File name:

BetterTogetherSetup.exe

Full analysis: https://app.any.run/tasks/5abf599a-c4a6-4137-b830-0691618f3d5f
Verdict: Malicious activity
Analysis date: August 23, 2024, 11:45:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
qrcode
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DBDE67ED51CA9537638D4213332B83C1

SHA1:

B20B55A134368004CD0BA9146D83642B5BB4E847

SHA256:

3C393E423E366796E717B93FE16CE955917E2076F9788CE92256D627F4C80077

SSDEEP:

98304:Ufz4nHZjHlbPuXhJ0PRTL8LjN3RQHfj1mw1Y8oJy+gcBML9rW86oldXEBaB4E1sB:B0xh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • updater.exe (PID: 7016)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 6232)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 2068)
      • powershell.exe (PID: 2868)
      • powershell.exe (PID: 5112)
      • powershell.exe (PID: 488)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • BetterTogetherSetup.exe (PID: 6920)
      • updater.exe (PID: 7016)
      • updater.exe (PID: 7108)
      • msiexec.exe (PID: 6232)
    • Reads security settings of Internet Explorer

      • BetterTogetherSetup.exe (PID: 6920)
      • updater.exe (PID: 7016)
      • nearby_config.exe (PID: 7144)
    • Reads the date of Windows installation

      • BetterTogetherSetup.exe (PID: 6920)
    • Application launched itself

      • BetterTogetherSetup.exe (PID: 6920)
      • updater.exe (PID: 7016)
      • updater.exe (PID: 7108)
      • updater.exe (PID: 5148)
    • Executes as Windows Service

      • updater.exe (PID: 7108)
      • updater.exe (PID: 5148)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 7016)
      • updater.exe (PID: 7108)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6232)
    • The process bypasses the loading of PowerShell profile settings

      • msiexec.exe (PID: 6256)
    • Starts POWERSHELL.EXE for commands execution

      • msiexec.exe (PID: 6256)
    • The process hide an interactive prompt from the user

      • msiexec.exe (PID: 6256)
    • Checks Windows Trust Settings

      • updater.exe (PID: 7016)
    • The process hides Powershell's copyright startup banner

      • msiexec.exe (PID: 6256)
    • Executes powershell module file

      • msiexec.exe (PID: 6256)
  • INFO

    • Reads the computer name

      • BetterTogetherSetup.exe (PID: 6920)
      • updater.exe (PID: 7016)
      • updater.exe (PID: 5148)
      • updater.exe (PID: 7108)
      • msiexec.exe (PID: 6256)
      • msiexec.exe (PID: 6232)
      • nearby_config.exe (PID: 1776)
      • nearby_config.exe (PID: 7144)
    • Checks supported languages

      • BetterTogetherSetup.exe (PID: 6920)
      • BetterTogetherSetup.exe (PID: 6992)
      • updater.exe (PID: 7016)
      • updater.exe (PID: 7036)
      • updater.exe (PID: 7108)
      • updater.exe (PID: 7128)
      • updater.exe (PID: 5148)
      • updater.exe (PID: 2096)
      • msiexec.exe (PID: 6232)
      • msiexec.exe (PID: 6256)
      • nearby_config.exe (PID: 1776)
      • nearby_config.exe (PID: 5516)
      • nearby_config.exe (PID: 7144)
    • Process checks computer location settings

      • BetterTogetherSetup.exe (PID: 6920)
      • nearby_config.exe (PID: 1776)
      • nearby_config.exe (PID: 5516)
      • nearby_config.exe (PID: 7144)
    • Creates files in the program directory

      • BetterTogetherSetup.exe (PID: 6992)
      • updater.exe (PID: 7016)
      • updater.exe (PID: 7036)
      • updater.exe (PID: 7108)
      • updater.exe (PID: 5148)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 7016)
      • updater.exe (PID: 7108)
      • updater.exe (PID: 5148)
    • Checks proxy server information

      • updater.exe (PID: 7016)
    • Reads the software policy settings

      • updater.exe (PID: 5148)
      • updater.exe (PID: 7016)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 5148)
      • updater.exe (PID: 7016)
    • Creates files or folders in the user directory

      • updater.exe (PID: 7016)
    • Create files in a temporary directory

      • updater.exe (PID: 7016)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6232)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 7164)
      • powershell.exe (PID: 2868)
      • powershell.exe (PID: 5112)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6232)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 2068)
      • powershell.exe (PID: 488)
    • Reads security settings of Internet Explorer

      • OpenWith.exe (PID: 6388)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 6388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:11 15:02:23+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2877440
InitializedDataSize: 6053376
UninitializedDataSize: -
EntryPoint: 0x1511f0
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 129.0.6651.0
ProductVersionNumber: 129.0.6651.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Chrome Installer
FileVersion: 129.0.6651.0
InternalName: Google Chrome
LegalCopyright: Copyright 2024 Google LLC. All rights reserved.
ProductName: Google Chrome Installer
ProductVersion: 129.0.6651.0
CompanyShortName: Google
ProductShortName: Chrome Installer
LastChange: 1fee8392336d433471a03f97efee1a8eded6ccce-refs/branch-heads/6651@{#1}
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
29
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bettertogethersetup.exe no specs bettertogethersetup.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs nearby_config.exe conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs nearby_config.exe conhost.exe no specs nearby_config.exe conhost.exe no specs nearby_share_launcher.exe no specs openwith.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
232msiexec REBOOT=ReallySuppress /qn /i "C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping5148_1612572624\better_together.msi" /log "C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping5148_1612572624\better_together.msi.log"C:\Windows\SysWOW64\msiexec.exeupdater.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
488"C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -NoLogo -windowstyle Hidden -Command "Import-Module \"C:\Program Files\Google\NearbyShare\scripts\nearby_management.psm1\";Install-IntelDriver"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\oleaut32.dll
964"C:\Program Files\Google\NearbyShare\nearby_share_launcher.exe"C:\Program Files\Google\NearbyShare\nearby_share_launcher.exemsiexec.exe
User:
SYSTEM
Company:
Google
Integrity Level:
SYSTEM
Description:
Quick Share from Google
Exit code:
3221225473
Version:
1.0.1724.0
Modules
Images
c:\program files\google\nearbyshare\nearby_share_launcher.exe
c:\windows\system32\ntdll.dll
1480\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1776"C:\Program Files\Google\NearbyShare\nearby_config.exe" --create_shortcutC:\Program Files\Google\NearbyShare\nearby_config.exe
msiexec.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\google\nearbyshare\nearby_config.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
1928\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2024\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenearby_config.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2068"C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -NoLogo -windowstyle Hidden -Command "Import-Module \"C:\Program Files\Google\NearbyShare\scripts\nearby_management.psm1\";Clear-NearbyShareInstallation"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\oleaut32.dll
2096"C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=129.0.6651.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2b4,0x2b8,0x2bc,0x290,0x2c0,0xab06cc,0xab06d8,0xab06e4C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
129.0.6651.0
Modules
Images
c:\program files (x86)\google\googleupdater\129.0.6651.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2820\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
51 613
Read events
51 266
Write events
313
Delete events
34

Modification events

(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
129.0.6651.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
129.0.6651.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
Operation:writeName:AppID
Value:
{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
Operation:writeName:LocalService
Value:
GoogleUpdaterInternalService129.0.6651.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{D4757239-55B2-5C3D-8B06-DDE147267C2D}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4757239-55B2-5C3D-8B06-DDE147267C2D}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7016) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{119413E1-D553-5881-9669-43EB131F5143}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
31
Suspicious files
59
Text files
49
Unknown types
6

Dropped files

PID
Process
Filename
Type
6992BetterTogetherSetup.exeC:\Windows\SystemTemp\Google6992_2124990791\UPDATER.PACKED.7Z
MD5:
SHA256:
7016updater.exeC:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\uninstall.cmdtext
MD5:FBC297EE9060D4256192E4EDB98CAD1B
SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044
7016updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:AECBD8FE3F7B64DDF70A33B920FD4BB4
SHA256:8BB68574186A8C571E687AF459DC5917A5FE2FB8EAD1048E6286E74A87AD06A3
7016updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:F521F8DD2F7A21A968E38B1638AEBA0D
SHA256:2C1FAA2BC3F66650FA2AFF0385A891A5A44ED1BFA00A800742DE73DACAED27D3
7016updater.exeC:\Program Files (x86)\Google\GoogleUpdater\1216862d-8e82-40df-882a-20235e19ead2.tmpbinary
MD5:AECBD8FE3F7B64DDF70A33B920FD4BB4
SHA256:8BB68574186A8C571E687AF459DC5917A5FE2FB8EAD1048E6286E74A87AD06A3
5148updater.exeC:\Windows\SystemTemp\chrome_url_fetcher_5148_1358365643\-232066fe-ff4d-4c25-83b4-3f8747cf7e3a-_1.0.1724.0_all_adj6ihimzxwuvnm3hyqu22jr2qmq.crx3
MD5:
SHA256:
5148updater.exeC:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping5148_1612572624\better_together.msi
MD5:
SHA256:
7016updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DDE8B1B7E253A9758EC380BD648952AF_68D058512F3515153DEB95A1F4E72552der
MD5:422606778F6D2E49A58DB1BBF3C1151A
SHA256:B8DB68A61414973A8DF9BF4EADA88200D0D8780F6B8990D1B1A481F53872266D
7016updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:739EB707C36625F012CF6E9E01DF584B
SHA256:5FDFD8C859CC0455B96477179E3B1464E73628B864FFC8A5298D7EC118695E50
7108updater.exeC:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\prefs.jsonbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
64
DNS requests
29
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7016
updater.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
5148
updater.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/Nearby/adimotrslp4l442caegiaqkgmhrq_1.0.1724.0/-232066fe-ff4d-4c25-83b4-3f8747cf7e3a-_1.0.1724.0_all_adj6ihimzxwuvnm3hyqu22jr2qmq.crx3
unknown
whitelisted
7016
updater.exe
GET
200
142.250.185.131:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
7016
updater.exe
GET
200
172.217.16.195:80
http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEHGN%2BKTRSIp4CcztJxB9gYQ%3D
unknown
whitelisted
236
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
236
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
236
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5940
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3324
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
3324
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA5EGOLe3jbdKXTDRDr7XOU%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5540
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1492
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
5148
updater.exe
216.58.212.131:443
update.googleapis.com
GOOGLE
US
whitelisted
7016
updater.exe
142.250.185.206:443
dl.google.com
GOOGLE
US
whitelisted
5148
updater.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE
US
whitelisted
7016
updater.exe
142.250.184.195:80
ocsp.pki.goog
GOOGLE
US
whitelisted
7016
updater.exe
142.250.185.131:80
c.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.46
whitelisted
update.googleapis.com
  • 216.58.212.131
whitelisted
dl.google.com
  • 142.250.185.206
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
ocsp.pki.goog
  • 142.250.184.195
whitelisted
c.pki.goog
  • 142.250.185.131
whitelisted
o.pki.goog
  • 172.217.16.195
whitelisted
client.wns.windows.com
  • 40.113.103.199
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.72
  • 20.190.160.20
  • 40.126.32.136
  • 40.126.32.134
  • 20.190.160.17
  • 40.126.32.138
  • 40.126.32.68
whitelisted

Threats

No threats detected
Process
Message
nearby_config.exe
I0823 11:46:05.132365 8 main.cc:336] GetPreferredLanguages() returns: en-US. nearby::localization::InitializeL10n returns: en
nearby_config.exe
I0823 11:46:05.132669 8 main.cc:414] CreateShortcut: Creating shortcut.
nearby_config.exe
I0823 11:46:05.135810 8 main.cc:378] GetPublicDesktopPath: the public desktop path is C:\Users\Public\Desktop
nearby_config.exe
I0823 11:46:05.136388 8 main.cc:427] CreateShortcut: shortcut_path is C:\Users\Public\Desktop\Quick Share from Google.lnk, target_path is C:\Program Files\Google\NearbyShare\nearby_share.exe
nearby_config.exe
I0823 11:46:05.181823 8 main.cc:572] Nearby configuration Done
nearby_config.exe
I0823 11:46:16.046622 5524 main.cc:336] GetPreferredLanguages() returns: en-US. nearby::localization::InitializeL10n returns: en
nearby_config.exe
I0823 11:46:16.046834 5524 main.cc:301] FixSparsePackage: Failed to delete registry key for user .DEFAULT
nearby_config.exe
I0823 11:46:16.046880 5524 main.cc:301] FixSparsePackage: Failed to delete registry key for user S-1-5-19
nearby_config.exe
I0823 11:46:16.046919 5524 main.cc:301] FixSparsePackage: Failed to delete registry key for user S-1-5-20
nearby_config.exe
I0823 11:46:16.046970 5524 main.cc:301] FixSparsePackage: Failed to delete registry key for user S-1-5-21-1693682860-607145093-2874071422-1001