File name:

Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe

Full analysis: https://app.any.run/tasks/15d14621-3f6b-4ac2-a749-4f682e44290b
Verdict: Malicious activity
Analysis date: June 14, 2025, 15:26:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

D2C2F7974BCB8A531CC9F138A58BD70B

SHA1:

90164DE94F87BEDF84FA4DE45D12CFEF56FD6E29

SHA256:

1CE27D561F9ACD3C80EC78B439F6C44E03873C2E3B1AE9D5BDAE4E9D2C11D879

SSDEEP:

6144:/7WnDPPIUfR0x82Z/5tga9dkYQUFzqnt1qz:z0D/UZ/5ON8UI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Installer.exe (PID: 6672)
      • Zoom.exe (PID: 5124)
    • The process creates files with name similar to system file names

      • Installer.exe (PID: 6672)
      • Zoom.exe (PID: 5124)
    • Process drops legitimate windows executable

      • Installer.exe (PID: 6672)
    • Reads security settings of Internet Explorer

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Installer.exe (PID: 6672)
      • Zoom.exe (PID: 5124)
      • Zoom.exe (PID: 2288)
    • Application launched itself

      • Installer.exe (PID: 6672)
      • Zoom.exe (PID: 5124)
    • Reads the date of Windows installation

      • Installer.exe (PID: 6672)
      • Zoom.exe (PID: 5124)
    • The process drops C-runtime libraries

      • Installer.exe (PID: 6672)
    • Starts itself from another location

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
    • Creates a software uninstall entry

      • Installer.exe (PID: 6672)
    • Starts application with an unusual extension

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
    • The process checks if it is being run in the virtual environment

      • Zoom.exe (PID: 5124)
      • Zoom.exe (PID: 2288)
  • INFO

    • The sample compiled with english language support

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Installer.exe (PID: 6672)
      • Zoom.exe (PID: 5124)
    • Reads the computer name

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Installer.exe (PID: 6672)
      • Installer.exe (PID: 3908)
      • Zoom.exe (PID: 5124)
      • Zoom.exe (PID: 2288)
      • Installer.exe (PID: 1816)
    • Checks supported languages

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Installer.exe (PID: 6672)
      • Installer.exe (PID: 3908)
      • zmAD66.tmp (PID: 3392)
      • Zoom.exe (PID: 5124)
      • Zoom.exe (PID: 2288)
      • Installer.exe (PID: 1816)
    • Process checks computer location settings

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Installer.exe (PID: 6672)
      • Zoom.exe (PID: 5124)
      • Zoom.exe (PID: 2288)
    • Reads the machine GUID from the registry

      • Installer.exe (PID: 6672)
      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Zoom.exe (PID: 5124)
      • Zoom.exe (PID: 2288)
    • Creates files or folders in the user directory

      • Installer.exe (PID: 6672)
      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Zoom.exe (PID: 5124)
      • Zoom.exe (PID: 2288)
    • The sample compiled with chinese language support

      • Installer.exe (PID: 6672)
      • Zoom.exe (PID: 5124)
    • Reads the software policy settings

      • Installer.exe (PID: 6672)
      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Zoom.exe (PID: 5124)
      • Zoom.exe (PID: 2288)
    • Checks proxy server information

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Zoom.exe (PID: 5124)
      • Zoom.exe (PID: 2288)
    • Create files in a temporary directory

      • Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe (PID: 5020)
      • Zoom.exe (PID: 5124)
    • Reads Environment values

      • Zoom.exe (PID: 5124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:27 08:33:58+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 103424
InitializedDataSize: 51712
UninitializedDataSize: -
EntryPoint: 0x6de0
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 6.4.5.69
ProductVersionNumber: 6.4.5.69
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: Zoom Opener
CompanyName: Zoom Communications, Inc.
FileDescription: Zoom Opener
FileVersion: 6,4,5,69
InternalName: Zoom Opener
LegalCopyright: © Zoom Communications, Inc. All rights reserved.
LegalTrademarks: Zoom Opener
OriginalFileName: Zoom Opener
ProductName: Zoom Opener
ProductVersion: 6,4,5,69
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start zoom_cm_fo42mnktz9vvrzo4_mphwljnhudkq++ec5ptjdjkbaollckd-ivd4@hmkgkjcdqb1jul4n_k90d62a369dbc50a6_.exe installer.exe installer.exe zoom.exe zmad66.tmp no specs zoom.exe installer.exe no specs slui.exe no specs zoom.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1816"C:\Users\admin\AppData\Roaming\Zoom\bin\Installer.exe" "C:\Users\admin\AppData\Roaming\Zoom\bin\Installer.exe" /tskschdC:\Users\admin\AppData\Roaming\Zoom\bin\Installer.exeZoom.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Installer
Exit code:
0
Version:
6,4,12,64384
Modules
Images
c:\users\admin\appdata\roaming\zoom\bin\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
2288"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe" --action=join --runaszvideo=TRUE C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
Zoom.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Meetings
Exit code:
0
Version:
6.4.12.64384
Modules
Images
c:\users\admin\appdata\roaming\zoom\bin\zoom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\users\admin\appdata\roaming\zoom\bin\cmmlib.dll
c:\windows\system32\gdi32.dll
3392"C:\Users\admin\AppData\Local\Temp\zmAD66.tmp" -DAF8C715436E44649F1312698287E6A5=C:\Users\admin\Downloads\Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeC:\Users\admin\AppData\Local\Temp\zmAD66.tmpZoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Opener
Exit code:
0
Version:
6,4,5,69
Modules
Images
c:\users\admin\appdata\local\temp\zmad66.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
3908"C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe" /addfwexception --bin_home="C:\Users\admin\AppData\Roaming\Zoom\bin"C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe
Installer.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
HIGH
Description:
Zoom Installer
Exit code:
0
Version:
6,4,12,64384
Modules
Images
c:\users\admin\appdata\roaming\zoom\zoomdownload\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
5020"C:\Users\admin\Downloads\Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe" C:\Users\admin\Downloads\Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe
explorer.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Opener
Exit code:
0
Version:
6,4,5,69
Modules
Images
c:\users\admin\downloads\zoom_cm_fo42mnktz9vvrzo4_mphwljnhudkq++ec5ptjdjkbaollckd-ivd4@hmkgkjcdqb1jul4n_k90d62a369dbc50a6_.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
5124"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe" "--url=zoommtg://win.launch?h.domain=us05web.zoom.us&h.path=join&stype=0&zc=0&action=join&confno=9406110000"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Meetings
Version:
6.4.12.64384
Modules
Images
c:\users\admin\appdata\roaming\zoom\bin\zoom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
6312"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe" --action=preload --runaszvideo=TRUE C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exeZoom.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Meetings
Version:
6.4.12.64384
Modules
Images
c:\users\admin\appdata\roaming\zoom\bin\zoom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\users\admin\appdata\roaming\zoom\bin\cmmlib.dll
c:\windows\system32\gdi32.dll
6672"C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe" ZInstaller --conf.mode=silent --ipc_wnd=721710C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe
Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe
User:
admin
Company:
Zoom Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Installer
Exit code:
0
Version:
6,4,12,64384
Modules
Images
c:\users\admin\appdata\roaming\zoom\zoomdownload\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
7048C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
26 483
Read events
26 342
Write events
107
Delete events
34

Modification events

(PID) Process:(5020) Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5020) Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5020) Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5020) Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5020) Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5020) Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(5020) Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6672) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
(PID) Process:(6672) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:DisplayName
Value:
Zoom Workplace
(PID) Process:(6672) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:DisplayVersion
Value:
6.4.12 (64384)
Executable files
263
Suspicious files
232
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
5020Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeC:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Zoom.msi
MD5:
SHA256:
5020Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:8CF86583145841E7E26C83D0DD82D6A3
SHA256:98A994EF8B7A831D0846C3DC47F616B641EA6E217600617C9AD622741F7DF52B
5020Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:55E1A0A3D1354E94807002F8E983D8AF
SHA256:F279E64002CFD8191B621D91C6626EB95C26B775F77A059940B034DFB0840943
6672Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\dingdong.pcmbinary
MD5:54511224E61E71D2915FF67E57DCB268
SHA256:7AADF0E317831D287B51E41992B43F0F381AE48A312CB77A426EEB3B6129D6D7
6672Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\archival.pcmbinary
MD5:2DA32E501E9720B40D438FF7352A5573
SHA256:5E7D1491E7D6969EB67646F87AB2DBF0FF1D1CB4F5CF631128A305E2B67D4A1B
6672Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\dingdong1.pcmbinary
MD5:8FE86D9E8AA5C709BB0563243172E580
SHA256:2FBBB9AE6A463B360E1459BEE558DAFA8D864DB2423F0FE4D2C56D22C3F3A5A2
6672Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\directui_license.txttext
MD5:AB54B14548A4CC76DD7C27414D971111
SHA256:6033476BE3D1D41166B65984E2BE94C87AC98DCE55BFEC887E932B696E859295
6672Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\crashrpt_lang.initext
MD5:FCF61AED8F093BFCF571CDD8F8162A05
SHA256:1F5B45A5411F7FC71B9DA789D6D1EAD8AD30551FBEA7BBB40FC7EA576D581ABB
6672Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\clap-medium.pcmbinary
MD5:AA93AB138EC89CF7CFB8B4B0EA8990A6
SHA256:D754FC9D9378772B7A17A53E6598C9CFE4A0F3EC492F0ED30241020562F58509
6672Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\clap-high.pcmbinary
MD5:C32F95839557340B4B4197A68847CA1D
SHA256:0A16435CB3F7B8B1787476575AD646361E6FB4C07587DF874940413DE004DD08
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
41
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5020
Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5896
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6960
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6960
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5476
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1268
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5944
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5020
Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe
170.114.52.5:443
us05web.zoom.us
US
whitelisted
5020
Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe
170.114.46.1:443
cdn.zoom.us
Cloudflare London, LLC
US
whitelisted
5020
Zoom_cm_fo42mnktZ9vvrZo4_mpHwljNhUDkq++ec5ptJdJKBAoLlckD-iVD4@hmKGKjcDqb1JuL4n_k90d62a369dbc50a6_.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5896
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
us05web.zoom.us
  • 170.114.52.5
whitelisted
cdn.zoom.us
  • 170.114.46.1
  • 170.114.45.1
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.76
  • 20.190.160.64
  • 20.190.160.132
  • 40.126.32.138
  • 40.126.32.134
  • 40.126.32.136
  • 40.126.32.140
  • 20.190.160.14
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.22
whitelisted

Threats

No threats detected
Process
Message
Installer.exe
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\zoom_install_src
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\tmp_uninstall
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\tmp_bin
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is: