File name:

winzip.exe

Full analysis: https://app.any.run/tasks/3c79600d-848c-4ed7-9654-fff1541d1a2f
Verdict: Malicious activity
Analysis date: October 15, 2019, 00:45:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1828F174D1DC0E479F659756E3AD8A72

SHA1:

8A9F8E2BA671EC0D5E19EF612DF7CE7950D600D2

SHA256:

80AABFCC6EE5E98A9CC7F949E141019E353EBB941C1FDBC1FDFEDC50F5B42462

SSDEEP:

24576:KZbDbHvHRCG+YF8JmiyeVnnZNXMICDmJo03oT1KJV:eHvHn+YF8JmiyeVnnZNcIdJx3oTwJV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CloseFAH.exe (PID: 2448)
      • WzCABCacheSyncHelper32.exe (PID: 4000)
      • adxregistrator.exe (PID: 2828)
      • adxregistrator.exe (PID: 2776)
      • FAHWindow32.exe (PID: 4068)
      • FAHConsole.exe (PID: 3224)
      • WzBGTComServer32.exe (PID: 2480)
      • WzCABCacheSyncHelper32.exe (PID: 2860)
      • WzBGTools32.exe (PID: 3928)
      • WzPreloader.exe (PID: 1972)
      • WzPreviewer32.exe (PID: 3880)
      • WZUpdateNotifier.exe (PID: 3244)
      • WzCABCacheSyncHelper32.exe (PID: 1992)
    • Loads dropped or rewritten executable

      • svchost.exe (PID: 864)
      • WzCABCacheSyncHelper32.exe (PID: 4000)
      • csrss.exe (PID: 404)
      • winzip32.exe (PID: 3468)
      • adxregistrator.exe (PID: 2828)
      • adxregistrator.exe (PID: 2776)
      • winzip32.exe (PID: 1708)
      • FAHWindow32.exe (PID: 4068)
      • explorer.exe (PID: 352)
      • WzCABCacheSyncHelper32.exe (PID: 2860)
      • WzBGTools32.exe (PID: 3928)
      • winzip32.exe (PID: 2380)
      • WzCABCacheSyncHelper32.exe (PID: 1992)
    • Writes to a start menu file

      • msiexec.exe (PID: 4016)
    • Runs injected code in another process

      • FAHWindow32.exe (PID: 4068)
    • Application was injected by another process

      • explorer.exe (PID: 352)
    • Loads the Task Scheduler COM API

      • winzip32.exe (PID: 1708)
      • schtasks.exe (PID: 3824)
      • schtasks.exe (PID: 4076)
      • schtasks.exe (PID: 3324)
    • Uses Task Scheduler to run other applications

      • MsiExec.exe (PID: 3424)
    • Loads the Task Scheduler DLL interface

      • winzip32.exe (PID: 1708)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • winzip.exe (PID: 3700)
      • MsiExec.exe (PID: 3424)
      • msiexec.exe (PID: 4016)
      • winzip32.exe (PID: 2380)
    • Creates files in the program directory

      • winzip.exe (PID: 1160)
      • winzip32.exe (PID: 3468)
      • winzip32.exe (PID: 1708)
    • Reads internet explorer settings

      • winzip.exe (PID: 1160)
      • winzip32.exe (PID: 2380)
    • Modifies the open verb of a shell class

      • winzip32.exe (PID: 3468)
      • msiexec.exe (PID: 4016)
      • winzip32.exe (PID: 1708)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 4016)
    • Changes IE settings (feature browser emulation)

      • MsiExec.exe (PID: 4052)
      • msiexec.exe (PID: 4016)
    • Creates files in the user directory

      • winzip32.exe (PID: 3468)
      • winzip32.exe (PID: 1708)
      • winzip32.exe (PID: 2380)
    • Creates a software uninstall entry

      • winzip32.exe (PID: 3468)
    • Loads DLL from Mozilla Firefox

      • csrss.exe (PID: 404)
    • Creates COM task schedule object

      • winzip32.exe (PID: 3468)
      • adxregistrator.exe (PID: 2828)
      • adxregistrator.exe (PID: 2776)
      • MsiExec.exe (PID: 4052)
    • Creates files in the Windows directory

      • svchost.exe (PID: 864)
    • Starts Internet Explorer

      • explorer.exe (PID: 352)
    • Reads Internet Cache Settings

      • winzip32.exe (PID: 2380)
      • explorer.exe (PID: 352)
    • Reads Environment values

      • winzip32.exe (PID: 2380)
    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 1560)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3424)
      • msiexec.exe (PID: 4016)
    • Application launched itself

      • msiexec.exe (PID: 4016)
      • iexplore.exe (PID: 3148)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 4016)
    • Dropped object may contain Bitcoin addresses

      • msiexec.exe (PID: 4016)
    • Creates files in the program directory

      • msiexec.exe (PID: 4016)
      • MsiExec.exe (PID: 4052)
    • Reads Microsoft Office registry keys

      • adxregistrator.exe (PID: 2828)
      • adxregistrator.exe (PID: 2776)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2932)
    • Changes internet zones settings

      • iexplore.exe (PID: 3148)
    • Reads settings of System Certificates

      • winzip32.exe (PID: 2380)
      • iexplore.exe (PID: 2932)
    • Creates files in the user directory

      • iexplore.exe (PID: 2932)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 1560)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2932)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3148)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:08:15 14:48:12+02:00
PEType: PE32
LinkerVersion: 14
CodeSize: 519168
InitializedDataSize: 196096
UninitializedDataSize: -
EntryPoint: 0x4ece0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 24.0.13543.0
ProductVersionNumber: 24.0.13543.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: WinZip Computing
FileDescription: WinZipStub Installer
FileVersion: 24.0.13543.0
InternalName: WinZipStubInstaller.exe
LegalCopyright: (c) 2015-2019 Corel Corporation All rights reserved.
ProductName: WinZipStub
ProductVersion: 24.0.13543.0

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 15-Aug-2019 12:48:12
Detected languages:
  • English - United States
CompanyName: WinZip Computing
FileDescription: WinZipStub Installer
FileVersion: 24.0.13543.0
InternalName: WinZipStubInstaller.exe
LegalCopyright: (c) 2015-2019 Corel Corporation All rights reserved.
ProductName: WinZipStub
ProductVersion: 24.0.13543.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000118

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 7
Time date stamp: 15-Aug-2019 12:48:12
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0007EB3C
0x0007EC00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.61195
.rdata
0x00080000
0x0002005A
0x00020200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.97357
.data
0x000A1000
0x00003BCC
0x00002E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.69667
.gfids
0x000A5000
0x000007CC
0x00000800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.97267
.tls
0x000A6000
0x00000009
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.0203931
.rsrc
0x000A7000
0x00004E58
0x00005000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.53812
.reloc
0x000AC000
0x000065F4
0x00006600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.62785

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.16947
2013
UNKNOWN
English - United States
RT_MANIFEST
101
1.91924
20
UNKNOWN
English - United States
RT_GROUP_ICON

Imports

ADVAPI32.dll
KERNEL32.dll
RPCRT4.dll
USER32.dll (delay-loaded)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
31
Malicious processes
16
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start inject winzip.exe winzip.exe msiexec.exe msiexec.exe closefah.exe no specs msiexec.exe no specs wzpreviewer32.exe no specs wzpreloader.exe no specs winzip32.exe no specs svchost.exe wzcabcachesynchelper32.exe csrss.exe no specs fahconsole.exe no specs fahwindow32.exe no specs adxregistrator.exe no specs adxregistrator.exe no specs explorer.exe winzip32.exe no specs wzcabcachesynchelper32.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs wzbgtcomserver32.exe no specs wzupdatenotifier.exe no specs wzbgtools32.exe no specs iexplore.exe iexplore.exe winzip32.exe wzcabcachesynchelper32.exe no specs flashutil32_26_0_0_131_activex.exe no specs winzip.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
352C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
404%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\System32\csrss.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Client Server Runtime Process
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\csrss.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\csrsrv.dll
c:\windows\system32\basesrv.dll
c:\windows\system32\winsrv.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
864C:\Windows\system32\svchost.exe -k netsvcsC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1160 run=1 shortcut="C:\Users\admin\AppData\Local\Temp\winzip.exe"C:\Users\admin\AppData\Local\Temp\39ad80\winzip.exe
winzip.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
HIGH
Description:
WinZipStub Installer
Exit code:
0
Version:
24.0.13543.0
Modules
Images
c:\users\admin\appdata\local\temp\39ad80\winzip.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\lpk.dll
1560C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Exit code:
0
Version:
26,0,0,131
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1708"C:\Program Files\WinZip\winzip32.exe" /BgtoolSetting {3CA58CC9-3F11-4AB2-AFD2-6794B3DB3891}#1 {FAAAEF6D-4059-42EE-902F-63D0666B9DBC}#1 {AEFFAA16-A5CE-42F9-8931-AD72DDB2DFD7}#1 {F1869396-0E7B-4C45-A6A1-AD24CAD220C8}#1 {B0EF9A73-A12A-4543-A9B5-505FBCE2E4DE}#1C:\Program Files\WinZip\winzip32.exemsiexec.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
HIGH
Description:
WinZip
Exit code:
0
Version:
33.0 (32-bit)
Modules
Images
c:\program files\winzip\winzip32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1972"C:\Program Files\WinZip\WzPreloader.exe"C:\Program Files\WinZip\WzPreloader.exemsiexec.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
HIGH
Description:
WinZip Preloader
Exit code:
0
Version:
24.0.13573.0
Modules
Images
c:\program files\winzip\wzpreloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1992"C:\Program Files\WinZip\WzCABCacheSyncHelper32.exe" C:\Program Files\WinZip\WzCABCacheSyncHelper32.exewinzip32.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
MEDIUM
Description:
WinZip Combined Address Book SyncHelper
Exit code:
1
Version:
24.0.13577.0
Modules
Images
c:\program files\winzip\wzcabcachesynchelper32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2380"C:\Program Files\WinZip\winzip32.exe" C:\Program Files\WinZip\winzip32.exe
explorer.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
MEDIUM
Description:
WinZip
Exit code:
0
Version:
33.0 (32-bit)
Modules
Images
c:\program files\winzip\winzip32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2448"C:\Users\admin\AppData\Local\Temp\CloseFAH.exe" C:\Users\admin\AppData\Local\Temp\CloseFAH.exeMsiExec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\closefah.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
8 565
Read events
6 447
Write events
2 095
Delete events
23

Modification events

(PID) Process:(352) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1160) winzip.exeKey:HKEY_CURRENT_USER\Software\Corel\stubframework\WNZP\24
Operation:writeName:install_language
Value:
English
(PID) Process:(1160) winzip.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1160) winzip.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1160) winzip.exeKey:HKEY_CURRENT_USER\Software\Corel\stubframework\WNZP\24
Operation:writeName:status
Value:
0
(PID) Process:(1160) winzip.exeKey:HKEY_CURRENT_USER\Software\Corel\stubframework\WNZP\24
Operation:writeName:channel
Value:
nkln24-downwz
(PID) Process:(1160) winzip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winzip_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1160) winzip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winzip_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1160) winzip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winzip_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(1160) winzip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winzip_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
Executable files
213
Suspicious files
19
Text files
180
Unknown types
23

Dropped files

PID
Process
Filename
Type
864svchost.exeC:\Windows\appcompat\programs\RecentFileCache.bcftxt
MD5:
SHA256:
1160winzip.exeC:\Users\admin\AppData\Local\Temp\39af94\common\css\common.csstext
MD5:
SHA256:
3700winzip.exeC:\Users\admin\AppData\Local\Temp\39ad80\winzip.exeexecutable
MD5:
SHA256:
1160winzip.exeC:\ProgramData\UniqueId\databinary
MD5:
SHA256:
1160winzip.exeC:\Users\admin\AppData\Local\Temp\39af94\common\js\common.jstext
MD5:
SHA256:
1160winzip.exeC:\Users\admin\AppData\Local\Temp\39af94\common\img\arrow.pngimage
MD5:407F46749E54353D1EDA4E776A7AE505
SHA256:56F5FCC00CD244C8D7EEA8A03F627DB1DBC74CBF48553CCC0F10AB33FC09AA05
1160winzip.exeC:\Users\admin\AppData\Local\Temp\39af94\common\css\jquery-ui.csstext
MD5:1CE4EB3E5153F4C9B93A3CFDF3EF2E77
SHA256:95F4C300D84EEDD0C43A30A1B6F0DFBBF7B8C47725511981E4CFE12DFAEB0E93
1160winzip.exeC:\Users\admin\AppData\Local\Temp\39af94\common\img\button-hover.pngimage
MD5:7D3A382C149EE7588958281A816918BF
SHA256:97E35A7F7DC87983E8D1DDAA120BBA9D81BFE3AE4A6F99301A4749224CFBDD02
1160winzip.exeC:\Users\admin\AppData\Local\Temp\39af94\common\img\centerImg.pngimage
MD5:F1F71117A2C77649963C8B4CCF4B5CF8
SHA256:44C4E7A6E7293B855830F94496D7ADDC6916BFE62E36AC8142CDA1919745950E
1160winzip.exeC:\Users\admin\AppData\Local\Temp\39af94\common\img\footerImg.pngimage
MD5:F766FA02DECAFCBDC7B54311436E5931
SHA256:D334FB1C34872899D08183154C14151D2D2A65E99F37C41B5B23E320FD340F94
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
52
DNS requests
29
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1160
winzip.exe
POST
200
18.236.15.144:80
http://i.installportal.com/v1/logUserActivity
US
xml
186 b
malicious
1160
winzip.exe
POST
200
54.68.21.135:80
http://www.installportal.com/v1/token
US
text
188 b
malicious
1160
winzip.exe
POST
200
18.236.15.144:80
http://i.installportal.com/v1/logAnalytics
US
xml
204 b
malicious
1160
winzip.exe
POST
200
54.68.21.135:80
http://www.installportal.com/v1/token
US
text
194 b
malicious
1160
winzip.exe
POST
200
18.236.15.144:80
http://i.installportal.com/v1/logUserActivity
US
xml
186 b
malicious
2380
winzip32.exe
GET
200
2.18.232.154:80
http://download.winzip.com/prodad/en/WzProdAdv.zip
unknown
compressed
2.41 Mb
whitelisted
2380
winzip32.exe
GET
200
18.208.0.71:80
http://update.winzip.com/ipm.cgi?pid=WNZP&lang=EN&dy=0&du=1&ct=0&ver=24.0.13618.0&vid=nkln&wzbits=32&osbits=32&win=495x285&bid=&paid=&x-at=nkln
US
xml
283 b
unknown
2380
winzip32.exe
GET
302
18.208.0.71:80
http://update.winzip.com/shownag.cgi?prod=WNZP&lang=EN&vid=nkln&reg=EVAL&ver=24.0.13618.0&mah=229ACC476490FFE566A9442A3CE4371D31740ADD&days=0&opened=0&osbits=32&reg=EVAL&wzbits=32&x-at=nkln&nid=1017Nag1but1&win=495x285&dpi=100
US
xml
283 b
unknown
2380
winzip32.exe
GET
200
13.107.4.50:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.0 Kb
whitelisted
1160
winzip.exe
POST
200
18.236.15.144:80
http://i.installportal.com/v1/logAnalytics
US
xml
204 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2932
iexplore.exe
172.217.22.66:443
www.googleadservices.com
Google Inc.
US
whitelisted
2932
iexplore.exe
216.58.207.40:443
www.googletagmanager.com
Google Inc.
US
whitelisted
2932
iexplore.exe
172.217.16.130:443
googleads.g.doubleclick.net
Google Inc.
US
whitelisted
2932
iexplore.exe
159.122.87.148:443
dev.visualwebsiteoptimizer.com
SoftLayer Technologies Inc.
DE
unknown
2932
iexplore.exe
172.217.18.164:443
www.google.com
Google Inc.
US
whitelisted
2932
iexplore.exe
35.186.235.23:443
cdn.mxpnl.com
Google Inc.
US
whitelisted
2932
iexplore.exe
130.211.34.183:443
api.mixpanel.com
Google Inc.
US
whitelisted
1160
winzip.exe
18.236.15.144:80
i.installportal.com
US
malicious
1160
winzip.exe
54.68.21.135:80
i.installportal.com
Amazon.com, Inc.
US
malicious
1160
winzip.exe
2.18.232.154:443
download.winzip.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
i.installportal.com
  • 18.236.15.144
  • 54.68.21.135
unknown
www.installportal.com
  • 54.68.21.135
  • 18.236.15.144
unknown
download.winzip.com
  • 2.18.232.154
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.winzip.com
  • 2.18.232.154
whitelisted
www.googletagmanager.com
  • 216.58.207.40
whitelisted
www.zipshare.com
  • 157.55.160.240
unknown
update.winzip.com
  • 18.208.0.71
  • 34.200.170.187
unknown
ssl.google-analytics.com
  • 172.217.16.136
whitelisted
www.googleadservices.com
  • 172.217.22.66
whitelisted

Threats

Found threats are available for the paid subscriptions
4 ETPRO signatures available at the full report
No debug info