File name:

Zemana.AntiMalware.Setup (1).exe

Full analysis: https://app.any.run/tasks/a88aaa2f-805c-43c2-9f72-beda36a256cd
Verdict: Malicious activity
Threats:

Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil.

Analysis date: February 17, 2024, 18:36:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
metamorfo
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

718F0C6E5BFB1381253630CE22ECE28F

SHA1:

B19BAB73B9FB61A2DBF2EA82D2C76F1565870AA1

SHA256:

4BA132E2F3FDADD2A485D73C8EF59FC7A392A1D9DEDBCF4F69BD42E135655C9D

SSDEEP:

98304:bmRw6tNuQhDuz4/omppEQFDritxLzu1ob4nOSuY0EgdiotIgdEq6r4ZvdOz/cutE:ajWlsk539ZD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Zemana.AntiMalware.Setup (1).exe (PID: 3672)
      • Zemana.AntiMalware.Setup (1).exe (PID: 2964)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 1928)
    • Creates a writable file in the system directory

      • ZAM.exe (PID: 1928)
      • ZAM.exe (PID: 1992)
    • Changes the autorun value in the registry

      • ZAM.exe (PID: 1928)
    • METAMORFO has been detected (YARA)

      • ZAM.exe (PID: 1928)
    • Registers / Runs the DLL via REGSVR32.EXE

      • ZAM.exe (PID: 1928)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Zemana.AntiMalware.Setup (1).exe (PID: 3672)
      • Zemana.AntiMalware.Setup (1).exe (PID: 2964)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 1928)
    • Process drops legitimate windows executable

      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
    • Reads the Windows owner or organization settings

      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
    • Checks Windows Trust Settings

      • ZAM.exe (PID: 1928)
    • Reads security settings of Internet Explorer

      • ZAM.exe (PID: 1928)
    • Reads settings of System Certificates

      • ZAM.exe (PID: 1928)
    • Creates files in the driver directory

      • ZAM.exe (PID: 1928)
    • Drops a system driver (possible attempt to evade defenses)

      • ZAM.exe (PID: 1928)
    • Reads the Internet Settings

      • ZAM.exe (PID: 1928)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2432)
    • Reads Internet Explorer settings

      • ZAM.exe (PID: 1928)
    • Reads Microsoft Outlook installation path

      • ZAM.exe (PID: 1928)
    • Executes as Windows Service

      • ZAM.exe (PID: 1992)
  • INFO

    • Checks supported languages

      • Zemana.AntiMalware.Setup (1).exe (PID: 3672)
      • Zemana.AntiMalware.Setup (1).exe (PID: 2964)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 4052)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 3956)
      • ZAM.exe (PID: 3276)
      • ZAM.exe (PID: 4044)
      • ZAM.exe (PID: 2672)
      • ZAM.exe (PID: 1928)
      • ZAM.exe (PID: 1992)
      • ZAM.exe (PID: 3460)
      • ZAM.exe (PID: 3212)
    • Create files in a temporary directory

      • Zemana.AntiMalware.Setup (1).exe (PID: 2964)
      • Zemana.AntiMalware.Setup (1).exe (PID: 3672)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
    • Reads the computer name

      • Zemana.AntiMalware.Setup (1).tmp (PID: 4052)
      • ZAM.exe (PID: 3460)
      • ZAM.exe (PID: 3956)
      • ZAM.exe (PID: 3276)
      • ZAM.exe (PID: 4044)
      • ZAM.exe (PID: 2672)
      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 3212)
      • ZAM.exe (PID: 1928)
      • ZAM.exe (PID: 1992)
    • Creates files or folders in the user directory

      • ZAM.exe (PID: 3460)
      • ZAM.exe (PID: 3212)
      • ZAM.exe (PID: 3276)
      • ZAM.exe (PID: 3956)
      • ZAM.exe (PID: 2672)
      • ZAM.exe (PID: 4044)
      • ZAM.exe (PID: 1928)
    • Reads the machine GUID from the registry

      • ZAM.exe (PID: 1928)
    • Reads the software policy settings

      • ZAM.exe (PID: 1928)
    • Creates files in the program directory

      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 1928)
    • Creates a software uninstall entry

      • Zemana.AntiMalware.Setup (1).tmp (PID: 2752)
    • Reads CPU info

      • ZAM.exe (PID: 1928)
    • Checks proxy server information

      • ZAM.exe (PID: 1928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:07:16 13:24:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 53248
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.72.0.327
ProductVersionNumber: 2.72.0.327
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Zemana Ltd.
FileDescription: Advanced Malware Protection
FileVersion: 2.72.0.327
LegalCopyright: © Copyright 2017
ProductName: Advanced Malware Protection
ProductVersion: 2.72.0.327
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
13
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start zemana.antimalware.setup (1).exe zemana.antimalware.setup (1).tmp no specs zemana.antimalware.setup (1).exe zemana.antimalware.setup (1).tmp zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs #METAMORFO zam.exe zam.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1928"C:\Program Files\Zemana AntiMalware\ZAM.exe" /install /realtime_protection 1 /set_lang "English"C:\Program Files\Zemana AntiMalware\ZAM.exe
Zemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\program files\zemana antimalware\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
1992"C:\Program Files\Zemana AntiMalware\ZAM.exe" /serviceC:\Program Files\Zemana AntiMalware\ZAM.exeservices.exe
User:
SYSTEM
Company:
Copyright 2017.
Integrity Level:
SYSTEM
Description:
ZAM
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\program files\zemana antimalware\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
2432C:\Windows\System32\regsvr32.exe /s "C:\Program Files\Zemana AntiMalware\ZAMShellExt32.dll"C:\Windows\System32\regsvr32.exeZAM.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2672"C:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exe" /killallC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeZemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\is-c5bdp.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
2752"C:\Users\admin\AppData\Local\Temp\is-6ARJN.tmp\Zemana.AntiMalware.Setup (1).tmp" /SL5="$100130,5214585,119296,C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-6ARJN.tmp\Zemana.AntiMalware.Setup (1).tmp
Zemana.AntiMalware.Setup (1).exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-6arjn.tmp\zemana.antimalware.setup (1).tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2964"C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe
Zemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Zemana Ltd.
Integrity Level:
HIGH
Description:
Advanced Malware Protection
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\zemana.antimalware.setup (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3212"C:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exe" /get_installer_product_idC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeZemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
2
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\is-c5bdp.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
3276"C:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exe" /is_newer_version_installedC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeZemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\is-c5bdp.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
3460"C:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exe" /get_and_set_installer_partner_idC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeZemana.AntiMalware.Setup (1).tmp
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
2
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\is-c5bdp.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
3672"C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe" C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Setup (1).exe
explorer.exe
User:
admin
Company:
Zemana Ltd.
Integrity Level:
MEDIUM
Description:
Advanced Malware Protection
Exit code:
0
Version:
2.72.0.327
Modules
Images
c:\users\admin\appdata\local\temp\zemana.antimalware.setup (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
11 448
Read events
11 351
Write events
80
Delete events
17

Modification events

(PID) Process:(2752) Zemana.AntiMalware.Setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
C00A00005433D832D061DA01
(PID) Process:(2752) Zemana.AntiMalware.Setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
9D3802A3B207FF5FEBAD5F921C128EA7567139F95392DDB5C6F2015627730B0F
(PID) Process:(2752) Zemana.AntiMalware.Setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
Operation:writeName:CUID
Value:
122F47044D0197891995B5
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:CUID
Value:
122F47044D0197891995B5
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Zemana\AntiMalware
Operation:writeName:Premium
Value:
1
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:PermanentPartnerID
Value:
2
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMPartnerID
Value:
2
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMSubPartnerID
Value:
0
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMDownloadID
Value:
3805498
Executable files
14
Suspicious files
4
Text files
66
Unknown types
0

Dropped files

PID
Process
Filename
Type
2964Zemana.AntiMalware.Setup (1).exeC:\Users\admin\AppData\Local\Temp\is-6ARJN.tmp\Zemana.AntiMalware.Setup (1).tmpexecutable
MD5:129B8E200A6E90E813080C9CE0474063
SHA256:CF0018AFFDD0B7921F922F1741AD229EC52C8A7D6C2B19889A149E0CC24AA839
3956ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:8475DCF4B2247866842BEA54D1234DA4
SHA256:CB885FA85801D55D58C0DD3A909D98ECEA7841CA17C773CA47D255F91C356321
2752Zemana.AntiMalware.Setup (1).tmpC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3212ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:0311748A4ABFDE730E474DF56ED68F6D
SHA256:DA2558000D57AD51BDDFD2691B74FC3D9CF888B75D937F04E56DD6EA67EA3CCF
3672Zemana.AntiMalware.Setup (1).exeC:\Users\admin\AppData\Local\Temp\is-PU6P8.tmp\Zemana.AntiMalware.Setup (1).tmpexecutable
MD5:129B8E200A6E90E813080C9CE0474063
SHA256:CF0018AFFDD0B7921F922F1741AD229EC52C8A7D6C2B19889A149E0CC24AA839
3276ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:82A755D9AD7BC3CC4B3AA646827EBBE0
SHA256:1908F0EA0F0F3BEFD0BB992E1472B5C573807CA962B3372EFD954702E5CB5D8F
4044ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:27D35884F1F1D3D80475C2127FCE788C
SHA256:2D8D12A99B6C67EA17C8B02E75E76A833192AEB3995E651A18E140E3DD748D08
2672ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:74A6A92198763B3112123BA2EFA0FFCD
SHA256:D1800AE071CFBA5DCBF03F49405274FAE3809605C30BF4748A49144AB461BE5F
2752Zemana.AntiMalware.Setup (1).tmpC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\zam.eula.rtftext
MD5:D8F67DA37A0AF157E6D5065AD335D15B
SHA256:B6A8596D7D5A2A2B4A8AD4027E697619350FAB83083B9261C34E63C9F7CD29DE
2752Zemana.AntiMalware.Setup (1).tmpC:\Users\admin\AppData\Local\Temp\is-C5BDP.tmp\ZAM.exeexecutable
MD5:67A883DB7D3F973FDD8F0ECF9BD0E364
SHA256:7F10E2729FA7421F0894AC01360B61CB3DC5BEB152481DE3F9BC42EB757E8EB2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
18
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1928
ZAM.exe
POST
301
208.109.191.195:80
http://zamcloud.zemana.com/api/client/settings/122F47044D0197891995B5/2/2/2072327
unknown
html
178 b
unknown
1928
ZAM.exe
POST
200
208.109.191.195:80
http://zamcloud.zemana.com/api/client/settings/122F47044D0197891995B5/2/2/2072327/
unknown
text
1.41 Kb
unknown
1928
ZAM.exe
GET
404
208.109.191.195:80
http://zamcloud.zemana.com/api/stats/install?ProductId=2&PartnerID=2&IsPortable=0&IsBeta=0&IsPremium=1&cuid=122F47044D0197891995B5&DownloadID=3805498&v=2.72.2.327&vi=2072327&os=Windows%207%2032-bit
unknown
html
564 b
unknown
1928
ZAM.exe
GET
404
208.109.191.195:80
http://zamcloud.zemana.com/api/stats/install?ProductId=2&PartnerID=2&IsPortable=0&IsBeta=0&IsPremium=1&cuid=122F47044D0197891995B5&DownloadID=3805498&v=2.72.2.327&vi=2072327&os=Windows%25207%252032-bit
unknown
html
564 b
unknown
1928
ZAM.exe
POST
301
208.109.191.195:80
http://zamcloud.zemana.com/api/ig2/check/2074664?cuid=122F47044D0197891995B5
unknown
html
178 b
unknown
1928
ZAM.exe
POST
200
208.109.191.195:80
http://zamcloud.zemana.com/api/ig2/check/2074664/?cuid=122F47044D0197891995B5
unknown
text
207 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1928
ZAM.exe
45.79.153.218:80
dl12.zemana.com
Linode, LLC
US
unknown
1928
ZAM.exe
208.109.191.195:80
zamcloud.zemana.com
GO-DADDY-COM-LLC
US
unknown
1928
ZAM.exe
208.67.220.220:53
OPENDNS
US
unknown
1928
ZAM.exe
45.79.154.56:80
cdn.go.zemana.com
Linode, LLC
US
unknown

DNS requests

Domain
IP
Reputation
dl12.zemana.com
  • 45.79.153.218
whitelisted
zamcloud.zemana.com
  • 208.109.191.195
whitelisted
cdn.go.zemana.com
  • 45.79.154.56
whitelisted

Threats

No threats detected
No debug info