download:

/installers/windows/ChromeSetup.exe

Full analysis: https://app.any.run/tasks/f4300dfe-943c-4397-9a6d-046bfc07aeae
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: February 09, 2025, 11:53:48
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
auto
generic
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

D6490D72CBFE1C2FAD5FC8E89A7B39B3

SHA1:

030B756EB7AC5FD244C5B8A9F03D20CCA6155778

SHA256:

08D68B3CE8AD8E9ABE42AB427F7B9539251598BEC3A335E6D75C52B6F03BD58E

SSDEEP:

98304:effg337JihQyXP9KxXO7zPHNlSTARBslUnpIxGC2jKgHbwce/Unba+O+CB3jD9:2HNlBP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GENERIC has been found (auto)

      • ChromeSetup.exe (PID: 2232)
    • Actions looks like stealing of personal data

      • chrome.exe (PID: 1400)
      • chrome.exe (PID: 3808)
      • chrome.exe (PID: 2436)
    • Steals credentials from Web Browsers

      • chrome.exe (PID: 2436)
  • SUSPICIOUS

    • Application launched itself

      • ChromeSetup.exe (PID: 2232)
      • chrome.exe (PID: 2436)
      • chrome.exe (PID: 4392)
    • Potential Corporate Privacy Violation

      • ChromeSetup.exe (PID: 2324)
    • Reads the date of Windows installation

      • ChromeSetup.exe (PID: 2232)
      • ChromeSetup.exe (PID: 2324)
    • Reads security settings of Internet Explorer

      • ChromeSetup.exe (PID: 2232)
      • ChromeSetup.exe (PID: 2324)
    • There is functionality for taking screenshot (YARA)

      • ChromeSetup.exe (PID: 2324)
      • GoogleChromeInstall.exe (PID: 5464)
    • Process drops legitimate windows executable

      • GoogleChromeInstall.exe (PID: 5464)
    • Creates a software uninstall entry

      • GoogleChromeInstall.exe (PID: 5464)
    • Executable content was dropped or overwritten

      • GoogleChromeInstall.exe (PID: 5464)
    • The process checks if it is being run in the virtual environment

      • chrome.exe (PID: 2436)
    • Connects to unusual port

      • chrome.exe (PID: 1400)
  • INFO

    • Reads the computer name

      • ChromeSetup.exe (PID: 2232)
      • ChromeSetup.exe (PID: 2324)
      • chrome.exe (PID: 2436)
      • GoogleChromeInstall.exe (PID: 5464)
      • chrome.exe (PID: 4392)
      • chrome.exe (PID: 712)
      • chrome.exe (PID: 1400)
      • chrome.exe (PID: 6340)
    • Checks supported languages

      • ChromeSetup.exe (PID: 2232)
      • GoogleChromeInstall.exe (PID: 5464)
      • ChromeSetup.exe (PID: 2324)
      • chrome.exe (PID: 5316)
      • chrome.exe (PID: 4392)
      • chrome.exe (PID: 2436)
      • chrome.exe (PID: 712)
      • chrome.exe (PID: 2548)
      • chrome.exe (PID: 2632)
      • chrome.exe (PID: 6160)
      • chrome.exe (PID: 6228)
      • chrome.exe (PID: 1400)
      • chrome.exe (PID: 3808)
      • chrome.exe (PID: 6340)
    • The sample compiled with english language support

      • ChromeSetup.exe (PID: 2232)
      • GoogleChromeInstall.exe (PID: 5464)
    • Creates files or folders in the user directory

      • ChromeSetup.exe (PID: 2324)
      • GoogleChromeInstall.exe (PID: 5464)
      • chrome.exe (PID: 2436)
      • chrome.exe (PID: 1400)
    • Process checks computer location settings

      • ChromeSetup.exe (PID: 2232)
      • ChromeSetup.exe (PID: 2324)
      • chrome.exe (PID: 2548)
      • chrome.exe (PID: 2436)
      • chrome.exe (PID: 2632)
      • chrome.exe (PID: 6160)
      • chrome.exe (PID: 6228)
    • Creates files in the program directory

      • GoogleChromeInstall.exe (PID: 5464)
      • chrome.exe (PID: 2436)
    • Create files in a temporary directory

      • GoogleChromeInstall.exe (PID: 5464)
      • chrome.exe (PID: 2436)
    • Checks proxy server information

      • chrome.exe (PID: 2436)
    • Reads the machine GUID from the registry

      • chrome.exe (PID: 2436)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:12:19 12:37:58+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.16
CodeSize: 2155008
InitializedDataSize: 2418688
UninitializedDataSize: -
EntryPoint: 0x1b7984
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 132.0.6883.0
ProductVersionNumber: 132.0.6883.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google Inc.
FileDescription: Google Installer
FileVersion: 132.0.6883.0
InternalName: ChromeSetup.exe
LegalCopyright: Copyright 2024 Google LLC. All rights reserve
OriginalFileName: UpdateSetup.exe
ProductName: Google Installer
ProductVersion: 132.0.6883.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
14
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start chromesetup.exe no specs chromesetup.exe googlechromeinstall.exe chrome.exe chrome.exe chrome.exe chrome.exe no specs chrome.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
712"C:\Program Files (x86)\Qoom\Chrome\chrome.exe" --type=gpu-process --string-annotations --no-pre-read-main-dll --start-stack-profiler --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAADAAAMAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --metrics-shmem-handle=1792,i,5416329721927028252,9910403962422258604,262144 --field-trial-handle=1984,i,5066040463616350092,8790244695979560174,262144 --variations-seed-version --mojo-platform-channel-handle=1976 /prefetch:2C:\Program Files (x86)\Qoom\Chrome\chrome.exechrome.exe
User:
admin
Company:
The Chrome Authors
Integrity Level:
LOW
Description:
Chrome
Exit code:
0
Version:
132.0.6827.0
Modules
Images
c:\program files (x86)\qoom\chrome\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\qoom\chrome\132.0.6827.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1400"C:\Program Files (x86)\Qoom\Chrome\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=network --string-annotations --start-stack-profiler --metrics-shmem-handle=2116,i,4231965078612227671,8640479530251734692,524288 --field-trial-handle=2124,i,5066040463616350092,8790244695979560174,262144 --variations-seed-version --mojo-platform-channel-handle=2064 /prefetch:3C:\Program Files (x86)\Qoom\Chrome\chrome.exe
chrome.exe
User:
admin
Company:
The Chrome Authors
Integrity Level:
LOW
Description:
Chrome
Exit code:
0
Version:
132.0.6827.0
Modules
Images
c:\program files (x86)\qoom\chrome\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\qoom\chrome\132.0.6827.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2232"C:\Users\admin\Desktop\ChromeSetup.exe" C:\Users\admin\Desktop\ChromeSetup.exeexplorer.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Installer
Exit code:
0
Version:
132.0.6883.0
Modules
Images
c:\users\admin\desktop\chromesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2324"C:\Users\admin\Desktop\ChromeSetup.exe" 1C:\Users\admin\Desktop\ChromeSetup.exe
ChromeSetup.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
27
Version:
132.0.6883.0
Modules
Images
c:\users\admin\desktop\chromesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2436"C:\Program Files (x86)\Qoom\Chrome\chrome.exe"C:\Program Files (x86)\Qoom\Chrome\chrome.exe
GoogleChromeInstall.exe
User:
admin
Company:
The Chrome Authors
Integrity Level:
HIGH
Description:
Chrome
Exit code:
0
Version:
132.0.6827.0
Modules
Images
c:\program files (x86)\qoom\chrome\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\qoom\chrome\132.0.6827.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
2548"C:\Program Files (x86)\Qoom\Chrome\chrome.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --metrics-shmem-handle=3348,i,722332423387354712,2505185807654376398,2097152 --field-trial-handle=3364,i,5066040463616350092,8790244695979560174,262144 --variations-seed-version --mojo-platform-channel-handle=3360 /prefetch:1C:\Program Files (x86)\Qoom\Chrome\chrome.exechrome.exe
User:
admin
Company:
The Chrome Authors
Integrity Level:
LOW
Description:
Chrome
Exit code:
0
Version:
132.0.6827.0
Modules
Images
c:\program files (x86)\qoom\chrome\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\qoom\chrome\132.0.6827.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
2632"C:\Program Files (x86)\Qoom\Chrome\chrome.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --metrics-shmem-handle=3368,i,17387630245164917565,1649982745153438426,2097152 --field-trial-handle=3412,i,5066040463616350092,8790244695979560174,262144 --variations-seed-version --mojo-platform-channel-handle=3408 /prefetch:1C:\Program Files (x86)\Qoom\Chrome\chrome.exechrome.exe
User:
admin
Company:
The Chrome Authors
Integrity Level:
LOW
Description:
Chrome
Exit code:
0
Version:
132.0.6827.0
Modules
Images
c:\program files (x86)\qoom\chrome\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\qoom\chrome\132.0.6827.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
3808"C:\Program Files (x86)\Qoom\Chrome\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --string-annotations --metrics-shmem-handle=2592,i,5265301152603714590,16695414999763958913,524288 --field-trial-handle=2616,i,5066040463616350092,8790244695979560174,262144 --variations-seed-version --mojo-platform-channel-handle=2612 /prefetch:8C:\Program Files (x86)\Qoom\Chrome\chrome.exe
chrome.exe
User:
admin
Company:
The Chrome Authors
Integrity Level:
LOW
Description:
Chrome
Exit code:
0
Version:
132.0.6827.0
Modules
Images
c:\program files (x86)\qoom\chrome\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\qoom\chrome\132.0.6827.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
4392"C:\Program Files (x86)\Qoom\Chrome\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Chromium\User Data" /prefetch:4 --monitor-self --monitor-self-argument=--type=crashpad-handler "--monitor-self-argument=--user-data-dir=C:\Users\admin\AppData\Local\Chromium\User Data" --monitor-self-argument=/prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Chromium\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=132.0.6827.0 --initial-client-data=0x148,0x14c,0x150,0x124,0x154,0x7ff82191e7b8,0x7ff82191e7c4,0x7ff82191e7d0C:\Program Files (x86)\Qoom\Chrome\chrome.exe
chrome.exe
User:
admin
Company:
The Chrome Authors
Integrity Level:
HIGH
Description:
Chrome
Exit code:
1
Version:
132.0.6827.0
Modules
Images
c:\program files (x86)\qoom\chrome\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\qoom\chrome\132.0.6827.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
5316"C:\Program Files (x86)\Qoom\Chrome\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Chromium\User Data" /prefetch:4 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Chromium\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=132.0.6827.0 --initial-client-data=0x1ac,0x1b0,0x1b4,0x168,0x1b8,0x7ff789c6da80,0x7ff789c6da8c,0x7ff789c6da98C:\Program Files (x86)\Qoom\Chrome\chrome.exe
chrome.exe
User:
admin
Company:
The Chrome Authors
Integrity Level:
HIGH
Description:
Chrome
Exit code:
1
Version:
132.0.6827.0
Modules
Images
c:\program files (x86)\qoom\chrome\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\qoom\chrome\132.0.6827.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
Total events
4 039
Read events
3 993
Write events
43
Delete events
3

Modification events

(PID) Process:(5464) GoogleChromeInstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
Operation:writeName:DisplayName
Value:
Google Chrome 132.0.6827.0
(PID) Process:(5464) GoogleChromeInstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\Qoom\Chrome\uninst.exe
(PID) Process:(5464) GoogleChromeInstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\Qoom\Chrome\chrome.exe
(PID) Process:(5464) GoogleChromeInstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
Operation:writeName:DisplayVersion
Value:
132.0.6827.0
(PID) Process:(2436) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Chromium\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2436) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Chromium
Operation:writeName:UsageStatsInSample
Value:
1
(PID) Process:(2436) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Chromium
Operation:writeName:usagestats
Value:
0
(PID) Process:(2436) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Chromium
Operation:writeName:metricsid
Value:
(PID) Process:(2436) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Chromium
Operation:writeName:metricsid_installdate
Value:
0
(PID) Process:(2436) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Chromium
Operation:writeName:metricsid_enableddate
Value:
0
Executable files
20
Suspicious files
586
Text files
58
Unknown types
0

Dropped files

PID
Process
Filename
Type
2324ChromeSetup.exeC:\Users\admin\AppData\Local\GoogleChromeInstall.exe
MD5:
SHA256:
5464GoogleChromeInstall.exeC:\Program Files (x86)\Qoom\Chrome\132.0.6827.0\chrome.dll
MD5:
SHA256:
5464GoogleChromeInstall.exeC:\Program Files (x86)\Qoom\Chrome\132.0.6827.0\icudtl.dat
MD5:
SHA256:
5464GoogleChromeInstall.exeC:\Program Files (x86)\Qoom\Chrome\132.0.6827.0\resources.pak
MD5:
SHA256:
5464GoogleChromeInstall.exeC:\Program Files (x86)\Qoom\Chrome\132.0.6827.0\dxcompiler.dllexecutable
MD5:3268039C7C1C3D06990B294171EF0BB5
SHA256:C1D2ADAB558928C2540A765E3DF197C738D2B8C56EF12C53DAEF5B6234F48B1A
5464GoogleChromeInstall.exeC:\Program Files (x86)\Qoom\Chrome\132.0.6827.0\chrome_200_percent.pakbinary
MD5:C049DDA42F2AF24CD9BA3EA737B06593
SHA256:6F63E18527919EF6022C85FC5B140745BB90E3A6F1DE98F804CDCBE488C67AFC
5464GoogleChromeInstall.exeC:\Program Files (x86)\Qoom\Chrome\132.0.6827.0\132.0.6827.0.manifesttext
MD5:A3CF0F46CB3D5956EBE194919EA56EA1
SHA256:AAF254A0CD86054A24805E8E0798CF008F6E0D961704534B099B6B7F1935B38D
5464GoogleChromeInstall.exeC:\Program Files (x86)\Qoom\Chrome\132.0.6827.0\chrome_pwa_launcher.exeexecutable
MD5:62C8F42E4012BCF9D5748FFF692C5FDE
SHA256:E4A81A8E7A51643BC65131C6F5B9C1E4E4B6E2D7591709D64CDD5EAB0702D748
5464GoogleChromeInstall.exeC:\Program Files (x86)\Qoom\Chrome\132.0.6827.0\chrome_wer.dllexecutable
MD5:62E3200E71958D7730B74227E6487D31
SHA256:B2997953E20A18FCA264F9B3D986523AE78964099DDD5AF0CA4D4FCCE68D5B29
5464GoogleChromeInstall.exeC:\Program Files (x86)\Qoom\Chrome\132.0.6827.0\v8_context_snapshot.binbinary
MD5:AC862044205C66FA766C9AEBB54DCC0B
SHA256:CDBB6F7CDDEB7EF1C25895EA9C8D9B14355BF3E62A57D9E54B1550BB27DF70CD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
48
DNS requests
40
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2324
ChromeSetup.exe
GET
110.42.46.21:80
http://setup.googoogle.cn/installer/Windows/win10/install.exe
unknown
unknown
5064
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5252
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5252
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3208
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1400
chrome.exe
GET
200
142.250.185.78:80
http://clients2.google.com/time/1/current?cup2key=8:LPliFBEH-PE_-i6EQapH1D4wNHySJoCD5uLcdxmhIHE&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2324
ChromeSetup.exe
110.42.46.21:80
setup.googoogle.cn
NINGBO, ZHEJIANG Province, P.R.China.
CN
unknown
5880
svchost.exe
52.140.118.28:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IN
whitelisted
5064
SearchApp.exe
2.21.65.132:443
www.bing.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
setup.googoogle.cn
  • 110.42.46.21
unknown
settings-win.data.microsoft.com
  • 52.140.118.28
whitelisted
www.bing.com
  • 2.21.65.132
  • 2.21.65.154
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.129
  • 40.126.31.71
  • 20.190.159.71
  • 40.126.31.131
  • 20.190.159.2
  • 40.126.31.1
  • 40.126.31.3
  • 20.190.159.68
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted

Threats

PID
Process
Class
Message
2324
ChromeSetup.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
1400
chrome.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
1400
chrome.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
1400
chrome.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
1400
chrome.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
1400
chrome.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
1400
chrome.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
1400
chrome.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
1400
chrome.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
1400
chrome.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
Process
Message
ChromeSetup.exe
percent:1 sec:2 all: 199
ChromeSetup.exe
percent:1
ChromeSetup.exe
percent:2
ChromeSetup.exe
percent:2 sec:3 all: 148
ChromeSetup.exe
percent:3
ChromeSetup.exe
percent:3 sec:3 all: 98
ChromeSetup.exe
percent:4 sec:4 all: 97
ChromeSetup.exe
percent:4
ChromeSetup.exe
percent:5 sec:4 all: 77
ChromeSetup.exe
percent:5