I was looking at our M365 Defender and was doing some looking around. I noticed the process GoogleUpdate.exe run an encoded ping.
The command was "GoogleUpdate.exe" /ping <encoded stuff>
.
I tried decoding using chef and below is what I saw. Some xml output that provides info. I can't seem to find any other info on this. Is this expected behavior of the process? The device that I found this on currently has no active alerts in Defender nor our AV but I was still curious as I've never seen this before.