| download: | /chrome/install/375.126/chrome_installer.exe |
| Full analysis: | https://app.any.run/tasks/e316c518-f503-44cb-b7cb-bfdedb07cef5 |
| Verdict: | Malicious activity |
| Analysis date: | April 17, 2025, 04:27:54 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections |
| MD5: | 9A9EAC4311CD46BC5AB368006915BF1B |
| SHA1: | 66ED7C2557FAB5A12ED35E0FBD61DCC2F87F9658 |
| SHA256: | 21E70F16C46077D78CE6B6DC9B6237930BA4DBC4CC2A1BF5017891E933E89827 |
| SSDEEP: | 98304:gWWgAN8OG/jc1p1lNRYqhxC9W2pq6vJiUaqk8Nzf/r1KsDdDeu6g5zGJz3f6z1OK:VMwf |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:04:08 03:01:57+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 3664384 |
| InitializedDataSize: | 7646720 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1cd530 |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 137.0.7115.0 |
| ProductVersionNumber: | 137.0.7115.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Installer (x86) |
| FileVersion: | 137.0.7115.0 |
| InternalName: | Google Installer (x86) |
| LegalCopyright: | Copyright 2025 Google LLC. All rights reserved. |
| OriginalFileName: | UpdaterSetup.exe |
| ProductName: | Google Installer (x86) |
| ProductVersion: | 137.0.7115.0 |
| CompanyShortName: | |
| ProductShortName: | GoogleUpdater |
| LastChange: | 2a601c83a31cb312ebe3f9e228b32f1e300f9a8c-refs/branch-heads/7115@{#1} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1276 | "C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=137.0.7115.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a0,0x2a4,0x2a8,0x27c,0x2ac,0x10617f0,0x10617fc,0x1061808 | C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater (x86) Exit code: 0 Version: 137.0.7115.0 Modules
| |||||||||||||||
| 3268 | "C:\Users\admin\AppData\Local\Temp\chrome_installer.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&browser=0&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&brand=GTPM --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevated | C:\Users\admin\AppData\Local\Temp\chrome_installer.exe | chrome_installer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer (x86) Version: 137.0.7115.0 Modules
| |||||||||||||||
| 3332 | "C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=137.0.7115.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x298,0x29c,0x2a0,0x274,0x2a4,0x10617f0,0x10617fc,0x1061808 | C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater (x86) Version: 137.0.7115.0 Modules
| |||||||||||||||
| 4120 | C:\WINDOWS\SystemTemp\Google3268_1574781579\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=137.0.7115.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a8,0x2ac,0x2b0,0x220,0x2b4,0x8517f0,0x8517fc,0x851808 | C:\Windows\SystemTemp\Google3268_1574781579\bin\updater.exe | — | updater.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Updater (x86) Version: 137.0.7115.0 Modules
| |||||||||||||||
| 4724 | "C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe" --system --windows-service --service=update | C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater (x86) Version: 137.0.7115.0 Modules
| |||||||||||||||
| 5668 | "C:\WINDOWS\SystemTemp\Google3268_1574781579\bin\updater.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&browser=0&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&brand=GTPM --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevated | C:\Windows\SystemTemp\Google3268_1574781579\bin\updater.exe | chrome_installer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Updater (x86) Version: 137.0.7115.0 Modules
| |||||||||||||||
| 5720 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5960 | "C:\Users\admin\AppData\Local\Temp\chrome_installer.exe" | C:\Users\admin\AppData\Local\Temp\chrome_installer.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Installer (x86) Version: 137.0.7115.0 Modules
| |||||||||||||||
| 6112 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6988 | "C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe" --system --windows-service --service=update-internal | C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater (x86) Exit code: 0 Version: 137.0.7115.0 Modules
| |||||||||||||||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 137.0.7115.0 | |||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\Elevation |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\LocalServer32 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\ProgID |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\VersionIndependentProgID |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}\ProgID |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}\VersionIndependentProgID |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6988) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{521FDB42-7130-4806-822A-FC5163FAD983} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3268 | chrome_installer.exe | C:\Windows\SystemTemp\Google3268_124570851\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 5668 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\updater.log | text | |
MD5:A9F5A6D85E28D389B0DC9A4D57575639 | SHA256:6648C3BAD6D36BF9814CA626E5CE1516B6BE25B4717335D49BAD73E2226F3D1C | |||
| 5668 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\uninstall.cmd | text | |
MD5:FBC297EE9060D4256192E4EDB98CAD1B | SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044 | |||
| 5668 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\Crashpad\settings.dat | binary | |
MD5:4D11154B281A45BB2F7392B0066D0140 | SHA256:F9FE6070C837328761633C545ABA271F43B6212048046D79997A7EF230184B56 | |||
| 6988 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\f483d70f-8af9-487e-a390-9b080efa85f8.tmp | binary | |
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56 | SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C | |||
| 5668 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D6AA22DA63AEAA61826C0D7C76455F33_438C9676D2A7E56564A97E1F656C97D6 | binary | |
MD5:7C8D37C5A6BAC3FEE65A4CCF1B850FF6 | SHA256:397F54FEE9E819A53777548BB974B1140C444B102C2C45315A3A227689DFCBCC | |||
| 6988 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\prefs.json | binary | |
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56 | SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C | |||
| 6988 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json | binary | |
MD5:2B537F135611617F886653BE6A557C0C | SHA256:6D7A8337E81AF7273FCE68F976C3D7F7EFA58CBB408F9A28B52BFBB22FF6B13B | |||
| 4724 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_4724_1551898827\-8a69d345-d564-463c-aff1-a69d9e530f96-_135.0.7049.85_all_k2h3m242oimh5kxnl55lko4vze.crx3 | — | |
MD5:— | SHA256:— | |||
| 4724 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\crx_cache\388479ce16bd7c2d446ff2a663a31b1fc72c3a7bb9928ad1fa36a71713eb3c2c | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.32.238.112:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5668 | updater.exe | GET | 200 | 142.250.74.195:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5668 | updater.exe | GET | 200 | 142.250.181.227:80 | http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDQZgpWpezrXAmFnbj86J49 | unknown | — | — | whitelisted |
5668 | updater.exe | GET | 200 | 142.250.74.195:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
4724 | updater.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/mtgl4pv3x5mbcrbsdcnc3rctp4_135.0.7049.85/-8a69d345-d564-463c-aff1-a69d9e530f96-_135.0.7049.85_all_k2h3m242oimh5kxnl55lko4vze.crx3 | unknown | — | — | whitelisted |
7332 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7332 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 23.32.238.112:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 20.190.160.5:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
5668 | updater.exe | 142.250.184.206:443 | dl.google.com | GOOGLE | US | whitelisted |
4724 | updater.exe | 142.250.181.227:443 | update.googleapis.com | GOOGLE | US | whitelisted |
5668 | updater.exe | 142.250.74.195:80 | c.pki.goog | GOOGLE | US | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |