| File name: | GoogleChromePortable_126.0.6478.127_online.paf.exe |
| Full analysis: | https://app.any.run/tasks/16c4d4fa-e403-4242-b981-115d931cfbcb |
| Verdict: | Malicious activity |
| Analysis date: | July 04, 2024, 20:18:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | C6D00740547A08D71FB98DEA124A01AA |
| SHA1: | 128E1D147BDE8267EE972B32293CA8CBCC6ED259 |
| SHA256: | 1BAB6C43BC8C410DADC54AAE94F55A4EAC3F744F83DA7373FCBAE533F01BC567 |
| SSDEEP: | 49152:SyZXummRwL8mTv955Ptppj2KeAE7CiBNMByPid+NIGWijAUgeriyubZt/0JmGRaK:SaX1mRw4Sv955PDpkAE1xPm+NMoWVj/Y |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:03:30 16:56:02+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 412160 |
| UninitializedDataSize: | 16384 |
| EntryPoint: | 0x3665 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 126.0.6478.127 |
| ProductVersionNumber: | 126.0.6478.127 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | For additional details, visit PortableApps.com |
| CompanyName: | PortableApps.com |
| FileDescription: | Google Chrome Portable |
| FileVersion: | 126.0.6478.127 |
| InternalName: | Google Chrome Portable |
| LegalCopyright: | 2007-2024 PortableApps.com, PortableApps.com Installer 3.8.11.0 |
| LegalTrademarks: | PortableApps.com is a registered trademark of Rare Ideas, LLC. |
| OriginalFileName: | GoogleChromePortable_126.0.6478.127_online.paf.exe |
| PortableAppscomAppID: | GoogleChromePortable |
| PortableAppscomDownloadFileName: | 126.0.6478.127_chrome_installer.exe |
| PortableAppscomDownloadKnockURL: | ${DownloadKnockURL} |
| PortableAppscomDownloadName: | Google Chrome (Stable) |
| PortableAppscomDownloadSHA256: | 338a8a612e288e8babc594bddf3208f8411b21c99dfbeda2695212fdc2d41953 |
| PortableAppscomDownloadURL: | https://dl.google.com/release2/chrome/hlannckzzfju63p3z34onymzai_126.0.6478.127/126.0.6478.127_chrome_installer.exe |
| PortableAppscomFormatVersion: | 3.8 |
| PortableAppscomInstallerVersion: | 3.8.11.0 |
| ProductName: | Google Chrome Portable |
| ProductVersion: | 126.0.6478.127 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3384 | "C:\Users\admin\AppData\Local\Temp\GoogleChromePortable_126.0.6478.127_online.paf.exe" | C:\Users\admin\AppData\Local\Temp\GoogleChromePortable_126.0.6478.127_online.paf.exe | explorer.exe | ||||||||||||
User: admin Company: PortableApps.com Integrity Level: MEDIUM Description: Google Chrome Portable Version: 126.0.6478.127 Modules
| |||||||||||||||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-2 |
Value: Access the computers and devices that are on your network. | |||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | Browse For Folder Width |
Value: 318 | |||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | Browse For Folder Height |
Value: 288 | |||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (3384) GoogleChromePortable_126.0.6478.127_online.paf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\Local\Temp\nsiE2FC.tmp\modern-header.bmp | image | |
MD5:89D65CD06E72C9D364347B9117761B7E | SHA256:F2362A761EEEBE553D224C104A60F7962E6B692389C669AB635F51E81DBF6B09 | |||
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\Local\Temp\nsiE2FC.tmp\w7tbp.dll | executable | |
MD5:9A3031CC4CEF0DBA236A28EECDF0AFB5 | SHA256:53BB519E3293164947AC7CBD7E612F637D77A7B863E3534BA1A7E39B350D3C00 | |||
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\Local\Temp\nsiE2FC.tmp\modern-wizard.bmp | image | |
MD5:4DF53EFCAA2C52F39618B2AAD77BB552 | SHA256:EE13539F3D66CC0592942EA1A4C35D8FD9AF67B1A7F272D0D791931E6E9CE4EB | |||
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\Local\Temp\nsiE2FC.tmp\inetc.dll | executable | |
MD5:40D7ECA32B2F4D29DB98715DD45BFAC5 | SHA256:85E03805F90F72257DD41BFDAA186237218BBB0EC410AD3B6576A88EA11DCCB9 | |||
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:7FD15407681659A0E40132A99863D0B8 | SHA256:E7926DF6379E4BDE047E29FF7B55C92C597EE0226F5D76F3D0D90F1E3424C286 | |||
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 | binary | |
MD5:C4B711B191014F7D933E3BD3DA1DEC81 | SHA256:426C06DCF561567C80D53CAC5E41224C7C66110A0EF5D157817ADBB6F0BEE777 | |||
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | der | |
MD5:4D18CABB9261024E3AC55EDADC6E70E6 | SHA256:0819700FC5B16E7C422A9F9BAF8BA06555318BEE710AE56BD5AFFFABCB51E7BE | |||
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DDE8B1B7E253A9758EC380BD648952AF_A3D4688236962EEA03574DE4F61B95D9 | binary | |
MD5:A6D955B15A70C5D8AE5244DD27208E9D | SHA256:512748112521451859C1E7881E38CA0B63F5055D29FD9816DA71C57E2EFF83C2 | |||
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 | der | |
MD5:8D1040B12A663CA4EC7277CFC1CE44F0 | SHA256:3086094D4198A5BBD12938B0D2D5F696C4DFC77E1EAE820ADDED346A59AA8727 | |||
| 3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DDE8B1B7E253A9758EC380BD648952AF_A3D4688236962EEA03574DE4F61B95D9 | binary | |
MD5:0C820E320731FE71355204A07E7F95BC | SHA256:5D1AF5EDC1B5AB0E08D7F580C349A94CA3DAFAA1C6AB093E9C604821C30F1874 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1372 | svchost.exe | GET | 304 | 41.63.96.0:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33 | unknown | — | — | unknown |
1372 | svchost.exe | GET | 200 | 23.48.23.135:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | GET | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | unknown |
1372 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | GET | 200 | 142.250.185.99:80 | http://c.pki.goog/r/r1.crl | unknown | — | — | unknown |
3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | GET | 200 | 142.250.185.99:80 | http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQCRq%2FXldMamzQqGAD6YrjKf | unknown | — | — | unknown |
1060 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5445ebff82c5850f | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2564 | svchost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
1372 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1372 | svchost.exe | 41.63.96.0:80 | ctldl.windowsupdate.com | LLNW | ZA | unknown |
1372 | svchost.exe | 23.48.23.135:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
1372 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | 142.250.184.238:443 | dl.google.com | GOOGLE | US | whitelisted |
3384 | GoogleChromePortable_126.0.6478.127_online.paf.exe | 142.250.185.99:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
dl.google.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
c.pki.goog |
| unknown |
o.pki.goog |
| unknown |