File name:

ChromeSetup.exe

Full analysis: https://app.any.run/tasks/143124da-f4f4-428b-81e8-d0e1b487667d
Verdict: Malicious activity
Threats:

XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails.

Analysis date: July 29, 2024, 19:06:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
xworm
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

929D771116E678E8D4A97E2C69160963

SHA1:

63A3FF5DDCDD094D5A3C01330AC768AACC1DD19C

SHA256:

2EAD6E7387F2F85606FA5590CF9D0D93D958337F721FA9B68EF60AAAC5CDDBCA

SSDEEP:

98304:YY6cqxk93Q0DB+eKqNoZxfXbOEMJrq2uEi2ANb7uCeff9WvcEd7OLstmMimsm4ap:4mm9c5Na0jwU/sFMWUL9eVS98/1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ChromeSetup.exe (PID: 6952)
      • updater.exe (PID: 1780)
      • service.exe (PID: 2928)
      • updater.exe (PID: 5496)
      • 126.0.6478.185_chrome_installer.exe (PID: 5236)
      • setup.exe (PID: 1340)
    • Scans artifacts that could help determine the target

      • updater.exe (PID: 5496)
    • XWORM has been detected (YARA)

      • service.exe (PID: 2928)
      • ChromeService.exe (PID: 6396)
    • Uses Task Scheduler to run other applications

      • service.exe (PID: 2928)
    • Changes the autorun value in the registry

      • setup.exe (PID: 1340)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ChromeSetup.exe (PID: 6952)
      • ChromeSetup.exe (PID: 6480)
      • updater.exe (PID: 5496)
      • service.exe (PID: 2928)
    • Reads the date of Windows installation

      • ChromeSetup.exe (PID: 6952)
      • ChromeSetup.exe (PID: 6480)
      • service.exe (PID: 2928)
    • Executable content was dropped or overwritten

      • ChromeSetup.exe (PID: 6952)
      • updater.exe (PID: 5496)
      • service.exe (PID: 2928)
      • updater.exe (PID: 1780)
      • 126.0.6478.185_chrome_installer.exe (PID: 5236)
      • setup.exe (PID: 1340)
    • Application launched itself

      • ChromeSetup.exe (PID: 6480)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 1780)
      • updater.exe (PID: 2996)
      • setup.exe (PID: 1340)
      • setup.exe (PID: 7052)
    • Executes as Windows Service

      • updater.exe (PID: 1780)
      • updater.exe (PID: 2996)
    • Checks Windows Trust Settings

      • updater.exe (PID: 5496)
    • Checks for external IP

      • svchost.exe (PID: 2284)
      • service.exe (PID: 2928)
    • The process executes via Task Scheduler

      • ChromeService.exe (PID: 6396)
      • ChromeService.exe (PID: 1140)
    • Creates a software uninstall entry

      • setup.exe (PID: 1340)
    • Searches for installed software

      • setup.exe (PID: 1340)
  • INFO

    • Reads the computer name

      • ChromeSetup.exe (PID: 6952)
      • service.exe (PID: 2928)
      • ChromeSetup.exe (PID: 6480)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 1780)
      • updater.exe (PID: 2996)
      • ChromeService.exe (PID: 6396)
      • setup.exe (PID: 1340)
      • setup.exe (PID: 7052)
      • elevation_service.exe (PID: 6432)
      • ChromeService.exe (PID: 1140)
      • 126.0.6478.185_chrome_installer.exe (PID: 5236)
    • Checks supported languages

      • ChromeSetup.exe (PID: 6952)
      • ChromeSetup.exe (PID: 6480)
      • service.exe (PID: 2928)
      • ChromeSetup.exe (PID: 1468)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 6176)
      • updater.exe (PID: 6940)
      • updater.exe (PID: 2996)
      • updater.exe (PID: 2548)
      • ChromeService.exe (PID: 6396)
      • 126.0.6478.185_chrome_installer.exe (PID: 5236)
      • setup.exe (PID: 1340)
      • setup.exe (PID: 3484)
      • updater.exe (PID: 1780)
      • setup.exe (PID: 6584)
      • setup.exe (PID: 7052)
      • elevation_service.exe (PID: 6432)
      • ChromeService.exe (PID: 1140)
    • Reads the machine GUID from the registry

      • ChromeSetup.exe (PID: 6952)
      • service.exe (PID: 2928)
      • updater.exe (PID: 2996)
      • updater.exe (PID: 5496)
      • ChromeService.exe (PID: 6396)
      • ChromeService.exe (PID: 1140)
    • Process checks computer location settings

      • ChromeSetup.exe (PID: 6952)
      • ChromeSetup.exe (PID: 6480)
      • service.exe (PID: 2928)
    • Creates files or folders in the user directory

      • ChromeSetup.exe (PID: 6952)
      • updater.exe (PID: 5496)
      • service.exe (PID: 2928)
    • Creates files in the program directory

      • ChromeSetup.exe (PID: 1468)
      • updater.exe (PID: 6176)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 2996)
      • updater.exe (PID: 1780)
      • setup.exe (PID: 1340)
      • setup.exe (PID: 7052)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 5496)
      • updater.exe (PID: 1780)
      • updater.exe (PID: 2996)
    • Checks proxy server information

      • updater.exe (PID: 5496)
      • slui.exe (PID: 1340)
      • service.exe (PID: 2928)
      • slui.exe (PID: 2308)
    • Reads the software policy settings

      • slui.exe (PID: 1340)
      • updater.exe (PID: 2996)
      • updater.exe (PID: 5496)
      • slui.exe (PID: 2308)
    • Reads Environment values

      • service.exe (PID: 2928)
    • Disables trace logs

      • service.exe (PID: 2928)
    • Manual execution by a user

      • chrome.exe (PID: 6628)
    • Executes as Windows Service

      • elevation_service.exe (PID: 6432)
    • Application launched itself

      • chrome.exe (PID: 6628)
    • Reads Microsoft Office registry keys

      • chrome.exe (PID: 6628)
    • Create files in a temporary directory

      • updater.exe (PID: 5496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

XWorm

(PID) Process(2928) service.exe
C2127.0.0.1:7000
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep timeFun
USB drop nameUSB.exe
MutexeSKp869RLHB6w3x0
(PID) Process(6396) ChromeService.exe
C2127.0.0.1:7000
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep timeFun
USB drop nameUSB.exe
MutexeSKp869RLHB6w3x0
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:29 19:06:18+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 9101312
InitializedDataSize: 118272
UninitializedDataSize: -
EntryPoint: 0x8afe8e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 128.0.6597.0
ProductVersionNumber: 128.0.6597.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Chrome Installer
FileVersion: 128.0.6597.0
InternalName: ChromeSetup.exe
LegalCopyright: Copyright 2024 Google LLC. All rights reserved.
OriginalFileName: ChromeSetup.exe
ProductName: Google Chrome Installer
ProductVersion: 128.0.6597.0
AssemblyVersion: 128.0.6597.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
172
Monitored processes
35
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start chromesetup.exe chromesetup.exe no specs #XWORM service.exe chromesetup.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs slui.exe svchost.exe slui.exe schtasks.exe no specs conhost.exe no specs #XWORM chromeservice.exe no specs 126.0.6478.185_chrome_installer.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs elevation_service.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chromeservice.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1140"C:\Users\admin\AppData\Roaming\ChromeService.exe"C:\Users\admin\AppData\Roaming\ChromeService.exesvchost.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome Installer
Version:
128.0.6597.0
Modules
Images
c:\users\admin\appdata\roaming\chromeservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1264"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=4928,i,13241302053712816492,178494292679883311,262144 --variations-seed-version --mojo-platform-channel-handle=4940 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
126.0.6478.185
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1340C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1340"C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\CR_99473.tmp\setup.exe" --install-archive="C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\CR_99473.tmp\CHROME.PACKED.7Z" --verbose-logging --do-not-launch-chrome --channel=stable --installerdata="C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\568e90a1-831b-4212-ac03-8fa3d210c6e6.tmp"C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\CR_99473.tmp\setup.exe
126.0.6478.185_chrome_installer.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome Installer
Exit code:
0
Version:
126.0.6478.185
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping2996_2065277108\cr_99473.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1468"C:\Users\admin\AppData\Roaming\ChromeSetup.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={40B8FEF4-77B7-10A9-3F16-920F3CF0B764}&lang=en&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&brand=VDKB&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Roaming\ChromeSetup.exe
ChromeSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Exit code:
0
Version:
128.0.6597.0
Modules
Images
c:\users\admin\appdata\roaming\chromesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1780"C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe" --system --windows-service --service=update-internalC:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
128.0.6597.0
Modules
Images
c:\program files (x86)\google\googleupdater\128.0.6597.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2284C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2308C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2548"C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=128.0.6597.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x50c694,0x50c6a0,0x50c6acC:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
128.0.6597.0
Modules
Images
c:\program files (x86)\google\googleupdater\128.0.6597.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2692"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3184,i,13241302053712816492,178494292679883311,262144 --variations-seed-version --mojo-platform-channel-handle=3200 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
126.0.6478.185
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
30 627
Read events
30 354
Write events
234
Delete events
39

Modification events

(PID) Process:(6952) ChromeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6952) ChromeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6952) ChromeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6952) ChromeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
128.0.6597.0
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
128.0.6597.0
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{44B969D4-48B7-5A30-9CD6-CAC179D81F9C}
Operation:writeName:AppID
Value:
{44B969D4-48B7-5A30-9CD6-CAC179D81F9C}
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{44B969D4-48B7-5A30-9CD6-CAC179D81F9C}
Operation:writeName:LocalService
Value:
GoogleUpdaterInternalService128.0.6597.0
Executable files
12
Suspicious files
64
Text files
29
Unknown types
10

Dropped files

PID
Process
Filename
Type
1468ChromeSetup.exeC:\Windows\SystemTemp\Google1468_1914518675\UPDATER.PACKED.7Z
MD5:
SHA256:
6952ChromeSetup.exeC:\Users\admin\AppData\Roaming\service.exeexecutable
MD5:9E648ECF689E7A9F71E2324A031453E7
SHA256:F816907918B31FA5F2C4CA1D694CC686AB8BFF3B5ECBA8A842F98A4E895F698D
5496updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:ECC5EAB1AE20D131940E241806A05883
SHA256:F882EA78921B20522C694CCC5BED9326B7E139ECF41937ED5A453E29E749759F
5496updater.exeC:\Program Files (x86)\Google\GoogleUpdater\82355d5c-980a-4c7d-adae-5b19f302ea50.tmpbinary
MD5:7B693A82168C33EC9E8CF276859DDF7F
SHA256:84A9A7F43DB56CD6E9A408F88244E8BA5EFBE48A5B5168D321F112B8C8FD8E3F
1780updater.exeC:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\prefs.jsonbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
2996updater.exeC:\Windows\SystemTemp\chrome_url_fetcher_2996_1602856595\-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.185_all_dki7xbmbf4uwyjehq4wg2ptqdm.crx3
MD5:
SHA256:
2996updater.exeC:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\126.0.6478.185_chrome_installer.exe
MD5:
SHA256:
5496updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:7B693A82168C33EC9E8CF276859DDF7F
SHA256:84A9A7F43DB56CD6E9A408F88244E8BA5EFBE48A5B5168D321F112B8C8FD8E3F
1780updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:FE493C7028E00B36B842F612692DBD25
SHA256:6338A0549E1AC903691CDD7817ECE75B3A10A64D626E26CC406CBCF362EDB676
1780updater.exeC:\Program Files (x86)\Google\GoogleUpdater\2359fd85-b8ef-4e5e-928e-fe0ede549bf9.tmpbinary
MD5:FE493C7028E00B36B842F612692DBD25
SHA256:6338A0549E1AC903691CDD7817ECE75B3A10A64D626E26CC406CBCF362EDB676
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
46
DNS requests
35
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2996
updater.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/fk7y73e6x3yfec6kkxw4fcvrxu_126.0.6478.185/-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.185_all_dki7xbmbf4uwyjehq4wg2ptqdm.crx3
unknown
whitelisted
2928
service.exe
GET
200
208.95.112.1:80
http://ip-api.com/line/?fields=hosting
unknown
shared
GET
172.217.16.196:443
https://www.google.com/async/ddljson?async=ntp:2
unknown
unknown
POST
200
142.250.181.227:443
https://update.googleapis.com/service/update2/json?cup2key=14:tFX5Ri-fIgRvlbWNG9-9XV5uBgPybuBybtXMVQ2VHPk&cup2hreq=73258891c1a3774fd3acc6aab31eb92b5786606f028baa0e328de70f87e2a4e4
unknown
text
681 Kb
unknown
POST
200
20.189.173.23:443
https://self.events.data.microsoft.com/OneCollector/1.0/
unknown
binary
9 b
unknown
GET
200
172.217.16.196:443
https://dl.google.com/update2/installers/icons/%7B8a69d345-d564-463c-aff1-a69d9e530f96%7D.bmp?lang=en-US
unknown
image
6.52 Kb
unknown
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
unknown
POST
204
95.100.146.32:443
https://www.bing.com/threshold/xls.aspx
unknown
unknown
GET
200
172.217.16.196:443
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
unknown
text
2.98 Kb
unknown
GET
404
172.217.16.196:443
https://www.google.com/chrome/whats-new/m126?internal=true
unknown
html
183 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4580
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
6012
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2424
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1108
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
92.123.104.34:443
Akamai International B.V.
DE
unknown
3228
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 216.58.212.174
whitelisted
update.googleapis.com
  • 142.250.186.99
whitelisted
dl.google.com
  • 216.58.206.78
whitelisted
self.events.data.microsoft.com
  • 20.189.173.14
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
ip-api.com
  • 208.95.112.1
shared
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.44
whitelisted
safebrowsingohttpgateway.googleapis.com
  • 142.250.186.106
  • 216.58.206.74
  • 172.217.16.138
  • 142.250.186.42
  • 142.250.184.202
  • 142.250.181.234
  • 142.250.185.170
  • 172.217.18.10
  • 142.250.185.234
  • 142.250.74.202
  • 142.250.185.138
  • 142.250.185.202
  • 142.250.185.106
  • 142.250.186.74
  • 172.217.16.202
  • 216.58.212.170
whitelisted

Threats

PID
Process
Class
Message
2284
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
2284
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
2928
service.exe
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External Hosting Lookup by ip-api
2928
service.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
No debug info