| File name: | ZenithProxy-1.20.1.zip |
| Full analysis: | https://app.any.run/tasks/335baaee-347b-49b8-adca-1a559de899b2 |
| Verdict: | Malicious activity |
| Analysis date: | January 11, 2024, 18:26:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 6EA09AE745B0AC410F8E7D4CA81B705C |
| SHA1: | 0948DC2405706F94F9D447B9866B2D04DD69ECBB |
| SHA256: | A0772FC3A034D692E88CEAEC7B283253836B9C893D9C635F2DE18BE3B7B32F84 |
| SSDEEP: | 49152:HZ+kA790CzM0N1qrAsm36T6vvBHppWyJpE+WJ/tsCafsAAYyBv+zG6H0s8YkEB/o:H0kqdzM0N4AeKoJ1sFUTYyBv+zG6HvFW |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:01:11 00:57:50 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | ZenithProxy-1.20.1/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 956 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1504 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\ZenithProxy-1.20.1\launch.bat" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1776 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ZenithProxy-1.20.1.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1780 | where python3 | C:\Windows\System32\where.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Where - Lists location of files Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1840 | where python | C:\Windows\System32\where.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Where - Lists location of files Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1776) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.github\dependabot.yml | text | |
MD5:A4FB9F4D52564B938DBB0B15BA5964B8 | SHA256:199D0C42270C5E11681AD92907207937BD064519C127A8868A274D1101CB9C78 | |||
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.gitattributes | text | |
MD5:8095CB36B34CF76FEF441CB096D1427B | SHA256:5FA58A927FA11BF3E1E503426EE1A6646D93C88AE78C8539B4367953248BD31E | |||
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.github\workflows\build.yml | text | |
MD5:AAF80135D543035232D1CA3E0BB33596 | SHA256:B749141D68D95C9C220C6F8F806A1E7DA83624A99135D92C45A26FA0D9E2F926 | |||
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.idea\runConfigurations\GraalVM_Agent_Run.xml | text | |
MD5:EEF328C696AEF61011B56116ABD39B6A | SHA256:84E238A1168DEEC36C2FA615091E8F401B0796F9434B271D2AC6A84F9746FDC8 | |||
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.github\workflows\publish_launcher.yml | text | |
MD5:DCFAA59AF24081A03D4AD60E0235689C | SHA256:AA5C67AF601C418F9460422258462435D2B5AE1B006D3727C14D6A549184CE51 | |||
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.gitignore | text | |
MD5:A5090B06388A814C0DCE0D6568261190 | SHA256:C30718C34862FEDA84C012C0455A6458375E1E8B33079A59DC9E5C244B6B9E1A | |||
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.github\workflows\native-prerelease.yml | text | |
MD5:1F1B6E963519E6D164DF67CAEE0FF625 | SHA256:DFB1ED1527D7BDBA376D82049E1B6D15582B652A0EE4ECCDBCBC827C049CB664 | |||
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.github\workflows\native-release.yml | text | |
MD5:F8CCD0AEDE298DB6977DFA2E73E861C1 | SHA256:D7D7F207F6A67BE1E025B3162DDF7D407A938D4CD4DD348FD155C8B040A69D5B | |||
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.tokeignore | text | |
MD5:698D4D6CBD1D3DD3985CBAE47122E3DB | SHA256:99B996F43C63CBF158A93B73BBEDCEBA0A244E98E84141CBD348EFB57F7F010B | |||
| 1776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1776.10860\ZenithProxy-1.20.1\.github\workflows\act-local.yml | text | |
MD5:41EA4CAEDD46EE643D90FB98880E6158 | SHA256:F58AFBC5E508F28CC68B2834732233D59DA8B1044E6F2422E62422F497B21639 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |