File name:

your_file.zip

Full analysis: https://app.any.run/tasks/3aa7f9ec-a622-49f8-beeb-48cc871a2c5d
Verdict: Malicious activity
Analysis date: January 21, 2024, 03:25:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C661D74D59CE778783E81968549E5F44

SHA1:

F56626C19DB62C17E74FA15151626D68877824AC

SHA256:

65FA77C5EFB0B01B7E7D959B1A058DD5EEECB9C5BC505BBDF4648C43A56CE50E

SSDEEP:

98304:8jLf3ybjIOkhotuVNoW+x2Rw4H0DgD5CfsuL4vScBIofrYQMYzffu4tv3ECp2yY7:SBVs3Ws

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • passfab-for-zip.exe (PID: 2112)
      • passfab-for-zip.exe (PID: 1956)
      • passfab-for-zip.tmp (PID: 2892)
      • passfab-for-zip.tmp (PID: 2916)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • passfab-for-zip.exe (PID: 2112)
      • passfab-for-zip.exe (PID: 1956)
      • passfab-for-zip.tmp (PID: 2916)
      • passfab-for-zip.tmp (PID: 2892)
    • Reads the Windows owner or organization settings

      • passfab-for-zip.tmp (PID: 2916)
      • passfab-for-zip.tmp (PID: 2892)
    • Reads the Internet Settings

      • passfab-for-zip.tmp (PID: 2916)
      • PassFab for ZIP.exe (PID: 3248)
    • Reads settings of System Certificates

      • passfab-for-zip.tmp (PID: 2916)
    • Drops 7-zip archiver for unpacking

      • passfab-for-zip.tmp (PID: 2916)
    • Reads security settings of Internet Explorer

      • passfab-for-zip.tmp (PID: 2916)
    • Checks Windows Trust Settings

      • passfab-for-zip.tmp (PID: 2916)
    • Checks for external IP

      • passfab-for-zip.tmp (PID: 2916)
    • Process drops legitimate windows executable

      • passfab-for-zip.tmp (PID: 2916)
    • Searches for installed software

      • PassFab for ZIP.exe (PID: 3248)
    • Starts CMD.EXE for commands execution

      • PassFab for ZIP.exe (PID: 3248)
  • INFO

    • Manual execution by a user

      • passfab-for-zip.exe (PID: 2072)
      • passfab-for-zip.exe (PID: 1540)
      • passfab-for-zip.exe (PID: 1264)
      • passfab-for-zip.exe (PID: 2128)
      • passfab-for-zip.exe (PID: 1604)
      • passfab-for-zip.exe (PID: 1864)
      • passfab-for-zip.exe (PID: 2340)
      • passfab-for-zip.exe (PID: 2384)
      • passfab-for-zip.exe (PID: 148)
      • passfab-for-zip.exe (PID: 980)
      • passfab-for-zip.exe (PID: 2112)
      • passfab-for-zip.exe (PID: 2896)
      • passfab-for-zip.exe (PID: 1956)
      • WinRAR.exe (PID: 884)
      • PassFab for ZIP.exe (PID: 3116)
      • PassFab for ZIP.exe (PID: 3248)
      • msedge.exe (PID: 3504)
    • Checks supported languages

      • passfab-for-zip.exe (PID: 1604)
      • passfab-for-zip.exe (PID: 1264)
      • passfab-for-zip.exe (PID: 1540)
      • passfab-for-zip.exe (PID: 2384)
      • passfab-for-zip.exe (PID: 148)
      • passfab-for-zip.exe (PID: 2112)
      • passfab-for-zip.tmp (PID: 2892)
      • passfab-for-zip.exe (PID: 1956)
      • passfab-for-zip.tmp (PID: 2916)
      • PassFab for ZIP.exe (PID: 3248)
      • zip2john.exe (PID: 664)
      • john.exe (PID: 3548)
      • john.exe (PID: 3972)
      • john.exe (PID: 3764)
      • john.exe (PID: 3600)
      • john.exe (PID: 2100)
      • john.exe (PID: 2884)
      • john.exe (PID: 2512)
    • Create files in a temporary directory

      • passfab-for-zip.exe (PID: 2112)
      • passfab-for-zip.exe (PID: 1956)
      • passfab-for-zip.tmp (PID: 2916)
      • passfab-for-zip.tmp (PID: 2892)
      • PassFab for ZIP.exe (PID: 3248)
      • john.exe (PID: 3600)
      • john.exe (PID: 3972)
      • john.exe (PID: 3764)
      • john.exe (PID: 2100)
      • john.exe (PID: 2884)
      • john.exe (PID: 2512)
    • Creates files or folders in the user directory

      • passfab-for-zip.tmp (PID: 2916)
    • Reads the computer name

      • passfab-for-zip.tmp (PID: 2916)
      • passfab-for-zip.tmp (PID: 2892)
      • PassFab for ZIP.exe (PID: 3248)
      • john.exe (PID: 3972)
      • zip2john.exe (PID: 664)
      • john.exe (PID: 3548)
      • john.exe (PID: 3600)
      • john.exe (PID: 3764)
      • john.exe (PID: 2100)
      • john.exe (PID: 2884)
      • john.exe (PID: 2512)
    • Checks proxy server information

      • passfab-for-zip.tmp (PID: 2916)
    • Creates files in the program directory

      • passfab-for-zip.tmp (PID: 2916)
      • PassFab for ZIP.exe (PID: 3248)
      • john.exe (PID: 3600)
      • john.exe (PID: 3972)
      • john.exe (PID: 3764)
    • Reads the machine GUID from the registry

      • passfab-for-zip.tmp (PID: 2916)
      • PassFab for ZIP.exe (PID: 3248)
    • Application launched itself

      • msedge.exe (PID: 3232)
      • msedge.exe (PID: 3504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:01:20 22:38:32
ZipCRC: 0xc9e9bb69
ZipCompressedSize: 3415
ZipUncompressedSize: 782838
ZipFileName: password.jpg
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
109
Monitored processes
44
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe no specs passfab-for-zip.exe no specs passfab-for-zip.exe passfab-for-zip.exe no specs passfab-for-zip.exe passfab-for-zip.exe no specs passfab-for-zip.exe passfab-for-zip.exe no specs passfab-for-zip.exe passfab-for-zip.exe passfab-for-zip.exe no specs passfab-for-zip.exe passfab-for-zip.tmp passfab-for-zip.exe no specs passfab-for-zip.exe passfab-for-zip.tmp winrar.exe no specs passfab for zip.exe no specs passfab for zip.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cmd.exe no specs zip2john.exe no specs john.exe no specs john.exe no specs john.exe no specs john.exe no specs john.exe no specs john.exe no specs john.exe no specs john.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2308 --field-trial-handle=1324,i,9521769580893620097,17395907571657435531,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
128"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\your_file.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
148"C:\Users\admin\Desktop\passfab-for-zip.exe" C:\Users\admin\Desktop\passfab-for-zip.exe
explorer.exe
User:
admin
Company:
PassFab, Inc.
Integrity Level:
HIGH
Description:
PassFab for ZIP Setup
Exit code:
1
Version:
Modules
Images
c:\users\admin\desktop\passfab-for-zip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
324"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1428 --field-trial-handle=1324,i,9521769580893620097,17395907571657435531,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
664"C:\Program Files\PassFab for ZIP\john\plan1\zip2john.exe" "C:\ziptmp.zip" C:\Program Files\PassFab for ZIP\john\plan1\zip2john.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\passfab for zip\john\plan1\zip2john.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\passfab for zip\john\plan1\cygwin1.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
884"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\your_file.zip" C:\Users\admin\Desktop\your_file\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
956"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1484 --field-trial-handle=1324,i,9521769580893620097,17395907571657435531,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
980"C:\Users\admin\Desktop\passfab-for-zip.exe" C:\Users\admin\Desktop\passfab-for-zip.exeexplorer.exe
User:
admin
Company:
PassFab, Inc.
Integrity Level:
MEDIUM
Description:
PassFab for ZIP Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\desktop\passfab-for-zip.exe
c:\windows\system32\ntdll.dll
1232"C:\Windows\System32\cmd.exe" /c ""C:\Program Files\PassFab for ZIP\john\plan1\zip2john.exe" "C:\ziptmp.zip" > "C:\Users\admin\AppData\Local\Temp\temp.hash""C:\Windows\System32\cmd.exePassFab for ZIP.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1264"C:\Users\admin\Desktop\passfab-for-zip.exe" C:\Users\admin\Desktop\passfab-for-zip.exe
explorer.exe
User:
admin
Company:
PassFab, Inc.
Integrity Level:
HIGH
Description:
PassFab for ZIP Setup
Exit code:
1
Version:
Modules
Images
c:\users\admin\desktop\passfab-for-zip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
12 287
Read events
12 121
Write events
165
Delete events
1

Modification events

(PID) Process:(128) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
141
Suspicious files
98
Text files
305
Unknown types
0

Dropped files

PID
Process
Filename
Type
2112passfab-for-zip.exeC:\Users\admin\AppData\Local\Temp\is-P8999.tmp\passfab-for-zip.tmpexecutable
MD5:507B5870D106E5746C4A1328DD008973
SHA256:244891F4A30401C8727B72D10F081E340EE147972E3C86A403B7C8674C876B32
1956passfab-for-zip.exeC:\Users\admin\AppData\Local\Temp\is-I8IEB.tmp\passfab-for-zip.tmpexecutable
MD5:507B5870D106E5746C4A1328DD008973
SHA256:244891F4A30401C8727B72D10F081E340EE147972E3C86A403B7C8674C876B32
2916passfab-for-zip.tmpC:\Program Files\PassFab for ZIP\is-0H007.tmpexecutable
MD5:22E71692E58F514E97000F1917C1D690
SHA256:C89DC5B66FBD310F0A12B0A0F0606A37BA5268B53523208E384090E97DE194A3
2916passfab-for-zip.tmpC:\Program Files\PassFab for ZIP\errordump.dllexecutable
MD5:1DB13A9006CEE9C055A10E0EF0EDB6A4
SHA256:4FE09AFDB3BF9E4AE3692D978D9CCF94908E0DA4FF609FB7872CEFB025E438D9
2916passfab-for-zip.tmpC:\Program Files\PassFab for ZIP\unins000.exeexecutable
MD5:F37284AE127C415D4EAD3AC3A756FBBA
SHA256:F258523CA0F1728634E4A6014DA952511DD6B17C8E52B3B661CD6E2462C11C4F
2916passfab-for-zip.tmpC:\Program Files\PassFab for ZIP\is-42RQR.tmpexecutable
MD5:1E2D2D7BFD4C99923DEFBBA57EA6A939
SHA256:7C826F84BAC8BEECEDD61203A73B891986722BC137B11C001EF7485846FD2732
2916passfab-for-zip.tmpC:\Program Files\PassFab for ZIP\is-4RM8I.tmptext
MD5:24DF3D2EAD9720670E32F52B088F4BE7
SHA256:F42EEA598FB2481311578DEE7F38AE3506E8A4B5994009685D1AA242930A1CDC
2916passfab-for-zip.tmpC:\Users\admin\AppData\Local\Temp\is-GN0SL.tmp\SoftwareLog1.dllexecutable
MD5:5F236BC79AF30D9A703E76CF06458CEC
SHA256:639892E93EEE182EAC88CE1BE23DF1A3C01130686C32D47F85728E6B332602D5
2916passfab-for-zip.tmpC:\Program Files\PassFab for ZIP\deviceQuery.exeexecutable
MD5:6CCC9CCC39AC097D0C9B21B8F0453C03
SHA256:22F5347B955388F6514A2B4AF6AB71102E33ACCAD9C1D5BEA1FA1C88114B1A4B
2916passfab-for-zip.tmpC:\Program Files\PassFab for ZIP\BugSplatRc.dllexecutable
MD5:22E71692E58F514E97000F1917C1D690
SHA256:C89DC5B66FBD310F0A12B0A0F0606A37BA5268B53523208E384090E97DE194A3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
42
DNS requests
59
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2916
passfab-for-zip.tmp
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
2916
passfab-for-zip.tmp
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
US
binary
471 b
unknown
2916
passfab-for-zip.tmp
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?65611f51d605a421
GB
compressed
4.66 Kb
unknown
2916
passfab-for-zip.tmp
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
2916
passfab-for-zip.tmp
GET
521
172.67.179.206:8080
http://recoverlostpassword.com:8080/AddUserInfo?guid=55AA7432-8372-4E18-B48D-A5C70714DC78&IP=192.168.100.57&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40
US
html
6.72 Kb
unknown
2916
passfab-for-zip.tmp
GET
200
208.95.112.1:80
http://ip-api.com/csv
US
text
155 b
unknown
2916
passfab-for-zip.tmp
GET
172.67.179.206:8080
http://recoverlostpassword.com:8080/AddUserInfo?guid=D0F3F69D-6D5F-447E-B885-882E1ADFE3C1&IP=192.168.100.57&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40
US
unknown
2916
passfab-for-zip.tmp
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
2916
passfab-for-zip.tmp
GET
172.67.179.206:8080
http://recoverlostpassword.com:8080/AddUserInfo?guid=9513A371-FFB6-41D6-B34F-6E9BFCA10E64&IP=192.168.100.57&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40
US
unknown
3248
PassFab for ZIP.exe
POST
200
142.250.185.78:80
http://www.google-analytics.com/collect
US
image
35 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2916
passfab-for-zip.tmp
104.18.24.249:80
www.tenorshare.com
CLOUDFLARENET
unknown
2916
passfab-for-zip.tmp
104.18.24.249:443
www.tenorshare.com
CLOUDFLARENET
unknown
2916
passfab-for-zip.tmp
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2916
passfab-for-zip.tmp
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2916
passfab-for-zip.tmp
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
2916
passfab-for-zip.tmp
172.67.179.206:8080
recoverlostpassword.com
CLOUDFLARENET
US
unknown
3248
PassFab for ZIP.exe
142.250.185.78:80
www.google-analytics.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
www.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ip-api.com
  • 208.95.112.1
shared
recoverlostpassword.com
  • 172.67.179.206
  • 104.21.56.69
whitelisted
www.google-analytics.com
  • 142.250.185.78
whitelisted
cbs.passfab.com
  • 104.18.25.142
  • 104.18.24.142
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.23.107.164
whitelisted

Threats

PID
Process
Class
Message
2916
passfab-for-zip.tmp
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2916
passfab-for-zip.tmp
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2916
passfab-for-zip.tmp
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
2916
passfab-for-zip.tmp
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
7 ETPRO signatures available at the full report
No debug info