A9D413021CB52130091A |
| SHA1: | D5A732C85B88EA5C3678D74E37616EEDC47A90D4 |
| SHA256: | F89AC0BAAE6C156DF0A99691084559F89A5905A6BBD89265EE8847D4610845BE |
| SSDEEP: | 49152:WZKd9kUTV48e/Jexts8dR7/AVLCpqkPu5vDJRQL++efbcHMRqkQRK2DI0gUiUyzL:LkUTQBOtoV7Iu51CC9baMYv/I0PitZ+K |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0801 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:12:28 11:49:32 |
| ZipCRC: | 0x370b3549 |
| ZipCompressedSize: | 1286904 |
| ZipUncompressedSize: | 1376304 |
| ZipFileName: | f_000089 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\googleupdatesetup (2).zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 668 | "C:\Users\admin\Desktop\f_000089.exe" | C:\Users\admin\Desktop\f_000089.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Update Setup Exit code: 0 Version: 1.3.36.352 Modules
| |||||||||||||||
| 1044 | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdate.exe /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={C57DC321-3F61-D3BC-FFF5-34625BD35338}&lang=pl&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=ONGR&installdataindex=empty" | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdate.exe | — | f_000089.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Installer Exit code: 0 Version: 1.3.36.351 Modules
| |||||||||||||||
| 1740 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /regserver | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 1792 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /regsvc | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 1832 | "C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdateSetup.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={C57DC321-3F61-D3BC-FFF5-34625BD35338}&lang=pl&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=ONGR&installdataindex=empty" /installelevated /nomitag | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdateSetup.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Update Setup Exit code: 0 Version: 1.3.36.352 Modules
| |||||||||||||||
| 1848 | "C:\Program Files\Google\Temp\GUM562B.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={C57DC321-3F61-D3BC-FFF5-34625BD35338}&lang=pl&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=ONGR&installdataindex=empty" /installelevated | C:\Program Files\Google\Temp\GUM562B.tmp\GoogleUpdate.exe | — | GoogleUpdateSetup.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.36.351 Modules
| |||||||||||||||
| 1892 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc | C:\Program Files\Google\Update\GoogleUpdate.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google Inc. Integrity Level: SYSTEM Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 2260 | "C:\Program Files\Google\Update\Install\{54604BA1-CAB9-479E-9D0F-01235097C891}\109.0.5414.120_chrome_installer.exe" --verbose-logging --do-not-launch-chrome --system-level /installerdata="C:\Program Files\Google\Update\Install\{54604BA1-CAB9-479E-9D0F-01235097C891}\gui6CF0.tmp" | C:\Program Files\Google\Update\Install\{54604BA1-CAB9-479E-9D0F-01235097C891}\109.0.5414.120_chrome_installer.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Chrome Installer Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2308 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNi4zNTIiIHNoZWxsX3ZlcnNpb249IjEuMy4zMy4yMyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins2RkEzNTE4My04RjI3LTQ5NjItODI2Qy1GRDI3OEQ0RjdBNTl9IiB1c2VyaWQ9IntFQTA5RUEyNS02NEQzLTRBNjEtQURENC1EQzM3QzVFQzQ1MUF9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7Mzk3N0Y1RTUtM0M4Ni00RTdDLUI4OEQtRTlBQTY4N0YxMDgyfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7NDMwRkQ0RDAtQjcyOS00RjYxLUFBMzQtOTE1MjY0ODE3OTlEfSIgdmVyc2lvbj0iMS4zLjM2LjMyIiBuZXh0dmVyc2lvbj0iMS4zLjM2LjM1MiIgbGFuZz0icGwiIGJyYW5kPSJPTkdSIiBjbGllbnQ9IiIgaWlkPSJ7QzU3REMzMjEtM0Y2MS1EM0JDLUZGRjUtMzQ2MjVCRDM1MzM4fSI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSI1MzIiLz48L2FwcD48L3JlcXVlc3Q- | C:\Program Files\Google\Update\GoogleUpdate.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 668 | f_000089.exe | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleCrashHandler.exe | executable | |
MD5:8EB5A3BCA26ACB6688A0CD7B35CFDAD9 | SHA256:24DFDF400D8514D3FBFC5F4AA5DD2143F38B160AD142417BBF83E4D2E425DD0C | |||
| 124 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb124.22371\f_000089 | executable | |
MD5:5D8FE4C37DA5CBE7848AB9CD1A266FCD | SHA256:A01209D723609CC19CAEFCADFD1CBF90BC3C2AEEEDC6E3F154DF0B5E7223FDFB | |||
| 668 | f_000089.exe | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdateComRegisterShell64.exe | executable | |
MD5:4B0BF7525348FD3B55B189C42F90633C | SHA256:F318DEB222E9F635F3A7B7DE3202169732EBDB4CCF0BE5FA8BB94E2E83913B74 | |||
| 668 | f_000089.exe | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\psmachine.dll | executable | |
MD5:76D2509EF0B2715A0BA5BE235D2996AB | SHA256:07876D2770A0E964DA62638D9793C8A4E6C9B546EC44B71AA8C45BE41767EE6D | |||
| 668 | f_000089.exe | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\psmachine_64.dll | executable | |
MD5:365CE91B8F2D6D85D246B0B64608F333 | SHA256:95AC9E810ABF9B37AAA84955A0741B14BAC1181504AA5237A2DF01F447972EB0 | |||
| 668 | f_000089.exe | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\psuser.dll | executable | |
MD5:FC9F15602C90829671D54FA6E72F0C88 | SHA256:9F581D8D8F3FC63FB3483D6094562E114F2E1F289D1C7A4B7FFE91E46E50C936 | |||
| 668 | f_000089.exe | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdateOnDemand.exe | executable | |
MD5:616E0D6AFDA084D967E49370BC5350CA | SHA256:BF88BBCF2B88823A94EFED3C4BC275C47F338D7788A4FA8444853BF637F5E253 | |||
| 668 | f_000089.exe | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\goopdate.dll | executable | |
MD5:2FA183E7B8B744B6761A008F6BC56B87 | SHA256:E80FCE87F2F4B87282FA38260ACFE5435E47FD2E0884DB4C7446AC00635A7CCF | |||
| 668 | f_000089.exe | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\goopdateres_da.dll | executable | |
MD5:F2676455A6CC1749B55F904FEF73CBE1 | SHA256:70CA4EB73A4F8D03E750929A4AFDB876076D39499F2016588F8B6FE85A80B0E5 | |||
| 668 | f_000089.exe | C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\goopdateres_bn.dll | executable | |
MD5:1D1E2D66464C7237E667FC8813847D27 | SHA256:825428867F14CE18169FE8705C0A5C941B87A7FEEC84F4E3DD4344BBE5FC7972 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2340 | GoogleUpdate.exe | GET | 200 | 216.58.212.131:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | unknown |
2340 | GoogleUpdate.exe | GET | 200 | 184.24.77.194:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?559a13cd175d8925 | unknown | compressed | 4.66 Kb | unknown |
2340 | GoogleUpdate.exe | GET | 200 | 216.58.212.131:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | binary | 724 b | unknown |
2340 | GoogleUpdate.exe | GET | 200 | 216.58.212.131:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGpYRvzN3kAuEMlMWsqSFLc%3D | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2308 | GoogleUpdate.exe | 142.250.185.99:443 | update.googleapis.com | GOOGLE | US | whitelisted |
1892 | GoogleUpdate.exe | 142.250.185.99:443 | update.googleapis.com | GOOGLE | US | whitelisted |
2340 | GoogleUpdate.exe | 142.250.186.142:443 | dl.google.com | GOOGLE | US | whitelisted |
2340 | GoogleUpdate.exe | 184.24.77.194:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2340 | GoogleUpdate.exe | 216.58.212.131:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
1528 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2532 | GoogleUpdate.exe | 142.250.185.99:443 | update.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| whitelisted |