File name:

KexSetup_Release_1_1_2_1428.exe

Full analysis: https://app.any.run/tasks/e26aa4df-311f-46e5-a08e-65623ae6c13f
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: December 23, 2024, 18:24:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

F424E7BA4308AB2F13299787DDB22915

SHA1:

D3337DBA64453CB4FB3084AA8AF224D40574C5DC

SHA256:

EBC942C3C08A44CAB27E4DECCEDB0653B6FBF7EBB11F92F7B23EAE8FFDDCF72B

SSDEEP:

98304:RA664IXggitiEaEurOw1PZOoyX7xtD5coTkRy4BekjaR5VYktN0qzd/6QzhV+3UD:G1ezFd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • taskhost.exe (PID: 3968)
      • setup.exe (PID: 3760)
    • Changes the autorun value in the registry

      • explorer.exe (PID: 3636)
      • unregmp2.exe (PID: 3008)
      • regsvr32.exe (PID: 1572)
    • Registers / Runs the DLL via REGSVR32.EXE

      • explorer.exe (PID: 3636)
    • Create files in the Startup directory

      • regsvr32.exe (PID: 1572)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • KexSetup_Release_1_1_2_1428.exe (PID: 1848)
      • KexSetup.exe (PID: 1232)
    • Process drops legitimate windows executable

      • KexSetup_Release_1_1_2_1428.exe (PID: 1848)
      • KexSetup.exe (PID: 1232)
    • Executable content was dropped or overwritten

      • KexSetup_Release_1_1_2_1428.exe (PID: 1848)
      • KexSetup.exe (PID: 1232)
      • 7z2409.exe (PID: 4032)
      • 7zG.exe (PID: 2804)
      • updater.exe (PID: 2364)
    • Reads security settings of Internet Explorer

      • KexSetup.exe (PID: 1016)
    • Reads the Internet Settings

      • KexSetup.exe (PID: 1016)
      • sipnotify.exe (PID: 1812)
      • ie4uinit.exe (PID: 3332)
      • rundll32.exe (PID: 3044)
      • taskhost.exe (PID: 3968)
      • rundll32.exe (PID: 3876)
      • ie4uinit.exe (PID: 3952)
      • ie4uinit.exe (PID: 1764)
    • Application launched itself

      • KexSetup.exe (PID: 1016)
      • ie4uinit.exe (PID: 3332)
      • rundll32.exe (PID: 3044)
      • setup.exe (PID: 3760)
      • updater.exe (PID: 2364)
    • Creates a software uninstall entry

      • KexSetup.exe (PID: 1232)
      • 7z2409.exe (PID: 4032)
    • Creates/Modifies COM task schedule object

      • KexSetup.exe (PID: 1232)
      • 7z2409.exe (PID: 4032)
    • The process executes via Task Scheduler

      • KexCfg.exe (PID: 1780)
      • KexCfg.exe (PID: 920)
      • sipnotify.exe (PID: 1812)
    • Drops 7-zip archiver for unpacking

      • chrome.exe (PID: 3108)
      • chrome.exe (PID: 3180)
      • 7z2409.exe (PID: 4032)
    • Executes as Windows Service

      • taskhost.exe (PID: 3968)
      • EOSNotify.exe (PID: 4000)
      • updater.exe (PID: 4072)
      • updater.exe (PID: 2108)
      • updater.exe (PID: 2576)
      • updater.exe (PID: 2776)
      • updater.exe (PID: 2268)
      • updater.exe (PID: 3412)
    • Changes internet zones settings

      • ie4uinit.exe (PID: 3332)
    • Reads Internet Explorer settings

      • ie4uinit.exe (PID: 3332)
    • Reads Microsoft Outlook installation path

      • ie4uinit.exe (PID: 3332)
    • Uses RUNDLL32.EXE to load library

      • ie4uinit.exe (PID: 3332)
      • rundll32.exe (PID: 3044)
    • Write to the desktop.ini file (may be used to cloak folders)

      • ie4uinit.exe (PID: 3332)
      • unregmp2.exe (PID: 3008)
      • regsvr32.exe (PID: 1572)
    • Changes default file association

      • unregmp2.exe (PID: 3008)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1812)
    • Creates file in the systems drive root

      • explorer.exe (PID: 3636)
  • INFO

    • The sample compiled with english language support

      • KexSetup_Release_1_1_2_1428.exe (PID: 1848)
      • KexSetup.exe (PID: 1232)
      • chrome.exe (PID: 2912)
      • chrome.exe (PID: 3108)
      • 7z2409.exe (PID: 4032)
      • chrome.exe (PID: 3180)
      • 7zG.exe (PID: 2804)
      • updater.exe (PID: 2364)
    • Checks supported languages

      • KexSetup.exe (PID: 1016)
      • KexSetup_Release_1_1_2_1428.exe (PID: 1848)
      • KexSetup.exe (PID: 1232)
      • KexCfg.exe (PID: 1780)
      • KexCfg.exe (PID: 920)
      • wmpnscfg.exe (PID: 3600)
      • 7z2409.exe (PID: 4032)
      • 7zG.exe (PID: 3416)
      • 7zG.exe (PID: 2804)
      • setup.exe (PID: 3760)
      • setup.exe (PID: 3740)
      • setup.exe (PID: 3368)
      • IMEKLMG.EXE (PID: 2804)
      • IMEKLMG.EXE (PID: 3080)
      • IMKRMIG.EXE (PID: 2744)
      • wmpnscfg.exe (PID: 1888)
      • ChromeStandaloneSetup.exe (PID: 3952)
      • wmpnscfg.exe (PID: 2548)
      • updater.exe (PID: 2364)
      • updater.exe (PID: 3748)
    • Create files in a temporary directory

      • KexSetup_Release_1_1_2_1428.exe (PID: 1848)
    • Reads the computer name

      • KexSetup.exe (PID: 1016)
      • KexSetup.exe (PID: 1232)
      • KexCfg.exe (PID: 920)
      • wmpnscfg.exe (PID: 3600)
      • KexCfg.exe (PID: 1780)
      • 7z2409.exe (PID: 4032)
      • 7zG.exe (PID: 2804)
      • setup.exe (PID: 3740)
      • setup.exe (PID: 3368)
      • IMEKLMG.EXE (PID: 3080)
      • IMEKLMG.EXE (PID: 2804)
      • wmpnscfg.exe (PID: 2548)
      • wmpnscfg.exe (PID: 1888)
      • updater.exe (PID: 2364)
      • 7zG.exe (PID: 3416)
    • The process uses the downloaded file

      • KexSetup.exe (PID: 1016)
      • chrome.exe (PID: 2644)
      • chrome.exe (PID: 3180)
      • chrome.exe (PID: 3960)
      • explorer.exe (PID: 3636)
    • Creates files in the program directory

      • KexSetup.exe (PID: 1232)
      • 7z2409.exe (PID: 4032)
      • ie4uinit.exe (PID: 3332)
      • chrmstp.exe (PID: 2584)
      • setup.exe (PID: 3760)
      • chrmstp.exe (PID: 2600)
      • setup.exe (PID: 3740)
      • setup.exe (PID: 3368)
      • ChromeStandaloneSetup.exe (PID: 3952)
      • updater.exe (PID: 2364)
      • updater.exe (PID: 3748)
    • Creates files or folders in the user directory

      • KexSetup.exe (PID: 1232)
    • Manual execution by a user

      • chrome.exe (PID: 3180)
      • ChromeStandaloneSetup.exe (PID: 2296)
      • wmpnscfg.exe (PID: 3600)
      • explorer.exe (PID: 2660)
      • ChromeStandaloneSetup.exe (PID: 580)
      • ChromeStandaloneSetup.exe (PID: 3904)
      • 7zG.exe (PID: 2804)
      • 7zG.exe (PID: 3416)
      • 131.0.6778.205_chrome_installer.exe (PID: 448)
      • ie4uinit.exe (PID: 3332)
      • ie4uinit.exe (PID: 3952)
      • unregmp2.exe (PID: 3008)
      • ie4uinit.exe (PID: 1764)
      • regsvr32.exe (PID: 1572)
      • chrmstp.exe (PID: 2600)
      • setup.exe (PID: 3760)
      • IMEKLMG.EXE (PID: 2804)
      • IMEKLMG.EXE (PID: 3080)
      • explorer.exe (PID: 4036)
      • wmpnscfg.exe (PID: 2548)
      • wmpnscfg.exe (PID: 1888)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 3180)
      • chrome.exe (PID: 2912)
      • chrome.exe (PID: 3108)
    • Application launched itself

      • chrome.exe (PID: 3180)
      • chrmstp.exe (PID: 2600)
      • chrmstp.exe (PID: 2584)
      • msedge.exe (PID: 880)
    • Reads the Internet Settings

      • explorer.exe (PID: 3636)
    • Reads security settings of Internet Explorer

      • ie4uinit.exe (PID: 3332)
      • sipnotify.exe (PID: 1812)
      • explorer.exe (PID: 3636)
    • Checks proxy server information

      • ie4uinit.exe (PID: 3332)
    • Local mutex for internet shortcut management

      • ie4uinit.exe (PID: 3332)
      • explorer.exe (PID: 3636)
    • Reads the software policy settings

      • sipnotify.exe (PID: 1812)
      • explorer.exe (PID: 3636)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 3080)
      • IMEKLMG.EXE (PID: 2804)
      • updater.exe (PID: 2364)
    • Reads settings of System Certificates

      • explorer.exe (PID: 3636)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 2364)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:06:20 07:00:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 28160
InitializedDataSize: 5632
UninitializedDataSize: -
EntryPoint: 0x7b04
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.1.2.1428
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Windows NT
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
LegalCopyright: https://github.com/i486/VxKex
FileDescription: VxKex Setup and Maintenance Tool
FileVersion: 1.1.2.1428
InternalName: KexSetup
OriginalFileName: KEXSETUP.EXE
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
95
Malicious processes
8
Suspicious processes
5

Behavior graph

Click at the process to see the details
start kexsetup_release_1_1_2_1428.exe kexsetup.exe no specs kexsetup.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs wmpnscfg.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs explorer.exe no specs chromestandalonesetup.exe no specs kexcfg.exe no specs chromestandalonesetup.exe no specs chrome.exe kexcfg.exe no specs chromestandalonesetup.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs 7z2409.exe no specs 7z2409.exe chrome.exe no specs 7zg.exe no specs 7zg.exe 131.0.6778.205_chrome_installer.exe no specs chrome.exe no specs taskhost.exe sipnotify.exe ie4uinit.exe no specs ie4uinit.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs ie4uinit.exe no specs unregmp2.exe ie4uinit.exe no specs regsvr32.exe chrmstp.exe no specs chrmstp.exe no specs chrmstp.exe no specs chrmstp.exe no specs setup.exe setup.exe no specs setup.exe no specs msedge.exe no specs imeklmg.exe no specs imeklmg.exe no specs imkrmig.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs explorer.exe no specs eosnotify.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs chrome.exe no specs explorer.exe chrome.exe no specs chromestandalonesetup.exe no specs updater.exe updater.exe no specs updater.exe no specs updater.exe no specs chrome.exe no specs updater.exe no specs updater.exe no specs updater.exe no specs updater.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
148"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3876 --field-trial-handle=1180,i,16584017506648793557,11451991716507382693,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
448"C:\Users\admin\Downloads\ChromeStandaloneSetup\updater\bin\Offline\{115cb937-6c49-4930-becd-bfc8d9aed12b}\{8A69D345-D564-463c-AFF1-A69D9E530F96}\131.0.6778.205_chrome_installer.exe" C:\Users\admin\Downloads\ChromeStandaloneSetup\updater\bin\Offline\{115cb937-6c49-4930-becd-bfc8d9aed12b}\{8A69D345-D564-463c-AFF1-A69D9E530F96}\131.0.6778.205_chrome_installer.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome Installer
Exit code:
0
Version:
131.0.6778.205
Modules
Images
c:\users\admin\downloads\chromestandalonesetup\updater\bin\offline\{115cb937-6c49-4930-becd-bfc8d9aed12b}\{8a69d345-d564-463c-aff1-a69d9e530f96}\131.0.6778.205_chrome_installer.exe
c:\windows\system32\ntdll.dll
532"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --disable-quic --mojo-platform-channel-handle=2300 --field-trial-handle=1180,i,16584017506648793557,11451991716507382693,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
580"C:\Users\admin\Downloads\ChromeStandaloneSetup.exe" C:\Users\admin\Downloads\ChromeStandaloneSetup.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Installer
Exit code:
0
Version:
131.0.6776.0
Modules
Images
c:\users\admin\downloads\chromestandalonesetup.exe
c:\windows\system32\ntdll.dll
580"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1656 --field-trial-handle=1344,i,15516626946703768983,5174284173302470199,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
Administrator
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
880"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --continue-active-setupC:\Program Files\Microsoft\Edge\Application\msedge.exesetup.exe
User:
Administrator
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
920"C:\Program Files\VxKex\KexCfg.exe" /SCHTASK /EXE:"C:\Users\admin\Downloads\ChromeStandaloneSetup.exe" /ENABLE:1 /DISABLEFORCHILD:0 /DISABLEAPPSPECIFIC:0 /WINVERSPOOF:4 /STRONGSPOOF:00000000C:\Program Files\VxKex\KexCfg.exetaskeng.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
VxKex Configuration Tool
Exit code:
0
Version:
1.1.2.1428
Modules
Images
c:\program files\vxkex\kexcfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
924"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=4124 --field-trial-handle=1180,i,16584017506648793557,11451991716507382693,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1016C:\Users\admin\AppData\Local\Temp\7z06EC1738\KexSetup.exe C:\Users\admin\AppData\Local\Temp\7z06EC1738\KexSetup.exeKexSetup_Release_1_1_2_1428.exe
User:
admin
Integrity Level:
MEDIUM
Description:
VxKex Setup and Maintenance Tool
Exit code:
0
Version:
1.1.2.1428
Modules
Images
c:\users\admin\appdata\local\temp\7z06ec1738\kexsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1028"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1544 --field-trial-handle=1180,i,16584017506648793557,11451991716507382693,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
49 573
Read events
47 226
Write events
2 119
Delete events
228

Modification events

(PID) Process:(1016) KexSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1016) KexSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1016) KexSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1016) KexSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1232) KexSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec.exe\VxKex_41BA17B80A6B67E2
Operation:writeName:GlobalFlag
Value:
256
(PID) Process:(1232) KexSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec.exe\VxKex_41BA17B80A6B67E2
Operation:writeName:VerifierFlags
Value:
(PID) Process:(1232) KexSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec.exe\VxKex_41BA17B80A6B67E2
Operation:writeName:VerifierDlls
Value:
kexdll.dll
(PID) Process:(1232) KexSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\VxKex Log Files
Operation:writeName:Display
Value:
VxKex Log Files
(PID) Process:(1232) KexSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\VxKex Log Files
Operation:writeName:Description
Value:
VxKex may create log files each time you launch an application, which consumes disk space. Log files older than 3 days can safely be deleted.
(PID) Process:(1232) KexSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\VxKex Log Files
Operation:writeName:Folder
Value:
C:\Users\admin\AppData\Local\VxKex\Logs
Executable files
99
Suspicious files
334
Text files
234
Unknown types
3

Dropped files

PID
Process
Filename
Type
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Core\Changelog.txttext
MD5:28F06CEE734A8FF74F03BA7742920E17
SHA256:DC20E31FA0FCB7B9A054940501821D39ED5E844BBDEDA08A8CA9568366B3A532
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Core32\VxlView.exeexecutable
MD5:D552CCCBC0A350CB6A1AF35C98B10DB2
SHA256:362A6F71CD9A2E39672B079109100AAB5F222E74AC6559919DFB42EC175D7DC9
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Core64\KexDll.dllexecutable
MD5:E88B1BE5B6A96DB028554DC7C841490D
SHA256:3E134E9757CADE330C41954EE99BD7EF43849F1B0A199CF28BD2291110653FF1
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Core64\VxKexLdr.exeexecutable
MD5:31227AEF52F3FCAA37E23FBE9BD9F80C
SHA256:0A1348192E66B077F039786C0CD45B898D023BB7AD960C29535E639E48672B03
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Core\Application Compatibility List.docxdocument
MD5:37BF15A43E5A2CC56DCAFAF449264AFE
SHA256:88CB1AC486D3B5C4CDFE43817E5B5C782D5B0D4FFFA048AF4EBCAD6F2DD23848
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Core32\KexShlEx.dllexecutable
MD5:A1239CFC3FAD5CDBE7ECA45DC8971D8B
SHA256:E26464260EFF1AD46214699D738E3DFA954C83EEF88A6CB8CFCDBF5C134602DA
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Core64\KexShlEx.dllexecutable
MD5:4FB14B73C665F346718311063C283940
SHA256:0B1E2ECA5131DD34ADF26B7826C8E79DF96EEE37D2CA2AA025854DC6BCCC93B9
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Core32\VxKexLdr.exeexecutable
MD5:8EAF0E84C47EA9717C3BCC1FDEBFCA72
SHA256:F091A3DE5AC14C161CDAEC11E51DF28A65406B5116CBCC4E583E0AAC37D4778D
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Kex32\KxCrt.dllexecutable
MD5:95F80B988BAF7FEEB95748C43C648D13
SHA256:03D22F206E1A56A1C63033AAA8F39385AA218937D6A28DF1A3DC63D5D6A8C26B
1848KexSetup_Release_1_1_2_1428.exeC:\Users\admin\AppData\Local\Temp\7z06EC1738\Core32\CpiwBypa.dllexecutable
MD5:550B25FEBDE5B4D75808CBF06AFA6892
SHA256:9CFCDB7CA2FF11123458DB26F976B2E46485B26EBD6AAC665021C2C2641FB24B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
41
TCP/UDP connections
66
DNS requests
75
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
860
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
860
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
whitelisted
860
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
whitelisted
860
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
whitelisted
860
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
whitelisted
860
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
whitelisted
860
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
whitelisted
860
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
whitelisted
860
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
whitelisted
860
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acvebl5hyowh6yyy3wmoaw5wbfpa_4.10.2830.100/oimompecagnajdejgnnjijobebaeigek_4.10.2830.100_win32_acmfn7n2mz6vs4wnlypsmq4uakaq.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
3108
chrome.exe
216.58.206.67:443
clientservices.googleapis.com
GOOGLE
US
whitelisted
3180
chrome.exe
239.255.255.250:1900
whitelisted
3108
chrome.exe
173.194.76.84:443
accounts.google.com
GOOGLE
US
whitelisted
3108
chrome.exe
216.58.206.36:443
www.google.com
GOOGLE
US
whitelisted
3180
chrome.exe
224.0.0.251:5353
unknown
3108
chrome.exe
142.250.186.163:443
update.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
clientservices.googleapis.com
  • 216.58.206.67
whitelisted
accounts.google.com
  • 173.194.76.84
whitelisted
www.google.com
  • 216.58.206.36
whitelisted
update.googleapis.com
  • 142.250.186.163
whitelisted
encrypted-tbn0.gstatic.com
  • 216.58.212.142
whitelisted
www.googleapis.com
  • 142.250.184.202
  • 142.250.74.202
  • 216.58.206.42
  • 142.250.185.234
  • 142.250.185.74
  • 142.250.186.106
  • 216.58.206.74
  • 172.217.18.10
  • 172.217.16.202
  • 142.250.184.234
  • 142.250.186.42
  • 142.250.181.234
  • 172.217.16.138
  • 142.250.186.138
  • 142.250.185.202
  • 142.250.186.170
whitelisted
fonts.googleapis.com
  • 142.250.185.170
whitelisted
www.google-analytics.com
  • 142.250.185.110
whitelisted
www.googletagmanager.com
  • 142.250.185.72
whitelisted

Threats

No threats detected
No debug info