| File name: | ChromeSetup (2).exe |
| Full analysis: | https://app.any.run/tasks/ac7f6fa8-06d1-4f15-82e9-27cf8aa70da0 |
| Verdict: | Malicious activity |
| Analysis date: | December 10, 2023, 18:57:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F04F90F9A17C16251D6905FE642EC644 |
| SHA1: | 9B8D4267829991A69D982FE1A0F50B7CA7EADD25 |
| SHA256: | B6F11933E1F38025701261E95AEBDE1C39D0FEEB5FB27A806B9463F43E20691F |
| SSDEEP: | 49152:H0CvStaF9hMkSxYGhaKT0cLkB48mvVQObiybRxSz82KRf9ePU1KH+IQ4TEKgVUUC:UoStaFOPaKTiyZv6jyb0CHu+l4TKPkuv |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:30 01:47:21+01:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.2 |
| CodeSize: | 96256 |
| InitializedDataSize: | 1259520 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x5374 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.36.352 |
| ProductVersionNumber: | 1.3.36.352 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Update Setup |
| FileVersion: | 1.3.36.352 |
| InternalName: | Google Update Setup |
| LegalCopyright: | Copyright 2018 Google LLC |
| OriginalFileName: | GoogleUpdateSetup.exe |
| ProductName: | Google Update |
| ProductVersion: | 1.3.36.352 |
| LanguageId: | en |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 240 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={20E5F0C7-9E99-8E6C-1DD1-4A11A63EDC1B}&lang=en&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=stable-arch_x86-statsdef_1&installdataindex=empty" /installsource taggedmi /sessionid "{8478AB21-D1DF-4030-AAC6-E49C212C8986}" | C:\Program Files\Google\Update\GoogleUpdate.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 600 | "C:\Program Files\Google\Temp\GUM2EE.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={20E5F0C7-9E99-8E6C-1DD1-4A11A63EDC1B}&lang=en&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=stable-arch_x86-statsdef_1&installdataindex=empty" /installelevated | C:\Program Files\Google\Temp\GUM2EE.tmp\GoogleUpdate.exe | — | GoogleUpdateSetup.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.36.351 Modules
| |||||||||||||||
| 880 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2152 --field-trial-handle=1188,i,8111708514322947509,382271166325328810,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 968 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1048 --field-trial-handle=1152,i,16344526245312827623,48978137474420908,131072 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1212 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3688 --field-trial-handle=1152,i,16344526245312827623,48978137474420908,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1452 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=2464 --field-trial-handle=1188,i,8111708514322947509,382271166325328810,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1496 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --from-installer | C:\Program Files\Google\Chrome\Application\chrome.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1528 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1992 --field-trial-handle=1152,i,16344526245312827623,48978137474420908,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1604 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1572 --field-trial-handle=1152,i,16344526245312827623,48978137474420908,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1608 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /regserver | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| (PID) Process: | (600) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (600) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | delete value | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (600) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update |
| Operation: | write | Name: | path |
Value: C:\Program Files\Google\Update\GoogleUpdate.exe | |||
| (PID) Process: | (600) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update |
| Operation: | write | Name: | UninstallCmdLine |
Value: "C:\Program Files\Google\Update\GoogleUpdate.exe" /uninstall | |||
| (PID) Process: | (600) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | pv |
Value: 1.3.36.32 | |||
| (PID) Process: | (600) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | name |
Value: Google Update | |||
| (PID) Process: | (600) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D} |
| Operation: | write | Name: | pv |
Value: 1.3.36.32 | |||
| (PID) Process: | (600) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe |
| Operation: | write | Name: | DisableExceptionChainValidation |
Value: 0 | |||
| (PID) Process: | (3856) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3856) GoogleUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\goopdateres_am.dll | executable | |
MD5:6B662CF1C75BF32F3F26A945C3F420D9 | SHA256:CD426D502F1B039F4D9BB8C199271C68B63700CD2203567BE7F3324A5755654F | |||
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\goopdateres_bg.dll | executable | |
MD5:848D712A48EE972E87517818DEDE7E41 | SHA256:B17E3507AA13334E21FB0FC98EEA44ADE4793A5B2EDF2D76694DA0772BF6FEB1 | |||
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\goopdateres_bn.dll | executable | |
MD5:1D1E2D66464C7237E667FC8813847D27 | SHA256:825428867F14CE18169FE8705C0A5C941B87A7FEEC84F4E3DD4344BBE5FC7972 | |||
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\psmachine_64.dll | executable | |
MD5:365CE91B8F2D6D85D246B0B64608F333 | SHA256:95AC9E810ABF9B37AAA84955A0741B14BAC1181504AA5237A2DF01F447972EB0 | |||
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\psuser_64.dll | executable | |
MD5:3235EA4154477ADA20432C11F717150A | SHA256:51C5F760CC6C509BA0974879B9CCB3D3545EF65D11CF0C7C9A62D39A0F6A2571 | |||
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\goopdateres_ar.dll | executable | |
MD5:ADAE3C47EDD1BD2E078F46E7DD448FF9 | SHA256:41A395DC1C9B6E10A32E39FC9BCC3C45611B30723C5A895AB46BD2ABDAC31D3A | |||
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\goopdateres_cs.dll | executable | |
MD5:5CF5DC21628DF3D52C372A3033918FDC | SHA256:487957B3EB2DADDF00808350C3CC52F8574EA585EA4A2EA742378B97AE4BBC71 | |||
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\psuser.dll | executable | |
MD5:FC9F15602C90829671D54FA6E72F0C88 | SHA256:9F581D8D8F3FC63FB3483D6094562E114F2E1F289D1C7A4B7FFE91E46E50C936 | |||
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\goopdateres_da.dll | executable | |
MD5:F2676455A6CC1749B55F904FEF73CBE1 | SHA256:70CA4EB73A4F8D03E750929A4AFDB876076D39499F2016588F8B6FE85A80B0E5 | |||
| 2920 | ChromeSetup (2).exe | C:\Users\admin\AppData\Local\Temp\GUMFFC1.tmp\goopdateres_ca.dll | executable | |
MD5:8A178EEDD7627E0B655EE3714FBF6766 | SHA256:BD6013798AD45B2791C829E01EF74CE123CBDD138F298E7A6EC762A643340D12 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
240 | GoogleUpdate.exe | GET | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | unknown |
240 | GoogleUpdate.exe | GET | 200 | 184.25.50.43:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e87dcf5dd0ddd9a0 | unknown | compressed | 4.66 Kb | unknown |
240 | GoogleUpdate.exe | GET | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | binary | 724 b | unknown |
240 | GoogleUpdate.exe | GET | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGpYRvzN3kAuEMlMWsqSFLc%3D | unknown | binary | 471 b | unknown |
868 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | — | — | unknown |
1080 | svchost.exe | GET | 200 | 184.25.50.16:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?20da42ca9bb40799 | unknown | compressed | 65.2 Kb | unknown |
868 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 9.97 Kb | unknown |
868 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 10.0 Kb | unknown |
868 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 23.4 Kb | unknown |
868 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 9.91 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3140 | GoogleUpdate.exe | 142.250.185.163:443 | update.googleapis.com | GOOGLE | US | whitelisted |
240 | GoogleUpdate.exe | 142.250.184.238:443 | dl.google.com | GOOGLE | US | whitelisted |
2364 | GoogleUpdate.exe | 142.250.185.163:443 | update.googleapis.com | GOOGLE | US | whitelisted |
240 | GoogleUpdate.exe | 184.25.50.43:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
240 | GoogleUpdate.exe | 142.250.186.131:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
1496 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| whitelisted |
optimizationguide-pa.googleapis.com |
| whitelisted |
www.googleapis.com |
| whitelisted |
encrypted-tbn0.gstatic.com |
| whitelisted |