File name:

zxmapper.exe

Full analysis: https://app.any.run/tasks/3d65e895-be93-4eb8-b243-cddab165039c
Verdict: Malicious activity
Analysis date: August 12, 2025, 15:01:41
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

9C407596D9B9D188E377A0A72FE4EEE1

SHA1:

2669C733F27D2FF79E24F69E82089F22B6096523

SHA256:

94FB2348DD6F1BB01C191713885715B8534A2A4EE9D96287151419E96B302870

SSDEEP:

98304:iGR4/igGgu6XJ72xMOr0RZ6GzM2k4wjDzyPcmoSaIejixUtETL82TJPiVcVTW7Xt:G4kR/Pid1Ram3ch/Y3Y55pD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts application with an unusual extension

      • zxmapper.exe (PID: 6524)
    • Creates or modifies Windows services

      • tmpD04B.tmp (PID: 6408)
    • Executable content was dropped or overwritten

      • zxmapper.exe (PID: 6524)
      • tmpD04B.tmp (PID: 6408)
    • Creates files in the driver directory

      • tmpD04B.tmp (PID: 6408)
    • Drops a system driver (possible attempt to evade defenses)

      • tmpD04B.tmp (PID: 6408)
  • INFO

    • Creates files in the program directory

      • zxmapper.exe (PID: 6524)
    • Checks supported languages

      • zxmapper.exe (PID: 6524)
      • tmpD04B.tmp (PID: 6408)
      • msiexec.exe (PID: 3160)
    • The sample compiled with english language support

      • tmpD04B.tmp (PID: 6408)
      • zxmapper.exe (PID: 6524)
    • Reads the computer name

      • zxmapper.exe (PID: 6524)
      • msiexec.exe (PID: 3160)
    • Reads the machine GUID from the registry

      • zxmapper.exe (PID: 6524)
    • Create files in a temporary directory

      • zxmapper.exe (PID: 6524)
      • msiexec.exe (PID: 4112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (55.8)
.exe | Win64 Executable (generic) (21)
.scr | Windows screen saver (9.9)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2059:05:29 23:25:29+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 7301120
InitializedDataSize: 5120
UninitializedDataSize: -
EntryPoint: 0x6f86ee
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileDescription:
FileVersion: 0.0.0.0
InternalName: zxmapper.exe
LegalCopyright:
OriginalFileName: zxmapper.exe
ProductVersion: 0.0.0.0
AssemblyVersion: 0.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start zxmapper.exe tmpd04b.tmp conhost.exe no specs msiexec.exe no specs msiexec.exe no specs zxmapper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1100\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetmpD04B.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3160C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4112"msiexec" /I "C:\Users\admin\AppData\Local\Temp\ViGEm.msi" /QN /L*V "C:\Users\admin\AppData\Local\Temp\zxmapper.log"C:\Windows\System32\msiexec.exezxmapper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
1619
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5968"C:\Users\admin\AppData\Local\Temp\zxmapper.exe" C:\Users\admin\AppData\Local\Temp\zxmapper.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\zxmapper.exe
c:\windows\system32\ntdll.dll
6408"C:\Users\admin\AppData\Local\Temp\tmpD04B.tmp" /installC:\Users\admin\AppData\Local\Temp\tmpD04B.tmp
zxmapper.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\tmpd04b.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6524"C:\Users\admin\AppData\Local\Temp\zxmapper.exe" C:\Users\admin\AppData\Local\Temp\zxmapper.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\zxmapper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
397
Read events
387
Write events
10
Delete events
0

Modification events

(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\keyboard
Operation:writeName:DisplayName
Value:
Keyboard Upper Filter Driver
(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\keyboard
Operation:writeName:Type
Value:
1
(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\keyboard
Operation:writeName:ErrorControl
Value:
1
(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\keyboard
Operation:writeName:Start
Value:
3
(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouse
Operation:writeName:DisplayName
Value:
Mouse Upper Filter Driver
(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouse
Operation:writeName:Type
Value:
1
(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouse
Operation:writeName:ErrorControl
Value:
1
(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouse
Operation:writeName:Start
Value:
3
(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}
Operation:writeName:UpperFilters
Value:
keyboard
(PID) Process:(6408) tmpD04B.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}
Operation:writeName:UpperFilters
Value:
mouse
Executable files
3
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6408tmpD04B.tmpC:\Windows\System32\drivers\keyboard.sysexecutable
MD5:9D39232310190DC8C0CB7472DB523A1E
SHA256:2CB5EC142CFAC879BCE4A2F9549258DB972AEBBD24F4551B6B748B464EB7DBA9
6524zxmapper.exeC:\Users\admin\AppData\Local\Temp\tmpD04B.tmpexecutable
MD5:0F0B50D92E030B8965CE669C8058FA6E
SHA256:E137863A79DA797F08E7A137280FF2A123809044A888FD75CE9C973198915ABE
6408tmpD04B.tmpC:\Windows\System32\drivers\mouse.sysexecutable
MD5:CCF564011EEFA7B44D74915D231B8FD7
SHA256:0F12D47D01864CA5E1EB663A52B3D2C060521E57B68FF99D70E7F01506E400F9
3160msiexec.exeC:\Users\admin\AppData\Local\Temp\zxmapper.logtext
MD5:2D49BF0773D729976BB3415745597307
SHA256:007EE221C8647EFDCE3F13902802F13599A4EEF1285476D7D5E1DF5A7F18EDA1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
28
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7040
WmiPrvSE.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
GET
200
2.23.206.76:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
GB
binary
814 b
whitelisted
7040
WmiPrvSE.exe
GET
200
104.78.173.167:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
GB
binary
727 b
whitelisted
7040
WmiPrvSE.exe
GET
200
104.78.173.167:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA5EGOLe3jbdKXTDRDr7XOU%3D
GB
binary
727 b
whitelisted
7040
WmiPrvSE.exe
GET
200
2.23.206.76:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
GB
binary
1.05 Kb
whitelisted
7040
WmiPrvSE.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
DE
binary
824 b
whitelisted
7040
WmiPrvSE.exe
GET
200
2.23.206.76:80
http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl
GB
binary
564 b
whitelisted
7040
WmiPrvSE.exe
GET
200
104.78.173.167:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
GB
binary
471 b
whitelisted
7040
WmiPrvSE.exe
GET
200
104.78.173.167:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAkQWITrlZ07yLmU%2BRintu4%3D
GB
binary
471 b
whitelisted
GET
200
2.23.206.76:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
GB
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.23.206.76:80
www.microsoft.com
CW Vodafone Group PLC
GB
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
7040
WmiPrvSE.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
7040
WmiPrvSE.exe
2.23.206.76:80
www.microsoft.com
CW Vodafone Group PLC
GB
whitelisted
7040
WmiPrvSE.exe
104.78.173.167:80
ocsp.digicert.com
AKAMAI-AS
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
www.microsoft.com
  • 2.23.206.76
  • 2.18.69.217
whitelisted
google.com
  • 142.250.186.46
whitelisted
ocsp.digicert.com
  • 104.78.173.167
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.4
  • 20.190.159.129
  • 40.126.31.71
  • 40.126.31.130
  • 20.190.159.131
  • 20.190.159.0
  • 40.126.31.3
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 74.178.240.61
whitelisted

Threats

No threats detected
No debug info