File name:

ZHPDIAG3.EXE

Full analysis: https://app.any.run/tasks/654075a5-da49-493a-90cf-1dcd2e23c102
Verdict: Malicious activity
Analysis date: March 24, 2025, 12:12:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
autoit
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

EDE81EF54D07EE7D1CC93A0C45D02EE1

SHA1:

3380DB1107D73C927C6A97B6218C5D84C36ED5F0

SHA256:

5727C834F0772BA82A38B49276A7BB34269F06D7DFA5B35F589A437A1F90933A

SSDEEP:

98304:8AGQX21RBt7QjTmcaTH/vU4do9Pcjq1GvXB1sg58N32+Rr181vWDZT3FcIwEAiRD:tFpRad

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • ZHPDIAG3.EXE.exe (PID: 7432)
      • ZHPDIAG3.EXE.exe (PID: 7524)
  • SUSPICIOUS

    • Detected use of alternative data streams (AltDS)

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • There is functionality for taking screenshot (YARA)

      • ZHPDIAG3.EXE.exe (PID: 7524)
  • INFO

    • Reads mouse settings

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • The sample compiled with french language support

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • Reads product name

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • Reads Environment values

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • Creates files or folders in the user directory

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • Checks supported languages

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • Reads the computer name

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • Create files in a temporary directory

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • The process uses AutoIt

      • ZHPDIAG3.EXE.exe (PID: 7524)
    • Reads the software policy settings

      • slui.exe (PID: 7592)
      • slui.exe (PID: 3304)
    • Checks proxy server information

      • slui.exe (PID: 3304)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:10:07 07:34:07+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 581120
InitializedDataSize: 2320896
UninitializedDataSize: -
EntryPoint: 0x27dcd
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2017.10.7.177
ProductVersionNumber: 3.3.14.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: French
CharacterSet: Unicode
FileVersion: 2017.10.7.177
Comments: Diagnostic du système.
FileDescription: ZHPDiag
ProductVersion: 3.3.14.0
LegalCopyright: Nicolas Coolman
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
5
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start zhpdiag3.exe.exe sppextcomobj.exe no specs slui.exe slui.exe zhpdiag3.exe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3304C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7432"C:\Users\admin\AppData\Local\Temp\ZHPDIAG3.EXE.exe" C:\Users\admin\AppData\Local\Temp\ZHPDIAG3.EXE.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ZHPDiag
Exit code:
3221226540
Version:
2017.10.7.177
Modules
Images
c:\users\admin\appdata\local\temp\zhpdiag3.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7524"C:\Users\admin\AppData\Local\Temp\ZHPDIAG3.EXE.exe" C:\Users\admin\AppData\Local\Temp\ZHPDIAG3.EXE.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
ZHPDiag
Exit code:
0
Version:
2017.10.7.177
Modules
Images
c:\users\admin\appdata\local\temp\zhpdiag3.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
7560C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7592"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
969
Read events
968
Write events
1
Delete events
0

Modification events

(PID) Process:(7524) ZHPDIAG3.EXE.exeKey:HKEY_CURRENT_USER\SOFTWARE\ZHP\ZHPdiag
Operation:writeName:EnableValidity
Value:
1
Executable files
0
Suspicious files
6
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\ZHP\ZHPCFileNav_GG.pngimage
MD5:D18D8C135E855CF99B2D1AA80F5D6E6C
SHA256:FD308F922990D4B48AC5B5F16723D381F251235D81D5BCB99F9AF0451D9D03DC
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\ZHP\ZHPCFileNav_FF.pngimage
MD5:68704E4AFD7239E116A636AB8D0C2D35
SHA256:7BEC6B4F6B27C6DDC47634C6365D11F1A227219093ABF027562E1DB4ED1E2595
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\Temp\autC084.tmpimage
MD5:68704E4AFD7239E116A636AB8D0C2D35
SHA256:7BEC6B4F6B27C6DDC47634C6365D11F1A227219093ABF027562E1DB4ED1E2595
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\Temp\autC095.tmpimage
MD5:463EBE5DCD388836C2DD309D8D09EA93
SHA256:C489BBF3042A296EF7C14968CF68F381F64A1891F094FEAA892CC7CA67BE60FA
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\ZHP\ZHPDFileCluff_FR.txttext
MD5:FDB95AD1A63162A361F3AA760EB1C503
SHA256:5438C46FBCC10EBE90D54722C70E4E418F8FBDC52A6674429EA85FE5D046F272
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\Temp\autC0C7.tmpbinary
MD5:77BCA1747EBB2DEA2B6660350203F943
SHA256:F5CEF7AFB6F80E2E2C41336188EDF902227514FE54BA208BC69E7112EB738AD1
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\ZHP\ZHPDFileCluff_EN.txttext
MD5:D0E050EBCAB82B04C7EC9EEFD33F001A
SHA256:369208FF11F0472F00F8DAD4C01B80921AE63BF14338DCDDD093DC0406DBF946
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\Temp\autC0C6.tmpbinary
MD5:0596F61B7B4FB0FDB3FE4C7EC179AFA0
SHA256:CD28EC25E949A67CC19519695B9928F700140C2E5641FE5E722615D629961EC9
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\ZHP\ZHPDFileIcone.icoimage
MD5:2727C3D8E9CB7397C15D20B92F119DAE
SHA256:B599E310D3CD479B5DCDCD1CF8A3FB24D11D82330619094520335924BBF30E58
7524ZHPDIAG3.EXE.exeC:\Users\admin\AppData\Local\Temp\autC0E8.tmpimage
MD5:4C8FAA1DED86E4928CFF58D6779B52C9
SHA256:C12AE7F488B2A2EA888BB9FA0AF8ED219EA893B0ACC99D1C845ACDE8B46FC9D7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
27
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7896
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7180
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7180
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7896
backgroundTaskHost.exe
20.31.169.57:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.81
  • 2.16.164.32
  • 2.16.164.51
  • 2.16.164.24
  • 2.16.164.18
  • 2.16.164.34
whitelisted
google.com
  • 142.250.184.238
whitelisted
client.wns.windows.com
  • 40.115.3.253
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.129
  • 20.190.159.128
  • 20.190.159.71
  • 40.126.31.129
  • 40.126.31.0
  • 40.126.31.1
  • 20.190.159.23
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info