| File name: | installbackupandsync.exe |
| Full analysis: | https://app.any.run/tasks/6ca67830-abdf-45a4-a6ee-8ea09c8dd060 |
| Verdict: | Malicious activity |
| Analysis date: | May 26, 2020, 08:14:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F005BD7C09852E1940FDE20E5EEB63AB |
| SHA1: | 722956F33F0BEE0332859B37E2399AE7EF860878 |
| SHA256: | 61BA88CDCFDE223D9C69446AB844BD2A2158B0D9D9BECA3E3A5F4D61E6F75453 |
| SSDEEP: | 24576:esSWkfRyE2ZcFGUEGNBffACErtoFAocYj+uY64YF5AjXEx2Je7CVSszVrmWW:0WJE2ZctEafitmGYj+uYP4D2VPrX |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:03:03 00:31:16+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 14.2 |
| CodeSize: | 83456 |
| InitializedDataSize: | 1187328 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4f17 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.35.452 |
| ProductVersionNumber: | 1.3.35.452 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Update Setup |
| FileVersion: | 1.3.35.452 |
| InternalName: | Google Update Setup |
| LegalCopyright: | Copyright 2018 Google LLC |
| OriginalFileName: | GoogleUpdateSetup.exe |
| ProductName: | Google Update |
| ProductVersion: | 1.3.35.452 |
| LanguageId: | en |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 02-Mar-2020 23:31:16 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Google LLC |
| FileDescription: | Google Update Setup |
| FileVersion: | 1.3.35.452 |
| InternalName: | Google Update Setup |
| LegalCopyright: | Copyright 2018 Google LLC |
| OriginalFilename: | GoogleUpdateSetup.exe |
| ProductName: | Google Update |
| ProductVersion: | 1.3.35.452 |
| LanguageId: | en |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000100 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 02-Mar-2020 23:31:16 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0001442F | 0x00014600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.65567 |
.rdata | 0x00016000 | 0x00006DAC | 0x00006E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26399 |
.data | 0x0001D000 | 0x00001290 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.99865 |
.rsrc | 0x0001F000 | 0x00119224 | 0x00119400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.98644 |
.reloc | 0x00139000 | 0x000010E0 | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.37311 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.20417 | 1166 | Latin 1 / Western European | UNKNOWN | RT_MANIFEST |
2 | 4.13669 | 1384 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.91985 | 744 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 4.83772 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 3.68656 | 1640 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 4.50268 | 3752 | Latin 1 / Western European | English - United States | RT_ICON |
101 | 2.86669 | 90 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
102 | 7.99984 | 1118511 | Latin 1 / Western European | UNKNOWN | B |
1321 | 3.68352 | 426 | Latin 1 / Western European | Serbian - Serbia (Cyrillic) | RT_STRING |
KERNEL32.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 356 | C:\Windows\system32\MsiExec.exe -Embedding 74590E17E956FCA7DC468C57DCA7DEE1 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 628 | "msiexec" REBOOT=ReallySuppress /qn /i "C:\Program Files\Google\Update\Install\{C0848D34-2901-40B0-8599-5639394B0354}\gsync.msi" /log "C:\Program Files\Google\Update\Install\{C0848D34-2901-40B0-8599-5639394B0354}\gsync.msi.log" | C:\Windows\system32\msiexec.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 680 | C:\Windows\system32\svchost.exe -k RPCSS | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 872 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 928 | "C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\GoogleUpdateSetup.exe" /installsource taggedmi /install "appguid={3C122445-AECE-4309-90B7-85A6AEF42AC0}&iid={9648D435-67BA-D2A7-54D2-1E0B5656BF03}&ap=uploader&appname=Backup%20and%20Sync&needsadmin=true" /installelevated /nomitag | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\GoogleUpdateSetup.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Update Setup Exit code: 0 Version: 1.3.35.452 Modules
| |||||||||||||||
| 996 | "C:\Users\admin\Desktop\installbackupandsync.exe" | C:\Users\admin\Desktop\installbackupandsync.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Update Setup Exit code: 0 Version: 1.3.35.452 Modules
| |||||||||||||||
| 1864 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNS40NTIiIHNoZWxsX3ZlcnNpb249IjEuMy4zMy4yMyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9InsxQjdFRUFGRC1EOTcxLTQzOEQtQTBCNS1DOUM3N0YzREUwNEN9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7QTBENThGMkUtMzMyRC00RUJDLTgwRkQtQjkzNTMwQjQzRjkxfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4wIiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing4NiIvPjxhcHAgYXBwaWQ9InszQzEyMjQ0NS1BRUNFLTQzMDktOTBCNy04NUE2QUVGNDJBQzB9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIzLjQ5Ljk4MDAuMDAwMCIgYXA9InVwbG9hZGVyIiBsYW5nPSIiIGJyYW5kPSIiIGNsaWVudD0iIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIiBpaWQ9Ins5NjQ4RDQzNS02N0JBLUQyQTctNTREMi0xRTBCNTY1NkJGMDN9Ij48ZXZlbnQgZXZlbnR0eXBlPSI5IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIvPjxldmVudCBldmVudHR5cGU9IjEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGRvd25sb2FkZXI9ImJpdHMiIHVybD0iaHR0cHM6Ly9yZWRpcmVjdG9yLmd2dDEuY29tL2VkZ2VkbC9kcml2ZS8zLjQ5Ljk4MDAuMDAwMC9nc3luYy5tc2kiIGRvd25sb2FkZWQ9IjU1OTQzMTY4IiB0b3RhbD0iNTU5NDMxNjgiIGRvd25sb2FkX3RpbWVfbXM9IjM0NTE2Ii8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIvPjxldmVudCBldmVudHR5cGU9IjYiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzb3VyY2VfdXJsX2luZGV4PSIwIiB1cGRhdGVfY2hlY2tfdGltZV9tcz0iNTg3NSIgZG93bmxvYWRfdGltZV9tcz0iMzUyOTciIGRvd25sb2FkZWQ9IjU1OTQzMTY4IiB0b3RhbD0iNTU5NDMxNjgiIGluc3RhbGxfdGltZV9tcz0iMTAzNTkiLz48L2FwcD48L3JlcXVlc3Q- | C:\Program Files\Google\Update\GoogleUpdate.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 2128 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNS40NTIiIHNoZWxsX3ZlcnNpb249IjEuMy4zMy4yMyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9InsxQjdFRUFGRC1EOTcxLTQzOEQtQTBCNS1DOUM3N0YzREUwNEN9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7QjMzN0FCQzctRjk0RC00NkYyLTlGMDMtMjU2MjIzMjU5MkM4fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4wIiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing4NiIvPjxhcHAgYXBwaWQ9Ins0MzBGRDREMC1CNzI5LTRGNjEtQUEzNC05MTUyNjQ4MTc5OUR9IiB2ZXJzaW9uPSIxLjMuMzQuMTEiIG5leHR2ZXJzaW9uPSIxLjMuMzUuNDUyIiBsYW5nPSIiIGJyYW5kPSIiIGNsaWVudD0iIiBpaWQ9Ins5NjQ4RDQzNS02N0JBLUQyQTctNTREMi0xRTBCNTY1NkJGMDN9Ij48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjExODgiLz48L2FwcD48L3JlcXVlc3Q- | C:\Program Files\Google\Update\GoogleUpdate.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 2420 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /handoff "appguid={3C122445-AECE-4309-90B7-85A6AEF42AC0}&iid={9648D435-67BA-D2A7-54D2-1E0B5656BF03}&ap=uploader&appname=Backup%20and%20Sync&needsadmin=true" /installsource taggedmi /sessionid "{1B7EEAFD-D971-438D-A0B5-C9C77F3DE04C}" | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 2432 | "C:\Program Files\Google\Temp\GUM6A35.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={3C122445-AECE-4309-90B7-85A6AEF42AC0}&iid={9648D435-67BA-D2A7-54D2-1E0B5656BF03}&ap=uploader&appname=Backup%20and%20Sync&needsadmin=true" /installelevated | C:\Program Files\Google\Temp\GUM6A35.tmp\GoogleUpdate.exe | GoogleUpdateSetup.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.35.451 Modules
| |||||||||||||||
| (PID) Process: | (872) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000 |
| Operation: | write | Name: | RefCount |
Value: 2 | |||
| (PID) Process: | (872) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000 |
| Operation: | write | Name: | RefCount |
Value: 1 | |||
| (PID) Process: | (2800) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69} |
| Operation: | delete key | Name: | |
Value: | |||
| (PID) Process: | (2800) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69} |
| Operation: | write | Name: | |
Value: ServiceModule | |||
| (PID) Process: | (2800) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe |
| Operation: | delete key | Name: | |
Value: | |||
| (PID) Process: | (2800) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe |
| Operation: | write | Name: | AppID |
Value: {4EB61BAC-A3B6-4760-9581-655041EF4D69} | |||
| (PID) Process: | (2800) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69} |
| Operation: | write | Name: | LocalService |
Value: gupdate | |||
| (PID) Process: | (2800) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69} |
| Operation: | write | Name: | ServiceParameters |
Value: /comsvc | |||
| (PID) Process: | (2800) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3COMClassService.1.0 |
| Operation: | write | Name: | |
Value: Update3COMClass | |||
| (PID) Process: | (2800) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3COMClassService.1.0\CLSID |
| Operation: | write | Name: | |
Value: {4EB61BAC-A3B6-4760-9581-655041EF4D69} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 872 | svchost.exe | C:\Windows\appcompat\programs\RecentFileCache.bcf | txt | |
MD5:— | SHA256:— | |||
| 996 | installbackupandsync.exe | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\psmachine.dll | executable | |
MD5:146A84692C2B149D170359DD716B0AF0 | SHA256:4ABA9A08E281DD328A4094D5EDC4C1F672391BA049A3C9DC682B283CE83D006F | |||
| 996 | installbackupandsync.exe | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\goopdateres_ca.dll | executable | |
MD5:345CD0CAA01849E883B0D64BB08BDCFB | SHA256:B608F8BB506D50A583EC5028DD65FD2AA5D9ECC67480158E2BBBC059661203E3 | |||
| 996 | installbackupandsync.exe | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\GoogleUpdate.exe | executable | |
MD5:0BCA3F16DD527B4150648EC1E36CB22A | SHA256:B60E92004D394D0B14A8953A2BA29951C79F2F8A6C94F495E3153DFBBEF115B6 | |||
| 996 | installbackupandsync.exe | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\GoogleUpdateHelper.msi | executable | |
MD5:1766B021B0BAB4F82259974154C5A920 | SHA256:4016DFF47234FF9031B634C5EC931783402EA3F7E40CBDA8CC9637EB947CC6C7 | |||
| 996 | installbackupandsync.exe | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\GoogleCrashHandler.exe | executable | |
MD5:74CDA8051136B80DC3AE4BF86623003C | SHA256:3C05CAF977003005770BCA7CD4C4586A3C2C2B749A5BB8659AF50B8637F5AC5E | |||
| 996 | installbackupandsync.exe | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\GoogleUpdateBroker.exe | executable | |
MD5:850406E45F31759D6ECFDACE92A684F6 | SHA256:0C79C3E81A841D479B00C0B867F69BDD8690C883D859AAA582DAD30EEC1A16CA | |||
| 996 | installbackupandsync.exe | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\GoogleUpdateOnDemand.exe | executable | |
MD5:9020315BBE57A2F88EFF3BE4BF04F349 | SHA256:C070E09AC50C460A33CEA55CCADB66413ABD53EBE871F549597DEF8A719B9CB1 | |||
| 996 | installbackupandsync.exe | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\psuser_64.dll | executable | |
MD5:DB303F26CB67F67361AEF8B5C79073FC | SHA256:B505EA6D42352E5C27501A33CC1CA3361875F6DBF2DB78F80DF277B170E49F6B | |||
| 996 | installbackupandsync.exe | C:\Users\admin\AppData\Local\Temp\GUM6275.tmp\goopdate.dll | executable | |
MD5:423A3E9172B85D03B338067A14E23A00 | SHA256:DEA45DD3A35A5D92EFA2726B52B0275121DCEAFDC7717A406F4CD294B10CD67E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3708 | googledrivesync.exe | GET | 200 | 216.58.206.3:80 | http://ocsp.pki.goog/gts1o1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEEiBIL60WSDMCAAAAAA%2BvlU%3D | US | der | 471 b | whitelisted |
3708 | googledrivesync.exe | GET | 200 | 216.58.206.3:80 | http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDEKiK1zGWeAwgAAAAAPr4Q | US | der | 472 b | whitelisted |
3708 | googledrivesync.exe | GET | 200 | 216.58.206.3:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
3708 | googledrivesync.exe | GET | 200 | 216.58.206.3:80 | http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDEKiK1zGWeAwgAAAAAPr4Q | US | der | 472 b | whitelisted |
3708 | googledrivesync.exe | GET | 200 | 216.58.206.3:80 | http://ocsp.pki.goog/gts1o1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEBqGiw2vm8c0CAAAAAA%2BvZc%3D | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2128 | GoogleUpdate.exe | 172.217.18.3:443 | update.googleapis.com | Google Inc. | US | whitelisted |
2856 | GoogleUpdate.exe | 172.217.18.3:443 | update.googleapis.com | Google Inc. | US | whitelisted |
— | — | 172.217.23.110:443 | redirector.gvt1.com | Google Inc. | US | whitelisted |
— | — | 216.58.206.14:443 | accounts.youtube.com | Google Inc. | US | whitelisted |
— | — | 172.217.22.3:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
— | — | 216.58.206.3:443 | ocsp.pki.goog | Google Inc. | US | whitelisted |
— | — | 216.58.206.3:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
3708 | googledrivesync.exe | 172.217.22.45:443 | accounts.google.com | Google Inc. | US | whitelisted |
3708 | googledrivesync.exe | 216.58.206.3:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
1864 | GoogleUpdate.exe | 172.217.18.3:443 | update.googleapis.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
update.googleapis.com |
| whitelisted |
redirector.gvt1.com |
| whitelisted |
r1---sn-4g5e6nze.gvt1.com |
| whitelisted |
accounts.google.com |
| shared |
ocsp.pki.goog |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
accounts.youtube.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
Process | Message |
|---|---|
MsiExec.exe | |
MsiExec.exe |