File name:

ZipThis.exe.zip

Full analysis: https://app.any.run/tasks/d62a1d2e-158a-450b-a897-b4ae303d285d
Verdict: Malicious activity
Analysis date: January 14, 2025, 23:17:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

15DB35DF8AC09548A7A9B9844143BF85

SHA1:

43F3CB6172022C5D1A537455059E92322642DC0B

SHA256:

72E86E145AA9C8AD3847144184B224ED23FFAF8D120DDDE53C20392E937D5299

SSDEEP:

98304:RZNf34+RWuF2zehSiNIwV8YIgojxuI0V/Y7DNsbdYhJ5UynXGsvKNPUko90m7D9U:CLfKRm6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2956)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ZipThis.exe (PID: 6844)
      • ZipThis.exe (PID: 7064)
    • Application launched itself

      • ZipThis.exe (PID: 6844)
    • Executable content was dropped or overwritten

      • ZipThis.exe (PID: 7064)
    • Searches for installed software

      • ZipThis.exe (PID: 7064)
    • Reads the date of Windows installation

      • ZipThis.exe (PID: 7064)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 2956)
      • ZipThis.exe (PID: 6844)
      • ZipThis.exe (PID: 7064)
    • Reads Environment values

      • ZipThis.exe (PID: 6844)
      • ZipThisApp.exe (PID: 5576)
      • ZipThisApp.exe (PID: 2800)
    • Disables trace logs

      • ZipThis.exe (PID: 6844)
      • ZipThisApp.exe (PID: 5576)
    • Reads the machine GUID from the registry

      • ZipThis.exe (PID: 6844)
      • ZipThis.exe (PID: 7064)
      • ZipThisApp.exe (PID: 5576)
      • ZipThisApp.exe (PID: 2800)
    • Checks supported languages

      • ZipThis.exe (PID: 6844)
      • ZipThis.exe (PID: 7064)
      • ZipThisApp.exe (PID: 5576)
    • Manual execution by a user

      • ZipThis.exe (PID: 6844)
      • ZipThisApp.exe (PID: 2800)
    • Reads the software policy settings

      • ZipThis.exe (PID: 6844)
      • ZipThis.exe (PID: 7064)
      • ZipThisApp.exe (PID: 2800)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2956)
    • Creates files in the program directory

      • ZipThis.exe (PID: 7064)
    • Reads the computer name

      • ZipThisApp.exe (PID: 5576)
    • Process checks computer location settings

      • ZipThis.exe (PID: 7064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2025:01:14 22:07:22
ZipCRC: 0x1c470906
ZipCompressedSize: 1811512
ZipUncompressedSize: 2821416
ZipFileName: ZipThis.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs zipthis.exe zipthis.exe zipthisapp.exe zipthisapp.exe

Process information

PID
CMD
Path
Indicators
Parent process
2800"C:\Program Files\ZipThis\ZipThisApp.exe" C:\Program Files\ZipThis\ZipThisApp.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ZipThisApp
Exit code:
0
Version:
9.10.100.100
Modules
Images
c:\program files\zipthis\zipthisapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2956"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\ZipThis.exe.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5576"C:\Program Files\ZipThis\ZipThisApp.exe" C:\Program Files\ZipThis\ZipThisApp.exe
ZipThis.exe
User:
admin
Integrity Level:
HIGH
Description:
ZipThisApp
Exit code:
0
Version:
9.10.100.100
Modules
Images
c:\program files\zipthis\zipthisapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6808C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6844"C:\Users\admin\Desktop\ZipThis.exe\ZipThis.exe" C:\Users\admin\Desktop\ZipThis.exe\ZipThis.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ZipThis
Exit code:
0
Version:
10.1.27.104
Modules
Images
c:\users\admin\desktop\zipthis.exe\zipthis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7064"C:\Users\admin\Desktop\ZipThis.exe\ZipThis.exe" -hcC:\Users\admin\Desktop\ZipThis.exe\ZipThis.exe
ZipThis.exe
User:
admin
Integrity Level:
HIGH
Description:
ZipThis
Exit code:
0
Version:
10.1.27.104
Modules
Images
c:\users\admin\desktop\zipthis.exe\zipthis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
8 529
Read events
8 456
Write events
60
Delete events
13

Modification events

(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\ZipThis.exe.zip
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:1
Value:
C:\Users\admin\Desktop\ext
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\ZipThis.exe
Executable files
3
Suspicious files
1
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
7064ZipThis.exeC:\Program Files\ZipThis\BaseV4.Belongings.favicon.icoimage
MD5:445F0C73332D5E55BD49681AD990527F
SHA256:AA354C95608D65898F835859327344D7B5342CC92AEEDC763D003C982F3AD286
7064ZipThis.exeC:\Program Files\ZipThis\zipthisUserId.txttext
MD5:015DAA018A888B5BD34EF37B83931B05
SHA256:43CFD46ACE299EB873AF2D3B01964726038E21E06BB44E86219C650F78B56F90
7064ZipThis.exeC:\Program Files\ZipThis\Uninstall.exeexecutable
MD5:C8D7C3648853C541B6AFE9F2F647FEAF
SHA256:F933937BDAF0DB26DEDB3EDD7C214F573D78D1738C69FCF47FC488C9849D99C0
6844ZipThis.exeC:\Users\admin\AppData\Local\ZipThis\zipthisUserId.txttext
MD5:015DAA018A888B5BD34EF37B83931B05
SHA256:43CFD46ACE299EB873AF2D3B01964726038E21E06BB44E86219C650F78B56F90
2956WinRAR.exeC:\Users\admin\Desktop\ZipThis.exe\checksums.txttext
MD5:105C3FD4A3484D0D4E134222DDEC0DC5
SHA256:1FE615E15F64F189E86AEA7A32A22DC65DA6CC1671AE464D13376C956A9B9D5A
6844ZipThis.exeC:\Users\admin\AppData\Roaming\SMCR\userId.txttext
MD5:015DAA018A888B5BD34EF37B83931B05
SHA256:43CFD46ACE299EB873AF2D3B01964726038E21E06BB44E86219C650F78B56F90
7064ZipThis.exeC:\Program Files\ZipThis\ZipThisApp.exeexecutable
MD5:5E53D108E91A1C46C0286243B5CB9EE9
SHA256:556124A66C705DCE7F724AA3E3CADCA90675CC0D65284B73D15F1F37BC409206
7064ZipThis.exeC:\Users\admin\Desktop\ZipThisApp.lnkbinary
MD5:F0EF4FA436ADEC4E90420F9DAF03ACA5
SHA256:3D52FECD89BB2E9AB82BED26B4D1C04B57F2C61D7F6E7AA68BA97B59E491C2D8
2956WinRAR.exeC:\Users\admin\Desktop\ZipThis.exe\ZipThis.exeexecutable
MD5:34E759DF0CB0BF304C9FD1D6B9631BCE
SHA256:7D607EE9ACBB7C4747B79F4E891736AD4AB30BF7BBF9B3519CA2B6E6553766DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
38
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6324
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3620
SIHClient.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3620
SIHClient.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3220
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
23.218.209.163:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 23.218.209.163
whitelisted
google.com
  • 142.250.186.174
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.138
  • 40.126.32.74
  • 40.126.32.133
  • 40.126.32.134
  • 40.126.32.72
  • 40.126.32.136
  • 40.126.32.140
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
apb.thisilient.com
  • 45.33.84.9
unknown
arc.msn.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
No debug info