File name:

Install-GooglePlayGames-DeveloperEmulator-Stable.exe

Full analysis: https://app.any.run/tasks/e3e9cfd1-122e-4b45-8a36-4834dcc0bc65
Verdict: Malicious activity
Analysis date: August 19, 2024, 19:00:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

66DB6C8C57D54F33630EA2866ABCD430

SHA1:

749AC58316CACC79909C4D2BE62B3BA9A3769164

SHA256:

CE168A1A230E0FD4CD9C17EA1652C435DB861C3EFE4D550D7FBCBCE47283CB05

SSDEEP:

98304:Ufz4nHZjHlbPuXhJ0PRTL8LjN3RQHfj1mw1Y8oJy+gcBML9rW86oldXEBaB4E1sB:B0xh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • updater.exe (PID: 6692)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Install-GooglePlayGames-DeveloperEmulator-Stable.exe (PID: 6596)
      • updater.exe (PID: 6692)
    • Reads the date of Windows installation

      • Install-GooglePlayGames-DeveloperEmulator-Stable.exe (PID: 6596)
    • Application launched itself

      • Install-GooglePlayGames-DeveloperEmulator-Stable.exe (PID: 6596)
      • updater.exe (PID: 6692)
      • updater.exe (PID: 6784)
      • updater.exe (PID: 6948)
    • Drops the executable file immediately after the start

      • Install-GooglePlayGames-DeveloperEmulator-Stable.exe (PID: 6596)
      • updater.exe (PID: 6784)
      • updater.exe (PID: 6692)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 6692)
      • updater.exe (PID: 6784)
    • Executes as Windows Service

      • updater.exe (PID: 6784)
      • updater.exe (PID: 6948)
    • Checks Windows Trust Settings

      • updater.exe (PID: 6692)
  • INFO

    • Reads the computer name

      • Install-GooglePlayGames-DeveloperEmulator-Stable.exe (PID: 6596)
      • updater.exe (PID: 6692)
      • updater.exe (PID: 6784)
      • updater.exe (PID: 6948)
    • Process checks computer location settings

      • Install-GooglePlayGames-DeveloperEmulator-Stable.exe (PID: 6596)
    • Checks supported languages

      • Install-GooglePlayGames-DeveloperEmulator-Stable.exe (PID: 6596)
      • Install-GooglePlayGames-DeveloperEmulator-Stable.exe (PID: 6668)
      • updater.exe (PID: 6692)
      • updater.exe (PID: 6804)
      • updater.exe (PID: 6712)
      • updater.exe (PID: 6784)
      • updater.exe (PID: 6948)
      • updater.exe (PID: 6968)
    • Creates files in the program directory

      • Install-GooglePlayGames-DeveloperEmulator-Stable.exe (PID: 6668)
      • updater.exe (PID: 6692)
      • updater.exe (PID: 6784)
      • updater.exe (PID: 6712)
      • updater.exe (PID: 6948)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 6784)
      • updater.exe (PID: 6692)
      • updater.exe (PID: 6948)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 6948)
      • updater.exe (PID: 6692)
    • Checks proxy server information

      • updater.exe (PID: 6692)
    • Reads the software policy settings

      • updater.exe (PID: 6948)
      • updater.exe (PID: 6692)
    • Creates files or folders in the user directory

      • updater.exe (PID: 6692)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:11 15:02:23+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2877440
InitializedDataSize: 6053376
UninitializedDataSize: -
EntryPoint: 0x1511f0
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 129.0.6651.0
ProductVersionNumber: 129.0.6651.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Chrome Installer
FileVersion: 129.0.6651.0
InternalName: Google Chrome
LegalCopyright: Copyright 2024 Google LLC. All rights reserved.
ProductName: Google Chrome Installer
ProductVersion: 129.0.6651.0
CompanyShortName: Google
ProductShortName: Chrome Installer
LastChange: 1fee8392336d433471a03f97efee1a8eded6ccce-refs/branch-heads/6651@{#1}
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
8
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start install-googleplaygames-developeremulator-stable.exe no specs install-googleplaygames-developeremulator-stable.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6596"C:\Users\admin\AppData\Local\Temp\Install-GooglePlayGames-DeveloperEmulator-Stable.exe" C:\Users\admin\AppData\Local\Temp\Install-GooglePlayGames-DeveloperEmulator-Stable.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome Installer
Version:
129.0.6651.0
Modules
Images
c:\users\admin\appdata\local\temp\install-googleplaygames-developeremulator-stable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6668"C:\Users\admin\AppData\Local\Temp\Install-GooglePlayGames-DeveloperEmulator-Stable.exe" --install=appguid={C601E9A4-03B0-4188-843E-80058BF16EF9}&appname=GPG_Developer_Emulator_Stable&needsadmin=true&ap=prod --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Local\Temp\Install-GooglePlayGames-DeveloperEmulator-Stable.exe
Install-GooglePlayGames-DeveloperEmulator-Stable.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Version:
129.0.6651.0
Modules
Images
c:\users\admin\appdata\local\temp\install-googleplaygames-developeremulator-stable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6692"C:\WINDOWS\SystemTemp\Google6668_352418530\bin\updater.exe" --install=appguid={C601E9A4-03B0-4188-843E-80058BF16EF9}&appname=GPG_Developer_Emulator_Stable&needsadmin=true&ap=prod --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Windows\SystemTemp\Google6668_352418530\bin\updater.exe
Install-GooglePlayGames-DeveloperEmulator-Stable.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
GoogleUpdater (x86)
Version:
129.0.6651.0
Modules
Images
c:\windows\systemtemp\google6668_352418530\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6712C:\WINDOWS\SystemTemp\Google6668_352418530\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=129.0.6651.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2ac,0x2b0,0x2b4,0x288,0x2b8,0x11a06cc,0x11a06d8,0x11a06e4C:\Windows\SystemTemp\Google6668_352418530\bin\updater.exeupdater.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
GoogleUpdater (x86)
Version:
129.0.6651.0
Modules
Images
c:\windows\systemtemp\google6668_352418530\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6784"C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe" --system --windows-service --service=update-internalC:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
129.0.6651.0
Modules
Images
c:\program files (x86)\google\googleupdater\129.0.6651.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
6804"C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=129.0.6651.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x10a06cc,0x10a06d8,0x10a06e4C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Exit code:
0
Version:
129.0.6651.0
Modules
Images
c:\program files (x86)\google\googleupdater\129.0.6651.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
6948"C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe" --system --windows-service --service=updateC:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Version:
129.0.6651.0
Modules
Images
c:\program files (x86)\google\googleupdater\129.0.6651.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
6968"C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=129.0.6651.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2b4,0x2b8,0x2bc,0x290,0x2c0,0x10a06cc,0x10a06d8,0x10a06e4C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
GoogleUpdater (x86)
Version:
129.0.6651.0
Modules
Images
c:\program files (x86)\google\googleupdater\129.0.6651.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
Total events
5 829
Read events
5 686
Write events
115
Delete events
28

Modification events

(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
129.0.6651.0
(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:pv
Value:
129.0.6651.0
(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab}
Operation:writeName:name
Value:
GoogleUpdater
(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
Operation:writeName:AppID
Value:
{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
Operation:writeName:LocalService
Value:
GoogleUpdaterInternalService129.0.6651.0
(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0E1D851D-4EAD-526F-B7CE-FCA5EC14314E}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{D4757239-55B2-5C3D-8B06-DDE147267C2D}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4757239-55B2-5C3D-8B06-DDE147267C2D}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6692) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{119413E1-D553-5881-9669-43EB131F5143}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
3
Suspicious files
16
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
6668Install-GooglePlayGames-DeveloperEmulator-Stable.exeC:\Windows\SystemTemp\Google6668_539561635\UPDATER.PACKED.7Z
MD5:
SHA256:
6784updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:A34CBF631EA340337064CBF943E0E4D3
SHA256:80D486340B6C4A49FB28BAED7D35A0973DBE100D2DB8CD01785CF13C5D9471BA
6784updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.json~RF12020b.TMPbinary
MD5:AECBD8FE3F7B64DDF70A33B920FD4BB4
SHA256:8BB68574186A8C571E687AF459DC5917A5FE2FB8EAD1048E6286E74A87AD06A3
6784updater.exeC:\Program Files (x86)\Google\GoogleUpdater\21f4537f-fde1-41d9-aad2-47e96aa14cdc.tmpbinary
MD5:A34CBF631EA340337064CBF943E0E4D3
SHA256:80D486340B6C4A49FB28BAED7D35A0973DBE100D2DB8CD01785CF13C5D9471BA
6784updater.exeC:\Program Files (x86)\Google\Update\GoogleUpdate.exeexecutable
MD5:A1361C84AE51AE71617978842D129712
SHA256:C06BF6776AA78E9AA48F7B1F19AE9B77B7E3277066003C653AB501304D8C2F10
6784updater.exeC:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\prefs.jsonbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
6692updater.exeC:\Program Files (x86)\Google\GoogleUpdater\prefs.jsonbinary
MD5:AECBD8FE3F7B64DDF70A33B920FD4BB4
SHA256:8BB68574186A8C571E687AF459DC5917A5FE2FB8EAD1048E6286E74A87AD06A3
6692updater.exeC:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.0\updater.exeexecutable
MD5:A1361C84AE51AE71617978842D129712
SHA256:C06BF6776AA78E9AA48F7B1F19AE9B77B7E3277066003C653AB501304D8C2F10
6692updater.exeC:\Program Files (x86)\Google\GoogleUpdater\d7f29df4-9825-4f4c-b0b7-40b4d5ed663e.tmpbinary
MD5:AECBD8FE3F7B64DDF70A33B920FD4BB4
SHA256:8BB68574186A8C571E687AF459DC5917A5FE2FB8EAD1048E6286E74A87AD06A3
6692updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:2AE964B940F330C2062706D614B45111
SHA256:B742E14703420ED9FDA674A7F53AC509145896E42D66A0DA8EB1F17669F73DD9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
48
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6692
updater.exe
GET
200
142.250.187.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
6948
updater.exe
GET
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/Play/nootememeczd4v2xr4k4x5qhai_24.7.1042.5/-c601e9a4-03b0-4188-843e-80058bf16ef9-_24.7.1042.5_all_cdw22ub3qijmzoigjbr2jc2zga.crx3
unknown
whitelisted
6692
updater.exe
GET
200
142.250.187.131:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
6692
updater.exe
GET
200
142.250.187.131:80
http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEHGN%2BKTRSIp4CcztJxB9gYQ%3D
unknown
whitelisted
2228
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6148
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5504
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
1028
SystemSettings.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2252
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:138
whitelisted
3840
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6948
updater.exe
172.217.169.195:443
update.googleapis.com
GOOGLE
US
whitelisted
6692
updater.exe
142.251.141.46:443
dl.google.com
GOOGLE
US
unknown
3840
svchost.exe
52.167.17.97:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6692
updater.exe
142.250.187.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
6948
updater.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE
US
whitelisted
2120
MoUsoCoreWorker.exe
52.167.17.97:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.14
whitelisted
update.googleapis.com
  • 172.217.169.195
whitelisted
dl.google.com
  • 142.251.141.46
whitelisted
settings-win.data.microsoft.com
  • 52.167.17.97
  • 40.127.240.158
whitelisted
ocsp.pki.goog
  • 142.250.187.131
whitelisted
c.pki.goog
  • 142.250.187.131
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
o.pki.goog
  • 142.250.187.131
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.133
  • 20.190.160.20
  • 40.126.32.68
  • 40.126.32.74
  • 20.190.160.22
  • 40.126.32.136
  • 40.126.32.72
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info