| File name: | ChromeSetup.exe |
| Full analysis: | https://app.any.run/tasks/e184084c-0ca6-4755-a77c-cb85d7e41c57 |
| Verdict: | Malicious activity |
| Analysis date: | May 31, 2025, 15:29:58 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections |
| MD5: | FA9B73C4FB818D0F63FA94B907C725A4 |
| SHA1: | A81E2545B6A280E5488D9B0EE45F156A6232C760 |
| SHA256: | A3F1ED04ACF987A11FECAA21709B4376F5EAD6F9E0B412D7996B575F6B2D7DE3 |
| SSDEEP: | 98304:4gPnebNC2wBNQQQ6HEMlAUWc4mlxE2PQuGCvpMkN2cxAcuGivgbkOwugPlxTLyRz:icV5nWA |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:03:20 03:02:12+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 3570176 |
| InitializedDataSize: | 7190528 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1c4e70 |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 136.0.7079.0 |
| ProductVersionNumber: | 136.0.7079.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Installer |
| FileVersion: | 136.0.7079.0 |
| InternalName: | Google Installer (x86) |
| LegalCopyright: | Copyright 2025 Google LLC. All rights reserved. |
| OriginalFileName: | UpdaterSetup.exe |
| ProductName: | Google Installer |
| ProductVersion: | 136.0.7079.0 |
| CompanyShortName: | |
| ProductShortName: | GoogleUpdater |
| LastChange: | 8fb48956fe1a2ea0dc2e5ad0a6d086968085ee0d-refs/branch-heads/7079@{#1} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 672 | "C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop" --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files (x86)\Microsoft\Skype for Desktop\resources\app.asar" --no-sandbox --no-zygote --autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --ms-disable-indexeddb-transaction-timeout --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2556 --field-trial-handle=2152,i,7406598894121983277,10899799299814477831,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --skype-process-type=Main --skype-window-id=__MAIN_ROOT_VIEW_ID__ /prefetch:1 | C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe | — | Skype.exe | |||||||||||
User: admin Company: Skype Technologies S.A. Integrity Level: MEDIUM Description: Skype Version: 8.104.0.207 Modules
| |||||||||||||||
| 968 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | reg.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1128 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | reg.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1244 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | reg.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1284 | "C:\WINDOWS\SystemTemp\Google6384_1165320951\bin\updater.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={00BA26A9-9B7A-DD46-9897-0B31D7DA1071}&lang=pl&browser=3&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-statsdef_1&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevated | C:\Windows\SystemTemp\Google6384_1165320951\bin\updater.exe | ChromeSetup.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Updater Version: 136.0.7079.0 Modules
| |||||||||||||||
| 1472 | C:\WINDOWS\SystemTemp\Google6384_1165320951\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\136.0.7079.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=136.0.7079.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a8,0x2ac,0x2b0,0x284,0x2b4,0x5bd810,0x5bd81c,0x5bd828 | C:\Windows\SystemTemp\Google6384_1165320951\bin\updater.exe | — | updater.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Updater Version: 136.0.7079.0 Modules
| |||||||||||||||
| 1660 | C:\WINDOWS\system32\reg.exe QUERY HKCU\Software\Microsoft\Edge\BLBeacon /v version | C:\Windows\SysWOW64\reg.exe | — | Skype.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2596 | "C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop" --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files (x86)\Microsoft\Skype for Desktop\resources\app.asar" --no-sandbox --no-zygote --enable-blink-features --disable-blink-features --autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --ms-disable-indexeddb-transaction-timeout --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3992 --field-trial-handle=2152,i,7406598894121983277,10899799299814477831,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1 | C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe | — | Skype.exe | |||||||||||
User: admin Company: Skype Technologies S.A. Integrity Level: MEDIUM Description: Skype Version: 8.104.0.207 Modules
| |||||||||||||||
| 3872 | C:\WINDOWS\system32\reg.exe QUERY HKCU\Software\Microsoft\Skype /v RestartForUpdate | C:\Windows\SysWOW64\reg.exe | — | Skype.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4020 | "C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop" --mojo-platform-channel-handle=2468 --field-trial-handle=2152,i,7406598894121983277,10899799299814477831,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe | Skype.exe | ||||||||||||
User: admin Company: Skype Technologies S.A. Integrity Level: MEDIUM Description: Skype Version: 8.104.0.207 Modules
| |||||||||||||||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 136.0.7079.0 | |||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 136.0.7079.0 | |||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4D055B91-EFED-5584-B591-3475C3026FF4} |
| Operation: | write | Name: | AppID |
Value: {4D055B91-EFED-5584-B591-3475C3026FF4} | |||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4D055B91-EFED-5584-B591-3475C3026FF4} |
| Operation: | write | Name: | LocalService |
Value: GoogleUpdaterInternalService136.0.7079.0 | |||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4D055B91-EFED-5584-B591-3475C3026FF4} |
| Operation: | write | Name: | ServiceParameters |
Value: --com-service | |||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{DA783627-77AC-54BC-AD32-CD03D63CF5C5}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA783627-77AC-54BC-AD32-CD03D63CF5C5}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (1284) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{1218B866-3AB4-5005-91B4-CF4AE54BEA28}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6384 | ChromeSetup.exe | C:\Windows\SystemTemp\Google6384_606170703\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 1284 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\136.0.7079.0\updater.exe | executable | |
MD5:4777717D98E9145355128FA96B40D0FC | SHA256:73206C19E6281013335B6C46219FCFBB29E95745225B4345126809BDABF4E3BD | |||
| 5624 | updater.exe | C:\Windows\SystemTemp\Google5624_417197696\scoped_dir5624_1309335764\GoogleUpdate.exe | executable | |
MD5:3AA2C853D6BC7AF7F2F9B8A934943EFD | SHA256:07034876B9EC0B59432B96FEDB7E10E332440159F9802FAAD5F5B99F01885F6B | |||
| 1284 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\updater.log | text | |
MD5:2AEC5F08CBE6AF048AD5C31364E42797 | SHA256:6D7B949829F1E3AE727E6BAB5FBCD334F8271FCE3E0082F2B07F65A55CAA8EC1 | |||
| 1284 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\136.0.7079.0\uninstall.cmd | text | |
MD5:FBC297EE9060D4256192E4EDB98CAD1B | SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044 | |||
| 1284 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\2b38ee6e-64a7-4cb2-8412-eefad28a2e93.tmp | binary | |
MD5:75BBDA62E58EE8F3585AD25F0AB66D03 | SHA256:2F65D82BC4038B8003886E6DBCF1BE5C07397C851D61257ADDB88E9B9B6F4E96 | |||
| 5624 | updater.exe | C:\Program Files (x86)\Google\Update\GoogleUpdate.exe | executable | |
MD5:4777717D98E9145355128FA96B40D0FC | SHA256:73206C19E6281013335B6C46219FCFBB29E95745225B4345126809BDABF4E3BD | |||
| 1284 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\136.0.7079.0\Crashpad\settings.dat | binary | |
MD5:A4342E7DCE488158D35076F9F0A69814 | SHA256:640D7E010B1F86E17222E5B7EBF3DB5E0864C958A38FD2D53A5B1FB7EF276D55 | |||
| 7872 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_7872_122089257\-8a69d345-d564-463c-aff1-a69d9e530f96-_137.0.7151.55_all_ol3c6uqc2c3ww7bl7tkyun7di4.crx3 | — | |
MD5:— | SHA256:— | |||
| 7872 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\crx_cache\ea1fda29872c4f43ed3cbb48923e05708c8b822dfa4936909b7cdd980c13329c | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.19.11.105:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2516 | svchost.exe | GET | 200 | 2.21.137.121:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.21.137.121:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
2516 | svchost.exe | GET | 200 | 2.19.11.105:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1284 | updater.exe | GET | 200 | 142.250.180.99:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | whitelisted |
1284 | updater.exe | GET | 200 | 142.250.180.99:80 | http://c.pki.goog/r/r1.crl | unknown | — | — | whitelisted |
1284 | updater.exe | GET | 200 | 142.250.178.195:80 | http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEGaG8H5w19%2FCCUy4WjTW49g%3D | unknown | — | — | whitelisted |
7872 | updater.exe | GET | 200 | 142.250.180.78:80 | http://dl.google.com/edgedl/release2/chrome/acoejbyzhsecipp4jgqreptr6epq_137.0.7151.55/-8a69d345-d564-463c-aff1-a69d9e530f96-_137.0.7151.55_all_ol3c6uqc2c3ww7bl7tkyun7di4.crx3 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2088 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.19.11.105:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
2516 | svchost.exe | 2.19.11.105:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.21.137.121:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2516 | svchost.exe | 2.21.137.121:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2516 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |