File name:

BetterTogetherSetup.exe

Full analysis: https://app.any.run/tasks/5abf599a-c4a6-4137-b830-0691618f3d5f
Verdict: Malicious activity
Analysis date: August 23, 2024, 11:45:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
qrcode
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DBDE67ED51CA9537638D4213332B83C1

SHA1:

B20B55A134368004CD0BA9146D83642B5BB4E847

SHA256:

3C393E423E366796E717B93FE16CE955917E2076F9788CE92256D627F4C80077

SSDEEP:

98304:Ufz4nHZjHlbPuXhJ0PRTL8LjN3RQHfj1mw1Y8oJy+gcBML9rW86oldXEBaB4E1sB:B0xh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • updater.exe (PID: 7016)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 6232)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 2868)
      • powershell.exe (PID: 5112)
      • powershell.exe (PID: 2068)
      • powershell.exe (PID: 488)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • BetterTogetherSetup.exe (PID: 6920)
      • updater.exe (PID: 7108)
      • updater.exe (PID: 7016)
      • msiexec.exe (PID: 6232)
    • Reads security settings of Internet Explorer

      • BetterTogetherSetup.exe (PID: 6920)
      • updater.exe (PID: 7016)
      • nearby_config.exe (PID: 7144)
    • Reads the date of Windows installation

      • BetterTogetherSetup.exe (PID: 6920)
    • Application launched itself

      • BetterTogetherSetup.exe (PID: 6920)
      • updater.exe (PID: 7016)
      • updater.exe (PID: 7108)
      • updater.exe (PID: 5148)
    • Executes as Windows Service

      • updater.exe (PID: 5148)
      • updater.exe (PID: 7108)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 7108)
      • updater.exe (PID: 7016)
    • Checks Windows Trust Settings

      • updater.exe (PID: 7016)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6232)
    • Starts POWERSHELL.EXE for commands execution

      • msiexec.exe (PID: 6256)
    • The process bypasses the loading of PowerShell profile settings

      • msiexec.exe (PID: 6256)
    • The process hide an interactive prompt from the user

      • msiexec.exe (PID: 6256)
    • Executes powershell module file

      • msiexec.exe (PID: 6256)
    • The process hides Powershell's copyright startup banner

      • msiexec.exe (PID: 6256)
  • INFO

    • Process checks computer location settings

      • BetterTogetherSetup.exe (PID: 6920)
      • nearby_config.exe (PID: 1776)
      • nearby_config.exe (PID: 5516)
      • nearby_config.exe (PID: 7144)
    • Reads the computer name

      • BetterTogetherSetup.exe (PID: 6920)
      • updater.exe (PID: 7016)
      • updater.exe (PID: 7108)
      • updater.exe (PID: 5148)
      • msiexec.exe (PID: 6232)
      • msiexec.exe (PID: 6256)
      • nearby_config.exe (PID: 1776)
      • nearby_config.exe (PID: 7144)
    • Checks supported languages

      • BetterTogetherSetup.exe (PID: 6920)
      • BetterTogetherSetup.exe (PID: 6992)
      • updater.exe (PID: 7016)
      • updater.exe (PID: 7036)
      • updater.exe (PID: 7128)
      • updater.exe (PID: 5148)
      • updater.exe (PID: 2096)
      • updater.exe (PID: 7108)
      • msiexec.exe (PID: 6232)
      • msiexec.exe (PID: 6256)
      • nearby_config.exe (PID: 1776)
      • nearby_config.exe (PID: 5516)
      • nearby_config.exe (PID: 7144)
    • Creates files in the program directory

      • BetterTogetherSetup.exe (PID: 6992)
      • updater.exe (PID: 7016)
      • updater.exe (PID: 7036)
      • updater.exe (PID: 7108)
      • updater.exe (PID: 5148)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 7016)
      • updater.exe (PID: 7108)
      • updater.exe (PID: 5148)
    • Checks proxy server information

      • updater.exe (PID: 7016)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 7016)
      • updater.exe (PID: 5148)
    • Reads the software policy settings

      • updater.exe (PID: 5148)
      • updater.exe (PID: 7016)
    • Creates files or folders in the user directory

      • updater.exe (PID: 7016)
    • Create files in a temporary directory

      • updater.exe (PID: 7016)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6232)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6232)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 2068)
      • powershell.exe (PID: 488)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 5112)
      • powershell.exe (PID: 2868)
      • powershell.exe (PID: 7164)
    • Reads security settings of Internet Explorer

      • OpenWith.exe (PID: 6388)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 6388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:11 15:02:23+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2877440
InitializedDataSize: 6053376
UninitializedDataSize: -
EntryPoint: 0x1511f0
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 129.0.6651.0
ProductVersionNumber: 129.0.6651.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Chrome Installer
FileVersion: 129.0.6651.0
InternalName: Google Chrome
LegalCopyright: Copyright 2024 Google LLC. All rights reserved.
ProductName: Google Chrome Installer
ProductVersion: 129.0.6651.0
CompanyShortName: Google
ProductShortName: Chrome Installer
LastChange: 1fee8392336d433471a03f97efee1a8eded6ccce-refs/branch-heads/6651@{#1}
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
29
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bettertogethersetup.exe no specs bettertogethersetup.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs nearby_config.exe conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs nearby_config.exe conhost.exe no specs nearby_config.exe conhost.exe no specs nearby_share_launcher.exe no specs openwith.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
232msiexec REBOOT=ReallySuppress /qn /i "C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping5148_1612572624\better_together.msi" /log "C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping5148_1612572624\better_together.msi.log"C:\Windows\SysWOW64\msiexec.exeupdater.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
488"C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -NoLogo -windowstyle Hidden -Command "Import-Module \"C:\Program Files\Google\NearbyShare\scripts\nearby_management.psm1\";Install-IntelDriver"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\oleaut32.dll
964"C:\Program Files\Google\NearbyShare\nearby_share_launcher.exe"C:\Program Files\Google\NearbyShare\nearby_share_launcher.exemsiexec.exe
User:
SYSTEM
Company:
Google
Integrity Level:
SYSTEM
Description:
Quick Share from Google
Exit code:
3221225473
Version:
1.0.1724.0
Modules
Images
c:\program files\google\nearbyshare\nearby_share_launcher.exe
c:\windows\system32\ntdll.dll
1480\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1776"C:\Program Files\Google\NearbyShare\nearby_config.exe" --create_shortcutC:\Program Files\Google\NearbyShare\nearby_config.exe
msiexec.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\google\nearbyshare\nearby_config.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
1928\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2024\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenearby_config.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2068"C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -NoLogo -windowstyle Hidden -Command "Import-Module \"C:\Program Files\Google\NearbyShare\scripts\nearby_management.psm1\";Clear-NearbyShareInstallation"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\oleaut32.dll
2096"C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=129.0.6651.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2b4,0x2b8,0x2bc,0x290,0x2c0,0xab06cc,0xab06d8,0xab06e4C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
129.0.6651.0
Modules
Images
c:\program files (x86)\google\googleupdater\129.0.6651.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2820\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
51 613
Read events
51 266
Write events
313
Delete events
34

Modification events

(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
129.0.6651.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
129.0.6651.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
Operation:writeName:AppID
Value:
{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
Operation:writeName:LocalService
Value:
GoogleUpdaterInternalService129.0.6651.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{D4757239-55B2-5C3D-8B06-DDE147267C2D}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4757239-55B2-5C3D-8B06-DDE147267C2D}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{119413E1-D553-5881-9669-43EB131F5143}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
31
Suspicious files
59
Text files
49
Unknown types
6

Dropped files

PID
Process
Filename
Type
6992BetterTogetherSetup.exeC:\Windows\SystemTemp\Google6992_2124990791\UPDATER.PACKED.7Z
MD5:
SHA256:
7108updater.exeC:\Windows\SystemTemp\Google7108_1004887511\scoped_dir7108_1262174470\GoogleUpdate.exeexecutable
MD5:3AA2C853D6BC7AF7F2F9B8A934943EFD
SHA256:07034876B9EC0B59432B96FEDB7E10E332440159F9802FAAD5F5B99F01885F6B
7016updater.exeC:\Program Files (x86)\Google\GoogleUpdater\1216862d-8e82-40df-882a-20235e19ead2.tmpbinary
MD5:AECBD8FE3F7B64DDF70A33B920FD4BB4
SHA256:8BB68574186A8C571E687AF459DC5917A5FE2FB8EAD1048E6286E74A87AD06A3
7108updater.exeC:\Program Files (x86)\Google\GoogleUpdater\d0450157-dd70-4c6c-9d52-3fd03e1462d5.tmpbinary
MD5:A34CBF631EA340337064CBF943E0E4D3
SHA256:80D486340B6C4A49FB28BAED7D35A0973DBE100D2DB8CD01785CF13C5D9471BA
7108updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:A34CBF631EA340337064CBF943E0E4D3
SHA256:80D486340B6C4A49FB28BAED7D35A0973DBE100D2DB8CD01785CF13C5D9471BA
5148updater.exeC:\Windows\SystemTemp\chrome_url_fetcher_5148_1358365643\-232066fe-ff4d-4c25-83b4-3f8747cf7e3a-_1.0.1724.0_all_adj6ihimzxwuvnm3hyqu22jr2qmq.crx3
MD5:
SHA256:
5148updater.exeC:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5148_1612572624\better_together.msi
MD5:
SHA256:
7016updater.exeC:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exeexecutable
MD5:A1361C84AE51AE71617978842D129712
SHA256:C06BF6776AA78E9AA48F7B1F19AE9B77B7E3277066003C653AB501304D8C2F10
7016updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:AECBD8FE3F7B64DDF70A33B920FD4BB4
SHA256:8BB68574186A8C571E687AF459DC5917A5FE2FB8EAD1048E6286E74A87AD06A3
7016updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DDE8B1B7E253A9758EC380BD648952AF_68D058512F3515153DEB95A1F4E72552binary
MD5:1774568CF39733B7E03508F5130BABDA
SHA256:7223B97E427619CF02CD815C2535404C435283DA2595D687799787A5A8795F6D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
64
DNS requests
29
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7016
updater.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
7016
updater.exe
GET
200
142.250.185.131:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
5148
updater.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/Nearby/adimotrslp4l442caegiaqkgmhrq_1.0.1724.0/-232066fe-ff4d-4c25-83b4-3f8747cf7e3a-_1.0.1724.0_all_adj6ihimzxwuvnm3hyqu22jr2qmq.crx3
unknown
whitelisted
7016
updater.exe
GET
200
172.217.16.195:80
http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEHGN%2BKTRSIp4CcztJxB9gYQ%3D
unknown
whitelisted
236
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
236
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
236
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5940
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3324
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6820
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5540
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1492
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
5148
updater.exe
216.58.212.131:443
update.googleapis.com
GOOGLE
US
whitelisted
7016
updater.exe
142.250.185.206:443
dl.google.com
GOOGLE
US
whitelisted
5148
updater.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE
US
whitelisted
7016
updater.exe
142.250.184.195:80
ocsp.pki.goog
GOOGLE
US
whitelisted
7016
updater.exe
142.250.185.131:80
c.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.46
whitelisted
update.googleapis.com
  • 216.58.212.131
whitelisted
dl.google.com
  • 142.250.185.206
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
ocsp.pki.goog
  • 142.250.184.195
whitelisted
c.pki.goog
  • 142.250.185.131
whitelisted
o.pki.goog
  • 172.217.16.195
whitelisted
client.wns.windows.com
  • 40.113.103.199
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.72
  • 20.190.160.20
  • 40.126.32.136
  • 40.126.32.134
  • 20.190.160.17
  • 40.126.32.138
  • 40.126.32.68
whitelisted

Threats

No threats detected
Process
Message
nearby_config.exe
I0823 11:46:05.132365 8 main.cc:336] GetPreferredLanguages() returns: en-US. nearby::localization::InitializeL10n returns: en
nearby_config.exe
I0823 11:46:05.132669 8 main.cc:414] CreateShortcut: Creating shortcut.
nearby_config.exe
I0823 11:46:05.135810 8 main.cc:378] GetPublicDesktopPath: the public desktop path is C:\Users\Public\Desktop
nearby_config.exe
I0823 11:46:05.136388 8 main.cc:427] CreateShortcut: shortcut_path is C:\Users\Public\Desktop\Quick Share from Google.lnk, target_path is C:\Program Files\Google\NearbyShare\nearby_share.exe
nearby_config.exe
I0823 11:46:05.181823 8 main.cc:572] Nearby configuration Done
nearby_config.exe
I0823 11:46:16.046622 5524 main.cc:336] GetPreferredLanguages() returns: en-US. nearby::localization::InitializeL10n returns: en
nearby_config.exe
I0823 11:46:16.046834 5524 main.cc:301] FixSparsePackage: Failed to delete registry key for user .DEFAULT
nearby_config.exe
I0823 11:46:16.046880 5524 main.cc:301] FixSparsePackage: Failed to delete registry key for user S-1-5-19
nearby_config.exe
I0823 11:46:16.046919 5524 main.cc:301] FixSparsePackage: Failed to delete registry key for user S-1-5-20
nearby_config.exe
I0823 11:46:16.046970 5524 main.cc:301] FixSparsePackage: Failed to delete registry key for user S-1-5-21-1693682860-607145093-2874071422-1001