| File name: | ChromeSetup.exe |
| Full analysis: | https://app.any.run/tasks/4689e262-0080-4ae9-a764-963c61a7022c |
| Verdict: | Malicious activity |
| Analysis date: | April 21, 2025, 15:59:03 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections |
| MD5: | 5A0A90E06F6B21C644F35081760C42B5 |
| SHA1: | DAF6F4560C19CB8879D075EB858B95DEE59DDA1A |
| SHA256: | 178A2CAC1C614775E24734ED47866EB111D5EB55877096D59920F98CA798AA9B |
| SSDEEP: | 98304:8YPRFCwRshSrbVvMsdPLsL+ZDT7YyDRB+6qZIq+fpwamXo6eAgdR9lVVwto7h0oh:9Wo |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:04:17 03:02:18+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 3718656 |
| InitializedDataSize: | 7758848 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1d67f0 |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 137.0.7129.0 |
| ProductVersionNumber: | 137.0.7129.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Installer (x86) |
| FileVersion: | 137.0.7129.0 |
| InternalName: | Google Installer (x86) |
| LegalCopyright: | Copyright 2025 Google LLC. All rights reserved. |
| OriginalFileName: | UpdaterSetup.exe |
| ProductName: | Google Installer (x86) |
| ProductVersion: | 137.0.7129.0 |
| CompanyShortName: | |
| ProductShortName: | GoogleUpdater |
| LastChange: | 5e9882868787d2a10021e0b7c6311f65b754c444-refs/branch-heads/7129@{#1} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 616 | "C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe" | C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Installer (x86) Version: 137.0.7129.0 Modules
| |||||||||||||||
| 1328 | "C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\CR_B4D68.tmp\setup.exe" --install-archive="C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\CR_B4D68.tmp\CHROME.PACKED.7Z" --verbose-logging --do-not-launch-chrome --channel=stable --installerdata="C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\270659c8-0116-4a69-849a-ed814339edd6.tmp" | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\CR_B4D68.tmp\setup.exe | 135.0.7049.96_chrome_installer.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Installer Exit code: 0 Version: 135.0.7049.96 Modules
| |||||||||||||||
| 1348 | C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\CR_B4D68.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=135.0.7049.96 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x7ff7167255b8,0x7ff7167255c4,0x7ff7167255d0 | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\CR_B4D68.tmp\setup.exe | — | setup.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Installer Exit code: 0 Version: 135.0.7049.96 Modules
| |||||||||||||||
| 2240 | "C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\135.0.7049.96_chrome_installer.exe" --verbose-logging --do-not-launch-chrome --channel=stable --installerdata="C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\270659c8-0116-4a69-849a-ed814339edd6.tmp" | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\135.0.7049.96_chrome_installer.exe | updater.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Installer Exit code: 0 Version: 135.0.7049.96 Modules
| |||||||||||||||
| 3900 | "C:\WINDOWS\SystemTemp\Google5968_1384100505\bin\updater.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={391009BF-0F07-616E-C9AC-449D08012F3D}&lang=en&browser=5&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevated | C:\Windows\SystemTemp\Google5968_1384100505\bin\updater.exe | ChromeSetup.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Updater (x86) Exit code: 0 Version: 137.0.7129.0 Modules
| |||||||||||||||
| 4040 | "C:\Program Files (x86)\Google\GoogleUpdater\137.0.7129.0\updater.exe" --system --windows-service --service=update-internal | C:\Program Files (x86)\Google\GoogleUpdater\137.0.7129.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater (x86) Exit code: 0 Version: 137.0.7129.0 Modules
| |||||||||||||||
| 4628 | C:\WINDOWS\SystemTemp\Google5968_1384100505\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\137.0.7129.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=137.0.7129.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a8,0x2ac,0x2b0,0x284,0x2b4,0xe77e50,0xe77e5c,0xe77e68 | C:\Windows\SystemTemp\Google5968_1384100505\bin\updater.exe | — | updater.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Updater (x86) Exit code: 0 Version: 137.0.7129.0 Modules
| |||||||||||||||
| 4740 | "C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\CR_B4D68.tmp\setup.exe" --channel=stable --system-level --verbose-logging --create-shortcuts=2 --install-level=1 | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\CR_B4D68.tmp\setup.exe | — | setup.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Installer Exit code: 73 Version: 135.0.7049.96 Modules
| |||||||||||||||
| 5344 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --from-installer | C:\Program Files\Google\Chrome\Application\chrome.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 135.0.7049.96 Modules
| |||||||||||||||
| 5600 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4040) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{247954F9-9EDC-4E68-8CC3-150C2B89EADF}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (4040) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{494B20CF-282E-4BDD-9F5D-B70CB09D351E}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (4040) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{494B20CF-282E-4BDD-9F5D-B70CB09D351E}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (4040) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{F63F6F8B-ACD5-413C-A44B-0409136D26CB}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (4040) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F63F6F8B-ACD5-413C-A44B-0409136D26CB}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (4040) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{34527502-D3DB-4205-A69B-789B27EE0414}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (5988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 137.0.7129.0 | |||
| (PID) Process: | (3900) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 137.0.7129.0 | |||
| (PID) Process: | (3900) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (3900) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 137.0.7129.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5968 | ChromeSetup.exe | C:\Windows\SystemTemp\Google5968_1118390115\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 3900 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\updater.log | text | |
MD5:3F82678119014E91EF3296092BAD5575 | SHA256:1EDC22D225A6202D9379B82D2EBCC210FC56A80FFA48EB54BCBA1839731BEFB2 | |||
| 3900 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D6AA22DA63AEAA61826C0D7C76455F33_438C9676D2A7E56564A97E1F656C97D6 | binary | |
MD5:0AA061D1589682E0E8EF51EDA07232AE | SHA256:365143F85743A8A9ABF4FE647233FCE3C06DA7A482601467D9E7EE9E941B617A | |||
| 3900 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 | binary | |
MD5:53220098DFB13E5BCA9FC1B38849930D | SHA256:64230C0B6ED3A7235FBD798F64423CD019F56E5D4BFDA96FB94F245AAD050085 | |||
| 3900 | updater.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\{8a69d345-d564-463c-aff1-a69d9e530f96}[1].bmp | image | |
MD5:64C3009B9F0526A4FD2C8A9825B86F7D | SHA256:B49EDF5F970FA5B4D0608C2934053929E20D54C5E052164B4D2B375F2CB7E409 | |||
| 3900 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D6AA22DA63AEAA61826C0D7C76455F33_438C9676D2A7E56564A97E1F656C97D6 | binary | |
MD5:B2B20F77E5876E7CD9100BB121A4D0A6 | SHA256:0FE633EB9FAAA2D4F768A36F5936404F7A030F8848A0D30A56024587148FD4A7 | |||
| 3900 | updater.exe | C:\Users\admin\AppData\Local\Temp\~DF7A3EF1249D23A218.TMP | binary | |
MD5:0FAC4740082325413BFCE8A3DE5F4D46 | SHA256:952B3ED1C74E0BE89DD808AE6253A4C76532D13DADB7C6464E34F360D23BB1DE | |||
| 5988 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_5988_387593988\-8a69d345-d564-463c-aff1-a69d9e530f96-_135.0.7049.96_all_fq4zsljozzr63bufvp7qdzh36m.crx3 | — | |
MD5:— | SHA256:— | |||
| 5988 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\crx_cache\b354ffb4bf730082b302e83eddfad4534da8f890282c66df6132a18701073686 | — | |
MD5:— | SHA256:— | |||
| 5988 | updater.exe | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5988_1707510151\135.0.7049.96_chrome_installer.exe | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.41:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2104 | svchost.exe | GET | 200 | 23.216.77.41:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
2104 | svchost.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
3900 | updater.exe | GET | 200 | 142.250.185.195:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
3900 | updater.exe | GET | 200 | 142.250.185.195:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
3900 | updater.exe | GET | 200 | 142.250.185.195:80 | http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDQZgpWpezrXAmFnbj86J49 | unknown | — | — | whitelisted |
5988 | updater.exe | GET | — | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/atdsaunm3znqpcz4q6kmsfafmq_135.0.7049.96/-8a69d345-d564-463c-aff1-a69d9e530f96-_135.0.7049.96_all_fq4zsljozzr63bufvp7qdzh36m.crx3 | unknown | — | — | whitelisted |
1180 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1180 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6108 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.216.77.41:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2104 | svchost.exe | 23.216.77.41:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.253.202:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
2104 | svchost.exe | 2.16.253.202:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
3900 | updater.exe | 172.217.23.110:443 | dl.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |
edgedl.me.gvt1.com |
| whitelisted |