File name: | ChromeSetup.exe |
Full analysis: | https://app.any.run/tasks/9cadf0f7-e09c-4707-b067-3c72e497e107 |
Verdict: | Malicious activity |
Analysis date: | May 10, 2025, 06:51:37 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections |
MD5: | E6378392A79331F675960A6EEE8DFC9E |
SHA1: | 47BDEE423813A953EB93D11684A1EF08670C4568 |
SHA256: | F0AB0F4DB5D7E988EDF30206507D6E71AF5FB95E62F5D2F83EFAADAACA9DB9F7 |
SSDEEP: | 98304:5l7pAEcLB806XcPEs0XQpe0DELXFAzz0Tpcky7+HlPmqPLQ4Za999RMAWDo5s7f4:Gyjk |
.exe | | | Generic Win/DOS Executable (50) |
---|---|---|
.exe | | | DOS Executable Generic (49.9) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2025:05:02 03:02:06+00:00 |
ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
PEType: | PE32 |
LinkerVersion: | 14 |
CodeSize: | 3700736 |
InitializedDataSize: | 7736320 |
UninitializedDataSize: | - |
EntryPoint: | 0x1d7410 |
OSVersion: | 10 |
ImageVersion: | - |
SubsystemVersion: | 10 |
Subsystem: | Windows GUI |
FileVersionNumber: | 138.0.7156.0 |
ProductVersionNumber: | 138.0.7156.0 |
FileFlagsMask: | 0x0017 |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
CompanyName: | Google LLC |
FileDescription: | Google Installer (x86) |
FileVersion: | 138.0.7156.0 |
InternalName: | Google Installer (x86) |
LegalCopyright: | Copyright 2025 Google LLC. All rights reserved. |
OriginalFileName: | UpdaterSetup.exe |
ProductName: | Google Installer (x86) |
ProductVersion: | 138.0.7156.0 |
CompanyShortName: | |
ProductShortName: | GoogleUpdater |
LastChange: | 1f8149e52d17f42e7cad03f331dfbac77fe56706-refs/branch-heads/7156@{#1} |
OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
672 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --field-trial-handle=2004,i,11066968771603925506,17752414749556829762,262144 --variations-seed-version --mojo-platform-channel-handle=7060 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 136.0.7103.93 Modules
| |||||||||||||||
720 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=2004,i,11066968771603925506,17752414749556829762,262144 --variations-seed-version --mojo-platform-channel-handle=3168 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 136.0.7103.93 Modules
| |||||||||||||||
1012 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --extension-process --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --field-trial-handle=2004,i,11066968771603925506,17752414749556829762,262144 --variations-seed-version --mojo-platform-channel-handle=4200 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 136.0.7103.93 Modules
| |||||||||||||||
1096 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=2004,i,11066968771603925506,17752414749556829762,262144 --variations-seed-version --mojo-platform-channel-handle=4112 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 136.0.7103.93 Modules
| |||||||||||||||
1228 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) | |||||||||||||||
1452 | "C:\Program Files\Google\Chrome\Application\136.0.7103.93\elevation_service.exe" | C:\Program Files\Google\Chrome\Application\136.0.7103.93\elevation_service.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Exit code: 0 Version: 136.0.7103.93 Modules
| |||||||||||||||
1540 | "C:\Program Files (x86)\Google\GoogleUpdater\138.0.7156.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\138.0.7156.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=138.0.7156.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x298,0x29c,0x2a0,0x274,0x2a4,0xf12e88,0xf12e94,0xf12ea0 | C:\Program Files (x86)\Google\GoogleUpdater\138.0.7156.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater (x86) Version: 138.0.7156.0 Modules
| |||||||||||||||
1672 | C:\Users\admin\AppData\Local\Temp\Google4380_251020318\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\138.0.7156.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=138.0.7156.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a8,0x2ac,0x2b0,0x284,0x2b4,0xb22e88,0xb22e94,0xb22ea0 | C:\Users\admin\AppData\Local\Temp\Google4380_251020318\bin\updater.exe | — | updater.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Updater (x86) Exit code: 0 Version: 138.0.7156.0 | |||||||||||||||
1764 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --field-trial-handle=2004,i,11066968771603925506,17752414749556829762,262144 --variations-seed-version --mojo-platform-channel-handle=5488 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 136.0.7103.93 Modules
| |||||||||||||||
2096 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --field-trial-handle=2004,i,11066968771603925506,17752414749556829762,262144 --variations-seed-version --mojo-platform-channel-handle=7120 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 136.0.7103.93 Modules
|
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | StubPath |
Value: "C:\Program Files\Google\Chrome\Application\136.0.7103.93\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable | |||
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | Localized Name |
Value: Google Chrome | |||
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | IsInstalled |
Value: 1 | |||
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | Version |
Value: 43,0,0,0 | |||
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade |
Operation: | write | Name: | CommandLine |
Value: "C:\Program Files\Google\Chrome\Application\136.0.7103.93\Installer\setup.exe" --on-os-upgrade --channel=stable --system-level --verbose-logging %1 | |||
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade |
Operation: | write | Name: | AutoRunOnOSUpgrade |
Value: 1 | |||
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\store-dmtoken |
Operation: | write | Name: | CommandLine |
Value: "C:\Program Files\Google\Chrome\Application\136.0.7103.93\Installer\setup.exe" --store-dmtoken=%1 --system-level --verbose-logging --channel=stable | |||
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\store-dmtoken |
Operation: | write | Name: | WebAccessible |
Value: 1 | |||
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\delete-dmtoken |
Operation: | write | Name: | CommandLine |
Value: "C:\Program Files\Google\Chrome\Application\136.0.7103.93\Installer\setup.exe" --delete-dmtoken --system-level --verbose-logging --channel=stable | |||
(PID) Process: | (7992) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\delete-dmtoken |
Operation: | write | Name: | WebAccessible |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
4380 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\Google4380_1865591791\UPDATER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
3332 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\138.0.7156.0\updater.exe | executable | |
MD5:FFDA3134E0823DECE997E1A4FB4FC146 | SHA256:802CE5E3714C0D7CCCE24629E9517034E9CCB1F601BC6D29C878985AAA9148C9 | |||
3332 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\138.0.7156.0\uninstall.cmd | text | |
MD5:FBC297EE9060D4256192E4EDB98CAD1B | SHA256:099592FFA867124D16C0C6D868AF1214FD2B7180FA76E4EEE01ABF2A5CF8F044 | |||
3332 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\138.0.7156.0\Crashpad\settings.dat | binary | |
MD5:DE7BD9B90E1CC2EB4943C5C96843D096 | SHA256:4C95469DB0147DA4067023FD56CD56A387300CF953B7F096E109417980B6CA2B | |||
5588 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\f2550f3a-2197-4b7b-bbd2-5559e3bf2adf.tmp | binary | |
MD5:00307500329DBCFB6E7CECB636DFF668 | SHA256:358E3107A9C3E118616970C39EA2F31ABF420C04CF5C384B9365E181614A5FE1 | |||
3332 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\b80f4481-9a87-4818-bcec-617521b1228c.tmp | binary | |
MD5:3F6427D2AB4B18D3993874E76EA4A70A | SHA256:8CD33DE899548BA6CBA67355CDF68040D6C9FAD2777B27220FFA49409266180C | |||
5588 | updater.exe | C:\Program Files (x86)\Google\Update\GoogleUpdate.exe | executable | |
MD5:FFDA3134E0823DECE997E1A4FB4FC146 | SHA256:802CE5E3714C0D7CCCE24629E9517034E9CCB1F601BC6D29C878985AAA9148C9 | |||
3332 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\updater.log | text | |
MD5:6410D937DBDB39B55970BD5ADF3116B9 | SHA256:DBBEE62FD943D7E0AF813F9913E6917205BD24DAA5C6CB7D3A359EB6F555C187 | |||
7268 | updater.exe | C:\Windows\SystemTemp\chrome_url_fetcher_7268_457342768\-8a69d345-d564-463c-aff1-a69d9e530f96-_136.0.7103.93_all_adh2yb6q7t3w4x6zy5f536dugexq.crx3 | — | |
MD5:— | SHA256:— | |||
7268 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\crx_cache\e025f58d009aa9f0caedff775f66d9d945801e93b5240cf2a5547c469cd7eec5 | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
6668 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3 | unknown | — | — | whitelisted |
6668 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3 | unknown | — | — | whitelisted |
6668 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3 | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.48.23.166:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/lavkrwitlza3b2ssskklc2whmi_136.0.7103.93/-8a69d345-d564-463c-aff1-a69d9e530f96-_136.0.7103.93_all_adh2yb6q7t3w4x6zy5f536dugexq.crx3 | unknown | — | — | whitelisted |
— | — | GET | 200 | 142.250.186.99:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 142.250.186.99:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 142.250.184.227:80 | http://o.pki.goog/we2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEA85wFTvuwmlCdtY0UxEIqg%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 23.48.23.166:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
— | — | 172.217.16.195:443 | update.googleapis.com | GOOGLE | US | whitelisted |
— | — | 142.250.185.142:443 | dl.google.com | GOOGLE | US | whitelisted |
— | — | 34.104.35.123:80 | edgedl.me.gvt1.com | GOOGLE | US | whitelisted |
— | — | 142.250.186.99:80 | c.pki.goog | GOOGLE | US | whitelisted |
— | — | 142.250.184.227:80 | o.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
edgedl.me.gvt1.com |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |