File name:

ChromeSetup.msi

Full analysis: https://app.any.run/tasks/255f94c0-6d14-43af-8bd1-e17d40f8b3cc
Verdict: Malicious activity
Analysis date: March 26, 2025, 11:02:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 14:06:51 2020, Security: 0, Code page: 1252, Revision Number: {36AF473F-86D2-45DF-825C-20CD202CA37B}, Number of Words: 2, Subject: Google chrome inc ., Author: Google chrome inc ., Name of Creating Application: Google chrome inc ., Template: ;1033, Comments: Google chrome inc ., Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
MD5:

8723362846A28C0E26722F5435C77275

SHA1:

43123208C662D2210A079FF66E13804852E7DEBD

SHA256:

BC7B93A41CDB7D5964C67BCEB989B90B1E9419051AF227946ADE1C9763B382B6

SSDEEP:

98304:t9IroVC6n2tN27teOIdvLuxhNKfgpmVqaUiCIzd0VdbW31obyim+AwbyRZYsVT0L:Fffj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a new scheduled task via Registry

      • msiexec.exe (PID: 7536)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7172)
    • Application launched itself

      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • updater.exe (PID: 8172)
      • setup.exe (PID: 7916)
      • setup.exe (PID: 6736)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • setup.exe (PID: 7916)
      • 134.0.6998.177_chrome_installer.exe (PID: 7800)
    • Executes as Windows Service

      • updater.exe (PID: 7976)
      • updater.exe (PID: 8172)
    • Reads security settings of Internet Explorer

      • updater.exe (PID: 7780)
    • Runs shell command (SCRIPT)

      • msiexec.exe (PID: 7536)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 7416)
      • updater.exe (PID: 7836)
      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • updater.exe (PID: 8172)
      • updater.exe (PID: 8008)
      • setup.exe (PID: 7916)
      • updater.exe (PID: 7184)
      • msiexec.exe (PID: 7172)
      • msiexec.exe (PID: 7536)
      • ChromeStandaloneSetup64.exe (PID: 7680)
    • Reads the computer name

      • msiexec.exe (PID: 7172)
      • ChromeStandaloneSetup64.exe (PID: 7680)
      • updater.exe (PID: 7780)
      • msiexec.exe (PID: 7416)
      • updater.exe (PID: 7976)
      • msiexec.exe (PID: 7536)
    • Creates files in the program directory

      • updater.exe (PID: 7836)
      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • updater.exe (PID: 8172)
      • setup.exe (PID: 7916)
      • setup.exe (PID: 6736)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • updater.exe (PID: 8172)
    • Reads Environment values

      • msiexec.exe (PID: 7416)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7172)
    • The sample compiled with english language support

      • msiexec.exe (PID: 7172)
      • updater.exe (PID: 7780)
      • updater.exe (PID: 7976)
      • setup.exe (PID: 7916)
      • 134.0.6998.177_chrome_installer.exe (PID: 7800)
    • Reads the software policy settings

      • updater.exe (PID: 7780)
      • updater.exe (PID: 8172)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 7780)
    • Creates files or folders in the user directory

      • updater.exe (PID: 7780)
    • Create files in a temporary directory

      • updater.exe (PID: 7780)
    • Manual execution by a user

      • chrome.exe (PID: 4068)
    • Application launched itself

      • chrome.exe (PID: 4068)
    • Executes as Windows Service

      • elevation_service.exe (PID: 6228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

LastPrinted: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
ModifyDate: 2020:09:18 14:06:51
Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {36AF473F-86D2-45DF-825C-20CD202CA37B}
Words: 2
Subject: Google chrome inc .
Author: Google chrome inc .
LastModifiedBy: -
Software: Google chrome inc .
Template: ;1033
Comments: Google chrome inc .
Title: Installation Database
Keywords: Installer, MSI, Database
Pages: 200
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
167
Monitored processes
33
Malicious processes
1
Suspicious processes
5

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe sppextcomobj.exe no specs slui.exe no specs msiexec.exe no specs msiexec.exe no specs chromestandalonesetup64.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs 134.0.6998.177_chrome_installer.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe elevation_service.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1012"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=134.0.6998.177 --initial-client-data=0x220,0x224,0x228,0x204,0x22c,0x7ffc89bd6f38,0x7ffc89bd6f44,0x7ffc89bd6f50C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1196"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --extension-process --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=4008 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2192"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=5276 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2316"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=3880 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2392"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=2264 /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3332"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=2416 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
4068"C:\Program Files\Google\Chrome\Application\chrome.exe" --from-installerC:\Program Files\Google\Chrome\Application\chrome.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4424"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\ChromeSetup.msiC:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4932"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --field-trial-handle=1948,i,5441395548799820473,9991163454187488809,262144 --variations-seed-version --mojo-platform-channel-handle=5008 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
134.0.6998.177
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\134.0.6998.177\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
5048C:\WINDOWS\SystemTemp\chrome_Unpacker_BeginUnzipping8172_182590635\CR_06E98.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=134.0.6998.177 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x7ff7b8d99ed8,0x7ff7b8d99ee4,0x7ff7b8d99ef0C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping8172_182590635\CR_06E98.tmp\setup.exesetup.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Chrome Installer
Exit code:
0
Version:
134.0.6998.177
Modules
Images
c:\windows\systemtemp\chrome_unpacker_beginunzipping8172_182590635\cr_06e98.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
5 628
Read events
5 403
Write events
186
Delete events
39

Modification events

(PID) Process:(7172) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
041C0000B7F8E48D3E9EDB01
(PID) Process:(7172) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
B1BF01340D980E32C43470804215BF89E8E003B83E0AD4C84A6BA23C157515D0
(PID) Process:(7172) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10bbd2.rbs
Value:
31170110
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10bbd2.rbsLow
Value:
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\80E8286A7A3BB4C448C585D9BE61E866
Operation:writeName:45273ADE14505A44EB4EFE08A0DA5FAC
Value:
C:\Program Files (x86)\Google chrome inc\Google chrome inc\
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E29B4F000C3731C46AAD3E04C39B6581
Operation:writeName:45273ADE14505A44EB4EFE08A0DA5FAC
Value:
02:\Software\Google chrome inc .\Google chrome inc .\Version
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B999057A7B9B3434B83D138408D37DC3
Operation:writeName:45273ADE14505A44EB4EFE08A0DA5FAC
Value:
C:\ProgramData\dbg.xml
(PID) Process:(7172) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48B36B066A69BB649B808B9D112D01B7
Operation:writeName:45273ADE14505A44EB4EFE08A0DA5FAC
Value:
C:\ProgramData\chrome\ChromeStandaloneSetup64.exe
Executable files
17
Suspicious files
87
Text files
66
Unknown types
0

Dropped files

PID
Process
Filename
Type
7172msiexec.exeC:\Windows\Installer\10bbd0.msi
MD5:
SHA256:
7172msiexec.exeC:\Windows\Installer\MSIBFF7.tmpexecutable
MD5:DB7612F0FD6408D664185CFC81BEF0CB
SHA256:E9E426B679B3EFB233F03C696E997E2DA3402F16A321E954B54454317FCEB240
7172msiexec.exeC:\Windows\Installer\MSIBF1C.tmpexecutable
MD5:DB7612F0FD6408D664185CFC81BEF0CB
SHA256:E9E426B679B3EFB233F03C696E997E2DA3402F16A321E954B54454317FCEB240
7172msiexec.exeC:\Windows\Installer\MSIC096.tmpexecutable
MD5:DB7612F0FD6408D664185CFC81BEF0CB
SHA256:E9E426B679B3EFB233F03C696E997E2DA3402F16A321E954B54454317FCEB240
7172msiexec.exeC:\Windows\Installer\MSIC143.tmpexecutable
MD5:B99996D89E20A4D894BC829C661C3B98
SHA256:B724C91B7E4674BBB2063315C9F6E461AB4D2AA8E1E5DFC3E8B609E58E77DD39
7172msiexec.exeC:\Windows\Temp\~DFADE3D65DDAAFB8E3.TMPbinary
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
7680ChromeStandaloneSetup64.exeC:\Windows\SystemTemp\Google7680_1920479298\UPDATER.PACKED.7Z
MD5:
SHA256:
7172msiexec.exeC:\Windows\Temp\~DF4B5B937849B809E7.TMPbinary
MD5:58A3853728F6DDFCB02FCAB4B792C520
SHA256:825AF0E88D45D9A9596283E1840FBE0EE40A9AFF3D5A1DA1D88476336F37BF1B
7172msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:58A3853728F6DDFCB02FCAB4B792C520
SHA256:825AF0E88D45D9A9596283E1840FBE0EE40A9AFF3D5A1DA1D88476336F37BF1B
7172msiexec.exeC:\Windows\Installer\MSIC1C1.tmpexecutable
MD5:B99996D89E20A4D894BC829C661C3B98
SHA256:B724C91B7E4674BBB2063315C9F6E461AB4D2AA8E1E5DFC3E8B609E58E77DD39
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
45
DNS requests
47
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7780
updater.exe
GET
200
142.250.186.131:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
7780
updater.exe
GET
200
142.250.186.131:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
7780
updater.exe
GET
200
172.217.23.99:80
http://o.pki.goog/we2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEG%2BorlfPZWf5CeqNw%2Flf3jE%3D
unknown
whitelisted
8172
updater.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome/de7r3siglrwoazqwczzulwb4ue_134.0.6998.177/-8a69d345-d564-463c-aff1-a69d9e530f96-_134.0.6998.177_all_e5ixn7inobb6ees6v5znqf5x6u.crx3
unknown
whitelisted
7820
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4932
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2392
chrome.exe
GET
200
142.250.186.46:80
http://clients2.google.com/time/1/current?cup2key=8:QtNTDv1Qcu6hG6rVkaOcw2AqRmzCaDlsWCozgsk2D2M&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
4932
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.3
  • 20.190.160.5
  • 20.190.160.130
  • 20.190.160.128
  • 20.190.160.65
  • 40.126.32.76
  • 20.190.160.4
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
update.googleapis.com
  • 142.250.186.99
whitelisted
dl.google.com
  • 142.250.186.46
whitelisted
c.pki.goog
  • 142.250.186.131
whitelisted
o.pki.goog
  • 172.217.23.99
whitelisted

Threats

No threats detected
No debug info