| File name: | ChromeSetup.exe |
| Full analysis: | https://app.any.run/tasks/f1c6f4f5-df4e-467e-b830-b6d156585650 |
| Verdict: | Malicious activity |
| Analysis date: | November 14, 2023, 14:32:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 357A859E4EBE58CBF9EA32C2E4838E84 |
| SHA1: | A05D0D9287212CD25E4F6B910CAB18E80B0BD2CC |
| SHA256: | 59520F027B2D305F636D0746F624B2ED8CC0DFC22BF71BFA69B7EA8BC0DD921A |
| SSDEEP: | 49152:x0CCgjrWixP7s/fi27SgIHhztL1HikHHH5nNWFTy6L0/xxoRm5Eofgirs21JCNXR:CJardz4IH1tBCkHHtAFTy8axoga321JH |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:10:31 21:55:02+01:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.2 |
| CodeSize: | 96256 |
| InitializedDataSize: | 1266176 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x5374 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.36.332 |
| ProductVersionNumber: | 1.3.36.332 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Update Setup |
| FileVersion: | 1.3.36.332 |
| InternalName: | Google Update Setup |
| LegalCopyright: | Copyright 2018 Google LLC |
| OriginalFileName: | GoogleUpdateSetup.exe |
| ProductName: | Google Update |
| ProductVersion: | 1.3.36.332 |
| LanguageId: | en |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 296 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1352 --field-trial-handle=1260,i,5176692645692509350,13717656912004742495,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 476 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /broker | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdateBroker.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 916 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1120 --field-trial-handle=1152,i,10518288542638294903,5453546924831082686,131072 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 968 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3796 --field-trial-handle=1152,i,10518288542638294903,5453546924831082686,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1004 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=1152,i,10518288542638294903,5453546924831082686,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1344 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2112 --field-trial-handle=1152,i,10518288542638294903,5453546924831082686,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1344 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=18 --mojo-platform-channel-handle=1040 --field-trial-handle=1152,i,10518288542638294903,5453546924831082686,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1356 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2104 --field-trial-handle=1152,i,10518288542638294903,5453546924831082686,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1436 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1548 --field-trial-handle=1152,i,10518288542638294903,5453546924831082686,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1644 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1288 --field-trial-handle=1152,i,10518288542638294903,5453546924831082686,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (3408) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3408) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | delete value | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3408) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update |
| Operation: | write | Name: | path |
Value: C:\Program Files\Google\Update\GoogleUpdate.exe | |||
| (PID) Process: | (3408) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update |
| Operation: | write | Name: | UninstallCmdLine |
Value: "C:\Program Files\Google\Update\GoogleUpdate.exe" /uninstall | |||
| (PID) Process: | (3408) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | pv |
Value: 1.3.36.32 | |||
| (PID) Process: | (3408) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | name |
Value: Google Update | |||
| (PID) Process: | (3408) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | pv |
Value: 1.3.36.32 | |||
| (PID) Process: | (3408) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe |
| Operation: | write | Name: | DisableExceptionChainValidation |
Value: 0 | |||
| (PID) Process: | (3492) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3492) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\goopdate.dll | executable | |
MD5:1B8476E8D19AD4AEF1A6358FE74F9DA2 | SHA256:9DA76ABE1412B24A468E03793285EA0D5D60463F67B9D512DB7839F2D85C9FC1 | |||
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\GoogleUpdate.exe | executable | |
MD5:B07F2B96517CF26510F56B0F51E576BE | SHA256:83F0585A53CB0C83E4FF4E9A405BFE65AA538E3DABE384896007D823E7244E4B | |||
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\GoogleUpdateOnDemand.exe | executable | |
MD5:1EEE1F961D3A499E7307B387164F3F04 | SHA256:4492E3FCBAB5594F3D480B20F9E7255143372925B1107DA668D47E5B1B0633EE | |||
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\GoogleUpdateBroker.exe | executable | |
MD5:DA290404FB2782937BF98B9F1403AE99 | SHA256:DBAF6C0089ED33DD8DB2874679AD2DB04836D1E222C9D7FEAC9C358173354CC9 | |||
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\goopdateres_bn.dll | executable | |
MD5:786A67D984853F1BB89231781DB16549 | SHA256:A55FA814B9AEC1F68F6D287DBA468F579FB8FD9BF3510E256F7F547DEACDA075 | |||
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\goopdateres_am.dll | executable | |
MD5:1D38140792B8F1717CE4A4D6A9886488 | SHA256:949E2130A99861303CD1C242B0E99FBA99D1D328CCB7E8AC387A6F74763102FD | |||
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\GoogleUpdateComRegisterShell64.exe | executable | |
MD5:D5C70ACAF478F02B04AC16F66FD50B37 | SHA256:76FCF8BEE94C621AE04EAB99982BA2D8A921AC26A9F4FC8FD95842941FB22141 | |||
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\psmachine.dll | executable | |
MD5:CE945DC53FB69D35E10DAF751F6B4FAB | SHA256:F0A129AF2122A32CA7410EECD7060E4044C11CBF60DDE9C2D543A70A968E6266 | |||
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\psuser_64.dll | executable | |
MD5:9C6C231596B870E77E260C81566483A8 | SHA256:A408199AE0E55F829CD0B4F2670DE263902A4B811731F85D3F5B98DFD1433E87 | |||
| 3428 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM6F68.tmp\psuser.dll | executable | |
MD5:B1E43F3E1CE2B2D68F6FEE1F69CA3135 | SHA256:AC4CD4C161A53CF6C1BCA4AE8E61035B843E9148494E2FDA2123F9D70520C085 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3644 | GoogleUpdate.exe | GET | 200 | 67.26.75.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?673e729f3e7fe27f | unknown | compressed | 4.66 Kb | unknown |
3644 | GoogleUpdate.exe | GET | 200 | 142.250.184.195:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | unknown |
3644 | GoogleUpdate.exe | GET | 200 | 142.250.184.195:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | binary | 724 b | unknown |
3644 | GoogleUpdate.exe | GET | 200 | 142.250.184.195:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCLPpgizFvtXApe3cL6kC3u | unknown | binary | 472 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3840 | GoogleUpdate.exe | 142.250.185.163:443 | update.googleapis.com | GOOGLE | US | whitelisted |
3652 | GoogleUpdate.exe | 142.250.185.163:443 | update.googleapis.com | GOOGLE | US | whitelisted |
3644 | GoogleUpdate.exe | 142.250.186.142:443 | dl.google.com | GOOGLE | US | whitelisted |
3644 | GoogleUpdate.exe | 67.26.75.254:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
3644 | GoogleUpdate.exe | 142.250.184.195:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
4088 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
clientservices.googleapis.com |
| unknown |
accounts.google.com |
| shared |
www.google.com |
| unknown |
optimizationguide-pa.googleapis.com |
| whitelisted |
dns.msftncsi.com |
| shared |
www.googleapis.com |
| whitelisted |