| File name: | ChromeSetup (3).exe |
| Full analysis: | https://app.any.run/tasks/8e0e5f64-9b15-4535-82c3-8af7a111056f |
| Verdict: | Malicious activity |
| Analysis date: | August 10, 2024, 06:09:53 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E79E96EA24000FA95718BE087AFEF156 |
| SHA1: | 9A1D9D1BC2ACBA1ABFF2ECCBB703F0B58ABD25FE |
| SHA256: | CE2EC43532763FA1873CBE7522740523DF04D07A77DC3FFFCCBC922098EE155C |
| SSDEEP: | 98304:TcOk2efVTg2kO6D7smWxayLMNeNKyftbLiwJeWXhDQEq4jjDA4DJW0qbVeZ8g0pW:B2x |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:07:15 03:02:05+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 2859008 |
| InitializedDataSize: | 6035456 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x14c620 |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 128.0.6597.0 |
| ProductVersionNumber: | 128.0.6597.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Google LLC |
| FileDescription: | Google Chrome Installer |
| FileVersion: | 128.0.6597.0 |
| InternalName: | Google Chrome |
| LegalCopyright: | Copyright 2024 Google LLC. All rights reserved. |
| ProductName: | Google Chrome Installer |
| ProductVersion: | 128.0.6597.0 |
| CompanyShortName: | |
| ProductShortName: | Chrome Installer |
| LastChange: | 1b78adace7d1f96d78dbe62440528477f723b004-refs/branch-heads/6597@{#1} |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 692 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=4396,i,5375596471166471405,3830617113987286437,262144 --variations-seed-version --mojo-platform-channel-handle=4324 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 127.0.6533.100 Modules
| |||||||||||||||
| 1248 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=5848,i,5375596471166471405,3830617113987286437,262144 --variations-seed-version --mojo-platform-channel-handle=5032 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 127.0.6533.100 Modules
| |||||||||||||||
| 1692 | "C:\Program Files\Google\Chrome\Application\127.0.6533.100\elevation_service.exe" | C:\Program Files\Google\Chrome\Application\127.0.6533.100\elevation_service.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Exit code: 0 Version: 127.0.6533.100 Modules
| |||||||||||||||
| 1984 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --from-installer | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 127.0.6533.100 Modules
| |||||||||||||||
| 2396 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=5292,i,5375596471166471405,3830617113987286437,262144 --variations-seed-version --mojo-platform-channel-handle=5844 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 127.0.6533.100 Modules
| |||||||||||||||
| 2436 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=5732,i,5375596471166471405,3830617113987286437,262144 --variations-seed-version --mojo-platform-channel-handle=5920 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 127.0.6533.100 Modules
| |||||||||||||||
| 2720 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --field-trial-handle=2268,i,5375596471166471405,3830617113987286437,262144 --variations-seed-version --mojo-platform-channel-handle=2356 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 127.0.6533.100 Modules
| |||||||||||||||
| 2872 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=4756,i,5375596471166471405,3830617113987286437,262144 --variations-seed-version --mojo-platform-channel-handle=4760 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 127.0.6533.100 Modules
| |||||||||||||||
| 2900 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
| 3568 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --field-trial-handle=2216,i,5375596471166471405,3830617113987286437,262144 --variations-seed-version --mojo-platform-channel-handle=2224 /prefetch:3 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 127.0.6533.100 Modules
| |||||||||||||||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 128.0.6597.0 | |||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | pv |
Value: 128.0.6597.0 | |||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientState\{44fc7fe2-65ce-487c-93f4-edee46eeaaab} |
| Operation: | write | Name: | name |
Value: GoogleUpdater | |||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{44B969D4-48B7-5A30-9CD6-CAC179D81F9C} |
| Operation: | write | Name: | AppID |
Value: {44B969D4-48B7-5A30-9CD6-CAC179D81F9C} | |||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{44B969D4-48B7-5A30-9CD6-CAC179D81F9C} |
| Operation: | write | Name: | LocalService |
Value: GoogleUpdaterInternalService128.0.6597.0 | |||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{44B969D4-48B7-5A30-9CD6-CAC179D81F9C} |
| Operation: | write | Name: | ServiceParameters |
Value: --com-service | |||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8A4B5D74-8832-5170-AB03-2415833EC703}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8A4B5D74-8832-5170-AB03-2415833EC703}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6512) updater.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{CCA9FC90-B200-5641-99C0-7907756A93CF}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6484 | ChromeSetup (3).exe | C:\Windows\SystemTemp\Google6484_1284814391\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 6604 | updater.exe | C:\Windows\SystemTemp\Google6604_2127378518\scoped_dir6604_733100683\GoogleUpdate.exe | executable | |
MD5:3AA2C853D6BC7AF7F2F9B8A934943EFD | SHA256:07034876B9EC0B59432B96FEDB7E10E332440159F9802FAAD5F5B99F01885F6B | |||
| 6512 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\56e4b91a-d4c8-406d-ae03-5e6c6951a9fc.tmp | binary | |
MD5:7B693A82168C33EC9E8CF276859DDF7F | SHA256:84A9A7F43DB56CD6E9A408F88244E8BA5EFBE48A5B5168D321F112B8C8FD8E3F | |||
| 6512 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\uninstall.cmd | text | |
MD5:FBC297EE9060D4256192E4EDB98CAD1B | SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044 | |||
| 6512 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\prefs.json | binary | |
MD5:7B693A82168C33EC9E8CF276859DDF7F | SHA256:84A9A7F43DB56CD6E9A408F88244E8BA5EFBE48A5B5168D321F112B8C8FD8E3F | |||
| 6512 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe | executable | |
MD5:823816B4A601C69C89435EE17EF7B9E0 | SHA256:C2A7C0FA80F228C2CE599E4427280997EA9E1A3F85ED32E5D5E4219DFB05DDB2 | |||
| 6696 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_6696_2117844770\-8a69d345-d564-463c-aff1-a69d9e530f96-_127.0.6533.100_all_ac4tvikqe3lnxu4y2ee34ln26kjq.crx3 | — | |
MD5:— | SHA256:— | |||
| 6696 | updater.exe | C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6696_1754484929\127.0.6533.100_chrome_installer.exe | — | |
MD5:— | SHA256:— | |||
| 6512 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\Crashpad\settings.dat | binary | |
MD5:B4D3119910B20534977A52757654F1C1 | SHA256:D69FED14CFAD7A7F41A3C7A45A8621CB3662D0FAF8FF338EFF123AA73A052FB8 | |||
| 6512 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\updater.log | text | |
MD5:12C596C2A06B758287D72062D33E6611 | SHA256:4CA00F7A15D88D348805D5431EFE400DA1A7548877DA6E8241CF25F540A30FC7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6512 | updater.exe | GET | 200 | 172.217.16.195:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | whitelisted |
6512 | updater.exe | GET | 200 | 172.217.16.195:80 | http://c.pki.goog/r/r1.crl | unknown | — | — | whitelisted |
6512 | updater.exe | GET | 200 | 172.217.16.131:80 | http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEHGN%2BKTRSIp4CcztJxB9gYQ%3D | unknown | — | — | whitelisted |
2876 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
2876 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6696 | updater.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/acdaripqq2wpsipn4qlevkzkaxaa_127.0.6533.100/-8a69d345-d564-463c-aff1-a69d9e530f96-_127.0.6533.100_all_ac4tvikqe3lnxu4y2ee34ln26kjq.crx3 | unknown | — | — | whitelisted |
6316 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6320 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3972 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4084 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6696 | updater.exe | 142.250.185.131:443 | update.googleapis.com | GOOGLE | US | whitelisted |
6512 | updater.exe | 142.250.186.46:443 | dl.google.com | GOOGLE | US | whitelisted |
6512 | updater.exe | 172.217.16.195:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
6512 | updater.exe | 172.217.16.131:80 | o.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |
edgedl.me.gvt1.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |