| URL: | https://www.zen-browser.app/ |
| Full analysis: | https://app.any.run/tasks/b5fbfc1a-415d-4061-a368-aa59ed7fe590 |
| Verdict: | Malicious activity |
| Analysis date: | August 30, 2024, 13:10:28 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 779EE76CF002D25B05086391A07B3778 |
| SHA1: | 741A5B316FE15F12BCB348CDF870E90F15623545 |
| SHA256: | 7DEC4B56424E2F2BA9197FEBD3518AF322C61F729423691CD097089F237C5A77 |
| SSDEEP: | 3:N8DSLo83tXwCn:2OLoigC |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 300 | "C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=5328 -childID 6 -isForBrowser -prefsHandle 1272 -prefMapHandle 4276 -prefsLen 29672 -prefMapSize 258448 -jsInitHandle 1376 -jsInitLen 234852 -parentBuildID 20240828093001 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {bc5c8486-9fa3-4569-bc00-e549c56c6ab1} 1452 tab | C:\Program Files\Zen Browser\zen.exe | — | zen.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Zen Browser Version: 129.0.2 Modules
| |||||||||||||||
| 532 | "C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=4336 -childID 3 -isForBrowser -prefsHandle 3588 -prefMapHandle 3512 -prefsLen 23612 -prefMapSize 258448 -jsInitHandle 1376 -jsInitLen 234852 -parentBuildID 20240828093001 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {227af474-661d-46fe-974e-7695bd7d6369} 1452 tab | C:\Program Files\Zen Browser\zen.exe | — | zen.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Zen Browser Exit code: 0 Version: 129.0.2 Modules
| |||||||||||||||
| 644 | "C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=3996 -parentBuildID 20240828093001 -prefsHandle 3984 -prefMapHandle 3976 -prefsLen 23728 -prefMapSize 258448 -appDir "C:\Program Files\Zen Browser\browser" - {77b06a2b-880b-4b01-b997-0bde4ec71df2} 1452 rdd | C:\Program Files\Zen Browser\zen.exe | — | zen.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Zen Browser Version: 129.0.2 Modules
| |||||||||||||||
| 1224 | "C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=3696 -childID 2 -isForBrowser -prefsHandle 3688 -prefMapHandle 3680 -prefsLen 23345 -prefMapSize 258448 -jsInitHandle 1376 -jsInitLen 234852 -parentBuildID 20240828093001 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {e4833ac7-a802-4606-96c7-27ac078d4ef6} 1452 tab | C:\Program Files\Zen Browser\zen.exe | — | zen.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Zen Browser Version: 129.0.2 Modules
| |||||||||||||||
| 1452 | "C:\Program Files\Zen Browser\zen.exe" -first-startup | C:\Program Files\Zen Browser\zen.exe | zen.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Zen Browser Version: 129.0.2 Modules
| |||||||||||||||
| 1764 | "C:\Program Files\Zen Browser\zen.exe" --backgroundtask install | C:\Program Files\Zen Browser\zen.exe | — | zen.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Zen Browser Exit code: 0 Version: 129.0.2 Modules
| |||||||||||||||
| 2024 | "C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=3340 -childID 1 -isForBrowser -prefsHandle 3332 -prefMapHandle 3324 -prefsLen 22383 -prefMapSize 258448 -jsInitHandle 1376 -jsInitLen 234852 -parentBuildID 20240828093001 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {bd9fd73e-04a0-4fd3-a3d1-c1c44ff2ae10} 1452 tab | C:\Program Files\Zen Browser\zen.exe | — | zen.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Zen Browser Exit code: 0 Version: 129.0.2 Modules
| |||||||||||||||
| 2096 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=4952 --field-trial-handle=1900,i,1510296123821093893,8232577726940474175,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 2136 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2988 --field-trial-handle=1900,i,1510296123821093893,8232577726940474175,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 2384 | "C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=4996 -childID 9 -isForBrowser -prefsHandle 4960 -prefMapHandle 5136 -prefsLen 30681 -prefMapSize 258448 -jsInitHandle 1376 -jsInitLen 234852 -parentBuildID 20240828093001 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {a0b3c07f-8d2e-4308-9f20-1e8733596e38} 1452 tab | C:\Program Files\Zen Browser\zen.exe | — | zen.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Zen Browser Version: 129.0.2 Modules
| |||||||||||||||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (4440) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF12b54e.TMP | — | |
MD5:— | SHA256:— | |||
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF12b55e.TMP | — | |
MD5:— | SHA256:— | |||
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:961E3604F228B0D10541EBF921500C86 | SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED | |||
| 4440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\0c6b4c7c-b9e5-4b01-b027-9525ae3a2d4e.tmp | binary | |
MD5:5058F1AF8388633F609CADB75A75DC9D | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1440 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7084 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
1028 | SystemSettings.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
2876 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acijrr7qbydr6hssggdavbpb736a_2024.8.29.1/kiabhabjdbkjdpjbpigfodbdjmbglcoo_2024.08.29.01_all_nw7h5ptqktkq3qyzg2r6wbaupe.crx3 | unknown | — | — | whitelisted |
2876 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acijrr7qbydr6hssggdavbpb736a_2024.8.29.1/kiabhabjdbkjdpjbpigfodbdjmbglcoo_2024.08.29.01_all_nw7h5ptqktkq3qyzg2r6wbaupe.crx3 | unknown | — | — | whitelisted |
2876 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acijrr7qbydr6hssggdavbpb736a_2024.8.29.1/kiabhabjdbkjdpjbpigfodbdjmbglcoo_2024.08.29.01_all_nw7h5ptqktkq3qyzg2r6wbaupe.crx3 | unknown | — | — | whitelisted |
2876 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acijrr7qbydr6hssggdavbpb736a_2024.8.29.1/kiabhabjdbkjdpjbpigfodbdjmbglcoo_2024.08.29.01_all_nw7h5ptqktkq3qyzg2r6wbaupe.crx3 | unknown | — | — | whitelisted |
1452 | zen.exe | GET | 200 | 23.53.40.129:80 | http://ciscobinary.openh264.org/openh264-win64-31c4d2e4a037526fd30d4e5c39f60885986cf865.zip | unknown | — | — | whitelisted |
2876 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acijrr7qbydr6hssggdavbpb736a_2024.8.29.1/kiabhabjdbkjdpjbpigfodbdjmbglcoo_2024.08.29.01_all_nw7h5ptqktkq3qyzg2r6wbaupe.crx3 | unknown | — | — | whitelisted |
1028 | SystemSettings.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6516 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1356 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3260 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4440 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
6988 | chrome.exe | 76.76.21.241:443 | www.zen-browser.app | AMAZON-02 | US | malicious |
6988 | chrome.exe | 173.194.76.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
6988 | chrome.exe | 142.250.186.164:443 | www.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
www.zen-browser.app |
| malicious |
accounts.google.com |
| whitelisted |
www.google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
cdn.jsdelivr.net |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
github.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
6988 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6988 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |