File name:

Security_Update_Chrome.exe

Full analysis: https://app.any.run/tasks/be47643a-c3ed-41b2-9e74-50c102685189
Verdict: Malicious activity
Threats:

Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.

Analysis date: May 09, 2026, 15:12:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
quasar
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

8887CF5DDFAA6DAABC64B29454DA9493

SHA1:

168931E5103A7B836EC45519975ED64294E3A2A6

SHA256:

279CFFBDA7C1A6BA3D06BEBC931517B5A8DF11C69A02E1DBA63A023C2C79FD7E

SSDEEP:

98304:u27sua2tb7ifHqDPlQZr0Io4DgACneEykUfO:yLgK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Security_Update_Chrome.exe (PID: 572)
      • GoogleUpdate.exe (PID: 2684)
    • QUASAR has been detected (YARA)

      • GoogleUpdate.exe (PID: 2684)
  • SUSPICIOUS

    • Starts itself from another location

      • Security_Update_Chrome.exe (PID: 572)
    • Executable content was dropped or overwritten

      • Security_Update_Chrome.exe (PID: 572)
  • INFO

    • Checks supported languages

      • Security_Update_Chrome.exe (PID: 572)
      • GoogleUpdate.exe (PID: 2684)
      • GoogleUpdate.exe (PID: 7800)
    • Reads the computer name

      • Security_Update_Chrome.exe (PID: 572)
      • GoogleUpdate.exe (PID: 2684)
      • GoogleUpdate.exe (PID: 7800)
    • Creates files or folders in the user directory

      • Security_Update_Chrome.exe (PID: 572)
    • Launching a file from a Registry key

      • Security_Update_Chrome.exe (PID: 572)
      • GoogleUpdate.exe (PID: 2684)
    • Reads the machine GUID from the registry

      • Security_Update_Chrome.exe (PID: 572)
      • GoogleUpdate.exe (PID: 2684)
      • GoogleUpdate.exe (PID: 7800)
    • Reads Environment values

      • Security_Update_Chrome.exe (PID: 572)
      • GoogleUpdate.exe (PID: 2684)
      • GoogleUpdate.exe (PID: 7800)
    • Manual execution by a user

      • GoogleUpdate.exe (PID: 7800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Quasar

(PID) Process(2684) GoogleUpdate.exe
C2 (10)92news24foryou.za.com:8080
92news24foryou.za.com:443
92news24foryou.za.com:80
92news24foryou.za.com:53
92news24foryou.za.com:1604
www.92news24foryou.za.com:1604
172.67.191.202:53
104.21.20.53:53
104.21.20.53:80
172.67.191.202:80
Version1.4.1
Sub_DirGoogle\Chrome\Update
Install_NameGoogleUpdate.exe
Mutex92news24foryou-22e01fb1-ff65-4cae-a164-b3091dfd4918
StartupGoogle Update Core
Tag92news24foryou
LogDirLogs
SignaturedNZpoLLUVhIUfmcJK6lRbtHWhMG7UA3NW8QEXqO9217ycZ87EAjwcgOobztpYTP/3AKM9VPila3a+ZsXk4GhkQ9sEJVaRYWWZ1ZDuMwvi0OLHBgKX3x2cdfcGMVq3wQ17cM20l2OuhimGcV5PDUhwgZOoNfrfSNH3FFBxq8V1MH4NgjOzE/KENPD1X49h8jmzbUmGEbu7Y36rZGlLYRDHDnFOC/b4r4lLRYfx4jdQkzUBAvryPUvzMGyWlK1FhYzPSQVGnyFpNk5qkZawCUvU7gvY275i8UYwB5X9NhqisAN...
CertificateMIIE9DCCAtygAwIBAgIQAMyLxOGLdEdAA8ENgAq9QzANBgkqhkiG9w0BAQ0FADAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMCAXDTI2MDIxODA4MDUyOVoYDzk5OTkxMjMxMjM1OTU5WjAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAgg/7VZFyN7dtlKk2iMKEFOIeUL/5GWZjvfRksIadzM8hqPhf42HDk6jOat07AqfE4+5fKi4c...
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:03:12 16:16:39+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 3262464
InitializedDataSize: 17408
UninitializedDataSize: -
EntryPoint: 0x31e69e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 120.0.6099.130
ProductVersionNumber: 120.0.6099.130
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: Google LLC
FileDescription: Google Chrome Installer
FileVersion: 120.0.6099.130
InternalName: chrome_installer.exe
LegalCopyright: Copyright 2024 Google LLC. All rights reserved.
LegalTrademarks: -
OriginalFileName: chrome_installer.exe
ProductName: Google Chrome
ProductVersion: 120.0.6099.130
AssemblyVersion: 120.0.6099.130
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start security_update_chrome.exe #QUASAR googleupdate.exe googleupdate.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
572"C:\Users\admin\Desktop\Security_Update_Chrome.exe" C:\Users\admin\Desktop\Security_Update_Chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome Installer
Exit code:
3
Version:
120.0.6099.130
Modules
Images
c:\users\admin\desktop\security_update_chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2684"C:\Users\admin\AppData\Roaming\Google\Chrome\Update\GoogleUpdate.exe"C:\Users\admin\AppData\Roaming\Google\Chrome\Update\GoogleUpdate.exe
Security_Update_Chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome Installer
Version:
120.0.6099.130
Modules
Images
c:\users\admin\appdata\roaming\google\chrome\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Quasar
(PID) Process(2684) GoogleUpdate.exe
C2 (10)92news24foryou.za.com:8080
92news24foryou.za.com:443
92news24foryou.za.com:80
92news24foryou.za.com:53
92news24foryou.za.com:1604
www.92news24foryou.za.com:1604
172.67.191.202:53
104.21.20.53:53
104.21.20.53:80
172.67.191.202:80
Version1.4.1
Sub_DirGoogle\Chrome\Update
Install_NameGoogleUpdate.exe
Mutex92news24foryou-22e01fb1-ff65-4cae-a164-b3091dfd4918
StartupGoogle Update Core
Tag92news24foryou
LogDirLogs
SignaturedNZpoLLUVhIUfmcJK6lRbtHWhMG7UA3NW8QEXqO9217ycZ87EAjwcgOobztpYTP/3AKM9VPila3a+ZsXk4GhkQ9sEJVaRYWWZ1ZDuMwvi0OLHBgKX3x2cdfcGMVq3wQ17cM20l2OuhimGcV5PDUhwgZOoNfrfSNH3FFBxq8V1MH4NgjOzE/KENPD1X49h8jmzbUmGEbu7Y36rZGlLYRDHDnFOC/b4r4lLRYfx4jdQkzUBAvryPUvzMGyWlK1FhYzPSQVGnyFpNk5qkZawCUvU7gvY275i8UYwB5X9NhqisAN...
CertificateMIIE9DCCAtygAwIBAgIQAMyLxOGLdEdAA8ENgAq9QzANBgkqhkiG9w0BAQ0FADAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMCAXDTI2MDIxODA4MDUyOVoYDzk5OTkxMjMxMjM1OTU5WjAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAgg/7VZFyN7dtlKk2iMKEFOIeUL/5GWZjvfRksIadzM8hqPhf42HDk6jOat07AqfE4+5fKi4c...
7800"C:\Users\admin\AppData\Roaming\Google\Chrome\Update\GoogleUpdate.exe"C:\Users\admin\AppData\Roaming\Google\Chrome\Update\GoogleUpdate.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome Installer
Exit code:
2
Version:
120.0.6099.130
Modules
Images
c:\users\admin\appdata\roaming\google\chrome\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
982
Read events
980
Write events
2
Delete events
0

Modification events

(PID) Process:(572) Security_Update_Chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Google Update Core
Value:
"C:\Users\admin\AppData\Roaming\Google\Chrome\Update\GoogleUpdate.exe"
(PID) Process:(2684) GoogleUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Google Update Core
Value:
"C:\Users\admin\AppData\Roaming\Google\Chrome\Update\GoogleUpdate.exe"
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
572Security_Update_Chrome.exeC:\Users\admin\AppData\Roaming\Google\Chrome\Update\GoogleUpdate.exeexecutable
MD5:8887CF5DDFAA6DAABC64B29454DA9493
SHA256:279CFFBDA7C1A6BA3D06BEBC931517B5A8DF11C69A02E1DBA63A023C2C79FD7E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
42
DNS requests
24
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5304
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
GET
200
23.11.40.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
NL
binary
312 b
whitelisted
5316
svchost.exe
GET
200
23.11.40.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
NL
binary
471 b
whitelisted
5304
SIHClient.exe
GET
200
135.233.95.135:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
5304
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
5304
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5316
svchost.exe
POST
400
20.190.159.0:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
5316
svchost.exe
POST
200
20.190.159.0:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
4044
svchost.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4044
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
95.101.23.99:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
23.11.40.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
2684
GoogleUpdate.exe
188.114.97.3:8080
92news24foryou.za.com
CLOUDFLARENET
US
whitelisted
2684
GoogleUpdate.exe
188.114.97.3:443
92news24foryou.za.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.104.136.2
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
www.bing.com
  • 95.101.23.99
  • 95.101.23.83
  • 95.101.23.81
  • 95.101.23.89
  • 95.101.23.65
  • 95.101.23.75
  • 95.101.23.105
  • 95.101.23.43
  • 95.101.23.91
whitelisted
ocsp.digicert.com
  • 23.11.40.157
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 142.250.154.102
  • 142.250.154.113
  • 142.250.154.139
  • 142.250.154.138
  • 142.250.154.101
  • 142.250.154.100
whitelisted
92news24foryou.za.com
  • 188.114.97.3
  • 188.114.96.3
unknown
login.live.com
  • 20.190.159.0
  • 40.126.31.131
  • 20.190.159.129
  • 40.126.31.71
  • 20.190.159.2
  • 40.126.31.73
  • 20.190.159.130
  • 40.126.31.128
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted

Threats

PID
Process
Class
Message
4044
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info