File name:

ChromeSetup (1).exe

Full analysis: https://app.any.run/tasks/e92a0b5f-8024-478b-9c03-c1299c4830a5
Verdict: Malicious activity
Analysis date: January 10, 2025, 12:54:05
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

B046865E90B14C9FE1C6B132FAB39A33

SHA1:

56CBB818459B0CD7DF64D4C3B2F37DCAD533348C

SHA256:

03348A963EB918CE588428B7A31744883DD0BDB2AAD6FFDC3E41C885E56BD620

SSDEEP:

98304:CvPHTg70qMK46SByzYBh9RWEdpa5pIIJjtOBJOWrLav4us1/nqj2xzG+oo2IJ5Xg:KfgTv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • setup.exe (PID: 5572)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ChromeSetup (1).exe (PID: 5300)
    • Application launched itself

      • ChromeSetup (1).exe (PID: 5300)
      • updater.exe (PID: 6436)
      • updater.exe (PID: 6572)
      • updater.exe (PID: 6680)
      • setup.exe (PID: 5572)
      • setup.exe (PID: 556)
      • updater.exe (PID: 6664)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 6436)
      • updater.exe (PID: 6572)
      • 131.0.6778.265_chrome_installer.exe (PID: 5740)
      • setup.exe (PID: 5572)
    • Executes as Windows Service

      • updater.exe (PID: 6572)
      • updater.exe (PID: 6680)
      • updater.exe (PID: 6664)
    • Searches for installed software

      • setup.exe (PID: 5572)
    • Creates a software uninstall entry

      • setup.exe (PID: 5572)
      • chrome.exe (PID: 6928)
  • INFO

    • The sample compiled with english language support

      • ChromeSetup (1).exe (PID: 5300)
      • updater.exe (PID: 6436)
      • updater.exe (PID: 6572)
      • 131.0.6778.265_chrome_installer.exe (PID: 5740)
      • setup.exe (PID: 5572)
    • Checks supported languages

      • ChromeSetup (1).exe (PID: 5300)
      • ChromeSetup (1).exe (PID: 6368)
      • 131.0.6778.265_chrome_installer.exe (PID: 5740)
      • setup.exe (PID: 5400)
      • setup.exe (PID: 556)
      • elevation_service.exe (PID: 4328)
      • setup.exe (PID: 5572)
      • setup.exe (PID: 4976)
      • updater.exe (PID: 6664)
      • updater.exe (PID: 6744)
    • Creates files in the program directory

      • ChromeSetup (1).exe (PID: 6368)
      • updater.exe (PID: 6680)
      • setup.exe (PID: 556)
      • setup.exe (PID: 5572)
    • Reads the computer name

      • ChromeSetup (1).exe (PID: 5300)
      • ChromeSetup (1).exe (PID: 6368)
      • 131.0.6778.265_chrome_installer.exe (PID: 5740)
      • elevation_service.exe (PID: 4328)
      • setup.exe (PID: 5572)
      • updater.exe (PID: 6664)
    • Process checks computer location settings

      • ChromeSetup (1).exe (PID: 5300)
    • Manual execution by a user

      • chrome.exe (PID: 6928)
    • Executes as Windows Service

      • elevation_service.exe (PID: 4328)
    • The process uses the downloaded file

      • chrome.exe (PID: 6372)
      • chrome.exe (PID: 5432)
      • chrome.exe (PID: 6572)
      • chrome.exe (PID: 6816)
      • chrome.exe (PID: 1604)
      • chrome.exe (PID: 432)
    • Application launched itself

      • chrome.exe (PID: 6928)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 6664)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:11:11 16:02:03+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 3429376
InitializedDataSize: 6935040
UninitializedDataSize: -
EntryPoint: 0x1be4e0
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 132.0.6833.0
ProductVersionNumber: 132.0.6833.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Installer
FileVersion: 132.0.6833.0
InternalName: Google Installer (x86)
LegalCopyright: Copyright 2024 Google LLC. All rights reserved.
OriginalFileName: UpdaterSetup.exe
ProductName: Google Installer
ProductVersion: 132.0.6833.0
CompanyShortName: Google
ProductShortName: GoogleUpdater
LastChange: fba838c6a3184f5070b77238fdbbca1b3d990105-refs/branch-heads/6833@{#1}
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
178
Monitored processes
47
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start chromesetup (1).exe no specs chromesetup (1).exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe no specs updater.exe no specs 131.0.6778.265_chrome_installer.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe elevation_service.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs updater.exe no specs updater.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
432"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations=is-enterprise-managed=no --field-trial-handle=6548,i,10404348973250299542,13035199848537021432,262144 --variations-seed-version --mojo-platform-channel-handle=6432 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
131.0.6778.265
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
556"C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping6680_587094799\CR_F8727.tmp\setup.exe" --channel=stable --system-level --verbose-logging --create-shortcuts=2 --install-level=1C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6680_587094799\CR_F8727.tmp\setup.exesetup.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome Installer
Exit code:
73
Version:
131.0.6778.265
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping6680_587094799\cr_f8727.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
644"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=5336,i,10404348973250299542,13035199848537021432,262144 --variations-seed-version --mojo-platform-channel-handle=5196 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
131.0.6778.265
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\131.0.6778.265\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1604"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations=is-enterprise-managed=no --field-trial-handle=6900,i,10404348973250299542,13035199848537021432,262144 --variations-seed-version --mojo-platform-channel-handle=6728 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
131.0.6778.265
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1856"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations=is-enterprise-managed=no --field-trial-handle=7032,i,10404348973250299542,13035199848537021432,262144 --variations-seed-version --mojo-platform-channel-handle=7024 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
131.0.6778.265
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\131.0.6778.265\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1988"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations=is-enterprise-managed=no --field-trial-handle=6848,i,10404348973250299542,13035199848537021432,262144 --variations-seed-version --mojo-platform-channel-handle=6840 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
131.0.6778.265
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\131.0.6778.265\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2260"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --string-annotations=is-enterprise-managed=no --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1972,i,10404348973250299542,13035199848537021432,262144 --variations-seed-version --mojo-platform-channel-handle=1968 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
131.0.6778.265
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3664"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations=is-enterprise-managed=no --extension-process --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=3940,i,10404348973250299542,13035199848537021432,262144 --variations-seed-version --mojo-platform-channel-handle=3952 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
131.0.6778.265
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\131.0.6778.265\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3816"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3288,i,10404348973250299542,13035199848537021432,262144 --variations-seed-version --mojo-platform-channel-handle=3300 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
131.0.6778.265
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\131.0.6778.265\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
4328"C:\Program Files\Google\Chrome\Application\131.0.6778.265\elevation_service.exe"C:\Program Files\Google\Chrome\Application\131.0.6778.265\elevation_service.exeservices.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome
Exit code:
0
Version:
131.0.6778.265
Modules
Images
c:\program files\google\chrome\application\131.0.6778.265\elevation_service.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
13 383
Read events
13 258
Write events
121
Delete events
4

Modification events

(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:StubPath
Value:
"C:\Program Files\Google\Chrome\Application\131.0.6778.265\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable
(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:Localized Name
Value:
Google Chrome
(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:IsInstalled
Value:
1
(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:Version
Value:
43,0,0,0
(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade
Operation:writeName:CommandLine
Value:
"C:\Program Files\Google\Chrome\Application\131.0.6778.265\Installer\setup.exe" --on-os-upgrade --channel=stable --system-level --verbose-logging %1
(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade
Operation:writeName:AutoRunOnOSUpgrade
Value:
1
(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\store-dmtoken
Operation:writeName:CommandLine
Value:
"C:\Program Files\Google\Chrome\Application\131.0.6778.265\Installer\setup.exe" --store-dmtoken=%1 --system-level --verbose-logging --channel=stable
(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\store-dmtoken
Operation:writeName:WebAccessible
Value:
1
(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\delete-dmtoken
Operation:writeName:CommandLine
Value:
"C:\Program Files\Google\Chrome\Application\131.0.6778.265\Installer\setup.exe" --delete-dmtoken --system-level --verbose-logging --channel=stable
(PID) Process:(5572) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\delete-dmtoken
Operation:writeName:WebAccessible
Value:
1
Executable files
9
Suspicious files
169
Text files
57
Unknown types
0

Dropped files

PID
Process
Filename
Type
6368ChromeSetup (1).exeC:\Windows\SystemTemp\Google6368_1326672054\UPDATER.PACKED.7Z
MD5:
SHA256:
6436updater.exeC:\Program Files (x86)\Google\GoogleUpdater\132.0.6833.0\Crashpad\settings.datbinary
MD5:D211E5D57DF11960D0BE9840177D64EF
SHA256:EBF11214640B28865EF916B0B45712971387CB7B6D5316909E9DA68CDC5D5418
6436updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:D6793DB3CF94E59231019422FBC29F9B
SHA256:C86E24C81124363CFADE94320032590CCE43482217B8CF3B58A10F51AC25DB83
6572updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:E00FF8BDFA321E45AD3732953A9EA225
SHA256:E3F4E495A70E6340AA3FA007A6775448DCE699FCC1B11FF483B1E97819714C53
6572updater.exeC:\Program Files (x86)\Google\GoogleUpdater\132.0.6833.0\prefs.jsonbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
6572updater.exeC:\Program Files (x86)\Google\GoogleUpdater\132.0.6833.0\134a67e6-5acc-4e8f-baa8-3348aa8291f1.tmpbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
6680updater.exeC:\Windows\SystemTemp\chrome_url_fetcher_6680_1729639543\-8a69d345-d564-463c-aff1-a69d9e530f96-_131.0.6778.265_all_goas4i6j2neaiiwto4vily6j5y.crx3
MD5:
SHA256:
6680updater.exeC:\Program Files (x86)\Google\GoogleUpdater\crx_cache\{8a69d345-d564-463c-aff1-a69d9e530f96}_1.61204da5dd7ea37f7f97ae7cf7b528047bbe74ae08baff61f6dfd29963c4481c
MD5:
SHA256:
6680updater.exeC:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6680_587094799\131.0.6778.265_chrome_installer.exe
MD5:
SHA256:
6436updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:C73FCE4429C5F0DC0BFDF925E16C9E2E
SHA256:23C499F655A88251AE11385EE8B19DA604FBAD4C9C0C5035F092DBB60AA6B6DB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
56
DNS requests
54
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5980
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acqrj4kzqecdpjnekrbehcituafa_2025.1.8.0/niikhdgajlphfehepabhhblakbdgeefj_2025.01.08.00_all_hw756lmgdhcxnxdw3wekrfnvyq.crx3
unknown
whitelisted
5980
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acqrj4kzqecdpjnekrbehcituafa_2025.1.8.0/niikhdgajlphfehepabhhblakbdgeefj_2025.01.08.00_all_hw756lmgdhcxnxdw3wekrfnvyq.crx3
unknown
whitelisted
5980
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acqrj4kzqecdpjnekrbehcituafa_2025.1.8.0/niikhdgajlphfehepabhhblakbdgeefj_2025.01.08.00_all_hw756lmgdhcxnxdw3wekrfnvyq.crx3
unknown
whitelisted
5980
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acqrj4kzqecdpjnekrbehcituafa_2025.1.8.0/niikhdgajlphfehepabhhblakbdgeefj_2025.01.08.00_all_hw756lmgdhcxnxdw3wekrfnvyq.crx3
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
GET
200
142.250.185.227:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2548
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.49
  • 2.16.164.24
  • 2.16.164.51
  • 2.16.164.114
  • 2.16.164.99
  • 2.16.164.18
  • 2.16.164.97
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 95.101.149.131
whitelisted
google.com
  • 142.250.184.206
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
  • 2.23.227.221
  • 2.23.227.198
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.140
  • 40.126.32.74
  • 20.190.160.14
  • 20.190.160.17
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.76
whitelisted
dl.google.com
  • 142.250.186.174
whitelisted
update.googleapis.com
  • 142.250.185.67
  • 216.58.212.131
whitelisted
ocsp.pki.goog
  • 142.250.181.227
whitelisted
c.pki.goog
  • 142.250.185.227
whitelisted

Threats

No threats detected
No debug info