File name:

ChromeSetup.exe

Full analysis: https://app.any.run/tasks/a4e48a7b-a6b2-49d5-8ba4-f368e7f5c502
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: September 03, 2024, 11:37:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0A4086E33A2F82461DD4E875CF73275B

SHA1:

98EBC91C4AF42E936889AAAA7FC6E700AC30E263

SHA256:

598B18F0457C045C30749881E5695DA1F42DEC29CE619FE3922714EDBB39C66C

SSDEEP:

49152:a/xmMcYYKpEuz/M1i/3m8sZvVA/nqQKSJvxHy4Oc21ZrTTHdxRlHGQ3nWKS5cs4y:g4t6pnPYZq/qQKSfu1FdjAmn82R6eGig

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • GoogleUpdate.exe (PID: 2068)
    • Changes the autorun value in the registry

      • setup.exe (PID: 1616)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ChromeSetup.exe (PID: 4996)
      • GoogleUpdateSetup.exe (PID: 508)
      • 128.0.6613.120_chrome_installer.exe (PID: 3812)
      • setup.exe (PID: 1616)
    • Reads the date of Windows installation

      • GoogleUpdate.exe (PID: 2180)
      • GoogleUpdate.exe (PID: 5276)
    • Reads security settings of Internet Explorer

      • GoogleUpdate.exe (PID: 2180)
      • GoogleUpdate.exe (PID: 2068)
      • GoogleUpdate.exe (PID: 5276)
    • Potential Corporate Privacy Violation

      • GoogleUpdate.exe (PID: 2068)
    • Process requests binary or script from the Internet

      • GoogleUpdate.exe (PID: 2068)
    • Application launched itself

      • setup.exe (PID: 1616)
      • GoogleUpdate.exe (PID: 2068)
      • setup.exe (PID: 6324)
    • Checks Windows Trust Settings

      • GoogleUpdate.exe (PID: 2068)
    • Creates a software uninstall entry

      • setup.exe (PID: 1616)
      • chrome.exe (PID: 6768)
    • Searches for installed software

      • setup.exe (PID: 1616)
  • INFO

    • Create files in a temporary directory

      • ChromeSetup.exe (PID: 4996)
      • GoogleUpdate.exe (PID: 2068)
    • Reads the computer name

      • GoogleUpdate.exe (PID: 2180)
      • GoogleUpdate.exe (PID: 5276)
      • GoogleUpdate.exe (PID: 2068)
      • GoogleUpdate.exe (PID: 5524)
      • GoogleUpdate.exe (PID: 6748)
      • setup.exe (PID: 1616)
      • 128.0.6613.120_chrome_installer.exe (PID: 3812)
      • GoogleUpdate.exe (PID: 1492)
      • elevation_service.exe (PID: 6140)
      • setup.exe (PID: 6324)
      • GoogleUpdate.exe (PID: 1116)
    • Process checks computer location settings

      • GoogleUpdate.exe (PID: 2180)
      • GoogleUpdate.exe (PID: 5276)
    • Checks supported languages

      • GoogleUpdate.exe (PID: 2180)
      • ChromeSetup.exe (PID: 4996)
      • GoogleUpdateSetup.exe (PID: 508)
      • GoogleUpdate.exe (PID: 5276)
      • GoogleUpdate.exe (PID: 5524)
      • GoogleUpdate.exe (PID: 2068)
      • GoogleUpdate.exe (PID: 6748)
      • setup.exe (PID: 1616)
      • 128.0.6613.120_chrome_installer.exe (PID: 3812)
      • setup.exe (PID: 2700)
      • setup.exe (PID: 3568)
      • GoogleUpdate.exe (PID: 1492)
      • GoogleUpdate.exe (PID: 1116)
      • GoogleUpdateOnDemand.exe (PID: 740)
      • elevation_service.exe (PID: 6140)
      • setup.exe (PID: 6324)
    • Creates files in the program directory

      • GoogleUpdateSetup.exe (PID: 508)
      • GoogleUpdate.exe (PID: 5276)
      • GoogleUpdate.exe (PID: 6748)
      • GoogleUpdate.exe (PID: 5524)
      • GoogleUpdate.exe (PID: 2068)
      • 128.0.6613.120_chrome_installer.exe (PID: 3812)
      • setup.exe (PID: 1616)
      • setup.exe (PID: 6324)
      • GoogleUpdate.exe (PID: 1492)
    • Checks proxy server information

      • GoogleUpdate.exe (PID: 6748)
      • GoogleUpdate.exe (PID: 2068)
      • GoogleUpdate.exe (PID: 1492)
      • slui.exe (PID: 3984)
    • Reads the software policy settings

      • GoogleUpdate.exe (PID: 2068)
      • GoogleUpdate.exe (PID: 6748)
      • GoogleUpdate.exe (PID: 1492)
      • slui.exe (PID: 1496)
      • slui.exe (PID: 3984)
    • Reads the machine GUID from the registry

      • GoogleUpdate.exe (PID: 2068)
    • Creates files or folders in the user directory

      • GoogleUpdate.exe (PID: 2068)
    • Executes as Windows Service

      • elevation_service.exe (PID: 6140)
    • The process uses the downloaded file

      • chrome.exe (PID: 2016)
      • chrome.exe (PID: 4820)
      • chrome.exe (PID: 3812)
      • chrome.exe (PID: 508)
      • chrome.exe (PID: 6816)
      • chrome.exe (PID: 6328)
      • chrome.exe (PID: 740)
      • chrome.exe (PID: 6648)
      • chrome.exe (PID: 1692)
      • chrome.exe (PID: 6328)
      • chrome.exe (PID: 6232)
    • Reads Microsoft Office registry keys

      • chrome.exe (PID: 6768)
    • Application launched itself

      • chrome.exe (PID: 6768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:04:12 23:29:54+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.2
CodeSize: 95232
InitializedDataSize: 1251840
UninitializedDataSize: -
EntryPoint: 0x4f0e
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.36.212
ProductVersionNumber: 1.3.36.212
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Update Setup
FileVersion: 1.3.36.212
InternalName: Google Update Setup
LegalCopyright: Copyright 2018 Google LLC
OriginalFileName: GoogleUpdateSetup.exe
ProductName: Google Update
ProductVersion: 1.3.36.212
LanguageId: en
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
193
Monitored processes
60
Malicious processes
7
Suspicious processes
3

Behavior graph

Click at the process to see the details
start chromesetup.exe googleupdate.exe no specs googleupdatesetup.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe sppextcomobj.exe no specs slui.exe 128.0.6613.120_chrome_installer.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs googleupdate.exe googleupdateondemand.exe no specs googleupdate.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe elevation_service.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs slui.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
508"C:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\GoogleUpdateSetup.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={087C33F0-2315-3640-F21B-55195BF81358}&lang=en-GB&browser=4&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=YTUH&installdataindex=empty" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\GoogleUpdateSetup.exe
GoogleUpdate.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Update Setup
Exit code:
0
Version:
1.3.36.212
Modules
Images
c:\users\admin\appdata\local\temp\gum9ef7.tmp\googleupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
508"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=5848,i,14927882301287369875,8192958840306937649,262144 --variations-seed-version --mojo-platform-channel-handle=6192 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
128.0.6613.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
740"C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleUpdateOnDemand.exe" -EmbeddingC:\Program Files (x86)\Google\Update\1.3.36.372\GoogleUpdateOnDemand.exesvchost.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Update
Exit code:
0
Version:
1.3.36.371
Modules
Images
c:\program files (x86)\google\update\1.3.36.372\googleupdateondemand.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
740"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=6272,i,14927882301287369875,8192958840306937649,262144 --variations-seed-version --mojo-platform-channel-handle=5612 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
128.0.6613.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
752"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --gpu-preferences=UAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAhAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=5768,i,14927882301287369875,8192958840306937649,262144 --variations-seed-version --mojo-platform-channel-handle=6564 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
128.0.6613.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1116"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /ondemand C:\Program Files (x86)\Google\Update\GoogleUpdate.exeGoogleUpdateOnDemand.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Installer
Exit code:
0
Version:
1.3.36.51
Modules
Images
c:\program files (x86)\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1156"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --field-trial-handle=6148,i,14927882301287369875,8192958840306937649,262144 --variations-seed-version --mojo-platform-channel-handle=6780 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
128.0.6613.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1492"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNi4zNzIiIHNoZWxsX3ZlcnNpb249IjEuMy4zNi41MSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3QzU4OEQ5Ri03Q0RDLTQ1MzEtQjI3NC1GODY3RkY4N0Q0NUV9IiB1c2VyaWQ9InszNTM5MjFDQi05RDhELTRFQUItQjIyRC0xRDE0ODVGNTFFMjJ9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7RjJBMjA4REItNkIyNS00REJDLUE0QUYtNTE5MzVFNTYzNUQwfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSI0IiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIvPjxhcHAgYXBwaWQ9Ins4QTY5RDM0NS1ENTY0LTQ2M0MtQUZGMS1BNjlEOUU1MzBGOTZ9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxMjguMC42NjEzLjEyMCIgYXA9Ing2NC1zdGFibGUtc3RhdHNkZWZfMSIgbGFuZz0iZW4tR0IiIGJyYW5kPSJZVFVIIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iMTE0NCIgaW5zdGFsbGRhdGU9IjYyNjUiIGlpZD0iezA4N0MzM0YwLTIzMTUtMzY0MC1GMjFCLTU1MTk1QkY4MTM1OH0iIGNvaG9ydD0iMTpndS9pMTk6IiBjb2hvcnRuYW1lPSJTdGFibGUgSW5zdGFsbHMgJmFtcDsgVmVyc2lvbiBQaW5zIj48ZXZlbnQgZXZlbnR0eXBlPSI5IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIvPjxldmVudCBldmVudHR5cGU9IjEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGRvd25sb2FkZXI9Indpbmh0dHAiIHVybD0iaHR0cDovL2VkZ2VkbC5tZS5ndnQxLmNvbS9lZGdlZGwvcmVsZWFzZTIvY2hyb21lL2FkNWEzeHhrdXM1NTN5YXNpcmRzaXF1a3dyNWFfMTI4LjAuNjYxMy4xMjAvMTI4LjAuNjYxMy4xMjBfY2hyb21lX2luc3RhbGxlci5leGUiIGRvd25sb2FkZWQ9IjExMjA4NjkwNCIgdG90YWw9IjExMjA4NjkwNCIgZG93bmxvYWRfdGltZV9tcz0iNjIyOTgiLz48ZXZlbnQgZXZlbnR0eXBlPSIxIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIvPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjE5NjYwOSIgc291cmNlX3VybF9pbmRleD0iMCIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjUxNSIgZG93bmxvYWRfdGltZV9tcz0iNjM4NDYiIGRvd25sb2FkZWQ9IjExMjA4NjkwNCIgdG90YWw9IjExMjA4NjkwNCIgaW5zdGFsbF90aW1lX21zPSIxMzM4OSIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
GoogleUpdate.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.36.51
Modules
Images
c:\program files (x86)\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1496"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1616"C:\Program Files (x86)\Google\Update\Install\{3C7515D9-1506-4041-A643-D69A97D0CF3F}\CR_D1497.tmp\setup.exe" --install-archive="C:\Program Files (x86)\Google\Update\Install\{3C7515D9-1506-4041-A643-D69A97D0CF3F}\CR_D1497.tmp\CHROME.PACKED.7Z" --verbose-logging --do-not-launch-chrome --channel=stable --system-level /installerdata="C:\Program Files (x86)\Google\Update\Install\{3C7515D9-1506-4041-A643-D69A97D0CF3F}\guiAC14.tmp"C:\Program Files (x86)\Google\Update\Install\{3C7515D9-1506-4041-A643-D69A97D0CF3F}\CR_D1497.tmp\setup.exe
128.0.6613.120_chrome_installer.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Exit code:
0
Version:
128.0.6613.120
Modules
Images
c:\program files (x86)\google\update\install\{3c7515d9-1506-4041-a643-d69a97d0cf3f}\cr_d1497.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
36 310
Read events
33 721
Write events
2 524
Delete events
65

Modification events

(PID) Process:(2180) GoogleUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update
Operation:delete valueName:uid
Value:
(PID) Process:(2180) GoogleUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update
Operation:delete valueName:old-uid
Value:
(PID) Process:(5276) GoogleUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update
Operation:delete valueName:uid
Value:
(PID) Process:(5276) GoogleUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update
Operation:delete valueName:old-uid
Value:
(PID) Process:(5276) GoogleUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
1
(PID) Process:(5276) GoogleUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:delete valueName:usagestats
Value:
(PID) Process:(5276) GoogleUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(5276) GoogleUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
Operation:delete valueName:UpdateAvailableCount
Value:
(PID) Process:(5276) GoogleUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
Operation:delete valueName:UpdateAvailableSince
Value:
(PID) Process:(5276) GoogleUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
Operation:writeName:iid
Value:
{087C33F0-2315-3640-F21B-55195BF81358}
Executable files
141
Suspicious files
211
Text files
65
Unknown types
3

Dropped files

PID
Process
Filename
Type
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\GoogleUpdate.exeexecutable
MD5:821B0F4851F4C474F24E392100DF177B
SHA256:7FDE73B7FC9EC88505AFB4F7D8A17FC951C95BDBA396381C5310C5660978906B
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\psuser.dllexecutable
MD5:4D511C1A5561F6A2D98FC72C442A79BD
SHA256:0A455DC8D40FD0BC5F92DF1BA1D41AC54F996017E8786760619A3E0155653E33
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\GoogleUpdateOnDemand.exeexecutable
MD5:BA4D902B59EBF572C1C9E20328F18B0C
SHA256:C1CF0BA7D0B68BBE6886B1FB1643A55CA2F717226F86CCA384BC428FC8A5C9EE
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\GoogleUpdateBroker.exeexecutable
MD5:A17DBD72E39392FC3856A5D0241241F7
SHA256:2C9B52BD4966A302537310684841E4C78DD2C6E83DE4D844406678E4DCB98244
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\GoogleUpdateCore.exeexecutable
MD5:B0136B2211993E54C3B044642B817AF5
SHA256:B03B8ACE4356EAF49BA20B304B23FCE140D8416DAC65C0E594CEC84840837D4B
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\psmachine.dllexecutable
MD5:3618FA0875B6677999D9E5733E994438
SHA256:58AB45038B2EBD700E414EA27084A2112EC3109CA5B5C190D3D3C248DFD0D1DD
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\GoogleUpdateComRegisterShell64.exeexecutable
MD5:338CCFC04924442871A12C961AA3AA6B
SHA256:9184B8FF08A9EBB3645CA68182D6F3E3629DB688D012A63B6FA0622C1BF504F7
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\psmachine_64.dllexecutable
MD5:C8214821278F83E9937798FD4C41A584
SHA256:B2E55632C7859188527B3CAB09005099DF83939765698D109E4BE490FFFA5ED4
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\psuser_64.dllexecutable
MD5:40C0D71D147023E668C689BC6D9B8C6D
SHA256:5DBA145A530EE7433CEB10202054323261782D1B099315DC3C2B11DC5885A920
4996ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUM9EF7.tmp\GoogleCrashHandler64.exeexecutable
MD5:2214802F3A22F714ED64A4BABD22A6AE
SHA256:0C836458BE76647754F7EA8D2E49FD02667955E16497F14C015F22B372454D63
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
62
DNS requests
63
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2068
GoogleUpdate.exe
GET
200
142.250.185.67:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
2068
GoogleUpdate.exe
GET
200
172.217.16.195:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
2068
GoogleUpdate.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/ad5a3xxkus553yasirdsiqukwr5a_128.0.6613.120/128.0.6613.120_chrome_installer.exe
unknown
whitelisted
2068
GoogleUpdate.exe
GET
200
216.58.206.67:80
http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEEY%2BBbWicZDJCutGRyts3so%3D
unknown
whitelisted
6208
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1292
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ads5b47vmt6o3yjujrzhvuykaybq_2024.8.23.0/niikhdgajlphfehepabhhblakbdgeefj_2024.08.23.00_all_ads63hkk2t6wtnkmfb6te6wtc4ha.crx3
unknown
whitelisted
1292
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ads5b47vmt6o3yjujrzhvuykaybq_2024.8.23.0/niikhdgajlphfehepabhhblakbdgeefj_2024.08.23.00_all_ads63hkk2t6wtnkmfb6te6wtc4ha.crx3
unknown
whitelisted
2360
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1292
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ads5b47vmt6o3yjujrzhvuykaybq_2024.8.23.0/niikhdgajlphfehepabhhblakbdgeefj_2024.08.23.00_all_ads63hkk2t6wtnkmfb6te6wtc4ha.crx3
unknown
whitelisted
2360
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
6232
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7056
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6748
GoogleUpdate.exe
142.250.184.227:443
update.googleapis.com
GOOGLE
US
whitelisted
2068
GoogleUpdate.exe
142.250.184.227:443
update.googleapis.com
GOOGLE
US
whitelisted
2068
GoogleUpdate.exe
172.217.18.14:443
dl.google.com
GOOGLE
US
whitelisted
2068
GoogleUpdate.exe
142.250.185.67:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2068
GoogleUpdate.exe
172.217.16.195:80
c.pki.goog
GOOGLE
US
whitelisted
2068
GoogleUpdate.exe
216.58.206.67:80
o.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
update.googleapis.com
  • 142.250.184.227
  • 142.250.186.163
whitelisted
dl.google.com
  • 172.217.18.14
whitelisted
ocsp.pki.goog
  • 142.250.185.67
whitelisted
c.pki.goog
  • 172.217.16.195
whitelisted
o.pki.goog
  • 216.58.206.67
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
settings-win.data.microsoft.com
  • 13.71.55.58
  • 4.231.128.59
  • 20.73.194.208
  • 40.127.240.158
whitelisted
client.wns.windows.com
  • 40.115.3.253
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.148.162
  • 40.126.16.166
  • 20.190.144.138
  • 20.190.148.164
  • 40.126.16.165
  • 20.190.144.160
  • 20.190.144.163
  • 20.190.144.162
whitelisted

Threats

PID
Process
Class
Message
2068
GoogleUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2068
GoogleUpdate.exe
Misc activity
ET INFO EXE - Served Attached HTTP
No debug info