File name:

GoogleAdsEditorSetup.exe.7z

Full analysis: https://app.any.run/tasks/f9a1bab0-0c46-4341-95f5-8f49417f9633
Verdict: Malicious activity
Analysis date: August 05, 2025, 06:25:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

668E7551D2D69D7BE680ADC039CB69A1

SHA1:

A9045F83AD795101AFC072593F590FD75AA225E8

SHA256:

BAE4ED1A42B9CF6278FD3AFCAF349156ADBD42156999F1001BB3674B4F014AEA

SSDEEP:

98304:QD48g8uXUTNWdGt3XGLi7MET7PbqNJcrdoD2ZuKposQ7wJl7F/ue28pYrjNSgnIW:3qHOGz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 512)
    • Changes the autorun value in the registry

      • updater.exe (PID: 3504)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 512)
      • updater.exe (PID: 3504)
    • Application launched itself

      • updater.exe (PID: 3504)
      • updater.exe (PID: 4072)
      • updater.exe (PID: 1160)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 4072)
      • updater.exe (PID: 3504)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 3572)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 3572)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 3572)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 512)
      • updater.exe (PID: 4072)
      • updater.exe (PID: 3504)
      • msiexec.exe (PID: 3572)
      • firefox.exe (PID: 5712)
    • Reads the computer name

      • GoogleAdsEditorSetup.exe (PID: 3948)
      • updater.exe (PID: 3504)
      • updater.exe (PID: 1160)
      • updater.exe (PID: 4072)
      • msiexec.exe (PID: 3572)
    • Checks supported languages

      • GoogleAdsEditorSetup.exe (PID: 3948)
      • updater.exe (PID: 3504)
      • updater.exe (PID: 3980)
      • updater.exe (PID: 1204)
      • updater.exe (PID: 1160)
      • updater.exe (PID: 4072)
      • msiexec.exe (PID: 3572)
      • updater.exe (PID: 440)
    • Create files in a temporary directory

      • GoogleAdsEditorSetup.exe (PID: 3948)
      • msiexec.exe (PID: 6876)
      • updater.exe (PID: 1160)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 512)
      • msiexec.exe (PID: 3572)
      • firefox.exe (PID: 5712)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 3504)
      • updater.exe (PID: 4072)
      • updater.exe (PID: 1160)
    • Creates files or folders in the user directory

      • updater.exe (PID: 3980)
      • updater.exe (PID: 4072)
      • updater.exe (PID: 3504)
      • updater.exe (PID: 1160)
      • msiexec.exe (PID: 3572)
    • Launching a file from a Registry key

      • updater.exe (PID: 3504)
    • Checks proxy server information

      • updater.exe (PID: 3504)
      • updater.exe (PID: 1160)
      • slui.exe (PID: 4196)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 3504)
      • msiexec.exe (PID: 3572)
    • Reads the software policy settings

      • msiexec.exe (PID: 3572)
      • updater.exe (PID: 1160)
      • updater.exe (PID: 3504)
      • slui.exe (PID: 4196)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3572)
    • Manual execution by a user

      • firefox.exe (PID: 6488)
    • Application launched itself

      • firefox.exe (PID: 6488)
      • firefox.exe (PID: 5712)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 5712)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2025:08:04 22:06:56+00:00
ArchivedFileName: GoogleAdsEditorSetup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
33
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe googleadseditorsetup.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs msiexec.exe no specs msiexec.exe slui.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
440C:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\updater.exe --crash-handler --database=C:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\Crashpad --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=140.0.7273.0 --attachment=C:\Users\admin\AppData\Local\Google\GoogleUpdater\updater.log --initial-client-data=0x2ac,0x2b0,0x2b4,0x288,0x2b8,0xaa31a8,0xaa31b4,0xaa31c0C:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\updater.exeupdater.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Updater (x86)
Version:
140.0.7273.0
Modules
Images
c:\users\admin\appdata\local\google\googleupdater\140.0.7273.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
512"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\GoogleAdsEditorSetup.exe.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1160"C:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\updater.exe" --server --service=update -EmbeddingC:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\updater.exe
svchost.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Updater (x86)
Version:
140.0.7273.0
Modules
Images
c:\users\admin\appdata\local\google\googleupdater\140.0.7273.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1204C:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\updater.exe --crash-handler --database=C:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\Crashpad --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=140.0.7273.0 --attachment=C:\Users\admin\AppData\Local\Google\GoogleUpdater\updater.log --initial-client-data=0x2a4,0x2a8,0x2ac,0x280,0x2b0,0xaa31a8,0xaa31b4,0xaa31c0C:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\updater.exeupdater.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Updater (x86)
Exit code:
0
Version:
140.0.7273.0
Modules
Images
c:\users\admin\appdata\local\google\googleupdater\140.0.7273.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1232"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3236 -prefsLen 39478 -prefMapHandle 5644 -prefMapSize 272997 -jsInitHandle 2716 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6052 -initialChannelId {1656ce3e-87db-4c00-89ad-bbbc7e607fd0} -parentPid 5712 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5712" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 12 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
1392"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4216 -prefsLen 44823 -prefMapHandle 4220 -prefMapSize 272997 -jsInitHandle 4224 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4232 -initialChannelId {7ea1f1d6-ccc7-42b8-8643-2209b217de81} -parentPid 5712 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5712" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
2320"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3404 -prefsLen 36996 -prefMapHandle 3408 -prefMapSize 272997 -ipcHandle 3428 -initialChannelId {43543578-6f68-4530-be67-d1ca90d6b6f5} -parentPid 5712 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5712" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2536"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3316 -prefsLen 36996 -prefMapHandle 3320 -prefMapSize 272997 -jsInitHandle 3324 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3332 -initialChannelId {82f08568-cfb3-4c33-8d06-d8de377055ca} -parentPid 5712 -crashReporter "\\.\pipe\gecko-crash-server-pipe.5712" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
3504"C:\Users\admin\AppData\Local\Temp\Google3948_1745889572\bin\updater.exe" --install=appguid={F7A0263C-9459-4A49-BDD5-AA35E1C35151}&iid={7292D602-56AE-0D13-6409-1178A5B7DDCE}&lang=en&browser=4&usagestats=0&appname=Google%20Ads%20Editor&needsadmin=False --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2C:\Users\admin\AppData\Local\Temp\Google3948_1745889572\bin\updater.exe
GoogleAdsEditorSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Updater (x86)
Version:
140.0.7273.0
Modules
Images
c:\users\admin\appdata\local\temp\google3948_1745889572\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3572C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
60 411
Read events
59 398
Write events
985
Delete events
28

Modification events

(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\GoogleAdsEditorSetup.exe.7z
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(4072) updater.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{D866C8ED-7F89-4A87-9760-CF24C770A667}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
93
Suspicious files
361
Text files
237
Unknown types
19

Dropped files

PID
Process
Filename
Type
3948GoogleAdsEditorSetup.exeC:\Users\admin\AppData\Local\Temp\Google3948_461004208\UPDATER.PACKED.7Z
MD5:
SHA256:
3504updater.exeC:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\updater.exeexecutable
MD5:D3E6B13F2D2A1CC59B9F603170EB678C
SHA256:4126BD01B54957203057F31E34FC19FB9486519AF65D05AD6A1DCEB23D2DDC9D
3504updater.exeC:\Users\admin\AppData\Local\Google\GoogleUpdater\updater.logtext
MD5:5CD6F5678232042D31F2528E3FEC75CB
SHA256:44F3D58D6421CABBB716B3A809817B60B92F04556593589FDEAC90EEA0C8587E
3504updater.exeC:\Users\admin\AppData\Local\Google\GoogleUpdater\ee7a2b75-5b9a-44d9-9b53-fc8c2f172994.tmpbinary
MD5:5CB858C993079CA7AADBC3F738BE4C88
SHA256:1B0576F3EB030B3CACF3FA8EC8CE8CCC7F7902B091DAFE8714BCDC3EB8B54F7D
4072updater.exeC:\Users\admin\AppData\Local\Google\GoogleUpdater\140.0.7273.0\80db466e-d166-4bd6-8ad1-afb1248e6916.tmpbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
1160updater.exeC:\Users\admin\AppData\Local\Temp\chrome_url_fetcher_1160_171643178\-f7a0263c-9459-4a49-bdd5-aa35e1c35151-_14.9.5.0_all_jupleef5r4grnlxrjxievtkbvy.crx3
MD5:
SHA256:
1160updater.exeC:\Users\admin\AppData\Local\Google\GoogleUpdater\crx_cache\34a56e47e4c17080a2e6c6456af3fb31283fbe668b080073c46507e84238de57
MD5:
SHA256:
1160updater.exeC:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1160_168304746\google_ads_editor.msi
MD5:
SHA256:
4072updater.exeC:\Users\admin\AppData\Local\Google\GoogleUpdater\prefs.json~RF18f160.TMPbinary
MD5:5CB858C993079CA7AADBC3F738BE4C88
SHA256:1B0576F3EB030B3CACF3FA8EC8CE8CCC7F7902B091DAFE8714BCDC3EB8B54F7D
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb512.46965\GoogleAdsEditorSetup.exeexecutable
MD5:2C4A7F3A7A81E465D8E352B1922813B0
SHA256:06CA173FF8C8277F400362BF1E59E3EDBE0AA5F6C106DD3A504909C4DE8438E0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
61
TCP/UDP connections
134
DNS requests
180
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1864
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1160
updater.exe
GET
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/misc/ac66znd66pamizjkry3r22qel4oa_14.9.5.0/-f7a0263c-9459-4a49-bdd5-aa35e1c35151-_14.9.5.0_all_jupleef5r4grnlxrjxievtkbvy.crx3
unknown
whitelisted
GET
200
216.58.206.67:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
3504
updater.exe
GET
200
216.58.206.67:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
3504
updater.exe
GET
200
172.217.18.3:80
http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDPZmByDOs98xJONhjjIZaE
unknown
whitelisted
1268
svchost.exe
GET
200
23.216.77.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4160
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4160
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3572
msiexec.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4460
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1864
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1864
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1160
updater.exe
142.250.184.227:443
update.googleapis.com
GOOGLE
US
whitelisted
3504
updater.exe
172.217.18.14:443
dl.google.com
GOOGLE
US
whitelisted
1160
updater.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.184.206
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.130
  • 40.126.31.1
  • 20.190.159.4
  • 40.126.31.67
  • 40.126.31.73
  • 20.190.159.2
  • 40.126.31.3
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
update.googleapis.com
  • 142.250.184.227
whitelisted
dl.google.com
  • 172.217.18.14
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
  • 2600:1900:4110:86f::
whitelisted
c.pki.goog
  • 216.58.206.67
whitelisted
o.pki.goog
  • 172.217.18.3
whitelisted
crl.microsoft.com
  • 23.216.77.8
  • 23.216.77.28
  • 23.216.77.6
  • 23.216.77.20
  • 23.216.77.25
  • 23.216.77.42
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info