File name:

Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe

Full analysis: https://app.any.run/tasks/488c722c-31c3-48d2-9e6d-1ea4730e4c87
Verdict: Malicious activity
Analysis date: July 01, 2024, 15:33:48
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0BBB5911A6323D29AC1110D790429DFA

SHA1:

33411A95E7F28BA84F6E94DBAE7E62EF047A0633

SHA256:

6B28E549FB3D89DFE58A251501F24D966B34160A442F0F2C3EEF1367A6F2F475

SSDEEP:

98304:tVacCr9dTCfWB1y2DSan4injrOJSTODj+NdLRisEe3v0j1UpEPj5KJzFGV9uuI1c:2SFx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • updater.exe (PID: 4116)
      • updater.exe (PID: 2720)
    • Scans artifacts that could help determine the target

      • updater.exe (PID: 2720)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • updater.exe (PID: 2720)
    • Application launched itself

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • updater.exe (PID: 2720)
      • updater.exe (PID: 4116)
      • updater.exe (PID: 992)
    • Reads the date of Windows installation

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 4116)
      • updater.exe (PID: 2720)
    • Executes as Windows Service

      • updater.exe (PID: 992)
      • updater.exe (PID: 4116)
    • Checks Windows Trust Settings

      • updater.exe (PID: 2720)
  • INFO

    • Reads the computer name

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • updater.exe (PID: 2720)
      • updater.exe (PID: 4116)
      • updater.exe (PID: 992)
      • TextInputHost.exe (PID: 1792)
      • identity_helper.exe (PID: 6756)
    • Checks supported languages

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 232)
      • updater.exe (PID: 2720)
      • updater.exe (PID: 448)
      • updater.exe (PID: 992)
      • updater.exe (PID: 5980)
      • TextInputHost.exe (PID: 1792)
      • identity_helper.exe (PID: 6756)
      • updater.exe (PID: 3512)
      • updater.exe (PID: 4116)
    • Creates files in the program directory

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 232)
      • updater.exe (PID: 2720)
      • updater.exe (PID: 4116)
      • updater.exe (PID: 992)
      • updater.exe (PID: 3512)
    • Process checks computer location settings

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 2720)
      • updater.exe (PID: 4116)
      • updater.exe (PID: 992)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 992)
      • updater.exe (PID: 2720)
    • Checks proxy server information

      • updater.exe (PID: 2720)
    • Reads the software policy settings

      • updater.exe (PID: 992)
      • updater.exe (PID: 2720)
    • Creates files or folders in the user directory

      • updater.exe (PID: 2720)
    • Manual execution by a user

      • msedge.exe (PID: 2520)
    • Create files in a temporary directory

      • updater.exe (PID: 2720)
    • Application launched itself

      • msedge.exe (PID: 2520)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 2520)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 5264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:13 15:02:23+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2662912
InitializedDataSize: 5737472
UninitializedDataSize: -
EntryPoint: 0xf2630
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 128.0.6537.0
ProductVersionNumber: 128.0.6537.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Chrome Installer
FileVersion: 128.0.6537.0
InternalName: Google Chrome
LegalCopyright: Copyright 2024 Google LLC. All rights reserved.
ProductName: Google Chrome Installer
ProductVersion: 128.0.6537.0
CompanyShortName: Google
ProductShortName: Chrome Installer
LastChange: e76d0a89298b90f3332e093f88a431261672e8de-refs/branch-heads/6537@{#1}
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
199
Monitored processes
56
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start mzk4mmi0mtczmtq0zjfmzjg1ztq2zdgyyzzhotu0zwe.exe no specs mzk4mmi0mtczmtq0zjfmzjg1ztq2zdgyyzzhotu0zwe.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs rundll32.exe no specs textinputhost.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2596 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
232"C:\Users\admin\AppData\Local\Temp\Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={8C758E1F-C967-47D7-5C67-897C757DB057}&lang=ru&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Local\Temp\Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe
Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Version:
128.0.6537.0
Modules
Images
c:\users\admin\appdata\local\temp\mzk4mmi0mtczmtq0zjfmzjg1ztq2zdgyyzzhotu0zwe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
448"C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=128.0.6537.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x1032604,0x1032610,0x103261cC:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
128.0.6537.0
Modules
Images
c:\program files (x86)\google\googleupdater\128.0.6537.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
564"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6552 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
648"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=6668 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
692"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1352 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
936"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=6484 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
992"C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --system --windows-service --service=updateC:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Version:
128.0.6537.0
Modules
Images
c:\program files (x86)\google\googleupdater\128.0.6537.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1164"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3796 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5864 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
16 689
Read events
16 441
Write events
217
Delete events
31

Modification events

(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
128.0.6537.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
128.0.6537.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4EB300E9-4F8A-5D14-B795-36796C40660C}
Operation:writeName:AppID
Value:
{4EB300E9-4F8A-5D14-B795-36796C40660C}
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB300E9-4F8A-5D14-B795-36796C40660C}
Operation:writeName:LocalService
Value:
GoogleUpdaterInternalService128.0.6537.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB300E9-4F8A-5D14-B795-36796C40660C}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8582249A-7E37-5C77-A5F4-1FBFEAFCBC5F}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8582249A-7E37-5C77-A5F4-1FBFEAFCBC5F}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8FCD652C-D470-570F-9A74-B31F9AB8F368}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
10
Suspicious files
522
Text files
136
Unknown types
6

Dropped files

PID
Process
Filename
Type
232Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exeC:\WINDOWS\SystemTemp\Google232_1145289527\UPDATER.PACKED.7Z
MD5:
SHA256:
2720updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:A640CA2E70D5D86EE61C65B5FA0A5DE3
SHA256:143F8C59A52692D27D38A2DA2D510F37237FAEEE74850381917768ADEE0975E6
4116updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:0A313C00FA4DD5B9C1D3F8288B41EF8C
SHA256:FB8AC41B88FB6E554D3DA9299646276501309D3DD1275D2BF651CA80DF0FBDFB
4116updater.exeC:\Windows\SystemTemp\Google4116_401862610\scoped_dir4116_1063098454\GoogleUpdate.exeexecutable
MD5:3AA2C853D6BC7AF7F2F9B8A934943EFD
SHA256:07034876B9EC0B59432B96FEDB7E10E332440159F9802FAAD5F5B99F01885F6B
4116updater.exeC:\Program Files (x86)\Google\Update\GoogleUpdate.exeexecutable
MD5:512A822CAED80F9FA3F0DFCE20D4FAA1
SHA256:8DE9266347276D18FE49F84B86F09E6035DF2C10E39F22D85BF33D43CF0F5F2C
992updater.exeC:\WINDOWS\SystemTemp\chrome_url_fetcher_992_109611158\-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.127_all_kqgvyxebv4r63jac66435t45xq.crx3
MD5:
SHA256:
992updater.exeC:\WINDOWS\SystemTemp\chrome_url_fetcher_992_542652863\-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.127_all_kqgvyxebv4r63jac66435t45xq.crx3
MD5:
SHA256:
4116updater.exeC:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\a1be4fb2-8ad8-4896-a4b0-accc85f5f438.tmpbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
4116updater.exeC:\Program Files (x86)\Google\GoogleUpdater\14ce2bd3-f529-4588-aa91-b22273311212.tmpbinary
MD5:0A313C00FA4DD5B9C1D3F8288B41EF8C
SHA256:FB8AC41B88FB6E554D3DA9299646276501309D3DD1275D2BF651CA80DF0FBDFB
4116updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.json~RF1adc48.TMPbinary
MD5:A640CA2E70D5D86EE61C65B5FA0A5DE3
SHA256:143F8C59A52692D27D38A2DA2D510F37237FAEEE74850381917768ADEE0975E6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
176
DNS requests
171
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2720
updater.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
unknown
2720
updater.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/r1.crl
unknown
unknown
992
updater.exe
GET
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/jcs2etny43kupyauxqlnc3ytci_126.0.6478.127/-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.127_all_kqgvyxebv4r63jac66435t45xq.crx3
unknown
unknown
1544
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
2568
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
5484
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
2720
updater.exe
GET
200
142.250.184.195:80
http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQCRq%2FXldMamzQqGAD6YrjKf
unknown
unknown
2568
svchost.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
unknown
7052
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
2568
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3156
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3868
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
992
updater.exe
142.250.184.227:443
update.googleapis.com
GOOGLE
US
whitelisted
2720
updater.exe
142.250.185.110:443
dl.google.com
GOOGLE
US
whitelisted
2720
updater.exe
142.250.184.195:80
ocsp.pki.goog
GOOGLE
US
whitelisted
992
updater.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE
US
whitelisted
1544
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
update.googleapis.com
  • 142.250.184.227
whitelisted
dl.google.com
  • 142.250.185.110
whitelisted
ocsp.pki.goog
  • 142.250.184.195
whitelisted
c.pki.goog
  • 142.250.184.195
unknown
o.pki.goog
  • 142.250.184.195
unknown
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.75
  • 40.126.31.71
  • 20.190.159.4
  • 20.190.159.71
  • 20.190.159.73
  • 20.190.159.64
  • 40.126.31.73
whitelisted
go.microsoft.com
  • 23.218.210.69
  • 23.35.238.131
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
whitelisted

Threats

PID
Process
Class
Message
32
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
32
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info