| File name: | QuickShareSetup.exe |
| Full analysis: | https://app.any.run/tasks/8f8a9eab-489e-443c-8d5f-f41c04487cf2 |
| Verdict: | Malicious activity |
| Analysis date: | November 16, 2024, 02:51:06 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections |
| MD5: | 3EDA6866A52656DE91FFD207B10DBB46 |
| SHA1: | EC1BED35B751D396973163CAE568C4EF62BA95ED |
| SHA256: | 2818BD811A77EDD9D32578A8F1E1A7501470EE8812602113E703577A4B746C58 |
| SSDEEP: | 98304:Pag16mBG8tStT/spngoC00KGbn9GqrzwXtSUiFG3Ul3/V100FcWQnSrpKic4FUt0:kbiFbE |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:10:29 15:02:02+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 3405312 |
| InitializedDataSize: | 6910464 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1ba050 |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 132.0.6806.0 |
| ProductVersionNumber: | 132.0.6806.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Installer |
| FileVersion: | 132.0.6806.0 |
| InternalName: | Google Installer(x86) |
| LegalCopyright: | Copyright 2024 Google LLC. All rights reserved. |
| OriginalFileName: | UpdaterSetup.exe |
| ProductName: | Google Installer |
| ProductVersion: | 132.0.6806.0 |
| CompanyShortName: | |
| ProductShortName: | GoogleUpdater |
| LastChange: | 3e95f75be9bb127c2cc81c7ffb997c0fbab2d566-refs/branch-heads/6806@{#1} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 692 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 948 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x320,0x324,0x328,0x318,0x330,0x7ffbc5295fd8,0x7ffbc5295fe4,0x7ffbc5295ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1068 | "C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -NoProfile -NonInteractive -NoLogo -windowstyle Hidden -Command "Register-ScheduledTask \"Google\Quick Share Relaunch\" -Force -Action (New-ScheduledTaskAction -Execute \"C:\Program Files\Google\NearbyShare\nearby_share_launcher.exe\" -Argument \"--relaunch_if_crashed\") -Trigger (New-ScheduledTaskTrigger -Once -At ((Get-Date).AddMinutes(15)) -RepetitionInterval (New-TimeSpan -Minutes 15)) -Principal (New-ScheduledTaskPrincipal -GroupId \"S-1-5-32-545\") -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries)" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1252 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=34 --mojo-platform-channel-handle=5456 --field-trial-handle=2424,i,11420433516246295293,9938996661481281617,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1568 | "C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -NoProfile -NonInteractive -NoLogo -windowstyle Hidden -Command "Import-Module \"C:\Program Files\Google\NearbyShare\scripts\nearby_management.psm1\";Clear-NearbyShareInstallation" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1748 | "C:\Program Files\Google\NearbyShare\nearby_config.exe" --fix_sparse_package | C:\Program Files\Google\NearbyShare\nearby_config.exe | msiexec.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 2076 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | nearby_config.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3000 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3604 | "C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=132.0.6806.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x298,0x29c,0x2a0,0x274,0x2a4,0x764400,0x76440c,0x764418 | C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Exit code: 0 Version: 132.0.6806.0 Modules
| |||||||||||||||
| 3644 | "C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\updater.exe" --system --windows-service --service=update-internal | C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Exit code: 0 Version: 132.0.6806.0 Modules
| |||||||||||||||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 132.0.6806.0 | |||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 132.0.6806.0 | |||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{87C5E238-FDCC-5A31-86FB-370B3934CA9B} |
| Operation: | write | Name: | AppID |
Value: {87C5E238-FDCC-5A31-86FB-370B3934CA9B} | |||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{87C5E238-FDCC-5A31-86FB-370B3934CA9B} |
| Operation: | write | Name: | LocalService |
Value: GoogleUpdaterInternalService132.0.6806.0 | |||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{87C5E238-FDCC-5A31-86FB-370B3934CA9B} |
| Operation: | write | Name: | ServiceParameters |
Value: --com-service | |||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{1C397B09-D7FB-5570-88B5-0006848AC975}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C397B09-D7FB-5570-88B5-0006848AC975}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{61CE7911-F412-5EEA-8302-9339D8C31A77}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6668 | QuickShareSetup.exe | C:\Windows\SystemTemp\Google6668_1284427147\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 5584 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_5584_769506100\-232066fe-ff4d-4c25-83b4-3f8747cf7e3a-_1.0.2002.2_all_adggeugvvlroxzymudgj5osxvyua.crx3 | — | |
MD5:— | SHA256:— | |||
| 5584 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\crx_cache\{232066fe-ff4d-4c25-83b4-3f8747cf7e3a}_1.ac96cbc542f261fcb2b3e530d68b56fea50f8018d20a571b4f839e6d1503eb0b | — | |
MD5:— | SHA256:— | |||
| 5584 | updater.exe | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5584_402463043\better_together.msi | — | |
MD5:— | SHA256:— | |||
| 6712 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json | binary | |
MD5:10BB5395F654EC235DD4B873B49443B8 | SHA256:46553F064C2E0F716DBC4CCDBDB07592EEEA44BCA378354819D3DF693DF8E4B9 | |||
| 692 | msiexec.exe | C:\Windows\Installer\98178.msi | — | |
MD5:— | SHA256:— | |||
| 6712 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\877fb94d-6218-463f-8ba6-65a1bd458a2b.tmp | binary | |
MD5:10BB5395F654EC235DD4B873B49443B8 | SHA256:46553F064C2E0F716DBC4CCDBDB07592EEEA44BCA378354819D3DF693DF8E4B9 | |||
| 3644 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\e9efbdae-ea56-4561-b697-ebf2f23bf654.tmp | binary | |
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56 | SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C | |||
| 6712 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\updater.exe | executable | |
MD5:CFEB1C8292FA4A22B1C8B5D81B8AABF9 | SHA256:AF4B596E960D17A2A06ECF7EEE0EE41CCEAB35DDA82D505D8B1C8B8D5AEAB4F2 | |||
| 6712 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\uninstall.cmd | text | |
MD5:FBC297EE9060D4256192E4EDB98CAD1B | SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6944 | svchost.exe | GET | 200 | 23.216.77.42:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6944 | svchost.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
864 | RUXIMICS.exe | GET | 200 | 23.216.77.42:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.42:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
864 | RUXIMICS.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5584 | updater.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/Nearby/e2huo7mnrzlp63sxy6d3dvblru_1.0.2002.2/-232066fe-ff4d-4c25-83b4-3f8747cf7e3a-_1.0.2002.2_all_adggeugvvlroxzymudgj5osxvyua.crx3 | unknown | — | — | whitelisted |
6504 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
6504 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | whitelisted |
6504 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAtQzyRrJj79hacpMVFY8%2F8%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6944 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
864 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5488 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6944 | svchost.exe | 23.216.77.42:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5488 | MoUsoCoreWorker.exe | 23.216.77.42:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
864 | RUXIMICS.exe | 23.216.77.42:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
6944 | svchost.exe | 2.23.181.156:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5488 | MoUsoCoreWorker.exe | 2.23.181.156:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
dl.google.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
edgedl.me.gvt1.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.googleapis.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO Possible Chrome Plugin install |
Process | Message |
|---|---|
nearby_config.exe | I1116 02:52:26.726718 4040 main.cc:319] FixSparsePackage: Failed to delete registry key for user S-1-5-20
|
nearby_config.exe | I1116 02:52:26.726504 4040 main.cc:319] FixSparsePackage: Failed to delete registry key for user .DEFAULT
|
nearby_config.exe | I1116 02:52:26.725817 4040 win32_utils.cc:49] GetThreadPreferredUILanguages() returns: en-US
|
nearby_config.exe | I1116 02:52:26.726915 4040 main.cc:319] FixSparsePackage: Failed to delete registry key for user S-1-5-21-1693682860-607145093-2874071422-1001_Classes
|
nearby_config.exe | I1116 02:52:26.727091 4040 main.cc:325] FixSparsePackage: Fixed sparse package.
|
nearby_config.exe | I1116 02:52:26.727158 4040 main.cc:589] Nearby configuration Done
|
nearby_config.exe | I1116 02:52:26.726644 4040 main.cc:319] FixSparsePackage: Failed to delete registry key for user S-1-5-19
|
nearby_config.exe | I1116 02:52:26.727003 4040 main.cc:319] FixSparsePackage: Failed to delete registry key for user S-1-5-18
|
nearby_config.exe | I1116 02:52:26.726002 4040 main.cc:347] GetPreferredLanguages() returns: 2 languages. nearby::localization::InitializeL10n returns: en
|
nearby_config.exe | I1116 02:52:26.726830 4040 main.cc:319] FixSparsePackage: Failed to delete registry key for user S-1-5-21-1693682860-607145093-2874071422-1001
|