| File name: | ChromeSetup (1).exe |
| Full analysis: | https://app.any.run/tasks/28f88d0d-72cb-4109-8339-b8848973fcdf |
| Verdict: | Malicious activity |
| Analysis date: | August 01, 2025, 02:48:57 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections |
| MD5: | 9586B6D12BD9A8EDAAF148226A5B001A |
| SHA1: | 16354C5A457551F77C97FF4EE4F8315395F2491C |
| SHA256: | 637A05FE65047F57E0F5EEFCC39B04F5E23A52A8867B6D2ACA09931282DDD163 |
| SSDEEP: | 98304:hTqNObjWFGfXZPphr6W787ri8caGRifRkYRf1kQik/Al5onCnXOhJbR7M4P4TM16:TUGSU |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:07:02 03:02:05+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 3554816 |
| InitializedDataSize: | 7469568 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1dd910 |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 140.0.7273.0 |
| ProductVersionNumber: | 140.0.7273.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Installer (x86) |
| FileVersion: | 140.0.7273.0 |
| InternalName: | Google Installer (x86) |
| LegalCopyright: | Copyright 2025 Google LLC. All rights reserved. |
| OriginalFileName: | UpdaterSetup.exe |
| ProductName: | Google Installer (x86) |
| ProductVersion: | 140.0.7273.0 |
| CompanyShortName: | |
| ProductShortName: | GoogleUpdater |
| LastChange: | cdbcba33653a1d72092fb0be472085f03b5f149d-refs/branch-heads/7273@{#1} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 512 | C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping1212_1674511762\CR_21676.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel=beta --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=139.0.7258.66 --initial-client-data=0x2a0,0x2a4,0x2a8,0x278,0x2ac,0x7ff60e7c2520,0x7ff60e7c252c,0x7ff60e7c2538 | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping1212_1674511762\CR_21676.tmp\setup.exe | — | setup.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Installer Exit code: 0 Version: 139.0.7258.66 Modules
| |||||||||||||||
| 768 | "C:\Users\admin\AppData\Local\Temp\ChromeSetup (1).exe" | C:\Users\admin\AppData\Local\Temp\ChromeSetup (1).exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Installer (x86) Exit code: 0 Version: 140.0.7273.0 Modules
| |||||||||||||||
| 1212 | "C:\Program Files (x86)\Google\GoogleUpdater\140.0.7273.0\updater.exe" --system --windows-service --service=update | C:\Program Files (x86)\Google\GoogleUpdater\140.0.7273.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater (x86) Exit code: 0 Version: 140.0.7273.0 Modules
| |||||||||||||||
| 1212 | "C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --wake --system | C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe | — | updater.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Updater Version: 134.0.6985.0 Modules
| |||||||||||||||
| 1332 | "C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=134.0.6985.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2b8,0x2bc,0x2c0,0x294,0x2c4,0x111c460,0x111c46c,0x111c478 | C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe | — | updater.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Updater Version: 134.0.6985.0 Modules
| |||||||||||||||
| 1636 | "C:\Program Files (x86)\Google\GoogleUpdater\140.0.7273.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\140.0.7273.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=140.0.7273.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a4,0x2a8,0x2ac,0x280,0x2b0,0x12631a8,0x12631b4,0x12631c0 | C:\Program Files (x86)\Google\GoogleUpdater\140.0.7273.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater (x86) Exit code: 0 Version: 140.0.7273.0 Modules
| |||||||||||||||
| 1872 | "C:\Program Files (x86)\Google\GoogleUpdater\140.0.7273.0\updater.exe" --system --windows-service --service=update-internal | C:\Program Files (x86)\Google\GoogleUpdater\140.0.7273.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater (x86) Exit code: 0 Version: 140.0.7273.0 Modules
| |||||||||||||||
| 2040 | "C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping1212_1674511762\139.0.7258.66_chrome_installer_uncompressed.exe" --verbose-logging --do-not-launch-chrome --chrome-beta --installerdata="C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping1212_1674511762\50ba7b15-7d93-46c8-9033-e38a194f7ed2.tmp" | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping1212_1674511762\139.0.7258.66_chrome_installer_uncompressed.exe | updater.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Installer Exit code: 0 Version: 139.0.7258.66 Modules
| |||||||||||||||
| 2112 | "C:\Program Files\Google\Chrome Beta\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --force-high-res-timeticks=disabled --subproc-heap-profiling --metrics-shmem-handle=4652,i,8362048473972344720,3443106308194850701,524288 --field-trial-handle=1976,i,1349853503361329288,14626102492595766520,262144 --variations-seed-version=20250730-050039.823000 --mojo-platform-channel-handle=4632 /prefetch:8 | C:\Program Files\Google\Chrome Beta\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 139.0.7258.66 Modules
| |||||||||||||||
| 2212 | "C:\Program Files\Google\Chrome Beta\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --force-high-res-timeticks=disabled --subproc-heap-profiling --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --metrics-shmem-handle=3120,i,17907118692933900107,635566478722582895,2097152 --field-trial-handle=1976,i,1349853503361329288,14626102492595766520,262144 --variations-seed-version=20250730-050039.823000 --mojo-platform-channel-handle=3148 /prefetch:1 | C:\Program Files\Google\Chrome Beta\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 139.0.7258.66 Modules
| |||||||||||||||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 140.0.7273.0 | |||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 140.0.7273.0 | |||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F712E7AB-1264-5F6D-AA77-7777672D1F2A} |
| Operation: | write | Name: | AppID |
Value: {F712E7AB-1264-5F6D-AA77-7777672D1F2A} | |||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F712E7AB-1264-5F6D-AA77-7777672D1F2A} |
| Operation: | write | Name: | LocalService |
Value: GoogleUpdaterInternalService140.0.7273.0 | |||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F712E7AB-1264-5F6D-AA77-7777672D1F2A} |
| Operation: | write | Name: | ServiceParameters |
Value: --com-service | |||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2A859659-6F92-5F49-B7A2-E5C8BAF5B060}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A859659-6F92-5F49-B7A2-E5C8BAF5B060}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (3788) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{B405A64A-6E9F-522E-8450-2C67038707C0}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2972 | ChromeSetup (1).exe | C:\Users\admin\AppData\Local\Temp\Google2972_689956066\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 3788 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\updater.log | text | |
MD5:F6230B57B2F78EEF3BF95869FC9D7065 | SHA256:74BDBBC591FF1C973B0D6527BFDADBD4DC96731241E9A6E4A1EA76B909D4C3B2 | |||
| 3788 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\140.0.7273.0\updater.exe | executable | |
MD5:D3E6B13F2D2A1CC59B9F603170EB678C | SHA256:4126BD01B54957203057F31E34FC19FB9486519AF65D05AD6A1DCEB23D2DDC9D | |||
| 1212 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_1212_1766969516\8d29e7b8e9038a98ff297d5c3f6b625dc2a9feca615f20d3771ec0ea3abd4580 | — | |
MD5:— | SHA256:— | |||
| 1872 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json~RF18d54c.TMP | binary | |
MD5:B0220CEA5E8C34F4D274D19B38E043DB | SHA256:939FA5BCA89134D865E556516D85ECC53F0C8669E46FA299B77E3035981445D6 | |||
| 3788 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 | der | |
MD5:1FBB37F79B317A9A248E7C4CE4F5BAC5 | SHA256:9BF639C595FE335B6F694EE35990BEFD2123F5E07FD1973FF619E3FC88F5F49F | |||
| 3788 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C60C0C29522E01E6A22BD2717F20782E_28B02351C637206CD4D376132D697D71 | der | |
MD5:35312AFBA7AAC1FFA572B9ADE857DD72 | SHA256:2D3940AFBE89A44819C38928810B601682AFD50D3784D75150F35D31EE8ECE2B | |||
| 3788 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json~RF18d452.TMP | binary | |
MD5:6A7C22B00ADBF302C1F53F51AF1AB2F6 | SHA256:BFD4268EDA9AB3F0E8D8D2ED0884BD28C0B34546332B36E54EBD30ACF45053FF | |||
| 3788 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 | binary | |
MD5:2DAF8DD9DC94201A833E17BF9B2396A1 | SHA256:7AEA694B563FD1C9F2A0EEB4403CA1DFF0691B9B959C90DA070106EF25CB036E | |||
| 1212 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_1212_1766969516\decoded_xz | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3788 | updater.exe | GET | 200 | 172.217.16.195:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
3788 | updater.exe | GET | 200 | 172.217.16.195:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
3788 | updater.exe | GET | 200 | 172.217.16.195:80 | http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDPZmByDOs98xJONhjjIZaE | unknown | — | — | whitelisted |
1212 | updater.exe | GET | — | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/%7B8237e44a-0054-442c-b6b6-ea0509993955%7D/8d29e7b8e9038a98ff297d5c3f6b625dc2a9feca615f20d3771ec0ea3abd4580 | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.216.77.28:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6388 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6176 | chrome.exe | GET | 200 | 142.250.181.238:80 | http://clients2.google.com/time/1/current?cup2key=9:wg_FmrIdp7LZqCqmrF8dukvc8Aq4t7YOYm1vGTBG9lQ&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
6756 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6388 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2348 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1212 | updater.exe | 142.250.185.195:443 | update.googleapis.com | GOOGLE | US | whitelisted |
3788 | updater.exe | 142.250.186.142:443 | dl.google.com | GOOGLE | US | whitelisted |
3788 | updater.exe | 172.217.16.195:80 | c.pki.goog | GOOGLE | US | whitelisted |
1212 | updater.exe | 34.104.35.123:80 | edgedl.me.gvt1.com | GOOGLE | US | whitelisted |
1268 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |
edgedl.me.gvt1.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
Process | Message |
|---|---|
chrome.exe | [0801/024945.973:ERROR:third_party\crashpad\crashpad\client\crash_report_database_win.cc:613] CreateDirectory C:\Users\admin\AppData\Local\Google\Chrome Beta\User Data\Crashpad: The system cannot find the path specified. (0x3)
|