File name:

ChormeGPT_install.exe

Full analysis: https://app.any.run/tasks/fce7cc3c-60e0-4eee-958d-dfe2507a65e2
Verdict: Malicious activity
Analysis date: November 11, 2024, 07:51:03
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

AD90E265345CD45C02B3698D60A53337

SHA1:

B2DC1C2D1E8162DED9D83248F4453D4B0C8B0BE1

SHA256:

04E45B9D973EABE61733CB378B607C7A8EB8890E0F1C588B2DB0AADD1C03F9B5

SSDEEP:

98304:CjC+FubTuta5+ag0hfIJvnEgAZHEt7Rt+/KMagvVQQzhCR2hELS/2u2LwIBQIQ:z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • ChormeGPT_install.exe (PID: 5828)
      • GptBrowser.exe (PID: 3860)
      • GptBrowser.exe (PID: 1884)
      • GptBrowser.exe (PID: 2100)
      • GptBrowser.exe (PID: 3024)
      • GptBrowser.exe (PID: 2652)
      • GptBrowser.exe (PID: 5496)
    • Reads security settings of Internet Explorer

      • ChormeGPT_install.exe (PID: 5828)
    • Process drops legitimate windows executable

      • 7za.exe (PID: 2428)
    • Executable content was dropped or overwritten

      • ChormeGPT_install.exe (PID: 4508)
      • 7za.exe (PID: 2428)
      • GptBrowser.exe (PID: 7980)
    • Executes as Windows Service

      • GptChromeService.exe (PID: 7056)
    • Drops 7-zip archiver for unpacking

      • ChormeGPT_install.exe (PID: 4508)
    • Connects to the server without a host name

      • GptBrowser.exe (PID: 2376)
  • INFO

    • Checks supported languages

      • ChormeGPT_install.exe (PID: 4508)
      • ChormeGPT_install.exe (PID: 5828)
    • Reads the computer name

      • ChormeGPT_install.exe (PID: 5828)
      • ChormeGPT_install.exe (PID: 4508)
    • The process uses the downloaded file

      • ChormeGPT_install.exe (PID: 5828)
    • Process checks computer location settings

      • ChormeGPT_install.exe (PID: 5828)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:22 17:03:04+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.35
CodeSize: 927232
InitializedDataSize: 1783296
UninitializedDataSize: -
EntryPoint: 0xb83be
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 109.0.5414.185
ProductVersionNumber: 109.0.5414.185
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: Guangxi Yuehai Yinghua Network Technology Co., Ltd.
FileDescription: GPT浏览器安装程序
FileVersion: 109.0.5414.185
InternalName: GptChrome
LegalCopyright: Copyright (C) 2024
OriginalFileName: GptChrome
ProductName: GPT浏览器
ProductVersion: 109.0.5414.185
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
197
Monitored processes
61
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start chormegpt_install.exe no specs chormegpt_install.exe 7za.exe conhost.exe no specs explorer.exe no specs explorer.exe no specs gptbrowser.exe gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe gptbrowser.exe no specs gptbrowser.exe no specs gptchromeservice.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs spupdate.exe gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
780"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3992,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=4004 /prefetch:2C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.205
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.205\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
848"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --field-trial-handle=5316,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=5444 /prefetch:1C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.205
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.205\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1112"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --field-trial-handle=5292,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=5308 /prefetch:1C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.205
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.205\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1432"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=4372,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=4388 /prefetch:2C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.205
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.205\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1792"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --field-trial-handle=5888,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=5288 /prefetch:1C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Version:
128.0.6541.205
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.205\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1884"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe
explorer.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
MEDIUM
Description:
GptBrowser
Version:
128.0.6541.205
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.205\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
2100C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\SPChrome\User Data" /prefetch:4 --monitor-self --monitor-self-argument=--type=crashpad-handler "--monitor-self-argument=--user-data-dir=C:\Users\admin\AppData\Local\SPChrome\User Data" --monitor-self-argument=/prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\SPChrome\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=GptBrowser --annotation=ver=128.0.6541.205 --initial-client-data=0x128,0x12c,0x130,0x100,0x134,0x7ffbca57fea8,0x7ffbca57feb4,0x7ffbca57fec0C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
MEDIUM
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.205
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.205\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2376"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --start-stack-profiler --field-trial-handle=2200,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=2320 /prefetch:3C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe
GptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
MEDIUM
Description:
GptBrowser
Version:
128.0.6541.205
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.205\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
2428"C:\Users\admin\AppData\Local\GptChrome\7za.exe" x "C:\Users\admin\AppData\Local\GptChrome\GInstallerPkg" -o"C:\Users\admin\AppData\Local\GptChrome" -aoa -y -p"ydhffhJsffFEfvgyu"C:\Users\admin\AppData\Local\GptChrome\7za.exe
ChormeGPT_install.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
19.00
Modules
Images
c:\users\admin\appdata\local\gptchrome\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2576C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\SPChrome\User Data" /prefetch:4 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\SPChrome\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=GptBrowser --annotation=ver=128.0.6541.205 --initial-client-data=0x164,0x168,0x16c,0x160,0x170,0x7ff6f4e18bf8,0x7ff6f4e18c04,0x7ff6f4e18c10C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
MEDIUM
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.205
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.205\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
Total events
24 632
Read events
24 519
Write events
106
Delete events
7

Modification events

(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\GptChrome\VisualElements\logo.ico
(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:DisplayName
Value:
GPT Chrome
(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\GptChrome
(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:Publisher
Value:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\GptChrome\uninstall.exe" --uninstall
(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:PackageName
Value:
ChormeGPT_install.exe
(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:DisplayVersion
Value:
109.0.5414.185
(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:InstallDate
Value:
1731311551
(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TSBrowserHTM.pdf\Application
Operation:writeName:ApplicationCompany
Value:
The GPT Chrome Authors
(PID) Process:(4508) ChormeGPT_install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TSBrowserHTM.pdf\Application
Operation:writeName:ApplicationDescription
Value:
访问互联网
Executable files
23
Suspicious files
279
Text files
89
Unknown types
8

Dropped files

PID
Process
Filename
Type
4508ChormeGPT_install.exeC:\Users\admin\AppData\Local\GptChrome\GInstallerPkg
MD5:
SHA256:
24287za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome.dll
MD5:
SHA256:
24287za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\icudtl.dat
MD5:
SHA256:
24287za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\icudtlex.dat
MD5:
SHA256:
24287za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome_pwa_launcher.exeexecutable
MD5:4A045F2A32E2FF6AECA13997C680F4F2
SHA256:7932C54BECE0F013F3318AD5181475C3640EBD16A19D532B51C27749F96CA05C
24287za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome_100_percent.pakbinary
MD5:A03FA168AFB041E27788865B74F96730
SHA256:75EA7BCF8FE9C4414D5C25F70250D733FFF3E00BD1213DDEAC2B564322AA3CB5
24287za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome_wer.dllexecutable
MD5:9E734A474804E05A70D78817640F930A
SHA256:B653855E7E7AFB59BC50288B048F6D3D5B002A7C3346853B0B78F659E1EFB8F3
24287za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\Locales\af.pakmmw
MD5:167427A06792D7687A6F4A9ABFDB5CDD
SHA256:74329D124075805A3C2968D8953A6D81B694A0022FC589CF5FC02B153F7D208A
24287za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome_200_percent.pakpgc
MD5:4ECE10C466D301B83BDBF9F59EBBC905
SHA256:E2D6D21A799C8E2BB34C24CA5405E1BA67389BB833FF0CFC0AB6A17BF124E77E
24287za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\dxcompiler.dllexecutable
MD5:DA3E2B1B3F8DF28835C7E6A8370968D1
SHA256:57E1E35752E8C16FAA067542BA6EF5D75BDD2A451174B6765AFC96B9E69FA996
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
57
DNS requests
75
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4508
ChormeGPT_install.exe
GET
200
121.199.42.172:80
http://work.yhyhtech.com/afg/?para=+VJCMTVAyvGG0tTizjEIow6U4GaFOKaXneGrhDZGy4mmUQMXwzGBmHwmsI3pRq5pPRwQxF/oSWZpWLktQYP056AIOl78FP6Iop7LkBuvQ64RQ3o+qeSes71T9F7T2wz2GwD5npbTPrZxo8oDA1XcXxlyR3ziM8K+xkFULz/q/Vd57af0C0w/2Ayl9UGO7lLeodQmAKqeS8r80m3grrWmm1EFQHV9kAJBfcTjF/mAD/Y=
unknown
unknown
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4508
ChormeGPT_install.exe
GET
200
121.199.42.172:80
http://work.yhyhtech.com/mm/
unknown
unknown
4508
ChormeGPT_install.exe
GET
121.199.42.172:80
http://work.yhyhtech.com/afg/?para=GNXYbx/fYXOcz4idWG2NxA6U4GaFOKaXneGrhDZGy4mmUQMXwzGBmHwmsI3pRq5pPRwQxF/oSWZpWLktQYP056AIOl78FP6Iop7LkBuvQ64RQ3o+qeSes71T9F7T2wz2GwD5npbTPrZxo8oDA1XcXxlyR3ziM8K+xkFULz/q/Vd57af0C0w/2Ayl9UGO7lLeodQmAKqeS8r80m3grrWmm1EFQHV9kAJBfcTjF/mAD/Y=
unknown
unknown
5488
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4376
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4508
ChormeGPT_install.exe
GET
221.178.86.52:80
http://dw.gptchrome.net/bropkg/GInstallerx64-185
unknown
unknown
7124
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7124
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7060
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4360
SearchApp.exe
2.23.209.154:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4508
ChormeGPT_install.exe
121.199.42.172:80
work.yhyhtech.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
4376
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4376
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 172.217.16.142
whitelisted
www.bing.com
  • 2.23.209.154
  • 2.23.209.156
  • 2.23.209.142
  • 2.23.209.143
  • 2.23.209.141
  • 2.23.209.144
  • 2.23.209.149
  • 2.23.209.158
  • 2.23.209.150
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
work.yhyhtech.com
  • 121.199.42.172
unknown
login.live.com
  • 20.190.159.4
  • 40.126.31.73
  • 20.190.159.64
  • 20.190.159.2
  • 20.190.159.73
  • 40.126.31.71
  • 20.190.159.68
  • 20.190.159.71
whitelisted
th.bing.com
  • 2.23.209.166
  • 2.23.209.161
  • 2.23.209.168
  • 2.23.209.167
  • 2.23.209.156
  • 2.23.209.171
  • 2.23.209.154
  • 2.23.209.162
  • 2.23.209.158
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

PID
Process
Class
Message
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2376
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info