File name: | ZA_Connect (2).exe |
Full analysis: | https://app.any.run/tasks/1fff51ca-2a09-4c82-8e09-ad792c4e88ae |
Verdict: | Malicious activity |
Analysis date: | August 12, 2024, 11:56:58 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | A6CE6408CE2EC212B9BE719EAF586EEA |
SHA1: | 9A46750A5C02AC1348BF7D1B178B702D4E3A42D1 |
SHA256: | 3D51F053BF0B22B63573D35F46AAD375F097F7DD7C5DA08EED3190A5601EC6D9 |
SSDEEP: | 98304:zWs0a3RKm46jF/GX/7d+DD66rKvjKaZDHaXZbpc1Ce308QvG6/Nn2aO2V3SlDyZK:rzf4D |
.exe | | | Win32 Executable (generic) (52.9) |
---|---|---|
.exe | | | Generic Win/DOS Executable (23.5) |
.exe | | | DOS Executable Generic (23.5) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2024:06:28 11:40:25+00:00 |
ImageFileCharacteristics: | Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 14.16 |
CodeSize: | 2794496 |
InitializedDataSize: | 1271296 |
UninitializedDataSize: | - |
EntryPoint: | 0x9b9d8 |
OSVersion: | 5.1 |
ImageVersion: | - |
SubsystemVersion: | 5.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.0.0.96 |
ProductVersionNumber: | 1.0.0.96 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Windows, Latin1 |
CompanyName: | ZOHO Corporation |
FileDescription: | Zoho Assist |
FileVersion: | 1.0.0.96 |
InternalName: | Zoho Assist |
LegalCopyright: | <Zoho meeting>. All rights reserved. |
OriginalFileName: | Connect.exe |
ProductName: | Zoho Assist |
ProductVersion: | 1.0.0.96 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2628 | -silientinstall -productID 1 | C:\Program Files (x86)\ZohoMeeting\ZAService.exe | — | ZA_Connect (2).exe | |||||||||||
User: admin Integrity Level: HIGH Description: Zoho Assist Exit code: 0 Version: 1.0.0.228 Modules
| |||||||||||||||
6324 | "C:\Program Files (x86)\ZohoMeeting\ZAService.exe" run -SessionType ASSIST -productID 1 | C:\Program Files (x86)\ZohoMeeting\ZAService.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: Zoho Assist Exit code: 0 Version: 1.0.0.228 Modules
| |||||||||||||||
6660 | "C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe" | C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe | — | explorer.exe | |||||||||||
User: admin Company: ZOHO Corporation Integrity Level: MEDIUM Description: Zoho Assist Exit code: 0 Version: 1.0.0.96 Modules
| |||||||||||||||
6684 | "C:\Program Files (x86)\ZohoMeeting\agent.exe" -agent -k 296356570 -ms assist.zoho.com -email Malike -SERVICEAGENT -demo_mode false -demo_tech false -ShowInit 0 -productID 1 -js join.zoho.com -c_check true -session_token f3dbb2adcaf5536807ad3b88861aa7de022dbb8277e78a15af541b0d83aee1de754487bd5af4b0a8be3cb084017277c2d74154a12ae72afc8b5003f6ab558ae8926a7d046a5e7319b3c546c93fc68247717589c9c7da1fa057c5c768df07277c | C:\Program Files (x86)\ZohoMeeting\agent.exe | ZAService.exe | ||||||||||||
User: SYSTEM Company: Zoho Corporation Integrity Level: SYSTEM Description: Zoho Assist Exit code: 0 Version: 111.0.3.283 Modules
| |||||||||||||||
6752 | "C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe" C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe | C:\Users\admin\AppData\Local\Temp\ZA_Connect (2).exe | ZA_Connect (2).exe | ||||||||||||
User: admin Company: ZOHO Corporation Integrity Level: HIGH Description: Zoho Assist Exit code: 0 Version: 1.0.0.96 Modules
|
(PID) Process: | (6660) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (6660) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (6660) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (6660) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
Operation: | write | Name: | DisplayName |
Value: Zoho Assist | |||
(PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files (x86)\ZohoMeeting\agent.exe | |||
(PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
Operation: | write | Name: | UnInstallString |
Value: C:\Program Files (x86)\ZohoMeeting\Connect.exe -UnInstall ASSIST | |||
(PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
Operation: | write | Name: | InstallLocation |
Value: C:\Program Files (x86)\ZohoMeeting\ | |||
(PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
Operation: | write | Name: | DisplayVersion |
Value: 1.0.0.0 | |||
(PID) Process: | (6752) ZA_Connect (2).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zoho Assist |
Operation: | write | Name: | HelpLink |
Value: https://www.zoho.com/assist/help/overview.html |
PID | Process | Filename | Type | |
---|---|---|---|---|
6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\ZohoMeeting.7z.tmp | — | |
MD5:— | SHA256:— | |||
6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\ZohoMeeting.7z | — | |
MD5:— | SHA256:— | |||
6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\SidebarConf.xml | text | |
MD5:00C38820945E541EA1A469DCE7F92642 | SHA256:9804FA5C943E8B92714F73707215C7D6801D2F81D9B40614AB2B920B1F00CAD6 | |||
6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\ch_zh.xml | text | |
MD5:38B1C4FA0C961E82E3C51DE35E6060DB | SHA256:59521E3C3B7AF3ACE650DA5D37D4006857790AB006134812D8CD44A2A164A5C0 | |||
6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\Tools\ZohoAssistAgent.iss | text | |
MD5:3F7ABF38D65ACE8C2C7286EC3EAD24E8 | SHA256:C965271BEBD93847C63422C821980A924D5579D1931AB01ECF6F3FAED1581258 | |||
6660 | ZA_Connect (2).exe | C:\Users\admin\AppData\Local\ZohoMeeting\log\Connect.log | text | |
MD5:7C280685EF8FA1DC4F37FC84345719C3 | SHA256:605BD0D93E96FE975FF8ED79034E3A998966435E1AA9B41683D5FA1121B8973D | |||
6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\DevExe64.exe.config | xml | |
MD5:C98570A2004587CCAC5AC6DE21859690 | SHA256:832208E81FB2CCABFA2EF289F89D47A2665B451A9550D597821B7D6F39373159 | |||
6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\AssistLogo_transparent_48.ico | image | |
MD5:1ED79C14F058ED3C29725E29BDF18F11 | SHA256:17970A1464B024AE456D950CA9DC845D81181BF1E08907C8F246489A8CBFB2A2 | |||
6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\Language.conf | text | |
MD5:00F2A1BEE0BD376D57D6D261EEDFDFC9 | SHA256:78CD71456CBDDB0D9397A7FD103920C2084C2DF78D36DFC4C125E1E8A0AADECD | |||
6752 | ZA_Connect (2).exe | C:\Program Files (x86)\ZohoMeeting\RSTemp\ZohoMeeting\Resource\AssistLogo_white_border_32.ico | image | |
MD5:D669E7BCEFF12A455FD097DEDEF847EB | SHA256:DD72CC36C3E664913059CC64A852FE673A8B6EB264632FEFAE20649A27E999D4 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1568 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7080 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7116 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3164 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2536 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6752 | ZA_Connect (2).exe | 204.141.43.95:443 | assist.zoho.com | ZOHO-AS | US | unknown |
6752 | ZA_Connect (2).exe | 89.36.170.147:443 | downloads.zohocdn.com | Computerline GmbH | CH | unknown |
5336 | SearchApp.exe | 184.86.251.5:443 | www.bing.com | Akamai International B.V. | DE | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3260 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |
assist.zoho.com |
| whitelisted |
downloads.zohocdn.com |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
Process | Message |
---|---|
ZA_Connect (2).exe | CustomURLProtocol::Failed with error 2: The system cannot find the file specified.
|
ZA_Connect (2).exe | CustomURLProtocol::Failed with error 2: The system cannot find the file specified.
|