| File name: | zero-install.exe |
| Full analysis: | https://app.any.run/tasks/9843f272-c42c-47f1-9d75-ebf3b8653901 |
| Verdict: | Malicious activity |
| Analysis date: | July 17, 2025, 17:05:01 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | E2CEBF590053E3F6CF87B62F9179CC36 |
| SHA1: | 95033A58B1A0D237AB571F478D9987C07A55E662 |
| SHA256: | 7B7704810EA3D2F47F9BCB3C3C1DDEF0CD943105645182D5FD5F4CB23CE0A8DD |
| SSDEEP: | 49152:15LO8aVwli8Pf4rOaVlWWerIhVkQQGT+StdVCFRPKcnZ9XE4zuoEvWqirQ6KDL9/:7lB6f3hASHORPhEn6KhcuNV |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2082:07:10 01:53:17+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 4332544 |
| InitializedDataSize: | 69632 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x423ace |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.27.0.0 |
| ProductVersionNumber: | 2.27.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | Downloads and runs Zero Install optionally showing a GUI. |
| CompanyName: | zero-install |
| FileDescription: | zero-install |
| FileVersion: | 2.27.0.0 |
| InternalName: | zero-install.exe |
| LegalCopyright: | Copyright Bastian Eicher et al. |
| OriginalFileName: | zero-install.exe |
| ProductName: | Zero Install |
| ProductVersion: | 2.27.0+2ab65cd2d9cdb26edd787236b9bb03f38e2d88fc |
| AssemblyVersion: | 2.27.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 320 | "C:\Users\admin\AppData\Local\0install.net\implementations\sha256new_5GFYJ7GVDF7K4BX36N7LALFJAXFJDOYSJTSPUZU4YRQDEVRXEK3A\0install-win.exe" self deploy --batch --restart-central | C:\Users\admin\AppData\Local\0install.net\implementations\sha256new_5GFYJ7GVDF7K4BX36N7LALFJAXFJDOYSJTSPUZU4YRQDEVRXEK3A\0install-win.exe | ZeroInstall.exe | ||||||||||||
User: admin Company: 0install-win Integrity Level: MEDIUM Description: 0install-win Exit code: 0 Version: 2.26.7.0 Modules
| |||||||||||||||
| 1508 | "C:\Users\admin\AppData\Roaming\Programs\Zero Install\ZeroInstall.exe" | C:\Users\admin\AppData\Roaming\Programs\Zero Install\ZeroInstall.exe | 0install-win.exe | ||||||||||||
User: admin Company: ZeroInstall Integrity Level: MEDIUM Description: ZeroInstall Exit code: 0 Version: 2.26.7.0 Modules
| |||||||||||||||
| 2716 | "C:\Users\admin\AppData\Local\0install.net\implementations\sha256new_5GFYJ7GVDF7K4BX36N7LALFJAXFJDOYSJTSPUZU4YRQDEVRXEK3A\0install-win.exe" central | C:\Users\admin\AppData\Local\0install.net\implementations\sha256new_5GFYJ7GVDF7K4BX36N7LALFJAXFJDOYSJTSPUZU4YRQDEVRXEK3A\0install-win.exe | — | zero-install.exe | |||||||||||
User: admin Company: 0install-win Integrity Level: MEDIUM Description: 0install-win Exit code: 0 Version: 2.26.7.0 Modules
| |||||||||||||||
| 4684 | "C:\Users\admin\AppData\Local\0install.net\implementations\sha256new_5GFYJ7GVDF7K4BX36N7LALFJAXFJDOYSJTSPUZU4YRQDEVRXEK3A\ZeroInstall.exe" | C:\Users\admin\AppData\Local\0install.net\implementations\sha256new_5GFYJ7GVDF7K4BX36N7LALFJAXFJDOYSJTSPUZU4YRQDEVRXEK3A\ZeroInstall.exe | 0install-win.exe | ||||||||||||
User: admin Company: ZeroInstall Integrity Level: MEDIUM Description: ZeroInstall Exit code: 0 Version: 2.26.7.0 Modules
| |||||||||||||||
| 5012 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5300 | "C:\Users\admin\AppData\Local\Temp\zero-install.exe" | C:\Users\admin\AppData\Local\Temp\zero-install.exe | explorer.exe | ||||||||||||
User: admin Company: zero-install Integrity Level: MEDIUM Description: zero-install Exit code: 0 Version: 2.27.0.0 Modules
| |||||||||||||||
| 5848 | "C:\Users\admin\AppData\Roaming\Programs\Zero Install\0install-win.exe" run --no-wait --version 2.50.1 https://apps.0install.net/devel/git.xml | C:\Users\admin\AppData\Roaming\Programs\Zero Install\0install-win.exe | ZeroInstall.exe | ||||||||||||
User: admin Company: 0install-win Integrity Level: MEDIUM Description: 0install-win Exit code: 100 Version: 2.26.7.0 Modules
| |||||||||||||||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASMANCS |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (5300) zero-install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zero-install_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5300 | zero-install.exe | C:\Users\admin\AppData\Local\0install.net\implementations\0install-extract-22sfna3n.imk\0install.exe.config | xml | |
MD5:8DF97952B844B6CAD1D1995C69361580 | SHA256:B799601B4ABF1DDB22CE2E9F2B3D689373F4C71C630ABB1E5788FB55A9B28948 | |||
| 5300 | zero-install.exe | C:\Users\admin\AppData\Roaming\0install.net\injector\trustdb.xml | xml | |
MD5:5C5E18C07D10AD5E6D09CC56D41D46BB | SHA256:D97E0412653C77DF28C22402CF1EAB50D20F5D8119EDD7B3B869BE5488DF9330 | |||
| 5300 | zero-install.exe | C:\Users\admin\AppData\Local\0install.net\interfaces\temp.3xgb0rvq.sex.https%3a%2f%2fapps.0install.net%2f0install%2f0install-win.xml | xml | |
MD5:2A77C1B6CCB11AC987993552221F5A63 | SHA256:369E25AA9E2093EB6C8568E3695D63A32EE16CB826A41A8398DC92F528898659 | |||
| 5300 | zero-install.exe | C:\Users\admin\AppData\Local\0install.net\implementations\0install-extract-22sfna3n.imk\Common.Logging.Core.dll | executable | |
MD5:314445E176CD8CCFE3CF274C263E2CDC | SHA256:3D806326BFCE9DDACDD922BDF9C96E45DE9172F45A8A0AF4CC515381CEA01984 | |||
| 5300 | zero-install.exe | C:\Users\admin\AppData\Roaming\0install.net\injector\temp.ccg4y03s.5fq.global | text | |
MD5:A0988EBDFDB06E4A52346F9B216ABED4 | SHA256:1292D8B4435C002D50542EB57CEEA79F58A03C6394A5B829A40966C2588904BA | |||
| 5300 | zero-install.exe | C:\Users\admin\AppData\Local\0install.net\implementations\0install-extract-22sfna3n.imk\ZeroInstall.Archives.dll | executable | |
MD5:FA11B744992EC072E1D59B334EA611AA | SHA256:47EA5234008DE70E5873A878D1D4934D4DB1C3661584F3E530A673BBA140499B | |||
| 5300 | zero-install.exe | C:\Users\admin\AppData\Local\0install.net\interfaces\https%3a%2f%2fapps.0install.net%2f0install%2f0install-win.xml | xml | |
MD5:2A77C1B6CCB11AC987993552221F5A63 | SHA256:369E25AA9E2093EB6C8568E3695D63A32EE16CB826A41A8398DC92F528898659 | |||
| 5300 | zero-install.exe | C:\Users\admin\AppData\Roaming\0install.net\injector\feeds\https%3a##apps.0install.net#0install#0install-win.xml | xml | |
MD5:66F9D68860444284C6C853A661B322AC | SHA256:C533AFD5556862AA7A13464F81CFC40DB34044325D982CA1B4C0D5F86A208DF5 | |||
| 5300 | zero-install.exe | C:\Users\admin\AppData\Roaming\0install.net\injector\temp.3q0t100u.4ul.trustdb.xml | xml | |
MD5:5C5E18C07D10AD5E6D09CC56D41D46BB | SHA256:D97E0412653C77DF28C22402CF1EAB50D20F5D8119EDD7B3B869BE5488DF9330 | |||
| 5300 | zero-install.exe | C:\Users\admin\AppData\Roaming\0install.net\injector\global | text | |
MD5:A0988EBDFDB06E4A52346F9B216ABED4 | SHA256:1292D8B4435C002D50542EB57CEEA79F58A03C6394A5B829A40966C2588904BA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3948 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4224 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4224 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
2940 | svchost.exe | GET | 200 | 2.23.197.184:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
7016 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.55.110.193:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5944 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6584 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5300 | zero-install.exe | 185.199.111.153:443 | apps.0install.net | FASTLY | US | shared |
5300 | zero-install.exe | 140.82.121.3:443 | github.com | GITHUB | US | whitelisted |
5300 | zero-install.exe | 185.199.110.133:443 | release-assets.githubusercontent.com | FASTLY | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4684 | ZeroInstall.exe | 185.199.111.153:443 | apps.0install.net | FASTLY | US | shared |
3948 | svchost.exe | 40.126.31.67:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
apps.0install.net |
| unknown |
github.com |
| whitelisted |
release-assets.githubusercontent.com |
| unknown |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |