File name:

ChromeSetup.msi

Full analysis: https://app.any.run/tasks/255f94c0-6d14-43af-8bd1-e17d40f8b3cc
Verdict: Malicious activity
Analysis date: March 26, 2025, 11:02:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 14:06:51 2020, Security: 0, Code page: 1252, Revision Number: {36AF473F-86D2-45DF-825C-20CD202CA37B}, Number of Words: 2, Subject: Google chrome inc ., Author: Google chrome inc ., Name of Creating Application: Google chrome inc ., Template: ;1033, Comments: Google chrome inc ., Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
MD5:

8723362846A28C0E26722F5435C77275

SHA1:

43123208C662D2210A079FF66E13804852E7DEBD

SHA256:

BC7B93A41CDB7D5964C67BCEB989B90B1E9419051AF227946ADE1C9763B382B6

SSDEEP:

98304:t9IroVC6n2tN27teOIdvLuxhNKfgpmVqaUiCIzd0VdbW31obyim+AwbyRZYsVT0L:Fffj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a new scheduled task via Registry

      • msiexec.exe (PID: 7536)
  • SUSPICIOUS

    • Runs shell command (SCRIPT)

      • msiexec.exe (PID: 7536)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7172)
    • Application launched itself

      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • updater.exe (PID: 8172)
      • setup.exe (PID: 6736)
      • setup.exe (PID: 7916)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • 134.0.6998.177_chrome_installer.exe (PID: 7800)
      • setup.exe (PID: 7916)
    • Executes as Windows Service

      • updater.exe (PID: 7976)
      • updater.exe (PID: 8172)
    • Reads security settings of Internet Explorer

      • updater.exe (PID: 7780)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 7536)
      • msiexec.exe (PID: 7416)
      • msiexec.exe (PID: 7172)
      • updater.exe (PID: 7780)
      • ChromeStandaloneSetup64.exe (PID: 7680)
      • updater.exe (PID: 7976)
    • Reads Environment values

      • msiexec.exe (PID: 7416)
    • Checks supported languages

      • msiexec.exe (PID: 7172)
      • msiexec.exe (PID: 7536)
      • updater.exe (PID: 7780)
      • ChromeStandaloneSetup64.exe (PID: 7680)
      • msiexec.exe (PID: 7416)
      • updater.exe (PID: 7836)
      • updater.exe (PID: 8008)
      • updater.exe (PID: 7976)
      • updater.exe (PID: 8172)
      • updater.exe (PID: 7184)
      • setup.exe (PID: 7916)
    • The sample compiled with english language support

      • msiexec.exe (PID: 7172)
      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • 134.0.6998.177_chrome_installer.exe (PID: 7800)
      • setup.exe (PID: 7916)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7172)
    • Creates files in the program directory

      • updater.exe (PID: 7836)
      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • setup.exe (PID: 7916)
      • setup.exe (PID: 6736)
      • updater.exe (PID: 8172)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • updater.exe (PID: 8172)
    • Reads the software policy settings

      • updater.exe (PID: 7780)
      • updater.exe (PID: 8172)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 7780)
    • Creates files or folders in the user directory

      • updater.exe (PID: 7780)
    • Create files in a temporary directory

      • updater.exe (PID: 7780)
    • Application launched itself

      • chrome.exe (PID: 4068)
    • Executes as Windows Service

      • elevation_service.exe (PID: 6228)
    • Manual execution by a user

      • chrome.exe (PID: 4068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

LastPrinted: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
ModifyDate: 2020:09:18 14:06:51
Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {36AF473F-86D2-45DF-825C-20CD202CA37B}
Words: 2
Subject: Google chrome inc .
Author: Google chrome inc .
LastModifiedBy: -
Software: Google chrome inc .
Template: ;1033
Comments: Google chrome inc .
Title: Installation Database
Keywords: Installer, MSI, Database
Pages: 200
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
167
Monitored processes
33
Malicious processes
1
Suspicious processes
5

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe sppextcomobj.exe no specs slui.exe no specs msiexec.exe no specs msiexec.exe no specs chromestandalonesetup64.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs 134.0.6998.177_chrome_installer.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe elevation_service.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1012"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=134.0.6998.177 --initial-client-data=0x220,0x224,0x228,0x204,0x22c,0x7ffc89bd6f38,0x7ffc89bd6f44,0x7ffc89bd6f50C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1196"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --extension-process --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=4008 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2192"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=5276 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2316"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=3880 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2392"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=2264 /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3332"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=2416 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
4068"C:\Program Files\Google\Chrome\Application\chrome.exe" --from-installerC:\Program Files\Google\Chrome\Application\chrome.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4424"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\ChromeSetup.msiC:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4932"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=5008 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
5048C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping8172_182590635\CR_06E98.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=134.0.6998.177 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x7ff7b8d99ed8,0x7ff7b8d99ee4,0x7ff7b8d99ef0C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping8172_182590635\CR_06E98.tmp\setup.exesetup.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome Installer
Exit code:
0
Version:
134.0.6998.177
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping8172_182590635\cr_06e98.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
5 628
Read events
5 403
Write events
186
Delete events
39

Modification events

(PID) Process:(7172) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
041C0000B7F8E48D3E9EDB01
(PID) Process:(7172) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
B1BF01340D980E32C43470804215BF89E8E003B83E0AD4C84A6BA23C157515D0
(PID) Process:(7172) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10bbd2.rbs
Value:
31170110
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10bbd2.rbsLow
Value:
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\80E8286A7A3BB4C448C585D9BE61E866
Operation:writeName:45273ADE14505A44EB4EFE08A0DA5FAC
Value:
C:\Program Files (x86)\Google chrome inc\Google chrome inc\
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E29B4F000C3731C46AAD3E04C39B6581
Operation:writeName:45273ADE14505A44EB4EFE08A0DA5FAC
Value:
02:\Software\Google chrome inc .\Google chrome inc .\Version
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B999057A7B9B3434B83D138408D37DC3
Operation:writeName:45273ADE14505A44EB4EFE08A0DA5FAC
Value:
C:\ProgramData\dbg.xml
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48B36B066A69BB649B808B9D112D01B7
Operation:writeName:45273ADE14505A44EB4EFE08A0DA5FAC
Value:
C:\ProgramData\chrome\ChromeStandaloneSetup64.exe
Executable files
17
Suspicious files
87
Text files
66
Unknown types
0

Dropped files

PID
Process
Filename
Type
7172msiexec.exeC:\Windows\Installer\10bbd0.msi
MD5:
SHA256:
7172msiexec.exeC:\Windows\Temp\~DF4B5B937849B809E7.TMPbinary
MD5:58A3853728F6DDFCB02FCAB4B792C520
SHA256:825AF0E88D45D9A9596283E1840FBE0EE40A9AFF3D5A1DA1D88476336F37BF1B
7172msiexec.exeC:\Windows\Installer\MSIBF1C.tmpexecutable
MD5:DB7612F0FD6408D664185CFC81BEF0CB
SHA256:E9E426B679B3EFB233F03C696E997E2DA3402F16A321E954B54454317FCEB240
7172msiexec.exeC:\Windows\Installer\MSIC133.tmpbinary
MD5:D6131592E7808952B7F7EDA3E0572CDC
SHA256:A203D6776BF363BEC7265B2C7AE862DB9DE81C18CE09C772CA75E0C37E8790E9
7172msiexec.exeC:\ProgramData\chrome\chromeUpdate.exeexecutable
MD5:DFE963D2FFC2902C581415F09EE9D193
SHA256:B5E3867F07B3D6875AA58478BBF76CF5FB230D98E09C492E963EE5C767763B36
7172msiexec.exeC:\ProgramData\chrome\ChromeStandaloneSetup64.exeexecutable
MD5:591FF9E99B8C87C4AFC81DC4228A54B8
SHA256:452ABDADF089C516B886BEC835129C5608E25A23F62E06EFE76E3D2C732E682C
7680ChromeStandaloneSetup64.exeC:\Windows\SystemTemp\Google7680_1920479298\UPDATER.PACKED.7Z
MD5:
SHA256:
7172msiexec.exeC:\ProgramData\dbg.xmltext
MD5:A3560F857511F746012BB42383E45065
SHA256:6EE77FEFF37801AA14DE31FE5C9718F3087A8B86331FD5D0AC20D204E5835DB7
7172msiexec.exeC:\Config.Msi\10bbd2.rbsbinary
MD5:EEE59581CACCA290445C90276E9124CB
SHA256:F8CC040E90F8EB4173E6D2A932509B94EB4A3CC3F4DBCC6A962248DA2945F40E
7172msiexec.exeC:\Windows\Temp\~DFE902DA8109C7CB2E.TMPbinary
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
45
DNS requests
47
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7780
updater.exe
GET
200
142.250.186.131:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
7780
updater.exe
GET
200
142.250.186.131:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
2392
chrome.exe
GET
200
142.250.186.46:80
http://clients2.google.com/time/1/current?cup2key=8:QtNTDv1Qcu6hG6rVkaOcw2AqRmzCaDlsWCozgsk2D2M&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
4932
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7820
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7780
updater.exe
GET
200
172.217.23.99:80
http://o.pki.goog/we2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEG%2BorlfPZWf5CeqNw%2Flf3jE%3D
unknown
whitelisted
8172
updater.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/de7r3siglrwoazqwczzulwb4ue_134.0.6998.177/-8a69d345-d564-463c-aff1-a69d9e530f96-_134.0.6998.177_all_e5ixn7inobb6ees6v5znqf5x6u.crx3
unknown
whitelisted
4932
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.3
  • 20.190.160.5
  • 20.190.160.130
  • 20.190.160.128
  • 20.190.160.65
  • 40.126.32.76
  • 20.190.160.4
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
update.googleapis.com
  • 142.250.186.99
whitelisted
dl.google.com
  • 142.250.186.46
whitelisted
c.pki.goog
  • 142.250.186.131
whitelisted
o.pki.goog
  • 172.217.23.99
whitelisted

Threats

No threats detected
No debug info