| File name: | ChromeSetup.exe |
| Full analysis: | https://app.any.run/tasks/ec25059e-5519-4c9d-93a8-aa1ead59a7f5 |
| Verdict: | Malicious activity |
| Analysis date: | July 02, 2024, 14:11:09 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 4EDD412D94AF11ED9679F89512FBCB67 |
| SHA1: | 1527583F60DEC6C3BF3E0934C0C806BBAA81334D |
| SHA256: | 6ADE367455BB99DA7CCD67D3A56E7F5A6E63FDEA27C99BFA5B250EB2028DF129 |
| SSDEEP: | 98304:tVacCr9dTCfWB1y2DSan4injrOJSTODj+NdLRisEe3v0j1UpEPj5KJzFGV9uuI1c:2SFx |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:13 15:02:23+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 2662912 |
| InitializedDataSize: | 5737472 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xf2630 |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 128.0.6537.0 |
| ProductVersionNumber: | 128.0.6537.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Chrome Installer |
| FileVersion: | 128.0.6537.0 |
| InternalName: | Google Chrome |
| LegalCopyright: | Copyright 2024 Google LLC. All rights reserved. |
| ProductName: | Google Chrome Installer |
| ProductVersion: | 128.0.6537.0 |
| CompanyShortName: | |
| ProductShortName: | Chrome Installer |
| LastChange: | e76d0a89298b90f3332e093f88a431261672e8de-refs/branch-heads/6537@{#1} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 308 | C:\WINDOWS\SystemTemp\Google2472_1980176090\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=128.0.6537.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2ac,0x2b0,0x2b4,0x288,0x2b8,0x1112604,0x1112610,0x111261c | C:\Windows\SystemTemp\Google2472_1980176090\bin\updater.exe | — | updater.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: GoogleUpdater (x86) Version: 128.0.6537.0 Modules
| |||||||||||||||
| 2472 | "C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={9FC4C950-9C5A-406C-3CAD-49E385FFEC3A}&lang=en&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevated | C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe | ChromeSetup.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Chrome Installer Version: 128.0.6537.0 Modules
| |||||||||||||||
| 2636 | "C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe" | C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Installer Version: 128.0.6537.0 Modules
| |||||||||||||||
| 3740 | "C:\WINDOWS\SystemTemp\Google2472_1980176090\bin\updater.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={9FC4C950-9C5A-406C-3CAD-49E385FFEC3A}&lang=en&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevated | C:\Windows\SystemTemp\Google2472_1980176090\bin\updater.exe | ChromeSetup.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: GoogleUpdater (x86) Version: 128.0.6537.0 Modules
| |||||||||||||||
| 4172 | "C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=128.0.6537.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x4c2604,0x4c2610,0x4c261c | C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: GoogleUpdater (x86) Exit code: 0 Version: 128.0.6537.0 Modules
| |||||||||||||||
| 4600 | "C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=128.0.6537.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x4c2604,0x4c2610,0x4c261c | C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: GoogleUpdater (x86) Version: 128.0.6537.0 Modules
| |||||||||||||||
| 4648 | "C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --system --windows-service --service=update | C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: GoogleUpdater (x86) Version: 128.0.6537.0 Modules
| |||||||||||||||
| 6120 | "C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --system --windows-service --service=update-internal | C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: GoogleUpdater (x86) Exit code: 0 Version: 128.0.6537.0 Modules
| |||||||||||||||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 128.0.6537.0 | |||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 128.0.6537.0 | |||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4EB300E9-4F8A-5D14-B795-36796C40660C} |
| Operation: | write | Name: | AppID |
Value: {4EB300E9-4F8A-5D14-B795-36796C40660C} | |||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB300E9-4F8A-5D14-B795-36796C40660C} |
| Operation: | write | Name: | LocalService |
Value: GoogleUpdaterInternalService128.0.6537.0 | |||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB300E9-4F8A-5D14-B795-36796C40660C} |
| Operation: | write | Name: | ServiceParameters |
Value: --com-service | |||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8582249A-7E37-5C77-A5F4-1FBFEAFCBC5F}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8582249A-7E37-5C77-A5F4-1FBFEAFCBC5F}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (3740) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8FCD652C-D470-570F-9A74-B31F9AB8F368}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2472 | ChromeSetup.exe | C:\WINDOWS\SystemTemp\Google2472_65519559\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 3740 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\Crashpad\settings.dat | binary | |
MD5:41A1AF76F502A98947CB10C5F509489F | SHA256:41DFECC180D8D69AAA17C1F44152D0B655782C68F1E4219025E4507D23E13837 | |||
| 3740 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json | binary | |
MD5:A640CA2E70D5D86EE61C65B5FA0A5DE3 | SHA256:143F8C59A52692D27D38A2DA2D510F37237FAEEE74850381917768ADEE0975E6 | |||
| 6120 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\prefs.json | binary | |
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56 | SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C | |||
| 3740 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | der | |
MD5:E06EE53B8A6215E3D571A5EC646B9320 | SHA256:7EDE483B1665D742364E5C2D51AC7432636261E76BA540DC14B963A8E61026A0 | |||
| 3740 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 | der | |
MD5:8D1040B12A663CA4EC7277CFC1CE44F0 | SHA256:3086094D4198A5BBD12938B0D2D5F696C4DFC77E1EAE820ADDED346A59AA8727 | |||
| 3740 | updater.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\{8a69d345-d564-463c-aff1-a69d9e530f96}[1].bmp | image | |
MD5:64C3009B9F0526A4FD2C8A9825B86F7D | SHA256:B49EDF5F970FA5B4D0608C2934053929E20D54C5E052164B4D2B375F2CB7E409 | |||
| 3740 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DDE8B1B7E253A9758EC380BD648952AF_A3D4688236962EEA03574DE4F61B95D9 | der | |
MD5:C9C2D47BCD977C1E6455721AB48676E1 | SHA256:A4C576435245C1252B33050AE66348DEC72215BEE08C2E976AE3AED319457D3A | |||
| 6120 | updater.exe | C:\Program Files (x86)\Google\Update\GoogleUpdate.exe | executable | |
MD5:512A822CAED80F9FA3F0DFCE20D4FAA1 | SHA256:8DE9266347276D18FE49F84B86F09E6035DF2C10E39F22D85BF33D43CF0F5F2C | |||
| 3740 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DDE8B1B7E253A9758EC380BD648952AF_A3D4688236962EEA03574DE4F61B95D9 | binary | |
MD5:DAC34ED64BBC3C908AACF0F1F3263585 | SHA256:1186D2F8E1BE1418018021B689938ADC903456983B251D9042DDFB3B4570C28C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4656 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | unknown |
3740 | updater.exe | GET | 200 | 172.217.18.3:80 | http://c.pki.goog/r/r1.crl | unknown | — | — | unknown |
3740 | updater.exe | GET | 200 | 172.217.18.3:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | unknown |
4648 | updater.exe | GET | — | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/jcs2etny43kupyauxqlnc3ytci_126.0.6478.127/-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.127_all_kqgvyxebv4r63jac66435t45xq.crx3 | unknown | — | — | unknown |
3740 | updater.exe | GET | 200 | 172.217.18.3:80 | http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQCRq%2FXldMamzQqGAD6YrjKf | unknown | — | — | unknown |
3040 | OfficeClickToRun.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | unknown |
1436 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
1436 | MoUsoCoreWorker.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
1544 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
5484 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4656 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2848 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3188 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1436 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4648 | updater.exe | 172.217.18.3:443 | update.googleapis.com | GOOGLE | US | whitelisted |
3740 | updater.exe | 142.250.184.238:443 | dl.google.com | GOOGLE | US | whitelisted |
3740 | updater.exe | 172.217.18.3:80 | update.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
ocsp.digicert.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
c.pki.goog |
| unknown |
o.pki.goog |
| unknown |
edgedl.me.gvt1.com |
| whitelisted |
login.live.com |
| whitelisted |
r.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |