| File name: | ChromeSetup.exe |
| Full analysis: | https://app.any.run/tasks/f3b830e8-ab40-42da-bc40-c5b3b082aa3f |
| Verdict: | Malicious activity |
| Analysis date: | September 03, 2024, 14:02:00 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BB25D4B8DB1B8FA058D6BAC6A20C541F |
| SHA1: | F5630DCFF48AB4DBDEB1673AF64591E96DEEEC01 |
| SHA256: | BA73BC4040AE29BC34F75E6529C5A66825BB9CBF8BD3ECC501AB82BCFEA559BE |
| SSDEEP: | 98304:BLEkbQIdDJR5kgCF7BWlL1OStuEKrfs65Q3HWg+4BKZBdXR5R+OwAHDExhfnsZH0:Bf |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:08:26 03:02:15+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 2866176 |
| InitializedDataSize: | 6031360 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x14f370 |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 130.0.6679.0 |
| ProductVersionNumber: | 130.0.6679.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Installer |
| FileVersion: | 130.0.6679.0 |
| InternalName: | Google Installer(x86) |
| LegalCopyright: | Copyright 2024 Google LLC. All rights reserved. |
| OriginalFileName: | UpdaterSetup.exe |
| ProductName: | Google Installer |
| ProductVersion: | 130.0.6679.0 |
| CompanyShortName: | |
| ProductShortName: | GoogleUpdater |
| LastChange: | 76ef045d11ea7b79d11f381d30e93459f1eb5017-refs/branch-heads/6679@{#1} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 644 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=516,i,11109068303403473296,9750516293475843019,262144 --variations-seed-version --mojo-platform-channel-handle=6064 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 128.0.6613.115 Modules
| |||||||||||||||
| 1288 | "C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=130.0.6679.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a4,0x2a8,0x2ac,0x280,0x2b0,0x4ca6cc,0x4ca6d8,0x4ca6e4 | C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Version: 130.0.6679.0 Modules
| |||||||||||||||
| 1432 | "C:\Users\admin\Desktop\ChromeSetup.exe" | C:\Users\admin\Desktop\ChromeSetup.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Installer Exit code: 0 Version: 130.0.6679.0 Modules
| |||||||||||||||
| 1480 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --field-trial-handle=4160,i,11109068303403473296,9750516293475843019,262144 --variations-seed-version --mojo-platform-channel-handle=5852 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 128.0.6613.115 Modules
| |||||||||||||||
| 1692 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --field-trial-handle=6076,i,11109068303403473296,9750516293475843019,262144 --variations-seed-version --mojo-platform-channel-handle=6180 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 128.0.6613.115 Modules
| |||||||||||||||
| 1776 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=6156,i,11109068303403473296,9750516293475843019,262144 --variations-seed-version --mojo-platform-channel-handle=5964 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 128.0.6613.115 Modules
| |||||||||||||||
| 1992 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=4976,i,11109068303403473296,9750516293475843019,262144 --variations-seed-version --mojo-platform-channel-handle=5420 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 128.0.6613.115 Modules
| |||||||||||||||
| 2056 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --field-trial-handle=1260,i,11109068303403473296,9750516293475843019,262144 --variations-seed-version --mojo-platform-channel-handle=6096 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 128.0.6613.115 Modules
| |||||||||||||||
| 2096 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=4528,i,11109068303403473296,9750516293475843019,262144 --variations-seed-version --mojo-platform-channel-handle=4548 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 128.0.6613.115 Modules
| |||||||||||||||
| 2488 | "C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=130.0.6679.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x4ca6cc,0x4ca6d8,0x4ca6e4 | C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Exit code: 0 Version: 130.0.6679.0 Modules
| |||||||||||||||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 130.0.6679.0 | |||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 130.0.6679.0 | |||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{53A53FE9-0D1A-5CE1-A982-92ECA1CB48BC} |
| Operation: | write | Name: | AppID |
Value: {53A53FE9-0D1A-5CE1-A982-92ECA1CB48BC} | |||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{53A53FE9-0D1A-5CE1-A982-92ECA1CB48BC} |
| Operation: | write | Name: | LocalService |
Value: GoogleUpdaterInternalService130.0.6679.0 | |||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{53A53FE9-0D1A-5CE1-A982-92ECA1CB48BC} |
| Operation: | write | Name: | ServiceParameters |
Value: --com-service | |||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{DC738913-8AA7-5CF3-912D-45FB81D79BCB}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DC738913-8AA7-5CF3-912D-45FB81D79BCB}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (5712) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{0125FBD6-CB11-5A7E-828A-0845F90C7D4E}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4680 | ChromeSetup.exe | C:\Windows\SystemTemp\Google4680_1238679821\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 5712 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\updater.log | text | |
MD5:6E92A323B2004518C65969B958541D13 | SHA256:CB5B8C85AFFAD75699621D8E3BB1E8CBECE25C5B6E78537FF69AAF5EF20226D8 | |||
| 5544 | updater.exe | C:\Program Files (x86)\Google\Update\GoogleUpdate.exe | executable | |
MD5:C583E91DDEE7C0E8AC2A3D3AACAD2F4C | SHA256:7F67129760223E5DDF31219F0B2E247555FBAC85F4B6F933212AC091A21DEBF9 | |||
| 5544 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json~RF12c06a.TMP | binary | |
MD5:C88C3AD52765A523B2B598BF2C5A9216 | SHA256:E450A8D057F11BB4CD98343448B3FD8A70B0F22BD7EB6B84B6FB03731B36FC32 | |||
| 5712 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 | binary | |
MD5:7ACD8FD4111978BBA5D2997C9E0F586A | SHA256:3537FE01D73C4C520509F57314B7F4558EA4248292738A05172DE2F77B4FAFB9 | |||
| 5712 | updater.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:533BDC9D79874762A3E527BA1DA83094 | SHA256:BF5ED9BED9520F785172018EF5EA3E18032A7287845D7800C60C2B4649708E06 | |||
| 6000 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_6000_186816027\-8a69d345-d564-463c-aff1-a69d9e530f96-_128.0.6613.115_all_pt6smlfg653fr4yqdqg3gcegjm.crx3 | — | |
MD5:— | SHA256:— | |||
| 6000 | updater.exe | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6000_1166583357\128.0.6613.115_chrome_installer.exe | — | |
MD5:— | SHA256:— | |||
| 5712 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json | binary | |
MD5:C88C3AD52765A523B2B598BF2C5A9216 | SHA256:E450A8D057F11BB4CD98343448B3FD8A70B0F22BD7EB6B84B6FB03731B36FC32 | |||
| 5544 | updater.exe | C:\Windows\SystemTemp\Google5544_716794807\scoped_dir5544_1007455230\GoogleUpdate.exe | executable | |
MD5:3AA2C853D6BC7AF7F2F9B8A934943EFD | SHA256:07034876B9EC0B59432B96FEDB7E10E332440159F9802FAAD5F5B99F01885F6B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5712 | updater.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | whitelisted |
5712 | updater.exe | GET | 200 | 142.250.184.195:80 | http://c.pki.goog/r/r1.crl | unknown | — | — | whitelisted |
5712 | updater.exe | GET | 200 | 216.58.212.163:80 | http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEEY%2BBbWicZDJCutGRyts3so%3D | unknown | — | — | whitelisted |
6000 | updater.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/nrcaklfaohcm42vpue4tht2c3a_128.0.6613.115/-8a69d345-d564-463c-aff1-a69d9e530f96-_128.0.6613.115_all_pt6smlfg653fr4yqdqg3gcegjm.crx3 | unknown | — | — | whitelisted |
6120 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6976 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6976 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5796 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ads5b47vmt6o3yjujrzhvuykaybq_2024.8.23.0/niikhdgajlphfehepabhhblakbdgeefj_2024.08.23.00_all_ads63hkk2t6wtnkmfb6te6wtc4ha.crx3 | unknown | — | — | whitelisted |
2136 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5796 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ads5b47vmt6o3yjujrzhvuykaybq_2024.8.23.0/niikhdgajlphfehepabhhblakbdgeefj_2024.08.23.00_all_ads63hkk2t6wtnkmfb6te6wtc4ha.crx3 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 52.183.220.149:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6652 | svchost.exe | 52.183.220.149:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6404 | RUXIMICS.exe | 52.183.220.149:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6000 | updater.exe | 142.250.185.163:443 | update.googleapis.com | GOOGLE | US | whitelisted |
5712 | updater.exe | 142.250.185.110:443 | dl.google.com | GOOGLE | US | whitelisted |
5712 | updater.exe | 172.217.16.131:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
5712 | updater.exe | 142.250.184.195:80 | c.pki.goog | GOOGLE | US | whitelisted |
5712 | updater.exe | 216.58.212.163:80 | o.pki.goog | GOOGLE | US | whitelisted |
6000 | updater.exe | 34.104.35.123:80 | edgedl.me.gvt1.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |
edgedl.me.gvt1.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |