File name:

ChromeSetup.exe

Full analysis: https://app.any.run/tasks/273b87e8-7733-400d-b885-f375a8c2e988
Verdict: Malicious activity
Analysis date: March 25, 2026, 18:20:35
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections
MD5:

206BC44AF03539539CF0637981445F36

SHA1:

4CCCB3C6DB8B836382A227CEF71B8DD2179F9AE1

SHA256:

F6722DEC3D1D59DBE49426DD120E311AE3AA6B691087B282359EB719DA815A19

SSDEEP:

98304:qfc93QQbqNR9XU49w0uMIjvM7e9WC4OtfGVt/K68xBNzDbeu8t3wXQlNERIMnpFJ:bKW5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the date of Windows installation

      • ChromeSetup.exe (PID: 8128)
    • Application launched itself

      • ChromeSetup.exe (PID: 8128)
      • updater.exe (PID: 7176)
    • Executable content was dropped or overwritten

      • ChromeSetup.exe (PID: 5920)
      • updater.exe (PID: 4328)
      • updater.exe (PID: 7176)
    • Executes as Windows Service

      • updater.exe (PID: 4328)
      • updater.exe (PID: 2100)
  • INFO

    • The sample compiled with english language support

      • ChromeSetup.exe (PID: 8128)
      • ChromeSetup.exe (PID: 5920)
      • updater.exe (PID: 7176)
      • updater.exe (PID: 4328)
    • Reads the computer name

      • ChromeSetup.exe (PID: 8128)
      • ChromeSetup.exe (PID: 5920)
      • updater.exe (PID: 7176)
    • Checks supported languages

      • ChromeSetup.exe (PID: 8128)
      • ChromeSetup.exe (PID: 5920)
      • updater.exe (PID: 7176)
      • updater.exe (PID: 7876)
    • Reads security settings of Internet Explorer

      • ChromeSetup.exe (PID: 8128)
      • updater.exe (PID: 7176)
    • Create files in a temporary directory

      • ChromeSetup.exe (PID: 5920)
      • updater.exe (PID: 7176)
    • Creates files in the program directory

      • updater.exe (PID: 7876)
      • updater.exe (PID: 7176)
      • updater.exe (PID: 4328)
      • updater.exe (PID: 2100)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 7176)
    • Reads the machine GUID from the registry

      • updater.exe (PID: 7176)
    • Creates files or folders in the user directory

      • updater.exe (PID: 7176)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2026:03:12 03:02:57+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 3717120
InitializedDataSize: 7749120
UninitializedDataSize: -
EntryPoint: 0x217e40
OSVersion: 10
ImageVersion: -
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 148.0.7730.0
ProductVersionNumber: 148.0.7730.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google LLC
FileDescription: Google Installer (x86)
FileVersion: 148.0.7730.0
InternalName: Google Installer (x86)
LegalCopyright: Copyright 2026 Google LLC. All rights reserved.
OriginalFileName: UpdaterSetup.exe
ProductName: Google Installer (x86)
ProductVersion: 148.0.7730.0
CompanyShortName: Google
ProductShortName: GoogleUpdater
LastChange: 7e38df31c02dfcf89afe77c0c3bcc5d360516d78-refs/branch-heads/7730@{#1}
OfficialBuild: 1
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
8
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2100"C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe" --system --windows-service --service=updateC:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater (x86)
Version:
148.0.7730.0
Modules
Images
c:\program files (x86)\google\googleupdater\148.0.7730.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2680"C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=148.0.7730.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater_history.jsonl" --initial-client-data=0x29c,0x2a0,0x2a4,0x298,0x2a8,0x9ec4ac,0x9ec4b8,0x9ec4c4C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe—updater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater (x86)
Exit code:
0
Version:
148.0.7730.0
Modules
Images
c:\program files (x86)\google\googleupdater\148.0.7730.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3560"C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=148.0.7730.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater_history.jsonl" --initial-client-data=0x29c,0x2a0,0x2a4,0x298,0x2a8,0x9ec4ac,0x9ec4b8,0x9ec4c4C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe—updater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater (x86)
Version:
148.0.7730.0
Modules
Images
c:\program files (x86)\google\googleupdater\148.0.7730.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
4328"C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe" --system --windows-service --service=update-internalC:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater (x86)
Exit code:
0
Version:
148.0.7730.0
Modules
Images
c:\program files (x86)\google\googleupdater\148.0.7730.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
5920"C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={167543FE-175C-D3CC-AE70-C08B56F87F1E}&lang=en&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=-arch_x64-statsdef_1&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Local\Temp\ChromeSetup.exe
ChromeSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Installer (x86)
Version:
148.0.7730.0
Modules
Images
c:\users\admin\appdata\local\temp\chromesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7176"C:\Users\admin\AppData\Local\Temp\Google5920_310512310\bin\updater.exe" --install=appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={167543FE-175C-D3CC-AE70-C08B56F87F1E}&lang=en&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=-arch_x64-statsdef_1&installdataindex=empty --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 --expect-elevatedC:\Users\admin\AppData\Local\Temp\Google5920_310512310\bin\updater.exe
ChromeSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Updater (x86)
Version:
148.0.7730.0
Modules
Images
c:\users\admin\appdata\local\temp\google5920_310512310\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7876C:\Users\admin\AppData\Local\Temp\Google5920_310512310\bin\updater.exe --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=148.0.7730.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater_history.jsonl" --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a8,0x2b8,0x8bc4ac,0x8bc4b8,0x8bc4c4C:\Users\admin\AppData\Local\Temp\Google5920_310512310\bin\updater.exe—updater.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Updater (x86)
Version:
148.0.7730.0
Modules
Images
c:\users\admin\appdata\local\temp\google5920_310512310\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
8128"C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe" C:\Users\admin\AppData\Local\Temp\ChromeSetup.exe—explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Installer (x86)
Version:
148.0.7730.0
Modules
Images
c:\users\admin\appdata\local\temp\chromesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
4 300
Read events
4 191
Write events
100
Delete events
9

Modification events

(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8018F647-BF07-55BB-82BE-A2D7049F7CE4}
Operation:writeName:AppID
Value:
{8018F647-BF07-55BB-82BE-A2D7049F7CE4}
(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8018F647-BF07-55BB-82BE-A2D7049F7CE4}
Operation:writeName:LocalService
Value:
GoogleUpdaterService148.0.7730.0
(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8018F647-BF07-55BB-82BE-A2D7049F7CE4}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
Operation:writeName:AppID
Value:
{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
Operation:writeName:LocalService
Value:
GoogleUpdaterService148.0.7730.0
(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}
Operation:writeName:AppID
Value:
{534F5323-3569-4F42-919D-1E1CF93E5BF6}
(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}
Operation:writeName:LocalService
Value:
GoogleUpdaterService148.0.7730.0
(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}
Operation:writeName:ServiceParameters
Value:
--com-service
(PID) Process:(4328) updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{521FDB42-7130-4806-822A-FC5163FAD983}
Operation:writeName:AppID
Value:
{521FDB42-7130-4806-822A-FC5163FAD983}
Executable files
4
Suspicious files
8
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
5920ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\Google5920_1624711866\UPDATER.PACKED.7Z —
MD5:—
SHA256:—
5920ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\Google5920_310512310\updater.7z —
MD5:—
SHA256:—
7876updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater_history.jsonltext
MD5:22DDC8B333B50F59733CF3FE9B1B8BFC
SHA256:754EAAB0015B5CBA7C22BFE977433193CFEAD0BD5B5AF39883C5A2D7693E00A0
7176updater.exeC:\Program Files (x86)\Google\GoogleUpdater\0eef81e6-c2bf-4bc2-9ec6-7a3e851dd937.tmptext
MD5:DB073BDA329DC0EFA54AB43CDE8B5D23
SHA256:888AFE299CFBE864743C1003FCCDA435545828FF694D35459AF7DA5E1A39CD50
4328updater.exeC:\Program Files (x86)\Google\GoogleUpdater\38c11d6e-5a45-4836-a48b-203a1d0c689c.tmptext
MD5:321A0068136C62DF1BD74CA575693511
SHA256:47F77BBBA69FA8C6D5893F506053234A037A848F0951CA61BFC2C771E74492CA
5920ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\Google5920_310512310\bin\updater.exeexecutable
MD5:96306010391D755EC750E9259633854C
SHA256:7DAFA7239F9D6256B1FD27F20B4791A4D00CE862B01921EEF6E46667ECAEEFBF
5920ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\Google5920_310512310\bin\uninstall.cmdtext
MD5:96D8312A0955F7169EC966EB46D93423
SHA256:A38E49C0E87A9DD81682346392D45C965783C25D5EC6AAA373CB9799C2A602E2
7176updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:0E500ADF4593452CE7296C8577986E95
SHA256:A859F97DC1E07D10B897A05401975BB13F05FE18B598761386A3F88A447A8C4C
7176updater.exeC:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\uninstall.cmdtext
MD5:96D8312A0955F7169EC966EB46D93423
SHA256:A38E49C0E87A9DD81682346392D45C965783C25D5EC6AAA373CB9799C2A602E2
7176updater.exeC:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\Crashpad\settings.datbinary
MD5:D59B4805303CF05BE2C89444D296492C
SHA256:02D3F3AAA2ECC87C5E145489CC7C497FF268D3677C73E671FF7EE206FECD4C59
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
27
DNS requests
22
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
52.140.118.28:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
—
—
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
52.140.118.28:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
—
—
whitelisted
7568
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
—
—
whitelisted
7568
SIHClient.exe
GET
200
135.233.95.135:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
—
—
whitelisted
7568
SIHClient.exe
GET
200
135.233.95.144:443
https://slscr.update.microsoft.com/sls/ping
US
—
—
whitelisted
7568
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
—
—
whitelisted
4872
svchost.exe
GET
200
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.74 Kb
whitelisted
4872
svchost.exe
GET
200
95.100.102.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
5316
svchost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
US
binary
471 b
whitelisted
4872
svchost.exe
GET
304
52.140.118.28:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
—
—
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4872
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
—
Not routed
—
whitelisted
—
—
184.86.251.21:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5276
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
—
—
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
—
Not routed
—
whitelisted
2100
updater.exe
142.251.140.163:443
update.googleapis.com
GOOGLE
US
whitelisted
7176
updater.exe
142.251.36.110:443
dl.google.com
GOOGLE
US
whitelisted
7176
updater.exe
172.217.168.67:80
c.pki.goog
GOOGLE
US
whitelisted
2100
updater.exe
34.104.35.123:80
edgedl.me.gvt1.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 52.140.118.28
whitelisted
www.bing.com
  • 184.86.251.21
  • 184.86.251.22
  • 184.86.251.28
  • 184.86.251.23
  • 184.86.251.24
  • 184.86.251.18
  • 184.86.251.19
  • 184.86.251.27
  • 184.86.251.26
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.251.13.138
  • 142.251.13.101
  • 142.251.13.100
  • 142.251.13.113
  • 142.251.13.139
  • 142.251.13.102
whitelisted
update.googleapis.com
  • 142.251.140.163
whitelisted
dl.google.com
  • 142.251.36.110
whitelisted
c.pki.goog
  • 172.217.168.67
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted
o.pki.goog
  • 142.251.143.99
whitelisted
crl.microsoft.com
  • 23.216.77.31
  • 23.216.77.41
  • 23.216.77.6
  • 23.216.77.13
  • 23.216.77.8
  • 23.216.77.30
  • 23.216.77.36
  • 23.216.77.37
  • 23.216.77.29
whitelisted

Threats

PID
Process
Class
Message
4872
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info