File name:

Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe

Full analysis: https://app.any.run/tasks/488c722c-31c3-48d2-9e6d-1ea4730e4c87
Verdict: Malicious activity
Analysis date: July 01, 2024, 15:33:48
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0BBB5911A6323D29AC1110D790429DFA

SHA1:

33411A95E7F28BA84F6E94DBAE7E62EF047A0633

SHA256:

6B28E549FB3D89DFE58A251501F24D966B34160A442F0F2C3EEF1367A6F2F475

SSDEEP:

98304:tVacCr9dTCfWB1y2DSan4injrOJSTODj+NdLRisEe3v0j1UpEPj5KJzFGV9uuI1c:2SFx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • updater.exe (PID: 2720)
      • updater.exe (PID: 4116)
    • Scans artifacts that could help determine the target

      • updater.exe (PID: 2720)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • updater.exe (PID: 2720)
    • Reads the date of Windows installation

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
    • Application launched itself

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • updater.exe (PID: 4116)
      • updater.exe (PID: 992)
      • updater.exe (PID: 2720)
    • Executes as Windows Service

      • updater.exe (PID: 4116)
      • updater.exe (PID: 992)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 2720)
      • updater.exe (PID: 4116)
    • Checks Windows Trust Settings

      • updater.exe (PID: 2720)
  • INFO

    • Checks supported languages

      • updater.exe (PID: 3512)
      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • updater.exe (PID: 4116)
      • updater.exe (PID: 448)
      • updater.exe (PID: 5980)
      • updater.exe (PID: 992)
      • TextInputHost.exe (PID: 1792)
      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 232)
      • updater.exe (PID: 2720)
      • identity_helper.exe (PID: 6756)
    • Reads the computer name

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
      • updater.exe (PID: 2720)
      • updater.exe (PID: 992)
      • updater.exe (PID: 4116)
      • TextInputHost.exe (PID: 1792)
      • identity_helper.exe (PID: 6756)
    • Creates files in the program directory

      • updater.exe (PID: 3512)
      • updater.exe (PID: 4116)
      • updater.exe (PID: 992)
      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 232)
      • updater.exe (PID: 2720)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 2720)
      • updater.exe (PID: 4116)
      • updater.exe (PID: 992)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 992)
      • updater.exe (PID: 2720)
    • Reads the software policy settings

      • updater.exe (PID: 992)
      • updater.exe (PID: 2720)
    • Checks proxy server information

      • updater.exe (PID: 2720)
    • Creates files or folders in the user directory

      • updater.exe (PID: 2720)
    • Create files in a temporary directory

      • updater.exe (PID: 2720)
    • Process checks computer location settings

      • Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe (PID: 3840)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 2520)
    • Application launched itself

      • msedge.exe (PID: 2520)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 5264)
    • Manual execution by a user

      • msedge.exe (PID: 2520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:13 15:02:23+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2662912
InitializedDataSize: 5737472
UninitializedDataSize: -
EntryPoint: 0xf2630
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 128.0.6537.0
ProductVersionNumber: 128.0.6537.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Chrome Installer
FileVersion: 128.0.6537.0
InternalName: Google Chrome
LegalCopyright: Copyright 2024 Google LLC. All rights reserved.
ProductName: Google Chrome Installer
ProductVersion: 128.0.6537.0
CompanyShortName: Google
ProductShortName: Chrome Installer
LastChange: e76d0a89298b90f3332e093f88a431261672e8de-refs/branch-heads/6537@{#1}
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
199
Monitored processes
56
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start mzk4mmi0mtczmtq0zjfmzjg1ztq2zdgyyzzhotu0zwe.exe no specs mzk4mmi0mtczmtq0zjfmzjg1ztq2zdgyyzzhotu0zwe.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs rundll32.exe no specs textinputhost.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2596 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
232"C:\Users\admin\AppData\Local\Temp\Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={8C758E1F-C967-47D7-5C67-897C757DB057}&lang=ru&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Local\Temp\Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe
Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Version:
128.0.6537.0
Modules
Images
c:\users\admin\appdata\local\temp\mzk4mmi0mtczmtq0zjfmzjg1ztq2zdgyyzzhotu0zwe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
448"C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=128.0.6537.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x1032604,0x1032610,0x103261cC:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
128.0.6537.0
Modules
Images
c:\program files (x86)\google\googleupdater\128.0.6537.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
564"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6552 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
648"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=6668 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
692"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1352 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
936"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=6484 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
992"C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --system --windows-service --service=updateC:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Version:
128.0.6537.0
Modules
Images
c:\program files (x86)\google\googleupdater\128.0.6537.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1164"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3796 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5864 --field-trial-handle=2392,i,12917699166024979361,10863301936132590436,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
16 689
Read events
16 441
Write events
217
Delete events
31

Modification events

(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
128.0.6537.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
128.0.6537.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4EB300E9-4F8A-5D14-B795-36796C40660C}
Operation:writeName:AppID
Value:
{4EB300E9-4F8A-5D14-B795-36796C40660C}
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB300E9-4F8A-5D14-B795-36796C40660C}
Operation:writeName:LocalService
Value:
GoogleUpdaterInternalService128.0.6537.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB300E9-4F8A-5D14-B795-36796C40660C}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8582249A-7E37-5C77-A5F4-1FBFEAFCBC5F}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8582249A-7E37-5C77-A5F4-1FBFEAFCBC5F}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2720) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8FCD652C-D470-570F-9A74-B31F9AB8F368}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
10
Suspicious files
522
Text files
136
Unknown types
6

Dropped files

PID
Process
Filename
Type
232Mzk4MmI0MTczMTQ0ZjFmZjg1ZTQ2ZDgyYzZhOTU0ZWE.exeC:\WINDOWS\SystemTemp\Google232_1145289527\UPDATER.PACKED.7Z
MD5:
SHA256:
2720updater.exeC:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\uninstall.cmdtext
MD5:FBC297EE9060D4256192E4EDB98CAD1B
SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044
2720updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:7F611A14B8D1241C95511FB8E7699012
SHA256:3B7BD80A99FC0C79C57B9EEDB0696A2A981F99CB289744B5394510B49B0A0439
4116updater.exeC:\Windows\SystemTemp\Google4116_401862610\scoped_dir4116_1063098454\GoogleUpdate.exeexecutable
MD5:3AA2C853D6BC7AF7F2F9B8A934943EFD
SHA256:07034876B9EC0B59432B96FEDB7E10E332440159F9802FAAD5F5B99F01885F6B
4116updater.exeC:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\a1be4fb2-8ad8-4896-a4b0-accc85f5f438.tmpbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
992updater.exeC:\WINDOWS\SystemTemp\chrome_url_fetcher_992_109611158\-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.127_all_kqgvyxebv4r63jac66435t45xq.crx3
MD5:
SHA256:
992updater.exeC:\WINDOWS\SystemTemp\chrome_url_fetcher_992_542652863\-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.127_all_kqgvyxebv4r63jac66435t45xq.crx3
MD5:
SHA256:
4116updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:0A313C00FA4DD5B9C1D3F8288B41EF8C
SHA256:FB8AC41B88FB6E554D3DA9299646276501309D3DD1275D2BF651CA80DF0FBDFB
4116updater.exeC:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\prefs.jsonbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
4116updater.exeC:\Program Files (x86)\Google\GoogleUpdater\14ce2bd3-f529-4588-aa91-b22273311212.tmpbinary
MD5:0A313C00FA4DD5B9C1D3F8288B41EF8C
SHA256:FB8AC41B88FB6E554D3DA9299646276501309D3DD1275D2BF651CA80DF0FBDFB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
176
DNS requests
171
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2720
updater.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/r1.crl
unknown
unknown
2720
updater.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
unknown
2720
updater.exe
GET
200
142.250.184.195:80
http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQCRq%2FXldMamzQqGAD6YrjKf
unknown
unknown
992
updater.exe
GET
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/jcs2etny43kupyauxqlnc3ytci_126.0.6478.127/-8a69d345-d564-463c-aff1-a69d9e530f96-_126.0.6478.127_all_kqgvyxebv4r63jac66435t45xq.crx3
unknown
unknown
2568
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
2568
svchost.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
unknown
1544
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
5484
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
32
msedge.exe
GET
304
23.32.238.48:80
http://apps.identrust.com/roots/dstrootcax3.p7c
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
2568
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3156
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3868
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
992
updater.exe
142.250.184.227:443
update.googleapis.com
GOOGLE
US
whitelisted
2720
updater.exe
142.250.185.110:443
dl.google.com
GOOGLE
US
whitelisted
2720
updater.exe
142.250.184.195:80
ocsp.pki.goog
GOOGLE
US
whitelisted
992
updater.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE
US
whitelisted
1544
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
update.googleapis.com
  • 142.250.184.227
whitelisted
dl.google.com
  • 142.250.185.110
whitelisted
ocsp.pki.goog
  • 142.250.184.195
whitelisted
c.pki.goog
  • 142.250.184.195
unknown
o.pki.goog
  • 142.250.184.195
unknown
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.75
  • 40.126.31.71
  • 20.190.159.4
  • 20.190.159.71
  • 20.190.159.73
  • 20.190.159.64
  • 40.126.31.73
whitelisted
go.microsoft.com
  • 23.218.210.69
  • 23.35.238.131
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
whitelisted

Threats

PID
Process
Class
Message
32
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
32
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info