URL:

https://us05web.zoom.us/j/83380604802?pwd=RnpEeWV6djZCTVNXWVU2NUZGNDJqQT09

Full analysis: https://app.any.run/tasks/f1f1c4dc-4d7a-4654-828f-96c8adc90a6c
Verdict: Malicious activity
Analysis date: March 23, 2021, 00:04:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

045A07CA2BCF20301FE1508D57BE4D8F

SHA1:

D9690BC1830ECCFAB6BAD30DF1924711AEDAAC9F

SHA256:

6970CEBCEB60E8FB93207F33CD98F5496DA0DA161D6C1B6B06ACBF06A8792AEC

SSDEEP:

3:N8+rRILQN5WXTZVOS42Ayszz7w0M0Q:2+V9GCS42Abn0T0Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe (PID: 3252)
      • Installer.exe (PID: 2268)
      • Installer.exe (PID: 2940)
      • zmEA8D.tmp (PID: 2480)
      • Zoom.exe (PID: 2356)
      • Zoom.exe (PID: 4016)
      • Zoom.exe (PID: 2940)
      • Zoom.exe (PID: 852)
    • Changes settings of System certificates

      • Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe (PID: 3252)
    • Loads dropped or rewritten executable

      • Installer.exe (PID: 2268)
      • Zoom.exe (PID: 852)
      • Zoom.exe (PID: 4016)
      • Zoom.exe (PID: 2940)
      • Zoom.exe (PID: 2356)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2548)
      • Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe (PID: 3252)
      • Installer.exe (PID: 2268)
    • Creates files in the user directory

      • Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe (PID: 3252)
      • Zoom.exe (PID: 852)
      • Zoom.exe (PID: 2940)
      • Installer.exe (PID: 2268)
    • Drops a file that was compiled in debug mode

      • chrome.exe (PID: 2548)
      • Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe (PID: 3252)
      • Installer.exe (PID: 2268)
    • Drops a file with a compile date too recent

      • Installer.exe (PID: 2268)
      • Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe (PID: 3252)
    • Adds / modifies Windows certificates

      • Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe (PID: 3252)
    • Drops a file with too old compile date

      • Installer.exe (PID: 2268)
    • Application launched itself

      • Installer.exe (PID: 2268)
      • Zoom.exe (PID: 852)
    • Changes default file association

      • Installer.exe (PID: 2268)
    • Creates a software uninstall entry

      • Installer.exe (PID: 2268)
    • Changes IE settings (feature browser emulation)

      • Installer.exe (PID: 2268)
    • Starts itself from another location

      • Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe (PID: 3252)
    • Starts application with an unusual extension

      • Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe (PID: 3252)
  • INFO

    • Reads the hosts file

      • chrome.exe (PID: 2548)
      • chrome.exe (PID: 1516)
    • Application launched itself

      • chrome.exe (PID: 2548)
    • Dropped object may contain Bitcoin addresses

      • Installer.exe (PID: 2268)
    • Reads settings of System Certificates

      • chrome.exe (PID: 2548)
      • chrome.exe (PID: 1516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
22
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs zoom_cm_fo42mnktz9vvrzo4_mm38alp6r3aoxmrtldfzdnviazawbyaltozm3@fqn06kiupwanwcj7_k06100581310f1f59_.exe chrome.exe no specs installer.exe installer.exe zoom.exe zmea8d.tmp no specs chrome.exe no specs zoom.exe chrome.exe no specs chrome.exe no specs zoom.exe zoom.exe

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=992,3970324009143107087,18433538490252259088,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=17477429842762214061 --mojo-platform-channel-handle=1008 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
832"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2436 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
852"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe" "--url=zoommtg://win.launch?h.domain=us05web.zoom.us&h.path=join&confid=dXNzPXRMclNQWE9HazE0enM4bUNySWJYUUV0d0hqN2djV2FXQ1ZpRWJXdndIQksybEdqSWV3Rlc2c0dUNnpmNTFxLU5iNkFUOVQxbW8xQ3E4U0h5OU1xQUZpeGh5YmIzUFFRcy5GdkZEUk1DR1hwenlhSFZBJnRpZD1hOTFkZDRkZWNjYTc0YTAyOWEzNTUyNjM2ZmVlNTc3ZA%3D%3D&mcv=0.92.11227.0929&stype=0&zc=0&browser=chrome&action=join&confno=83380604802&pwd=RnpEeWV6djZCTVNXWVU2NUZGNDJqQT09"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Meetings
Exit code:
0
Version:
5,5,13142,0301
Modules
Images
c:\users\admin\appdata\roaming\zoom\bin\zoom.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\zoom\bin\dllsafecheck.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1516"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=992,3970324009143107087,18433538490252259088,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=11738043791486849851 --mojo-platform-channel-handle=1440 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1980"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,3970324009143107087,18433538490252259088,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5147331813108242693 --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2356 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2096"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,3970324009143107087,18433538490252259088,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5442631975100997689 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2168 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2244"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=992,3970324009143107087,18433538490252259088,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=18051473211959486608 --mojo-platform-channel-handle=980 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2268"C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe" ZInstaller --conf.mode=silent --ipc_wnd=131438C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe
Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Installer
Exit code:
0
Version:
5,5,13142,0301
Modules
Images
c:\users\admin\appdata\roaming\zoom\zoomdownload\installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2320"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,3970324009143107087,18433538490252259088,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12507539498331038503 --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3232 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2344"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=992,3970324009143107087,18433538490252259088,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=9247698096341252802 --mojo-platform-channel-handle=4464 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
2 304
Read events
2 112
Write events
186
Delete events
6

Modification events

(PID) Process:(2548) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2548) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2548) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2548) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(832) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:2548-13260931456675125
Value:
259
(PID) Process:(2548) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2548) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2548) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2548) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3252-13245750958665039
Value:
0
(PID) Process:(2548) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
155
Suspicious files
38
Text files
93
Unknown types
3

Dropped files

PID
Process
Filename
Type
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-60593081-9F4.pma
MD5:
SHA256:
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old
MD5:
SHA256:
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp
MD5:
SHA256:
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\15dcb59b-9f2e-4a4c-a547-151b139ab6f5.tmp
MD5:
SHA256:
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF48614.TMPtext
MD5:
SHA256:
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENTtext
MD5:
SHA256:
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF4850b.TMPtext
MD5:
SHA256:
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
2548chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF486ef.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
25
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3252
Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1516
chrome.exe
3.235.83.191:443
us05web.zoom.us
US
unknown
13.32.21.59:443
static.ada.support
Amazon.com, Inc.
US
unknown
1516
chrome.exe
172.217.16.141:443
accounts.google.com
Google Inc.
US
suspicious
1516
chrome.exe
143.204.209.107:443
st1.zoom.us
US
unknown
65.9.58.44:443
zoom.ada.support
AT&T Services, Inc.
US
unknown
1516
chrome.exe
172.217.19.110:443
sb-ssl.google.com
Google Inc.
US
whitelisted
3252
Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe
3.235.83.191:443
us05web.zoom.us
US
unknown
1516
chrome.exe
172.217.20.3:443
ssl.gstatic.com
Google Inc.
US
whitelisted
1516
chrome.exe
65.9.58.7:443
rollout.ada.support
AT&T Services, Inc.
US
unknown
3252
Zoom_cm_fo42mnktZ9vvrZo4_mM38aLp6R3aOXMrtldFZdnviAZaWbYaLtoZM3@Fqn06kiuPwAnWcJ7_k06100581310f1f59_.exe
143.204.209.55:443
cdn.zoom.us
US
suspicious

DNS requests

Domain
IP
Reputation
us05web.zoom.us
  • 3.235.83.191
suspicious
accounts.google.com
  • 172.217.16.141
shared
static.ada.support
  • 13.32.21.59
  • 13.32.21.123
  • 13.32.21.33
  • 13.32.21.8
whitelisted
safebrowsing.googleapis.com
  • 172.217.20.10
whitelisted
st1.zoom.us
  • 143.204.209.107
  • 143.204.209.119
  • 143.204.209.57
  • 143.204.209.18
whitelisted
rollout.ada.support
  • 65.9.58.7
  • 65.9.58.74
  • 65.9.58.101
  • 65.9.58.96
shared
zoom.ada.support
  • 65.9.58.44
  • 65.9.58.69
  • 65.9.58.19
  • 65.9.58.14
whitelisted
sb-ssl.google.com
  • 172.217.19.110
whitelisted
ssl.gstatic.com
  • 172.217.20.3
whitelisted
cdn.zoom.us
  • 143.204.209.55
  • 143.204.209.115
  • 143.204.209.104
  • 143.204.209.75
whitelisted

Threats

No threats detected
Process
Message
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\zoom_install_src
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\zoom_install_src
Installer.exe
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\tmp_uninstall
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\tmp_uninstall
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is: