File name:

ChromeSetup.exe

Full analysis: https://app.any.run/tasks/143124da-f4f4-428b-81e8-d0e1b487667d
Verdict: Malicious activity
Threats:

XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails.

Analysis date: July 29, 2024, 19:06:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
xworm
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

929D771116E678E8D4A97E2C69160963

SHA1:

63A3FF5DDCDD094D5A3C01330AC768AACC1DD19C

SHA256:

2EAD6E7387F2F85606FA5590CF9D0D93D958337F721FA9B68EF60AAAC5CDDBCA

SSDEEP:

98304:YY6cqxk93Q0DB+eKqNoZxfXbOEMJrq2uEi2ANb7uCeff9WvcEd7OLstmMimsm4ap:4mm9c5Na0jwU/sFMWUL9eVS98/1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ChromeSetup.exe (PID: 6952)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 1780)
      • service.exe (PID: 2928)
      • 126.0.6478.185_chrome_installer.exe (PID: 5236)
      • setup.exe (PID: 1340)
    • XWORM has been detected (YARA)

      • service.exe (PID: 2928)
      • ChromeService.exe (PID: 6396)
    • Scans artifacts that could help determine the target

      • updater.exe (PID: 5496)
    • Uses Task Scheduler to run other applications

      • service.exe (PID: 2928)
    • Changes the autorun value in the registry

      • setup.exe (PID: 1340)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ChromeSetup.exe (PID: 6952)
      • ChromeSetup.exe (PID: 6480)
      • updater.exe (PID: 5496)
      • service.exe (PID: 2928)
    • Executable content was dropped or overwritten

      • ChromeSetup.exe (PID: 6952)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 1780)
      • service.exe (PID: 2928)
      • 126.0.6478.185_chrome_installer.exe (PID: 5236)
      • setup.exe (PID: 1340)
    • Reads the date of Windows installation

      • ChromeSetup.exe (PID: 6952)
      • ChromeSetup.exe (PID: 6480)
      • service.exe (PID: 2928)
    • Application launched itself

      • ChromeSetup.exe (PID: 6480)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 1780)
      • updater.exe (PID: 2996)
      • setup.exe (PID: 1340)
      • setup.exe (PID: 7052)
    • Executes as Windows Service

      • updater.exe (PID: 1780)
      • updater.exe (PID: 2996)
    • Checks Windows Trust Settings

      • updater.exe (PID: 5496)
    • Checks for external IP

      • svchost.exe (PID: 2284)
      • service.exe (PID: 2928)
    • The process executes via Task Scheduler

      • ChromeService.exe (PID: 6396)
      • ChromeService.exe (PID: 1140)
    • Creates a software uninstall entry

      • setup.exe (PID: 1340)
    • Searches for installed software

      • setup.exe (PID: 1340)
  • INFO

    • Checks supported languages

      • ChromeSetup.exe (PID: 6952)
      • ChromeSetup.exe (PID: 6480)
      • service.exe (PID: 2928)
      • ChromeSetup.exe (PID: 1468)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 6176)
      • updater.exe (PID: 1780)
      • updater.exe (PID: 6940)
      • updater.exe (PID: 2996)
      • updater.exe (PID: 2548)
      • ChromeService.exe (PID: 6396)
      • 126.0.6478.185_chrome_installer.exe (PID: 5236)
      • setup.exe (PID: 1340)
      • setup.exe (PID: 7052)
      • setup.exe (PID: 6584)
      • setup.exe (PID: 3484)
      • elevation_service.exe (PID: 6432)
      • ChromeService.exe (PID: 1140)
    • Creates files or folders in the user directory

      • ChromeSetup.exe (PID: 6952)
      • updater.exe (PID: 5496)
      • service.exe (PID: 2928)
    • Reads the machine GUID from the registry

      • ChromeSetup.exe (PID: 6952)
      • service.exe (PID: 2928)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 2996)
      • ChromeService.exe (PID: 6396)
      • ChromeService.exe (PID: 1140)
    • Reads the computer name

      • ChromeSetup.exe (PID: 6952)
      • service.exe (PID: 2928)
      • ChromeSetup.exe (PID: 6480)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 1780)
      • updater.exe (PID: 2996)
      • ChromeService.exe (PID: 6396)
      • 126.0.6478.185_chrome_installer.exe (PID: 5236)
      • setup.exe (PID: 7052)
      • setup.exe (PID: 1340)
      • elevation_service.exe (PID: 6432)
      • ChromeService.exe (PID: 1140)
    • Process checks computer location settings

      • ChromeSetup.exe (PID: 6952)
      • ChromeSetup.exe (PID: 6480)
      • service.exe (PID: 2928)
    • Creates files in the program directory

      • ChromeSetup.exe (PID: 1468)
      • updater.exe (PID: 6176)
      • updater.exe (PID: 5496)
      • updater.exe (PID: 1780)
      • updater.exe (PID: 2996)
      • setup.exe (PID: 1340)
      • setup.exe (PID: 7052)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 5496)
      • updater.exe (PID: 1780)
      • updater.exe (PID: 2996)
    • Reads the software policy settings

      • slui.exe (PID: 1340)
      • updater.exe (PID: 2996)
      • updater.exe (PID: 5496)
      • slui.exe (PID: 2308)
    • Checks proxy server information

      • updater.exe (PID: 5496)
      • slui.exe (PID: 1340)
      • service.exe (PID: 2928)
      • slui.exe (PID: 2308)
    • Create files in a temporary directory

      • updater.exe (PID: 5496)
    • Reads Environment values

      • service.exe (PID: 2928)
    • Disables trace logs

      • service.exe (PID: 2928)
    • Manual execution by a user

      • chrome.exe (PID: 6628)
    • Application launched itself

      • chrome.exe (PID: 6628)
    • Reads Microsoft Office registry keys

      • chrome.exe (PID: 6628)
    • Executes as Windows Service

      • elevation_service.exe (PID: 6432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

XWorm

(PID) Process(2928) service.exe
C2127.0.0.1:7000
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep timeFun
USB drop nameUSB.exe
MutexeSKp869RLHB6w3x0
(PID) Process(6396) ChromeService.exe
C2127.0.0.1:7000
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep timeFun
USB drop nameUSB.exe
MutexeSKp869RLHB6w3x0
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:29 19:06:18+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 9101312
InitializedDataSize: 118272
UninitializedDataSize: -
EntryPoint: 0x8afe8e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 128.0.6597.0
ProductVersionNumber: 128.0.6597.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Chrome Installer
FileVersion: 128.0.6597.0
InternalName: ChromeSetup.exe
LegalCopyright: Copyright 2024 Google LLC. All rights reserved.
OriginalFileName: ChromeSetup.exe
ProductName: Google Chrome Installer
ProductVersion: 128.0.6597.0
AssemblyVersion: 128.0.6597.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
172
Monitored processes
35
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start chromesetup.exe chromesetup.exe no specs #XWORM service.exe chromesetup.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs slui.exe svchost.exe slui.exe schtasks.exe no specs conhost.exe no specs #XWORM chromeservice.exe no specs 126.0.6478.185_chrome_installer.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs elevation_service.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chromeservice.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1140"C:\Users\admin\AppData\Roaming\ChromeService.exe"C:\Users\admin\AppData\Roaming\ChromeService.exesvchost.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome Installer
Version:
128.0.6597.0
Modules
Images
c:\users\admin\appdata\roaming\chromeservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1264"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=4928,i,13241302053712816492,178494292679883311,262144 --variations-seed-version --mojo-platform-channel-handle=4940 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
126.0.6478.185
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1340C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1340"C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\CR_99473.tmp\setup.exe" --install-archive="C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\CR_99473.tmp\CHROME.PACKED.7Z" --verbose-logging --do-not-launch-chrome --channel=stable --installerdata="C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\568e90a1-831b-4212-ac03-8fa3d210c6e6.tmp"C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\CR_99473.tmp\setup.exe
126.0.6478.185_chrome_installer.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome Installer
Exit code:
0
Version:
126.0.6478.185
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping2996_2065277108\cr_99473.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1468"C:\Users\admin\AppData\Roaming\ChromeSetup.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={40B8FEF4-77B7-10A9-3F16-920F3CF0B764}&lang=en&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&brand=VDKB&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Roaming\ChromeSetup.exe
ChromeSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Exit code:
0
Version:
128.0.6597.0
Modules
Images
c:\users\admin\appdata\roaming\chromesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1780"C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe" --system --windows-service --service=update-internalC:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
128.0.6597.0
Modules
Images
c:\program files (x86)\google\googleupdater\128.0.6597.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2284C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2308C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2548"C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=128.0.6597.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x50c694,0x50c6a0,0x50c6acC:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
128.0.6597.0
Modules
Images
c:\program files (x86)\google\googleupdater\128.0.6597.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2692"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3184,i,13241302053712816492,178494292679883311,262144 --variations-seed-version --mojo-platform-channel-handle=3200 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
126.0.6478.185
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
30 627
Read events
30 354
Write events
234
Delete events
39

Modification events

(PID) Process:(6952) ChromeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6952) ChromeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6952) ChromeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6952) ChromeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
128.0.6597.0
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
128.0.6597.0
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{44B969D4-48B7-5A30-9CD6-CAC179D81F9C}
Operation:writeName:AppID
Value:
{44B969D4-48B7-5A30-9CD6-CAC179D81F9C}
(PID) Process:(5496) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{44B969D4-48B7-5A30-9CD6-CAC179D81F9C}
Operation:writeName:LocalService
Value:
GoogleUpdaterInternalService128.0.6597.0
Executable files
12
Suspicious files
64
Text files
29
Unknown types
10

Dropped files

PID
Process
Filename
Type
1468ChromeSetup.exeC:\Windows\SystemTemp\Google1468_1914518675\UPDATER.PACKED.7Z
MD5:
SHA256:
5496updater.exeC:\Program Files (x86)\Google\GoogleUpdater\82355d5c-980a-4c7d-adae-5b19f302ea50.tmpbinary
MD5:7B693A82168C33EC9E8CF276859DDF7F
SHA256:84A9A7F43DB56CD6E9A408F88244E8BA5EFBE48A5B5168D321F112B8C8FD8E3F
5496updater.exeC:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\uninstall.cmdtext
MD5:FBC297EE9060D4256192E4EDB98CAD1B
SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044
5496updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:ECC5EAB1AE20D131940E241806A05883
SHA256:F882EA78921B20522C694CCC5BED9326B7E139ECF41937ED5A453E29E749759F
6952ChromeSetup.exeC:\Users\admin\AppData\Roaming\service.exeexecutable
MD5:9E648ECF689E7A9F71E2324A031453E7
SHA256:F816907918B31FA5F2C4CA1D694CC686AB8BFF3B5ECBA8A842F98A4E895F698D
2996updater.exeC:\Windows\SystemTemp\chrome_url_fetcher_2996_1602856595\-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.185_all_dki7xbmbf4uwyjehq4wg2ptqdm.crx3
MD5:
SHA256:
2996updater.exeC:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping2996_2065277108\126.0.6478.185_chrome_installer.exe
MD5:
SHA256:
5496updater.exeC:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exeexecutable
MD5:823816B4A601C69C89435EE17EF7B9E0
SHA256:C2A7C0FA80F228C2CE599E4427280997EA9E1A3F85ED32E5D5E4219DFB05DDB2
5496updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:7B693A82168C33EC9E8CF276859DDF7F
SHA256:84A9A7F43DB56CD6E9A408F88244E8BA5EFBE48A5B5168D321F112B8C8FD8E3F
5496updater.exeC:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\Crashpad\settings.datbinary
MD5:DE9366D034D9265C241098E3E1E79B85
SHA256:29F77EAE6727F8CB11C51FD76DE9803226569EA5CEE9E544815DF673199CA9BC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
46
DNS requests
35
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2928
service.exe
GET
200
208.95.112.1:80
http://ip-api.com/line/?fields=hosting
unknown
shared
2996
updater.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/fk7y73e6x3yfec6kkxw4fcvrxu_126.0.6478.185/-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.185_all_dki7xbmbf4uwyjehq4wg2ptqdm.crx3
unknown
whitelisted
POST
200
142.250.181.227:443
https://update.googleapis.com/service/update2/json?cup2key=14:tFX5Ri-fIgRvlbWNG9-9XV5uBgPybuBybtXMVQ2VHPk&cup2hreq=73258891c1a3774fd3acc6aab31eb92b5786606f028baa0e328de70f87e2a4e4
unknown
text
681 Kb
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
GET
200
172.217.16.196:443
https://dl.google.com/update2/installers/icons/%7B8a69d345-d564-463c-aff1-a69d9e530f96%7D.bmp?lang=en-US
unknown
image
6.52 Kb
POST
200
20.189.173.23:443
https://self.events.data.microsoft.com/OneCollector/1.0/
unknown
binary
9 b
POST
200
142.250.181.227:443
https://update.googleapis.com/service/update2/json
unknown
text
224 b
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
POST
204
95.100.146.32:443
https://www.bing.com/threshold/xls.aspx
unknown
GET
200
172.217.16.196:443
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
unknown
text
2.98 Kb
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4580
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
6012
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2424
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1108
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
92.123.104.34:443
Akamai International B.V.
DE
unknown
3228
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 216.58.212.174
whitelisted
update.googleapis.com
  • 142.250.186.99
whitelisted
dl.google.com
  • 216.58.206.78
whitelisted
self.events.data.microsoft.com
  • 20.189.173.14
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
ip-api.com
  • 208.95.112.1
shared
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.44
whitelisted
safebrowsingohttpgateway.googleapis.com
  • 142.250.186.106
  • 216.58.206.74
  • 172.217.16.138
  • 142.250.186.42
  • 142.250.184.202
  • 142.250.181.234
  • 142.250.185.170
  • 172.217.18.10
  • 142.250.185.234
  • 142.250.74.202
  • 142.250.185.138
  • 142.250.185.202
  • 142.250.185.106
  • 142.250.186.74
  • 172.217.16.202
  • 216.58.212.170
whitelisted

Threats

PID
Process
Class
Message
2284
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
2284
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
2928
service.exe
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External Hosting Lookup by ip-api
2928
service.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
No debug info