File name:

ChromeSetup.exe

Full analysis: https://app.any.run/tasks/500d1a14-b89b-450e-9e85-870bf8d3df9d
Verdict: Malicious activity
Analysis date: July 29, 2025, 18:25:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections
MD5:

E1C93B8E2866D3F31F95C289BD5E3B84

SHA1:

65F7C3DDBC75CF478826539C930760924E9F6C15

SHA256:

6BBD6FB3DA6EDE6DC3CD1F586199C39A2DBD585459B6753AC3FC2F97FE13A635

SSDEEP:

98304:ccA8SGZGtjCDKExxCYg5aJLegqNZYCZEspjKwVV8hSPD5IJY+E6CAU7mk21KW6bN:yyGx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ChromeSetup.exe (PID: 3844)
      • updater.exe (PID: 2704)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 2704)
      • updater.exe (PID: 2220)
      • 138.0.7204.169_chrome_installer_uncompressed.exe (PID: 4760)
    • Executes as Windows Service

      • updater.exe (PID: 2220)
      • updater.exe (PID: 6756)
    • Application launched itself

      • ChromeSetup.exe (PID: 3844)
      • updater.exe (PID: 2704)
      • updater.exe (PID: 2220)
      • updater.exe (PID: 6756)
      • updater.exe (PID: 6796)
      • setup.exe (PID: 6012)
    • The process executes via Task Scheduler

      • updater.exe (PID: 6796)
  • INFO

    • Reads the computer name

      • ChromeSetup.exe (PID: 3844)
      • ChromeSetup.exe (PID: 3392)
      • updater.exe (PID: 2704)
      • updater.exe (PID: 2220)
      • updater.exe (PID: 6756)
      • updater.exe (PID: 6796)
      • 138.0.7204.169_chrome_installer_uncompressed.exe (PID: 4760)
      • setup.exe (PID: 6012)
    • The sample compiled with english language support

      • ChromeSetup.exe (PID: 3844)
      • updater.exe (PID: 2704)
      • updater.exe (PID: 2220)
      • 138.0.7204.169_chrome_installer_uncompressed.exe (PID: 4760)
    • Checks supported languages

      • ChromeSetup.exe (PID: 3844)
      • ChromeSetup.exe (PID: 3392)
      • updater.exe (PID: 3788)
      • updater.exe (PID: 2704)
      • updater.exe (PID: 2220)
      • updater.exe (PID: 6756)
      • updater.exe (PID: 4120)
      • updater.exe (PID: 2040)
      • updater.exe (PID: 6796)
      • updater.exe (PID: 1588)
      • 138.0.7204.169_chrome_installer_uncompressed.exe (PID: 4760)
      • setup.exe (PID: 6012)
      • setup.exe (PID: 1100)
    • Creates files in the program directory

      • updater.exe (PID: 3788)
      • updater.exe (PID: 2704)
      • updater.exe (PID: 2220)
      • updater.exe (PID: 6756)
      • setup.exe (PID: 6012)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 2704)
      • updater.exe (PID: 2220)
      • updater.exe (PID: 6756)
      • updater.exe (PID: 6796)
    • Create files in a temporary directory

      • ChromeSetup.exe (PID: 3392)
      • updater.exe (PID: 2704)
    • Process checks computer location settings

      • ChromeSetup.exe (PID: 3844)
    • Checks proxy server information

      • updater.exe (PID: 2704)
    • Reads the software policy settings

      • updater.exe (PID: 2704)
      • updater.exe (PID: 6756)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 2704)
    • Creates files or folders in the user directory

      • updater.exe (PID: 2704)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:05:22 03:02:31+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 3659264
InitializedDataSize: 7652864
UninitializedDataSize: -
EntryPoint: 0x1d1990
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 138.0.7194.0
ProductVersionNumber: 138.0.7194.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Installer (x86)
FileVersion: 138.0.7194.0
InternalName: Google Installer (x86)
LegalCopyright: Copyright 2025 Google LLC. All rights reserved.
OriginalFileName: UpdaterSetup.exe
ProductName: Google Installer (x86)
ProductVersion: 138.0.7194.0
CompanyShortName: Google
ProductShortName: GoogleUpdater
LastChange: 5f61f8e2e5320b2ca29a33ef2235c25f1c198854-refs/branch-heads/7194@{#1}
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
13
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start chromesetup.exe no specs chromesetup.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe no specs updater.exe no specs 138.0.7204.169_chrome_installer_uncompressed.exe setup.exe no specs setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1100C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping6756_1235260139\CR_6390A.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=138.0.7204.169 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x7ff66cc925a0,0x7ff66cc925ac,0x7ff66cc925b8C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6756_1235260139\CR_6390A.tmp\setup.exesetup.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome Installer
Version:
138.0.7204.169
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping6756_1235260139\cr_6390a.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1588"C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=134.0.6985.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x298,0x29c,0x2a0,0x258,0x2a4,0x111c460,0x111c46c,0x111c478C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater
Exit code:
0
Version:
134.0.6985.0
Modules
Images
c:\program files (x86)\google\googleupdater\134.0.6985.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2040"C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=138.0.7194.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2b4,0x2b8,0x2bc,0x290,0x2c0,0x10129c0,0x10129cc,0x10129d8C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater (x86)
Exit code:
0
Version:
138.0.7194.0
Modules
Images
c:\program files (x86)\google\googleupdater\138.0.7194.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2220"C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --system --windows-service --service=update-internalC:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater (x86)
Exit code:
0
Version:
138.0.7194.0
Modules
Images
c:\program files (x86)\google\googleupdater\138.0.7194.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2704"C:\Users\admin\AppData\Local\Temp\Google3392_369065086\bin\updater.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={61EA7311-DEC6-BCBD-BD1D-8569202D58E3}&lang=en&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&brand=FKPE&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Local\Temp\Google3392_369065086\bin\updater.exe
ChromeSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Updater (x86)
Version:
138.0.7194.0
Modules
Images
c:\users\admin\appdata\local\temp\google3392_369065086\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3392"C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={61EA7311-DEC6-BCBD-BD1D-8569202D58E3}&lang=en&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&brand=FKPE&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Local\Temp\ChromeSetup.exe
ChromeSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Installer (x86)
Version:
138.0.7194.0
Modules
Images
c:\users\admin\appdata\local\temp\chromesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3788C:\Users\admin\AppData\Local\Temp\Google3392_369065086\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=138.0.7194.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2c8,0x2cc,0x2d0,0x2a4,0x2d4,0x14129c0,0x14129cc,0x14129d8C:\Users\admin\AppData\Local\Temp\Google3392_369065086\bin\updater.exeupdater.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Updater (x86)
Version:
138.0.7194.0
Modules
Images
c:\users\admin\appdata\local\temp\google3392_369065086\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3844"C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe" C:\Users\admin\AppData\Local\Temp\ChromeSetup.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Installer (x86)
Version:
138.0.7194.0
Modules
Images
c:\users\admin\appdata\local\temp\chromesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4120"C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=138.0.7194.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x10129c0,0x10129cc,0x10129d8C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater (x86)
Version:
138.0.7194.0
Modules
Images
c:\program files (x86)\google\googleupdater\138.0.7194.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
4760"C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping6756_1235260139\138.0.7204.169_chrome_installer_uncompressed.exe" --verbose-logging --do-not-launch-chrome --channel=stable --installerdata="C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6756_1235260139\4a8cde38-a552-472e-8fcf-702a43ec30ee.tmp"C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6756_1235260139\138.0.7204.169_chrome_installer_uncompressed.exe
updater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome Installer
Version:
138.0.7204.169
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping6756_1235260139\138.0.7204.169_chrome_installer_uncompressed.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
Total events
2 111
Read events
2 002
Write events
100
Delete events
9

Modification events

(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
138.0.7194.0
(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
138.0.7194.0
(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4A8EC270-ECA5-51BC-A8AB-551ED6D0CA26}
Operation:writeName:AppID
Value:
{4A8EC270-ECA5-51BC-A8AB-551ED6D0CA26}
(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4A8EC270-ECA5-51BC-A8AB-551ED6D0CA26}
Operation:writeName:LocalService
Value:
GoogleUpdaterInternalService138.0.7194.0
(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4A8EC270-ECA5-51BC-A8AB-551ED6D0CA26}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{D12C0CB6-7717-5083-8874-A3C30BB3C374}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D12C0CB6-7717-5083-8874-A3C30BB3C374}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2704) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{48D40B89-9B8C-53BE-9B9E-BEB2AD53DE28}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
4
Suspicious files
24
Text files
5
Unknown types
3

Dropped files

PID
Process
Filename
Type
3392ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\Google3392_1915346572\UPDATER.PACKED.7Z
MD5:
SHA256:
2704updater.exeC:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\uninstall.cmdtext
MD5:FBC297EE9060D4256192E4EDB98CAD1B
SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044
2704updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:8F169AAD46811B7C2C3EBCCECC7FAE9E
SHA256:4CE1CFE347047C3E3EFC07125C9082E94E9D8F4F2FEE916BB3D98A9365BF64D2
2704updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:4D8DF8FA0D5BE0C431DB342041019C34
SHA256:D9CF12B4F14BD5ABB0B6C967A3DFE3293FEBF1FF251E7ACECBEDB6801CF52E5C
2220updater.exeC:\Program Files (x86)\Google\GoogleUpdater\451859b8-4d38-412b-bee5-3ccbbc915ec1.tmpbinary
MD5:F0781A6FC9768A7A4C093D8514634CD5
SHA256:0125BDA47A5EF97E186C40B34C36627F2CB994B9B3C6928E56B7293659C5C337
6756updater.exeC:\Windows\SystemTemp\chrome_url_fetcher_6756_833231590\90ee204561905aa512c564e6fd0e8182cfb9a2574f5ebc579bb7a89870bb4441
MD5:
SHA256:
2704updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.json~RF18d694.TMPbinary
MD5:6A7C22B00ADBF302C1F53F51AF1AB2F6
SHA256:BFD4268EDA9AB3F0E8D8D2ED0884BD28C0B34546332B36E54EBD30ACF45053FF
2220updater.exeC:\Program Files (x86)\Google\Update\GoogleUpdate.exeexecutable
MD5:A1044445F76098186DE3B146ABDA9876
SHA256:8CA4F944172F0904B4D70E40A5D61B54439109502E7E3E20D71F8A83BEAD9CE8
2704updater.exeC:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\Crashpad\settings.datbinary
MD5:EBD54DDB86D27FEE565AFD30E42BD60D
SHA256:2C97DE665FCC0F0CB0A79CC5C94FD2D743F31C517E77AC23C3986E2CE22697C2
2704updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12der
MD5:CA8A9BDCA7AD59F5C8B7E1AA63160039
SHA256:81B7FA53B692B4D26E2E8943F2DDA2F9563CFCB0E11F48679EB2BE4F8C375B90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
24
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2704
updater.exe
GET
200
142.250.181.227:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
2704
updater.exe
GET
200
142.250.181.227:80
http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDPZmByDOs98xJONhjjIZaE
unknown
whitelisted
2704
updater.exe
GET
200
142.250.181.227:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
1380
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6540
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1268
svchost.exe
GET
200
184.24.77.34:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6756
updater.exe
GET
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/%7B8a69d345-d564-463c-aff1-a69d9e530f96%7D/90ee204561905aa512c564e6fd0e8182cfb9a2574f5ebc579bb7a89870bb4441
unknown
whitelisted
6540
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3480
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6756
updater.exe
142.250.184.227:443
update.googleapis.com
GOOGLE
US
whitelisted
2704
updater.exe
142.250.186.110:443
dl.google.com
GOOGLE
US
whitelisted
2704
updater.exe
142.250.181.227:80
c.pki.goog
GOOGLE
US
whitelisted
6756
updater.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE
US
whitelisted
1380
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.174
whitelisted
update.googleapis.com
  • 142.250.184.227
whitelisted
dl.google.com
  • 142.250.186.110
whitelisted
c.pki.goog
  • 142.250.181.227
whitelisted
o.pki.goog
  • 142.250.181.227
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
login.live.com
  • 20.190.160.17
  • 20.190.160.14
  • 20.190.160.3
  • 20.190.160.4
  • 20.190.160.128
  • 40.126.32.68
  • 20.190.160.2
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 184.24.77.34
  • 184.24.77.12
  • 184.24.77.30
  • 184.24.77.37
  • 184.24.77.6
  • 184.24.77.10
  • 184.24.77.38
  • 184.24.77.35
  • 184.24.77.31
whitelisted

Threats

No threats detected
No debug info