File name:

Zemana.AntiMalware.Setup (1).exe

Full analysis: https://app.any.run/tasks/a88aaa2f-805c-43c2-9f72-beda36a256cd
Verdict: Malicious activity
Threats:

Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil.

Analysis date: February 17, 2024, 18:36:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
metamorfo
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

718F0C6E5BFB1381253630CE22ECE28F

SHA1:

B19BAB73B9FB61A2DBF2EA82D2C76F1565870AA1

SHA256:

4BA132E2F3FDADD2A485D73C8EF59FC7A392A1D9DEDBCF4F69BD42E135655C9D

SSDEEP:

98304:bmRw6tNuQhDuz4/omppEQFDritxLzu1ob4nOSuY0EgdiotIgdEq6r4ZvdOz/cutE:ajWlsk539ZD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Zemana.AntiMalware.Setup (1).exe (PID: 3672)
      • Zemana.AntiMalware.Setup (1).exe (PID: 2964)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 1928)
    • Creates a writable file in the system directory

      • ZAM.exe (PID: 1928)
      • ZAM.exe (PID: 1992)
    • Registers / Runs the DLL via REGSVR32.EXE

      • ZAM.exe (PID: 1928)
    • Changes the autorun value in the registry

      • ZAM.exe (PID: 1928)
    • METAMORFO has been detected (YARA)

      • ZAM.exe (PID: 1928)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Zemana.AntiMalware.Setup (1).exe (PID: 2964)
      • Zemana.AntiMalware.Setup (1).exe (PID: 3672)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 1928)
    • Process drops legitimate windows executable

      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
    • Reads the Windows owner or organization settings

      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
    • Checks Windows Trust Settings

      • ZAM.exe (PID: 1928)
    • Reads settings of System Certificates

      • ZAM.exe (PID: 1928)
    • Reads security settings of Internet Explorer

      • ZAM.exe (PID: 1928)
    • Creates files in the driver directory

      • ZAM.exe (PID: 1928)
    • Reads the Internet Settings

      • ZAM.exe (PID: 1928)
    • Drops a system driver (possible attempt to evade defenses)

      • ZAM.exe (PID: 1928)
    • Executes as Windows Service

      • ZAM.exe (PID: 1992)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2432)
    • Reads Microsoft Outlook installation path

      • ZAM.exe (PID: 1928)
    • Reads Internet Explorer settings

      • ZAM.exe (PID: 1928)
  • INFO

    • Checks supported languages

      • Zemana.AntiMalware.Setup (1).exe (PID: 3672)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 4052)
      • Zemana.AntiMalware.Setup (1).exe (PID: 2964)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 3276)
      • ZAM.exe (PID: 3460)
      • ZAM.exe (PID: 3212)
      • ZAM.exe (PID: 3956)
      • ZAM.exe (PID: 1928)
      • ZAM.exe (PID: 4044)
      • ZAM.exe (PID: 2672)
      • ZAM.exe (PID: 1992)
    • Reads the computer name

      • Zemana.AntiMalware.Setup (1).tmp (PID: 4052)
      • ZAM.exe (PID: 3276)
      • ZAM.exe (PID: 3460)
      • ZAM.exe (PID: 3212)
      • ZAM.exe (PID: 3956)
      • ZAM.exe (PID: 1928)
      • ZAM.exe (PID: 4044)
      • ZAM.exe (PID: 2672)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 1992)
    • Create files in a temporary directory

      • Zemana.AntiMalware.Setup (1).exe (PID: 2964)
      • Zemana.AntiMalware.Setup (1).exe (PID: 3672)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
    • Creates files or folders in the user directory

      • ZAM.exe (PID: 3212)
      • ZAM.exe (PID: 3956)
      • ZAM.exe (PID: 3276)
      • ZAM.exe (PID: 3460)
      • ZAM.exe (PID: 1928)
      • ZAM.exe (PID: 4044)
      • ZAM.exe (PID: 2672)
    • Reads the machine GUID from the registry

      • ZAM.exe (PID: 1928)
    • Creates files in the program directory

      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 1928)
    • Creates a software uninstall entry

      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
    • Reads the software policy settings

      • ZAM.exe (PID: 1928)
    • Checks proxy server information

      • ZAM.exe (PID: 1928)
    • Reads CPU info

      • ZAM.exe (PID: 1928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:07:16 13:24:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 53248
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.72.0.327
ProductVersionNumber: 2.72.0.327
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Zemana Ltd.
FileDescription: Advanced Malware Protection
FileVersion: 2.72.0.327
LegalCopyright: © Copyright 2017
ProductName: Advanced Malware Protection
ProductVersion: 2.72.0.327
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
13
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start zemana.antimalware.setup (1).exe zemana.antimalware.setup (1).tmp no specs zemana.antimalware.setup (1).exe zemana.antimalware.setup (1).tmp zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs #METAMORFO zam.exe zam.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1928"C:\Program Files\Zemana AntiMalware\ZAM.exe" /install /realtime_protection 1 /set_lang "English"C:\Program Files\Zemana AntiMalware\ZAM.exe
Zemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\program files\zemana antimalware\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
1992"C:\Program Files\Zemana AntiMalware\ZAM.exe" /serviceC:\Program Files\Zemana AntiMalware\ZAM.exeservices.exe
User:
SYSTEM
Company:
Copyright 2017.
Integrity Level:
SYSTEM
Description:
ZAM
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\program files\zemana antimalware\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
2432C:\Windows\System32\regsvr32.exe /s "C:\Program Files\Zemana AntiMalware\ZAMShellExt32.dll"C:\Windows\System32\regsvr32.exeZAM.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2672"C:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exe" /killallC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeZemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\is-c5bdp.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
2752"C:\Users\admin\AppData\Local\Temp\is-6ARJN.tmp\Zemana.AntiMalware.Setup (1).tmp" /SL5="$100130,5214585,119296,C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-6ARJN.tmp\Zemana.AntiMalware.Setup (1).tmp
Zemana.AntiMalware.Setup (1).exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-6arjn.tmp\zemana.antimalware.setup (1).tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2964"C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe
Zemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Zemana Ltd.
Integrity Level:
HIGH
Description:
Advanced Malware Protection
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\zemana.antimalware.setup (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3212"C:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exe" /get_installer_product_idC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeZemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
2
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\is-c5bdp.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
3276"C:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exe" /is_newer_version_installedC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeZemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\is-c5bdp.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
3460"C:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exe" /get_and_set_installer_partner_idC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeZemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
2
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\is-c5bdp.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
3672"C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe" C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe
explorer.exe
User:
admin
Company:
Zemana Ltd.
Integrity Level:
MEDIUM
Description:
Advanced Malware Protection
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\zemana.antimalware.setup (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
11 448
Read events
11 351
Write events
80
Delete events
17

Modification events

(PID) Process:(2752) Zemana.AntiMalware.Setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
C00A00005433D832D061DA01
(PID) Process:(2752) Zemana.AntiMalware.Setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
9D3802A3B207FF5FEBAD5F921C128EA7567139F95392DDB5C6F2015627730B0F
(PID) Process:(2752) Zemana.AntiMalware.Setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
Operation:writeName:CUID
Value:
122F47044D0197891995B5
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:CUID
Value:
122F47044D0197891995B5
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Zemana\AntiMalware
Operation:writeName:Premium
Value:
1
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:PermanentPartnerID
Value:
2
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMPartnerID
Value:
2
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMSubPartnerID
Value:
0
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMDownloadID
Value:
3805498
Executable files
14
Suspicious files
4
Text files
66
Unknown types
0

Dropped files

PID
Process
Filename
Type
2752Zemana.AntiMalware.Setup (1).tmpC:\Program Files\Zemana AntiMalware\unins000.exeexecutable
MD5:9CC95F43B68062A0938AFEE169CD0CF6
SHA256:E6B7D854EA960EA6418E9F2D1F1F15A0E45A7DB90DEB453F808E987418A2463C
3672Zemana.AntiMalware.Setup (1).exeC:\Users\admin\AppData\Local\Temp\is-PU6P8.tmp\Zemana.AntiMalware.Setup (1).tmpexecutable
MD5:129B8E200A6E90E813080C9CE0474063
SHA256:CF0018AFFDD0B7921F922F1741AD229EC52C8A7D6C2B19889A149E0CC24AA839
2752Zemana.AntiMalware.Setup (1).tmpC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\zam.eula.rtftext
MD5:D8F67DA37A0AF157E6D5065AD335D15B
SHA256:B6A8596D7D5A2A2B4A8AD4027E697619350FAB83083B9261C34E63C9F7CD29DE
2752Zemana.AntiMalware.Setup (1).tmpC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeexecutable
MD5:67A883DB7D3F973FDD8F0ECF9BD0E364
SHA256:7F10E2729FA7421F0894AC01360B61CB3DC5BEB152481DE3F9BC42EB757E8EB2
2752Zemana.AntiMalware.Setup (1).tmpC:\Program Files\Zemana AntiMalware\is-V8FL7.tmpexecutable
MD5:67A883DB7D3F973FDD8F0ECF9BD0E364
SHA256:7F10E2729FA7421F0894AC01360B61CB3DC5BEB152481DE3F9BC42EB757E8EB2
3212ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:0311748A4ABFDE730E474DF56ED68F6D
SHA256:DA2558000D57AD51BDDFD2691B74FC3D9CF888B75D937F04E56DD6EA67EA3CCF
2964Zemana.AntiMalware.Setup (1).exeC:\Users\admin\AppData\Local\Temp\is-6ARJN.tmp\Zemana.AntiMalware.Setup (1).tmpexecutable
MD5:129B8E200A6E90E813080C9CE0474063
SHA256:CF0018AFFDD0B7921F922F1741AD229EC52C8A7D6C2B19889A149E0CC24AA839
4044ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:27D35884F1F1D3D80475C2127FCE788C
SHA256:2D8D12A99B6C67EA17C8B02E75E76A833192AEB3995E651A18E140E3DD748D08
3460ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:778DAC6A0F2B5F9C8DF19200B83F6D53
SHA256:7108251EF30A9581860C67CCB606B57003A52B618427857C02940C8A5C00432A
2672ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:74A6A92198763B3112123BA2EFA0FFCD
SHA256:D1800AE071CFBA5DCBF03F49405274FAE3809605C30BF4748A49144AB461BE5F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
18
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1928
ZAM.exe
POST
301
208.109.191.195:80
http://zamcloud.zemana.com/api/client/settings/122F47044D0197891995B5/2/2/2072327
unknown
html
178 b
unknown
1928
ZAM.exe
GET
404
208.109.191.195:80
http://zamcloud.zemana.com/api/stats/install?ProductId=2&PartnerID=2&IsPortable=0&IsBeta=0&IsPremium=1&cuid=122F47044D0197891995B5&DownloadID=3805498&v=2.72.2.327&vi=2072327&os=Windows%207%2032-bit
unknown
html
564 b
unknown
1928
ZAM.exe
GET
404
208.109.191.195:80
http://zamcloud.zemana.com/api/stats/install?ProductId=2&PartnerID=2&IsPortable=0&IsBeta=0&IsPremium=1&cuid=122F47044D0197891995B5&DownloadID=3805498&v=2.72.2.327&vi=2072327&os=Windows%25207%252032-bit
unknown
html
564 b
unknown
1928
ZAM.exe
POST
200
208.109.191.195:80
http://zamcloud.zemana.com/api/ig2/check/2074664/?cuid=122F47044D0197891995B5
unknown
text
207 b
unknown
1928
ZAM.exe
POST
200
208.109.191.195:80
http://zamcloud.zemana.com/api/client/settings/122F47044D0197891995B5/2/2/2072327/
unknown
text
1.41 Kb
unknown
1928
ZAM.exe
POST
301
208.109.191.195:80
http://zamcloud.zemana.com/api/ig2/check/2074664?cuid=122F47044D0197891995B5
unknown
html
178 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1928
ZAM.exe
45.79.153.218:80
dl12.zemana.com
Linode, LLC
US
unknown
1928
ZAM.exe
208.109.191.195:80
zamcloud.zemana.com
GO-DADDY-COM-LLC
US
unknown
1928
ZAM.exe
208.67.220.220:53
OPENDNS
US
unknown
1928
ZAM.exe
45.79.154.56:80
cdn.go.zemana.com
Linode, LLC
US
unknown

DNS requests

Domain
IP
Reputation
dl12.zemana.com
  • 45.79.153.218
whitelisted
zamcloud.zemana.com
  • 208.109.191.195
whitelisted
cdn.go.zemana.com
  • 45.79.154.56
whitelisted

Threats

No threats detected
No debug info