URL:

https://storage.googleapis.com/chromium-browser-snapshots/Win/486333/mini_installer.exe

Full analysis: https://app.any.run/tasks/2322b233-9097-40c8-b22d-5a1486367c8c
Verdict: Malicious activity
Analysis date: December 15, 2019, 23:19:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

B472C12297B65FEF9B30A95F16DF4B0F

SHA1:

DB4F05EAB9D1873B361E377C6AF402B1731695B8

SHA256:

DE176877463968DC4781D78D0BB47169391FFC2CA7AD7EEC09A4CB6F2D459B4A

SSDEEP:

3:N8cMECYKKhmHRNXKxd6aaX0WNKg3RWRKIM3NqOXLNn:2cMLZHRNaxd6aaFKkwsIJOXLN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • mini_installer.exe (PID: 3940)
      • setup.exe (PID: 2356)
      • setup.exe (PID: 1940)
      • chrome.exe (PID: 3912)
      • chrome.exe (PID: 2612)
      • chrome.exe (PID: 1788)
      • chrome.exe (PID: 1316)
      • chrome.exe (PID: 2912)
      • chrome.exe (PID: 2960)
      • chrome.exe (PID: 2684)
      • chrome.exe (PID: 1740)
      • chrome.exe (PID: 1152)
      • chrome.exe (PID: 3132)
      • chrome.exe (PID: 3520)
      • chrome.exe (PID: 2160)
      • chrome.exe (PID: 3932)
      • chrome.exe (PID: 1600)
    • Loads dropped or rewritten executable

      • chrome.exe (PID: 1788)
      • chrome.exe (PID: 3912)
      • chrome.exe (PID: 3132)
      • chrome.exe (PID: 2612)
      • chrome.exe (PID: 2912)
      • chrome.exe (PID: 1740)
      • chrome.exe (PID: 2684)
      • chrome.exe (PID: 2960)
      • chrome.exe (PID: 1316)
      • chrome.exe (PID: 1152)
      • chrome.exe (PID: 2160)
      • chrome.exe (PID: 3932)
      • chrome.exe (PID: 3520)
      • chrome.exe (PID: 1600)
    • Actions looks like stealing of personal data

      • chrome.exe (PID: 3912)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • mini_installer.exe (PID: 3940)
      • setup.exe (PID: 2356)
      • chrome.exe (PID: 2168)
    • Cleans NTFS data-stream (Zone Identifier)

      • chrome.exe (PID: 2168)
    • Modifies the open verb of a shell class

      • setup.exe (PID: 2356)
    • Application launched itself

      • chrome.exe (PID: 3132)
      • setup.exe (PID: 2356)
      • chrome.exe (PID: 3912)
    • Creates a software uninstall entry

      • setup.exe (PID: 2356)
    • Creates files in the user directory

      • setup.exe (PID: 2356)
  • INFO

    • Reads the hosts file

      • chrome.exe (PID: 2168)
      • chrome.exe (PID: 1780)
      • chrome.exe (PID: 3912)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 2168)
    • Application launched itself

      • chrome.exe (PID: 2168)
    • Dropped object may contain Bitcoin addresses

      • setup.exe (PID: 2356)
    • Reads settings of System Certificates

      • chrome.exe (PID: 3912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
26
Malicious processes
4
Suspicious processes
7

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs mini_installer.exe setup.exe setup.exe no specs chrome.exe chrome.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1152"C:\Users\admin\AppData\Local\Chromium\Application\chrome.exe" --type=utility --field-trial-handle=1656,12755002566270057458,10489152979372907507,131072 --lang=en-US --no-sandbox --service-request-channel-token=9339164B0C776339DC18BA36E527F67E --mojo-platform-channel-handle=3484 /prefetch:8C:\Users\admin\AppData\Local\Chromium\Application\chrome.exechrome.exe
User:
admin
Company:
The Chromium Authors
Integrity Level:
MEDIUM
Description:
Chromium
Exit code:
0
Version:
61.0.3157.0
Modules
Images
c:\users\admin\appdata\local\chromium\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\chromium\application\61.0.3157.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1316"C:\Users\admin\AppData\Local\Chromium\Application\chrome.exe" --type=utility --field-trial-handle=1656,12755002566270057458,10489152979372907507,131072 --lang=en-US --no-sandbox --service-request-channel-token=016C6FE70E13C1F4D5026FFF3FECC237 --mojo-platform-channel-handle=2428 /prefetch:8C:\Users\admin\AppData\Local\Chromium\Application\chrome.exechrome.exe
User:
admin
Company:
The Chromium Authors
Integrity Level:
MEDIUM
Description:
Chromium
Exit code:
0
Version:
61.0.3157.0
Modules
Images
c:\users\admin\appdata\local\chromium\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\chromium\application\61.0.3157.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1600"C:\Users\admin\AppData\Local\Chromium\Application\chrome.exe" --type=renderer --field-trial-handle=1656,12755002566270057458,10489152979372907507,131072 --service-pipe-token=CDD0E9140DB0F63AF3571CA7CBF77034 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,cssExternalScannerNoPreload=false,cssExternalScannerPreload=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-checker-imaging --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=CDD0E9140DB0F63AF3571CA7CBF77034 --renderer-client-id=12 --mojo-platform-channel-handle=3300 /prefetch:1C:\Users\admin\AppData\Local\Chromium\Application\chrome.exechrome.exe
User:
admin
Company:
The Chromium Authors
Integrity Level:
LOW
Description:
Chromium
Exit code:
0
Version:
61.0.3157.0
Modules
Images
c:\users\admin\appdata\local\chromium\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\chromium\application\61.0.3157.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1740"C:\Users\admin\AppData\Local\Chromium\Application\chrome.exe" --type=renderer --field-trial-handle=1656,12755002566270057458,10489152979372907507,131072 --service-pipe-token=F987FAA8B90591288B179EA18E5AD36B --lang=en-US --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,cssExternalScannerNoPreload=false,cssExternalScannerPreload=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-checker-imaging --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=F987FAA8B90591288B179EA18E5AD36B --renderer-client-id=4 --mojo-platform-channel-handle=3132 /prefetch:1C:\Users\admin\AppData\Local\Chromium\Application\chrome.exechrome.exe
User:
admin
Company:
The Chromium Authors
Integrity Level:
LOW
Description:
Chromium
Exit code:
0
Version:
61.0.3157.0
Modules
Images
c:\users\admin\appdata\local\chromium\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\chromium\application\61.0.3157.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1756"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1032,13688347169911420439,12862067013136980530,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=15099796943765351817 --mojo-platform-channel-handle=1052 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1780"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1032,13688347169911420439,12862067013136980530,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=9611298434865090058 --mojo-platform-channel-handle=1616 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1788C:\Users\admin\AppData\Local\Chromium\Application\chrome.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Chromium\User Data" /prefetch:7 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Chromium\User Data\Crashpad" --annotation=plat=Win32 --annotation=prod=Chromium --annotation=ver=61.0.3157.0-devel --initial-client-data=0x98,0x9c,0xa0,0x90,0xa4,0x13dc99c,0x13dc9ac,0x13dc9bcC:\Users\admin\AppData\Local\Chromium\Application\chrome.exe
chrome.exe
User:
admin
Company:
The Chromium Authors
Integrity Level:
MEDIUM
Description:
Chromium
Exit code:
0
Version:
61.0.3157.0
Modules
Images
c:\users\admin\appdata\local\chromium\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\chromium\application\61.0.3157.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1876"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1032,13688347169911420439,12862067013136980530,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1410929385435340933 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2236 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1940C:\Users\admin\AppData\Local\Temp\CR_00856.tmp\setup.exe --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Chromium\User Data\Crashpad" --annotation=plat=Win32 --annotation=prod=Chromium --annotation=ver=61.0.3157.0 --initial-client-data=0xf0,0xf4,0xf8,0xe0,0xfc,0x10b849c,0x10b84ac,0x10b84bcC:\Users\admin\AppData\Local\Temp\CR_00856.tmp\setup.exesetup.exe
User:
admin
Company:
The Chromium Authors
Integrity Level:
MEDIUM
Description:
Chromium Installer
Exit code:
0
Version:
61.0.3157.0
Modules
Images
c:\users\admin\appdata\local\temp\cr_00856.tmp\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\gdi32.dll
2160"C:\Users\admin\AppData\Local\Chromium\Application\chrome.exe" --type=renderer --field-trial-handle=1656,12755002566270057458,10489152979372907507,131072 --service-pipe-token=28FF8B2102B3EBF7F6A1865FB14215DA --lang=en-US --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,cssExternalScannerNoPreload=false,cssExternalScannerPreload=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-checker-imaging --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=28FF8B2102B3EBF7F6A1865FB14215DA --renderer-client-id=11 --mojo-platform-channel-handle=1660 /prefetch:1C:\Users\admin\AppData\Local\Chromium\Application\chrome.exechrome.exe
User:
admin
Company:
The Chromium Authors
Integrity Level:
LOW
Description:
Chromium
Exit code:
0
Version:
61.0.3157.0
Modules
Images
c:\users\admin\appdata\local\chromium\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\chromium\application\61.0.3157.0\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
1 783
Read events
1 620
Write events
159
Delete events
4

Modification events

(PID) Process:(2168) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2168) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2168) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2168) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2168) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2336) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:2168-13220925610546500
Value:
259
(PID) Process:(2168) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2168) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2168) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:1512-13197841398593750
Value:
0
(PID) Process:(2168) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
21
Suspicious files
205
Text files
133
Unknown types
15

Dropped files

PID
Process
Filename
Type
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\c496c21e-35ca-4937-a0b5-7d1710e976e1.tmp
MD5:
SHA256:
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp
MD5:
SHA256:
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.oldtext
MD5:
SHA256:
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF39aa06.TMPtext
MD5:
SHA256:
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF39aa15.TMPtext
MD5:
SHA256:
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
MD5:
SHA256:
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldtext
MD5:
SHA256:
2168chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RF39aa25.TMPtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
44
DNS requests
26
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3912
chrome.exe
172.217.22.46:443
ogs.google.com
Google Inc.
US
whitelisted
3912
chrome.exe
172.217.23.142:443
ogs.google.com
Google Inc.
US
whitelisted
3912
chrome.exe
172.217.22.3:443
fonts.gstatic.com
Google Inc.
US
whitelisted
3912
chrome.exe
172.217.18.98:443
adservice.google.com
Google Inc.
US
whitelisted
3912
chrome.exe
172.217.6.163:443
id.google.com
Google Inc.
US
whitelisted
1780
chrome.exe
172.217.18.99:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
1780
chrome.exe
172.217.16.144:443
storage.googleapis.com
Google Inc.
US
whitelisted
1780
chrome.exe
172.217.16.164:443
www.google.com
Google Inc.
US
whitelisted
1780
chrome.exe
172.217.16.131:443
ssl.gstatic.com
Google Inc.
US
whitelisted
1780
chrome.exe
216.58.207.77:443
accounts.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
storage.googleapis.com
  • 172.217.16.144
whitelisted
clientservices.googleapis.com
  • 172.217.18.99
whitelisted
accounts.google.com
  • 216.58.207.77
shared
www.google.com
  • 172.217.16.164
malicious
ssl.gstatic.com
  • 172.217.16.131
whitelisted
sb-ssl.google.com
  • 216.58.207.78
whitelisted
translate.googleapis.com
  • 172.217.22.42
whitelisted
www.gstatic.com
  • 172.217.22.35
whitelisted
apis.google.com
  • 172.217.18.110
whitelisted
ogs.google.com
  • 172.217.22.46
  • 172.217.23.142
whitelisted

Threats

No threats detected
Process
Message
chrome.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\Chromium\User Data directory exists )
chrome.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\Chromium\User Data directory exists )