File name:

chrome_cleanup_tool.exe

Full analysis: https://app.any.run/tasks/e603abd1-e6fc-4eea-8f9d-75dcd3a95250
Verdict: Malicious activity
Analysis date: May 17, 2025, 22:00:41
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

6D5C239321C8F27727C44B132B18E793

SHA1:

BC8EEC8D94E81447694940E8BD77EB84E5AF3135

SHA256:

0B17E676A6292722618BB4D1235B5D6C29C65099318BDF60280008B6B04C4622

SSDEEP:

98304:da/mxEqIEMH10Nr+v+yAFrwfSRFMcstJdSk4mUiwkHWLYy6rS07777777777N774:X

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • chrome_cleanup_tool.exe (PID: 5024)
      • chrome_cleanup_tool.exe (PID: 7268)
  • SUSPICIOUS

    • Application launched itself

      • chrome_cleanup_tool.exe (PID: 5024)
      • chrome_cleanup_tool.exe (PID: 7220)
    • Reads security settings of Internet Explorer

      • chrome_cleanup_tool.exe (PID: 5024)
    • The process verifies whether the antivirus software is installed

      • chrome_cleanup_tool.exe (PID: 7220)
    • Executable content was dropped or overwritten

      • chrome_cleanup_tool.exe (PID: 7220)
  • INFO

    • The sample compiled with english language support

      • chrome_cleanup_tool.exe (PID: 5024)
      • chrome_cleanup_tool.exe (PID: 7220)
    • Creates files or folders in the user directory

      • chrome_cleanup_tool.exe (PID: 672)
      • chrome_cleanup_tool.exe (PID: 7220)
    • Checks supported languages

      • chrome_cleanup_tool.exe (PID: 5024)
      • chrome_cleanup_tool.exe (PID: 672)
      • chrome_cleanup_tool.exe (PID: 7220)
      • chrome_cleanup_tool.exe (PID: 7268)
      • ChromeRecovery.exe (PID: 7368)
    • Reads the computer name

      • chrome_cleanup_tool.exe (PID: 5024)
      • chrome_cleanup_tool.exe (PID: 7220)
      • ChromeRecovery.exe (PID: 7368)
    • Process checks computer location settings

      • chrome_cleanup_tool.exe (PID: 5024)
    • Checks proxy server information

      • chrome_cleanup_tool.exe (PID: 7220)
      • ChromeRecovery.exe (PID: 7368)
      • slui.exe (PID: 8164)
    • Reads the software policy settings

      • chrome_cleanup_tool.exe (PID: 7220)
      • slui.exe (PID: 7436)
      • slui.exe (PID: 8164)
      • ChromeRecovery.exe (PID: 7368)
    • Create files in a temporary directory

      • chrome_cleanup_tool.exe (PID: 7220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:12:07 18:42:10+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1873920
InitializedDataSize: 2062848
UninitializedDataSize: -
EntryPoint: 0x17bf20
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 23.131.2.0
ProductVersionNumber: 23.131.2.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google
FileDescription: Chrome Cleanup Tool
FileVersion: 23.131.2
InternalName: chrome_cleanup_tool_exe
LegalCopyright: Copyright 2015 Google Inc. All Rights Reserved.
OriginalFileName: chrome_cleanup.exe
ProductName: Chrome Cleanup Tool
ProductVersion: 23.131.2
CompanyShortName: Google
ProductShortName: Chrome Cleanup Tool
LastChange: 20ca293ce8c191e2db51fa2093203354fa719c9a-
OfficialBuild: 1
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
10
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start chrome_cleanup_tool.exe no specs chrome_cleanup_tool.exe no specs chrome_cleanup_tool.exe rundll32.exe no specs chrome_cleanup_tool.exe no specs chromerecovery.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
672c:\users\admin\appdata\local\temp\chrome_cleanup_tool.exe --crash-handler "--database=c:\users\admin\appdata\local\Google\Chrome Cleanup Tool" --url=https://clients2.google.com/cr/report --annotation=plat=Win32 --annotation=prod=ChromeFoil --annotation=ver=23.131.2 --initial-client-data=0x2b4,0x2f8,0x2fc,0x2e4,0x300,0x5b9138,0x5b9148,0x5b9158C:\Users\admin\AppData\Local\Temp\chrome_cleanup_tool.exechrome_cleanup_tool.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Chrome Cleanup Tool
Exit code:
0
Version:
23.131.2
Modules
Images
c:\users\admin\appdata\local\temp\chrome_cleanup_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
5024"C:\Users\admin\AppData\Local\Temp\chrome_cleanup_tool.exe" C:\Users\admin\AppData\Local\Temp\chrome_cleanup_tool.exeexplorer.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Chrome Cleanup Tool
Exit code:
0
Version:
23.131.2
Modules
Images
c:\users\admin\appdata\local\temp\chrome_cleanup_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
7220"C:\Users\admin\AppData\Local\Temp\chrome_cleanup_tool.exe" --elevatedC:\Users\admin\AppData\Local\Temp\chrome_cleanup_tool.exe
chrome_cleanup_tool.exe
User:
admin
Company:
Google
Integrity Level:
HIGH
Description:
Chrome Cleanup Tool
Exit code:
2
Version:
23.131.2
Modules
Images
c:\users\admin\appdata\local\temp\chrome_cleanup_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
7244C:\WINDOWS\System32\rundll32.exeC:\Windows\SysWOW64\rundll32.exechrome_cleanup_tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7268c:\users\admin\appdata\local\temp\chrome_cleanup_tool.exe --crash-handler "--database=c:\users\admin\appdata\local\Google\Chrome Cleanup Tool" --url=https://clients2.google.com/cr/report --annotation=plat=Win32 --annotation=prod=ChromeFoil --annotation=ver=23.131.2 --initial-client-data=0x2f4,0x2f8,0x2fc,0x2f0,0x300,0x5b9138,0x5b9148,0x5b9158C:\Users\admin\AppData\Local\Temp\chrome_cleanup_tool.exechrome_cleanup_tool.exe
User:
admin
Company:
Google
Integrity Level:
HIGH
Description:
Chrome Cleanup Tool
Exit code:
0
Version:
23.131.2
Modules
Images
c:\users\admin\appdata\local\temp\chrome_cleanup_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
7368"C:\Users\admin\AppData\Local\Temp\scoped_dir7220_32433\ChromeRecovery.exe" /installsource swreporterC:\Users\admin\AppData\Local\Temp\scoped_dir7220_32433\ChromeRecovery.exe
chrome_cleanup_tool.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Update
Exit code:
1
Version:
1.3.36.371
Modules
Images
c:\users\admin\appdata\local\temp\scoped_dir7220_32433\chromerecovery.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7404C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7436"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7872C:\WINDOWS\System32\rundll32.exeC:\Windows\SysWOW64\rundll32.exechrome_cleanup_tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
8164C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
7 737
Read events
7 516
Write events
210
Delete events
11

Modification events

(PID) Process:(5024) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner
Operation:delete valueName:ExitCode
Value:
(PID) Process:(5024) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner
Operation:delete valueName:EndTime
Value:
(PID) Process:(5024) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner
Operation:writeName:Version
Value:
385909506
(PID) Process:(5024) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner
Operation:writeName:StartTime
Value:
03447A50F2932F00
(PID) Process:(7220) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner
Operation:delete valueName:ExitCode
Value:
(PID) Process:(7220) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner
Operation:delete valueName:EndTime
Value:
傅鏲/
(PID) Process:(7220) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner
Operation:writeName:Version
Value:
385909506
(PID) Process:(7220) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner
Operation:writeName:StartTime
Value:
CA928850F2932F00
(PID) Process:(7220) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner\ScanTimes
Operation:writeName:81
Value:
0000000000000000
(PID) Process:(7220) chrome_cleanup_tool.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Software Removal Tool\Cleaner\ScanTimes
Operation:writeName:11
Value:
443D000000000000
Executable files
2
Suspicious files
4
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
7220chrome_cleanup_tool.exeC:\Users\admin\AppData\Local\Temp\d5a1c2e1-b6ca-43ca-9d10-47962df9d05c.tmpbinary
MD5:E27F4B2C2F296D1F9229229B4F050B4F
SHA256:8BF126139E9BE41FB216BA3B753852C1330A73E2D33056409E3C3125F578998F
7220chrome_cleanup_tool.exeC:\Users\admin\AppData\Local\Temp\scoped_dir7220_32433\manifest.jsonbinary
MD5:CAD62D7AFBC543640472AC29412C2FA1
SHA256:C0D0872AA6037C6FE4A904D6039DD657F438ECE6199EDB8E087BDF2E651FA24C
672chrome_cleanup_tool.exeC:\Users\admin\AppData\Local\Google\Chrome Cleanup Tool\settings.datbinary
MD5:1DA61404157E9D90DCA4134848836794
SHA256:737DA235105ACF6A76FF385A5B4613FE6C2ABFE7DD82BC502523BEC40706E97B
5024chrome_cleanup_tool.exeC:\Users\admin\AppData\Local\Google\Chrome Cleanup Tool\chrome_cleanup.logtext
MD5:BCF1684441ED021A9A3C2BD6A033E078
SHA256:BDB99B1A1C26547C91E9EDBD050FAFA0051A7EB4BE831FDCAF7B959F7BAE6A49
7220chrome_cleanup_tool.exeC:\Users\admin\AppData\Local\Google\Chrome Cleanup Tool\4023fabc-2a4c-41c3-a213-ca33493bb76c.tmpbinary
MD5:9C28F8208E314D2F793A2FA20605DB20
SHA256:D559608E28B05641ABFA84FBF94FE7A87A14A5EA1DCFA0D4ECDB3C398FFE67DB
7220chrome_cleanup_tool.exeC:\Users\admin\AppData\Local\Temp\scoped_dir7220_32433\_metadata\verified_contents.jsontext
MD5:A8E5E52D9C2FE8E315E7A56965FB28E9
SHA256:2455478D250482CCD1C56A9A24E623D1CDA1F1F0BBB9E5087EBFAF1E073D3A2E
7220chrome_cleanup_tool.exeC:\Users\admin\AppData\Local\Google\Chrome Cleanup Tool\chrome_cleanup-elevated.logtext
MD5:BD4A2DB6AECABA9DA4FFEB14B936E156
SHA256:597709A5B95876CFCBE7B9366B40D3DEF23A72B59C30D8EBF8F49E1F0E90DB29
7220chrome_cleanup_tool.exeC:\Users\admin\AppData\Local\Temp\scoped_dir7220_32433\ChromeRecovery.exeexecutable
MD5:8C6AEED53A857F9C435CB2B430E9A8CE
SHA256:77CD1506A72643A1A3612F572B0D3A79D52AFC978E524ABC6E121108161DCF6F
672chrome_cleanup_tool.exeC:\Users\admin\AppData\Local\Google\Chrome Cleanup Tool\chrome_cleanup-crashpad.logtext
MD5:57CF4B9E2B458F71840C77CFDD255C15
SHA256:EEFE615907DADA0E0BF9F4326CCCDC07023918CB5F9CDAE0A851342A0F352A9C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
25
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8004
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8004
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2104
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
7220
chrome_cleanup_tool.exe
142.250.186.174:443
clients2.google.com
GOOGLE
US
whitelisted
7220
chrome_cleanup_tool.exe
142.250.181.228:443
www.google.com
GOOGLE
US
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7368
ChromeRecovery.exe
142.250.186.35:443
update.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.31
  • 23.216.77.28
  • 23.216.77.5
  • 23.216.77.38
  • 23.216.77.29
  • 23.216.77.39
  • 23.216.77.30
  • 23.216.77.35
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
clients2.google.com
  • 142.250.186.174
whitelisted
www.google.com
  • 142.250.181.228
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
update.googleapis.com
  • 142.250.186.35
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.4
  • 20.190.159.68
  • 20.190.159.129
  • 20.190.159.71
  • 40.126.31.128
  • 20.190.159.130
  • 40.126.31.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info