| File name: | ZA_Connect (2).exe |
| Full analysis: | https://app.any.run/tasks/1fff51ca-2a09-4c82-8e09-ad792c4e88ae |
| Verdict: | Malicious activity |
| Analysis date: | August 12, 2024, 11:56:58 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | A6CE6408CE2EC212B9BE719EAF586EEA |
| SHA1: | 9A46750A5C02AC1348BF7D1B178B702D4E3A42D1 |
| SHA256: | 3D51F053BF0B22B63573D35F46AAD375F097F7DD7C5DA08EED3190A5601EC6D9 |
| SSDEEP: | 98304:zWs0a3RKm46jF/GX/7d+DD66rKvjKaZDHaXZbpc1Ce308QvG6/Nn2aO2V3SlDyZK:rzf4D |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:28 11:40:25+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 2794496 |
| InitializedDataSize: | 1271296 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9b9d8 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.96 |
| ProductVersionNumber: | 1.0.0.96 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | ZOHO Corporation |
| FileDescription: | Zoho Assist |
| FileVersion: | 1.0.0.96 |
| InternalName: | Zoho Assist |
| LegalCopyright: | <Zoho meeting>. All rights reserved. |
| OriginalFileName: | Connect.exe |
| ProductName: | Zoho Assist |
| ProductVersion: | 1.0.0.96 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2628 | -silientinstall -productID 1 | C:\Program Files (x86)\ZohoMeeting\ZAService.exe | — | ZA_Connect (2).exe | |||||||||||
User: admin Integrity Level: HIGH Description: Zoho Assist Exit code: 0 Version: 1.0.0.228 Modules
| |||||||||||||||
| 6324 | "C:\Program Files (x86)\ZohoMeeting\ZAService.exe" run -SessionType ASSIST -productID 1 | C:\Program Files (x86)\ZohoMeeting\ZAService.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: Zoho Assist Exit code: 0 Version: 1.0.0.228 Modules
| |||||||||||||||
| 6660 | "C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe" | C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe | — | explorer.exe | |||||||||||
User: admin Company: ZOHO Corporation Integrity Level: MEDIUM Description: Zoho Assist Exit code: 0 Version: 1.0.0.96 Modules
| |||||||||||||||
| 6684 | "C:\Program Files (x86)\ZohoMeeting\agent.exe" -agent -k 296356570 -ms assist.zoho.com -email Malike -SERVICEAGENT -demo_mode false -demo_tech false -ShowInit 0 -productID 1 -js join.zoho.com -c_check true -session_token f3dbb2adcaf5536807ad3b88861aa7de022dbb8277e78a15af541b0d83aee1de754487bd5af4b0a8be3cb084017277c2d74154a12ae72afc8b5003f6ab558ae8926a7d046a5e7319b3c546c93fc68247717589c9c7da1fa057c5c768df07277c | C:\Program Files (x86)\ZohoMeeting\agent.exe | ZAService.exe | ||||||||||||
User: SYSTEM Company: Zoho Corporation Integrity Level: SYSTEM Description: Zoho Assist Exit code: 0 Version: 111.0.3.283 Modules
| |||||||||||||||
| 6752 | "C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe" C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe | C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe | ZA_Connect (2).exe | ||||||||||||
User: admin Company: ZOHO Corporation Integrity Level: HIGH Description: Zoho Assist Exit code: 0 Version: 1.0.0.96 Modules
| |||||||||||||||
| (PID) Process: | (6660) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6660) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6660) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6660) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
| Operation: | write | Name: | DisplayName |
Value: Zoho Assist | |||
| (PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files (x86)\ZohoMeeting\agent.exe | |||
| (PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
| Operation: | write | Name: | UnInstallString |
Value: C:\Program Files (x86)\ZohoMeeting\Connect.exe -UnInstall ASSIST | |||
| (PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files (x86)\ZohoMeeting\ | |||
| (PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
| Operation: | write | Name: | DisplayVersion |
Value: 1.0.0.0 | |||
| (PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
| Operation: | write | Name: | HelpLink |
Value: https://www.zoho.com/assist/help/overview.html | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\ZohoMeeting.7z.tmp | — | |
MD5:— | SHA256:— | |||
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\ZohoMeeting.7z | — | |
MD5:— | SHA256:— | |||
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\ch_en.xml | text | |
MD5:64A034349FD8521E308542E94402B2D8 | SHA256:0EE9942739773A76B3A84127E578FB7643966856C910A08003F3206AE2DAE53E | |||
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\AssistLogo_white_border_32.ico | image | |
MD5:D669E7BCEFF12A455FD097DEDEF847EB | SHA256:DD72CC36C3E664913059CC64A852FE673A8B6EB264632FEFAE20649A27E999D4 | |||
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\ViewerLanguage.conf | text | |
MD5:00F2A1BEE0BD376D57D6D261EEDFDFC9 | SHA256:78CD71456CBDDB0D9397A7FD103920C2084C2DF78D36DFC4C125E1E8A0AADECD | |||
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\SidebarConf.xml | text | |
MD5:00C38820945E541EA1A469DCE7F92642 | SHA256:9804FA5C943E8B92714F73707215C7D6801D2F81D9B40614AB2B920B1F00CAD6 | |||
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\ScriptLauncher.exe.config | xml | |
MD5:CE2FDB3342350A65B4EDBB8513967B2C | SHA256:04A430FD53FBA154D3093D3E8AC76C31D3BFF8D08A7E4DEC14656E576A880830 | |||
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\Tools\ZohoAssistAgent.iss | text | |
MD5:3F7ABF38D65ACE8C2C7286EC3EAD24E8 | SHA256:C965271BEBD93847C63422C821980A924D5579D1931AB01ECF6F3FAED1581258 | |||
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\ch_zh.xml | text | |
MD5:38B1C4FA0C961E82E3C51DE35E6060DB | SHA256:59521E3C3B7AF3ACE650DA5D37D4006857790AB006134812D8CD44A2A164A5C0 | |||
| 6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\widget_language.xml | xml | |
MD5:F24DD443724F39A0A4D8D5A898A9C06D | SHA256:3DA97B3EB9BF17724F6E65F53D76887C2473CF8E2BCE40024E05C31312907ED0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1568 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7116 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7080 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3164 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2536 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6752 | ZA_Connect (2).exe | 204.141.43.95:443 | assist.zoho.com | ZOHO-AS | US | unknown |
6752 | ZA_Connect (2).exe | 89.36.170.147:443 | downloads.zohocdn.com | Computerline GmbH | CH | unknown |
5336 | SearchApp.exe | 184.86.251.5:443 | www.bing.com | Akamai International B.V. | DE | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3260 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
assist.zoho.com |
| whitelisted |
downloads.zohocdn.com |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
ZA_Connect (2).exe | CustomURLProtocol::Failed with error 2: The system cannot find the file specified.
|
ZA_Connect (2).exe | CustomURLProtocol::Failed with error 2: The system cannot find the file specified.
|