File name:

googleupdatesetup (2).zip

Full analysis: https://app.any.run/tasks/a888a513-b26c-4d07-a52c-879486082447
Verdict: Malicious activity
Analysis date: December 28, 2023, 11:00:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

261EAE3405B2A9D413021CB52130091A

SHA1:

D5A732C85B88EA5C3678D74E37616EEDC47A90D4

SHA256:

F89AC0BAAE6C156DF0A99691084559F89A5905A6BBD89265EE8847D4610845BE

SSDEEP:

49152:WZKd9kUTV48e/Jexts8dR7/AVLCpqkPu5vDJRQL++efbcHMRqkQRK2DI0gUiUyzL:LkUTQBOtoV7Iu51CC9baMYv/I0PitZ+K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • setup.exe (PID: 2660)
  • SUSPICIOUS

    • Disables SEHOP

      • GoogleUpdate.exe (PID: 1848)
    • Creates/Modifies COM task schedule object

      • GoogleUpdate.exe (PID: 1740)
    • Reads the Internet Settings

      • GoogleUpdate.exe (PID: 2308)
      • GoogleUpdate.exe (PID: 2340)
    • Reads settings of System Certificates

      • GoogleUpdate.exe (PID: 2308)
      • GoogleUpdate.exe (PID: 2340)
    • Checks Windows Trust Settings

      • GoogleUpdate.exe (PID: 2340)
    • Reads security settings of Internet Explorer

      • GoogleUpdate.exe (PID: 2340)
    • Searches for installed software

      • setup.exe (PID: 2660)
    • Creates a software uninstall entry

      • setup.exe (PID: 2660)
  • INFO

    • Reads the computer name

      • GoogleUpdate.exe (PID: 1044)
      • GoogleUpdate.exe (PID: 1848)
      • GoogleUpdate.exe (PID: 1792)
      • GoogleUpdate.exe (PID: 1740)
      • GoogleUpdate.exe (PID: 2340)
      • GoogleUpdate.exe (PID: 2308)
      • GoogleUpdate.exe (PID: 1892)
      • 109.0.5414.120_chrome_installer.exe (PID: 2260)
      • setup.exe (PID: 2660)
      • GoogleCrashHandler.exe (PID: 2536)
      • GoogleUpdate.exe (PID: 2532)
      • GoogleUpdate.exe (PID: 2516)
      • setup.exe (PID: 2780)
      • elevation_service.exe (PID: 3308)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 124)
      • f_000089.exe (PID: 668)
      • GoogleUpdateSetup.exe (PID: 1832)
      • GoogleUpdate.exe (PID: 1848)
      • 109.0.5414.120_chrome_installer.exe (PID: 2260)
      • setup.exe (PID: 2660)
    • Create files in a temporary directory

      • f_000089.exe (PID: 668)
      • GoogleUpdate.exe (PID: 2340)
    • Checks supported languages

      • f_000089.exe (PID: 668)
      • GoogleUpdate.exe (PID: 1044)
      • GoogleUpdateSetup.exe (PID: 1832)
      • GoogleUpdate.exe (PID: 1848)
      • GoogleUpdate.exe (PID: 1792)
      • GoogleUpdate.exe (PID: 1740)
      • GoogleUpdate.exe (PID: 2308)
      • GoogleUpdate.exe (PID: 2340)
      • GoogleUpdate.exe (PID: 1892)
      • 109.0.5414.120_chrome_installer.exe (PID: 2260)
      • setup.exe (PID: 2828)
      • setup.exe (PID: 2780)
      • setup.exe (PID: 2660)
      • setup.exe (PID: 2728)
      • GoogleCrashHandler.exe (PID: 2536)
      • GoogleUpdate.exe (PID: 2532)
      • GoogleUpdate.exe (PID: 2516)
      • GoogleUpdateOnDemand.exe (PID: 2520)
      • elevation_service.exe (PID: 3308)
    • Manual execution by a user

      • f_000089.exe (PID: 668)
    • Reads the machine GUID from the registry

      • GoogleUpdate.exe (PID: 1044)
      • GoogleUpdate.exe (PID: 1848)
      • GoogleUpdate.exe (PID: 2340)
      • GoogleUpdate.exe (PID: 1892)
      • setup.exe (PID: 2660)
      • GoogleUpdate.exe (PID: 2308)
      • setup.exe (PID: 2780)
      • GoogleUpdate.exe (PID: 2516)
      • elevation_service.exe (PID: 3308)
      • GoogleUpdate.exe (PID: 2532)
    • Creates files in the program directory

      • GoogleUpdateSetup.exe (PID: 1832)
      • GoogleUpdate.exe (PID: 1848)
      • GoogleUpdate.exe (PID: 1792)
      • GoogleUpdate.exe (PID: 1740)
      • GoogleUpdate.exe (PID: 2308)
      • GoogleUpdate.exe (PID: 2340)
      • GoogleUpdate.exe (PID: 1892)
      • 109.0.5414.120_chrome_installer.exe (PID: 2260)
      • setup.exe (PID: 2660)
      • setup.exe (PID: 2780)
      • GoogleCrashHandler.exe (PID: 2536)
      • GoogleUpdate.exe (PID: 2532)
    • Executes as Windows Service

      • GoogleUpdate.exe (PID: 1892)
      • elevation_service.exe (PID: 3308)
    • Checks proxy server information

      • GoogleUpdate.exe (PID: 2340)
    • Creates files or folders in the user directory

      • GoogleUpdate.exe (PID: 2340)
    • Application launched itself

      • setup.exe (PID: 2660)
      • setup.exe (PID: 2780)
      • GoogleUpdate.exe (PID: 1892)
      • chrome.exe (PID: 2360)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 2023:12:28 11:49:32
ZipCRC: 0x370b3549
ZipCompressedSize: 1286904
ZipUncompressedSize: 1376304
ZipFileName: f_000089
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
69
Monitored processes
29
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs f_000089.exe no specs googleupdate.exe no specs googleupdatesetup.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe googleupdate.exe 109.0.5414.120_chrome_installer.exe no specs setup.exe setup.exe no specs setup.exe no specs setup.exe no specs googlecrashhandler.exe no specs googleupdateondemand.exe no specs googleupdate.exe googleupdate.exe no specs chrome.exe chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs elevation_service.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\googleupdatesetup (2).zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
668"C:\Users\admin\Desktop\f_000089.exe" C:\Users\admin\Desktop\f_000089.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Update Setup
Exit code:
0
Version:
1.3.36.352
Modules
Images
c:\users\admin\desktop\f_000089.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1044C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdate.exe /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={C57DC321-3F61-D3BC-FFF5-34625BD35338}&lang=pl&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=ONGR&installdataindex=empty"C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdate.exef_000089.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Installer
Exit code:
0
Version:
1.3.36.351
Modules
Images
c:\users\admin\appdata\local\temp\gum505e.tmp\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1740"C:\Program Files\Google\Update\GoogleUpdate.exe" /regserverC:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1792"C:\Program Files\Google\Update\GoogleUpdate.exe" /regsvcC:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1832"C:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdateSetup.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={C57DC321-3F61-D3BC-FFF5-34625BD35338}&lang=pl&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=ONGR&installdataindex=empty" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdateSetup.exe
GoogleUpdate.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Update Setup
Exit code:
0
Version:
1.3.36.352
Modules
Images
c:\users\admin\appdata\local\temp\gum505e.tmp\googleupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1848"C:\Program Files\Google\Temp\GUM562B.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={C57DC321-3F61-D3BC-FFF5-34625BD35338}&lang=pl&browser=5&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=ONGR&installdataindex=empty" /installelevatedC:\Program Files\Google\Temp\GUM562B.tmp\GoogleUpdate.exeGoogleUpdateSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.36.351
Modules
Images
c:\program files\google\temp\gum562b.tmp\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1892"C:\Program Files\Google\Update\GoogleUpdate.exe" /svcC:\Program Files\Google\Update\GoogleUpdate.exe
services.exe
User:
SYSTEM
Company:
Google Inc.
Integrity Level:
SYSTEM
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2260"C:\Program Files\Google\Update\Install\{54604BA1-CAB9-479E-9D0F-01235097C891}\109.0.5414.120_chrome_installer.exe" --verbose-logging --do-not-launch-chrome --system-level /installerdata="C:\Program Files\Google\Update\Install\{54604BA1-CAB9-479E-9D0F-01235097C891}\gui6CF0.tmp"C:\Program Files\Google\Update\Install\{54604BA1-CAB9-479E-9D0F-01235097C891}\109.0.5414.120_chrome_installer.exeGoogleUpdate.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome Installer
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\update\install\{54604ba1-cab9-479e-9d0f-01235097c891}\109.0.5414.120_chrome_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2308"C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNi4zNTIiIHNoZWxsX3ZlcnNpb249IjEuMy4zMy4yMyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins2RkEzNTE4My04RjI3LTQ5NjItODI2Qy1GRDI3OEQ0RjdBNTl9IiB1c2VyaWQ9IntFQTA5RUEyNS02NEQzLTRBNjEtQURENC1EQzM3QzVFQzQ1MUF9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgcmVxdWVzdGlkPSJ7Mzk3N0Y1RTUtM0M4Ni00RTdDLUI4OEQtRTlBQTY4N0YxMDgyfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7NDMwRkQ0RDAtQjcyOS00RjYxLUFBMzQtOTE1MjY0ODE3OTlEfSIgdmVyc2lvbj0iMS4zLjM2LjMyIiBuZXh0dmVyc2lvbj0iMS4zLjM2LjM1MiIgbGFuZz0icGwiIGJyYW5kPSJPTkdSIiBjbGllbnQ9IiIgaWlkPSJ7QzU3REMzMjEtM0Y2MS1EM0JDLUZGRjUtMzQ2MjVCRDM1MzM4fSI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSI1MzIiLz48L2FwcD48L3JlcXVlc3Q-C:\Program Files\Google\Update\GoogleUpdate.exe
GoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
18 708
Read events
18 026
Write events
580
Delete events
102

Modification events

(PID) Process:(124) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
211
Suspicious files
55
Text files
31
Unknown types
1

Dropped files

PID
Process
Filename
Type
668f_000089.exeC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleCrashHandler.exeexecutable
MD5:8EB5A3BCA26ACB6688A0CD7B35CFDAD9
SHA256:24DFDF400D8514D3FBFC5F4AA5DD2143F38B160AD142417BBF83E4D2E425DD0C
124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb124.22371\f_000089executable
MD5:5D8FE4C37DA5CBE7848AB9CD1A266FCD
SHA256:A01209D723609CC19CAEFCADFD1CBF90BC3C2AEEEDC6E3F154DF0B5E7223FDFB
668f_000089.exeC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdateComRegisterShell64.exeexecutable
MD5:4B0BF7525348FD3B55B189C42F90633C
SHA256:F318DEB222E9F635F3A7B7DE3202169732EBDB4CCF0BE5FA8BB94E2E83913B74
668f_000089.exeC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\psmachine.dllexecutable
MD5:76D2509EF0B2715A0BA5BE235D2996AB
SHA256:07876D2770A0E964DA62638D9793C8A4E6C9B546EC44B71AA8C45BE41767EE6D
668f_000089.exeC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\psmachine_64.dllexecutable
MD5:365CE91B8F2D6D85D246B0B64608F333
SHA256:95AC9E810ABF9B37AAA84955A0741B14BAC1181504AA5237A2DF01F447972EB0
668f_000089.exeC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\psuser.dllexecutable
MD5:FC9F15602C90829671D54FA6E72F0C88
SHA256:9F581D8D8F3FC63FB3483D6094562E114F2E1F289D1C7A4B7FFE91E46E50C936
668f_000089.exeC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\GoogleUpdateOnDemand.exeexecutable
MD5:616E0D6AFDA084D967E49370BC5350CA
SHA256:BF88BBCF2B88823A94EFED3C4BC275C47F338D7788A4FA8444853BF637F5E253
668f_000089.exeC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\goopdate.dllexecutable
MD5:2FA183E7B8B744B6761A008F6BC56B87
SHA256:E80FCE87F2F4B87282FA38260ACFE5435E47FD2E0884DB4C7446AC00635A7CCF
668f_000089.exeC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\goopdateres_da.dllexecutable
MD5:F2676455A6CC1749B55F904FEF73CBE1
SHA256:70CA4EB73A4F8D03E750929A4AFDB876076D39499F2016588F8B6FE85A80B0E5
668f_000089.exeC:\Users\admin\AppData\Local\Temp\GUM505E.tmp\goopdateres_bn.dllexecutable
MD5:1D1E2D66464C7237E667FC8813847D27
SHA256:825428867F14CE18169FE8705C0A5C941B87A7FEEC84F4E3DD4344BBE5FC7972
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
16
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2340
GoogleUpdate.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2340
GoogleUpdate.exe
GET
200
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?559a13cd175d8925
unknown
compressed
4.66 Kb
unknown
2340
GoogleUpdate.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2340
GoogleUpdate.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGpYRvzN3kAuEMlMWsqSFLc%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2308
GoogleUpdate.exe
142.250.185.99:443
update.googleapis.com
GOOGLE
US
whitelisted
1892
GoogleUpdate.exe
142.250.185.99:443
update.googleapis.com
GOOGLE
US
whitelisted
2340
GoogleUpdate.exe
142.250.186.142:443
dl.google.com
GOOGLE
US
whitelisted
2340
GoogleUpdate.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2340
GoogleUpdate.exe
216.58.212.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
1528
svchost.exe
239.255.255.250:1900
whitelisted
2532
GoogleUpdate.exe
142.250.185.99:443
update.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
update.googleapis.com
  • 142.250.185.99
whitelisted
dl.google.com
  • 142.250.186.142
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.194
  • 184.24.77.202
whitelisted
ocsp.pki.goog
  • 216.58.212.131
whitelisted
clientservices.googleapis.com
  • 216.58.206.35
whitelisted
accounts.google.com
  • 64.233.167.84
shared
www.google.com
  • 142.250.186.164
whitelisted

Threats

No threats detected
No debug info