File name:

ChromeSetup.exe

Full analysis: https://app.any.run/tasks/f10d8700-7f50-4489-b537-773283dc71c8
Verdict: Malicious activity
Analysis date: January 28, 2026, 18:55:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections
MD5:

0C8873AC7F7E41074A3B829BAD9F467C

SHA1:

A0AA1A62B53C1DCD7C68F0BCEF80CF02CED863C8

SHA256:

B9166B833868ED17435F30274450FEDCADFDE6F23197718505921E5FF2518398

SSDEEP:

98304:NSnRzocfpFvp26hFKCOBa2zR0kolhTxId2aFp0SskMVGI57+vM/SduYA5jWM31hX:icaj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • setup.exe (PID: 7164)
      • platform_experience_helper.exe (PID: 1488)
  • SUSPICIOUS

    • Application launched itself

      • ChromeSetup.exe (PID: 5520)
      • setup.exe (PID: 7164)
      • setup.exe (PID: 8636)
      • updater.exe (PID: 7236)
    • Executable content was dropped or overwritten

      • ChromeSetup.exe (PID: 8628)
      • updater.exe (PID: 4516)
      • updater.exe (PID: 7236)
      • 144.0.7559.110_chrome_installer_uncompressed.exe (PID: 2348)
      • setup.exe (PID: 7164)
      • updater.exe (PID: 5612)
      • platform_experience_helper.exe (PID: 1488)
    • Executes as Windows Service

      • updater.exe (PID: 4516)
      • updater.exe (PID: 5612)
    • Process drops legitimate windows executable

      • setup.exe (PID: 7164)
    • Possible stealing from browsers

      • os_update_handler.exe (PID: 8052)
    • Searches for installed software

      • setup.exe (PID: 7164)
  • INFO

    • Checks supported languages

      • ChromeSetup.exe (PID: 5520)
      • 144.0.7559.110_chrome_installer_uncompressed.exe (PID: 2348)
      • setup.exe (PID: 7164)
      • setup.exe (PID: 2096)
      • setup.exe (PID: 8636)
      • updater.exe (PID: 7208)
      • setup.exe (PID: 6552)
      • ChromeSetup.exe (PID: 8628)
      • updater.exe (PID: 7236)
      • elevation_service.exe (PID: 4340)
      • os_update_handler.exe (PID: 8052)
      • platform_experience_helper.exe (PID: 1488)
    • Reads the computer name

      • updater.exe (PID: 7236)
      • ChromeSetup.exe (PID: 5520)
      • 144.0.7559.110_chrome_installer_uncompressed.exe (PID: 2348)
      • setup.exe (PID: 7164)
      • setup.exe (PID: 8636)
      • ChromeSetup.exe (PID: 8628)
      • os_update_handler.exe (PID: 8052)
      • elevation_service.exe (PID: 4340)
    • Creates files in the program directory

      • updater.exe (PID: 7236)
      • updater.exe (PID: 7208)
      • updater.exe (PID: 4516)
      • updater.exe (PID: 5612)
      • setup.exe (PID: 7164)
      • setup.exe (PID: 8636)
      • platform_experience_helper.exe (PID: 1488)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 7236)
    • Drops script file

      • updater.exe (PID: 7236)
      • ChromeSetup.exe (PID: 8628)
    • The sample compiled with english language support

      • ChromeSetup.exe (PID: 5520)
      • updater.exe (PID: 7236)
      • updater.exe (PID: 4516)
      • 144.0.7559.110_chrome_installer_uncompressed.exe (PID: 2348)
      • setup.exe (PID: 7164)
      • ChromeSetup.exe (PID: 8628)
      • platform_experience_helper.exe (PID: 1488)
      • updater.exe (PID: 5612)
    • Process checks computer location settings

      • ChromeSetup.exe (PID: 5520)
    • Reads security settings of Internet Explorer

      • ChromeSetup.exe (PID: 5520)
      • updater.exe (PID: 7236)
    • Create files in a temporary directory

      • ChromeSetup.exe (PID: 8628)
      • updater.exe (PID: 7236)
    • Checks proxy server information

      • updater.exe (PID: 7236)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 7236)
    • Creates files or folders in the user directory

      • updater.exe (PID: 7236)
    • Creates a software uninstall entry

      • setup.exe (PID: 7164)
    • Manual execution by a user

      • chrome.exe (PID: 4852)
    • Executes as Windows Service

      • elevation_service.exe (PID: 4340)
    • Connects to unusual port

      • chrome.exe (PID: 7608)
    • Launching a file from a Registry key

      • platform_experience_helper.exe (PID: 1488)
    • Application launched itself

      • chrome.exe (PID: 4852)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:11:26 04:02:26+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 3403776
InitializedDataSize: 7327744
UninitializedDataSize: -
EntryPoint: 0x1e51c0
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 144.0.7547.0
ProductVersionNumber: 144.0.7547.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Installer (x86)
FileVersion: 144.0.7547.0
InternalName: Google Installer (x86)
LegalCopyright: Copyright 2025 Google LLC. All rights reserved.
OriginalFileName: UpdaterSetup.exe
ProductName: Google Installer (x86)
ProductVersion: 144.0.7547.0
CompanyShortName: Google
ProductShortName: GoogleUpdater
LastChange: 43ff84ab4732e1864649c417ca17b1c2149d1179-refs/branch-heads/7547@{#1}
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
189
Monitored processes
34
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
start chromesetup.exe no specs chromesetup.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe no specs updater.exe no specs 144.0.7559.110_chrome_installer_uncompressed.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe elevation_service.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs os_update_handler.exe no specs updater.exe no specs updater.exe no specs platform_experience_helper.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1324"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --force-high-res-timeticks=disabled --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --metrics-shmem-handle=3316,i,6672101718696670947,5254835066844821801,2097152 --field-trial-handle=2024,i,11681912947258148174,14767525777244097582,262144 --variations-seed-version --trace-process-track-uuid=3190708991934122588 --mojo-platform-channel-handle=3324 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
144.0.7559.110
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\144.0.7559.110\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1488"C:\WINDOWS\SystemTemp\updater_chrome_Unpacker_BeginUnzipping5612_1615055364\platform_experience_helper.exe" --installC:\Windows\SystemTemp\updater_chrome_Unpacker_BeginUnzipping5612_1615055364\platform_experience_helper.exe
updater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome
Exit code:
0
Version:
144.0.7512.2
Modules
Images
c:\windows\systemtemp\updater_chrome_unpacker_beginunzipping5612_1615055364\platform_experience_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
1704"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --extension-process --force-high-res-timeticks=disabled --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=9 --metrics-shmem-handle=4160,i,18300227755799090267,11476180207892333904,2097152 --field-trial-handle=2024,i,11681912947258148174,14767525777244097582,262144 --variations-seed-version --trace-process-track-uuid=3190708994745248135 --mojo-platform-channel-handle=4344 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
144.0.7559.110
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\144.0.7559.110\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2096C:\WINDOWS\SystemTemp\updater_chrome_Unpacker_BeginUnzipping5612_606639851\CR_560E2.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=144.0.7559.110 --attachment=C:\WINDOWS\SystemTemp\chrome_installer.log --initial-client-data=0x290,0x294,0x298,0x26c,0x29c,0x7ff7aa94fe80,0x7ff7aa94fe8c,0x7ff7aa94fe98C:\Windows\SystemTemp\updater_chrome_Unpacker_BeginUnzipping5612_606639851\CR_560E2.tmp\setup.exesetup.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome Installer
Exit code:
0
Version:
144.0.7559.110
Modules
Images
c:\windows\systemtemp\updater_chrome_unpacker_beginunzipping5612_606639851\cr_560e2.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2256"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --force-high-res-timeticks=disabled --metrics-shmem-handle=2444,i,3138605313362081082,14561521249599203881,524288 --field-trial-handle=2024,i,11681912947258148174,14767525777244097582,262144 --variations-seed-version --trace-process-track-uuid=3190708990060038890 --mojo-platform-channel-handle=2452 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
144.0.7559.110
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\144.0.7559.110\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2348"C:\WINDOWS\SystemTemp\updater_chrome_Unpacker_BeginUnzipping5612_606639851\144.0.7559.110_chrome_installer_uncompressed.exe" --verbose-logging --do-not-launch-chrome --channel=stable --installerdata="C:\Windows\SystemTemp\updater_chrome_Unpacker_BeginUnzipping5612_606639851\3d6c0592-cca7-47a3-8bff-1b7c518114a6.tmp"C:\Windows\SystemTemp\updater_chrome_Unpacker_BeginUnzipping5612_606639851\144.0.7559.110_chrome_installer_uncompressed.exe
updater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome Installer
Exit code:
0
Version:
144.0.7559.110
Modules
Images
c:\windows\systemtemp\updater_chrome_unpacker_beginunzipping5612_606639851\144.0.7559.110_chrome_installer_uncompressed.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
2820"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=144.0.7559.110 --initial-client-data=0x228,0x22c,0x230,0x1f0,0x234,0x7ffd700f2068,0x7ffd700f2074,0x7ffd700f2080C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
144.0.7559.110
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3404"C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=144.0.7547.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a0,0x2a4,0x2a8,0x29c,0x2ac,0x82e5fc,0x82e608,0x82e614C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater (x86)
Exit code:
0
Version:
144.0.7547.0
Modules
Images
c:\program files (x86)\google\googleupdater\144.0.7547.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
4340"C:\Program Files\Google\Chrome\Application\144.0.7559.110\elevation_service.exe"C:\Program Files\Google\Chrome\Application\144.0.7559.110\elevation_service.exeservices.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome
Exit code:
0
Version:
144.0.7559.110
Modules
Images
c:\program files\google\chrome\application\144.0.7559.110\elevation_service.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
4468C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
2 611
Read events
2 472
Write events
127
Delete events
12

Modification events

(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
144.0.7547.0
(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
144.0.7547.0
(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2B969405-02ED-533A-BA99-8636AC9232DC}
Operation:writeName:AppID
Value:
{2B969405-02ED-533A-BA99-8636AC9232DC}
(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{2B969405-02ED-533A-BA99-8636AC9232DC}
Operation:writeName:LocalService
Value:
GoogleUpdaterInternalService144.0.7547.0
(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{2B969405-02ED-533A-BA99-8636AC9232DC}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{94F856BF-2E93-5C36-A514-5D8EFB73B673}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94F856BF-2E93-5C36-A514-5D8EFB73B673}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7236) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{35886103-B77E-509F-9A68-68E782D38F3B}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
30
Suspicious files
307
Text files
125
Unknown types
0

Dropped files

PID
Process
Filename
Type
8628ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\Google8628_1001014032\UPDATER.PACKED.7Z
MD5:
SHA256:
8628ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\Google8628_189397408\updater.7z
MD5:
SHA256:
7236updater.exeC:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\uninstall.cmdtext
MD5:FBC297EE9060D4256192E4EDB98CAD1B
SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044
7236updater.exeC:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exeexecutable
MD5:66359E7E445803478383F3D2D35E9C6B
SHA256:810E9879FDB18D0A5D68CD455B7187C62EB44FE585346A34F17B8802AD065482
4516updater.exeC:\Program Files (x86)\Google\Update\GoogleUpdate.exeexecutable
MD5:66359E7E445803478383F3D2D35E9C6B
SHA256:810E9879FDB18D0A5D68CD455B7187C62EB44FE585346A34F17B8802AD065482
4516updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.json~RF1b4ca5.TMPtext
MD5:B57AC171B12E62654277F590FCF46A5E
SHA256:C94CC50752A9C91738507A2D93627E8D8F771DB8DDF0E357674D3896AE98DE4E
4516updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsontext
MD5:D989EC067B890CC46AEF34C82714628F
SHA256:9B4BBD8028B1D3CFB76F0D3EF223FB4256ACADDD5A800E9E8792E5E087F8FB90
7236updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.json~RF1b4b6d.TMPtext
MD5:6A7C22B00ADBF302C1F53F51AF1AB2F6
SHA256:BFD4268EDA9AB3F0E8D8D2ED0884BD28C0B34546332B36E54EBD30ACF45053FF
5612updater.exeC:\Windows\SystemTemp\updater_chrome_url_fetcher_5612_718347643\fbe95ee4e2bb4e7aeb1cc3ba8e7fb4491fcb19d43bc916224724b732618941af
MD5:
SHA256:
4516updater.exeC:\Windows\SystemTemp\Google4516_1336483278\scoped_dir4516_468047949\GoogleUpdate.exeexecutable
MD5:FC6BEC2FD20110CF75394784819949D6
SHA256:323C097DEFB278F09A20AACA7B05AEA20A1C859414CCA9CAEA263FA5A627A1AE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
104
TCP/UDP connections
53
DNS requests
48
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7076
svchost.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
unknown
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
unknown
whitelisted
1348
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
whitelisted
1348
SIHClient.exe
GET
200
40.69.42.241:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
unknown
whitelisted
1348
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
unknown
whitelisted
1348
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
whitelisted
7236
updater.exe
GET
200
142.251.141.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
7236
updater.exe
GET
200
142.250.185.131:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
5612
updater.exe
GET
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/%7B8a69d345-d564-463c-aff1-a69d9e530f96%7D/fbe95ee4e2bb4e7aeb1cc3ba8e7fb4491fcb19d43bc916224724b732618941af
unknown
whitelisted
5612
updater.exe
POST
200
192.178.170.94:443
https://update.googleapis.com/service/update2/json?cup2key=15:221j-nzjecrYX_bDWzPESchBBBcyJm7cRG1xyoB8nOE&cup2hreq=5cd09545c9836054e617a3cb85002c510462f464e6379d20df0d89683d9c7818
unknown
text
128 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7076
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
4188
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5612
updater.exe
192.178.170.94:443
update.googleapis.com
GOOGLE
US
whitelisted
7236
updater.exe
172.217.208.136:443
dl.google.com
GOOGLE
US
whitelisted
7236
updater.exe
142.251.141.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
7236
updater.exe
142.250.185.131:80
c.pki.goog
GOOGLE
US
whitelisted
7236
updater.exe
142.250.187.227:80
o.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.174
whitelisted
update.googleapis.com
  • 192.178.170.94
whitelisted
dl.google.com
  • 172.217.208.136
  • 172.217.208.91
  • 172.217.208.93
  • 172.217.208.190
whitelisted
ocsp.pki.goog
  • 142.251.141.131
whitelisted
c.pki.goog
  • 142.250.185.131
whitelisted
o.pki.goog
  • 142.250.187.227
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.48.23.35
  • 23.48.23.11
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info