Windows
Analysis Report
http://r2---sn-j5o7dn7e.gvt1-cn.com/edgedl/release2/chrome/ad4gif7s3quypxnza3f6jszozugq_121.0.6167.160/121.0.6167.160_121.0.6167.140_chrome_updater.exe?cms_redirect=yes&mh=bd&mip=116.6.73.146&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1707331490&mv=u&mvi=2&pl=22&rmhost=r4---sn-j5o7dn7e.gvt1-cn.com&shardbypass=s
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Creates files inside the system directory
Downloads executable code via HTTP
Drops PE files
Stores files to the Windows start menu directory
Classification
- System is w10x64_ra
chrome.exe (PID: 2916 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t http://r 2---sn-j5o 7dn7e.gvt1 -cn.com/ed gedl/relea se2/chrome /ad4gif7s3 quypxnza3f 6jszozugq_ 121.0.6167 .160/121.0 .6167.160_ 121.0.6167 .140_chrom e_updater. exe?cms_re direct=yes &mh=bd&mip =116.6.73. 146&mm=28& mn=sn-j5o7 dn7e&ms=nv h&mt=17073 31490&mv=u &mvi=2&pl= 22&rmhost= r4---sn-j5 o7dn7e.gvt 1-cn.com&s hardbypass =sd&smhost =r2---sn-j 5o76n7l.gv t1-cn.com MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 3528 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2176 --fi eld-trial- handle=194 4,i,871098 3719684139 060,181997 5420466054 104,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 6780 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= chrome.moj om.UtilRea dIcon --la ng=en-US - -service-s andbox-typ e=icon_rea der --mojo -platform- channel-ha ndle=5356 --field-tr ial-handle =1944,i,87 1098371968 4139060,18 1997542046 6054104,26 2144 --dis able-featu res=Optimi zationGuid eModelDown loading,Op timization Hints,Opti mizationHi ntsFetchin g,Optimiza tionTarget Prediction /prefetch :8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
- • Compliance
- • Software Vulnerabilities
- • Networking
- • System Summary
- • Persistence and Installation Behavior
- • Boot Survival
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Memory has grown: |
Source: | HTTP traffic detected: |