analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://zoom.us/j/178480130

Full analysis: https://app.any.run/tasks/e0ea0f7a-b336-4cb9-ab30-b469ffd06564
Verdict: Malicious activity
Analysis date: March 30, 2020, 23:00:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

E2BE6B1CD3466FDBAD399DDB1DED2A50

SHA1:

EDDEDCCBB85C9C0290704D22A4B48E7E1029A0E6

SHA256:

A3DAF8728F79C28DB3DFD8F1668404B6834536108900C0C06773B6E6059E947F

SSDEEP:

3:N88LWOvn:28LWOvn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Zoom_2283cff74d52b2a6.exe (PID: 3984)
      • Installer.exe (PID: 620)
      • Installer.exe (PID: 3612)
      • Zoom.exe (PID: 2464)
      • zm3926.tmp (PID: 1940)
    • Loads dropped or rewritten executable

      • Installer.exe (PID: 620)
    • Changes settings of System certificates

      • Zoom_2283cff74d52b2a6.exe (PID: 3984)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • Zoom_2283cff74d52b2a6.exe (PID: 3984)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 3448)
      • chrome.exe (PID: 2836)
      • Zoom_2283cff74d52b2a6.exe (PID: 3984)
      • Installer.exe (PID: 620)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 2836)
    • Creates files in the user directory

      • Zoom_2283cff74d52b2a6.exe (PID: 3984)
      • Installer.exe (PID: 620)
    • Application launched itself

      • Installer.exe (PID: 620)
    • Changes IE settings (feature browser emulation)

      • Installer.exe (PID: 620)
    • Starts application with an unusual extension

      • Zoom_2283cff74d52b2a6.exe (PID: 3984)
    • Starts itself from another location

      • Zoom_2283cff74d52b2a6.exe (PID: 3984)
    • Creates a software uninstall entry

      • Installer.exe (PID: 620)
    • Modifies the open verb of a shell class

      • Installer.exe (PID: 620)
    • Adds / modifies Windows certificates

      • Zoom_2283cff74d52b2a6.exe (PID: 3984)
  • INFO

    • Reads the hosts file

      • chrome.exe (PID: 2836)
      • chrome.exe (PID: 3448)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 2836)
    • Application launched itself

      • chrome.exe (PID: 2836)
    • Dropped object may contain Bitcoin addresses

      • Installer.exe (PID: 620)
    • Reads settings of System Certificates

      • Zoom_2283cff74d52b2a6.exe (PID: 3984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
69
Monitored processes
30
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs zoom_2283cff74d52b2a6.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs installer.exe installer.exe zoom.exe no specs zm3926.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
2836"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://zoom.us/j/178480130"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
75.0.3770.100
2244"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6fa8a9d0,0x6fa8a9e0,0x6fa8a9ecC:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
75.0.3770.100
2820"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3044 --on-initialized-event-handle=324 --parent-handle=328 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
75.0.3770.100
3108"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1032,8207175108809653409,16631101827843906530,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=5444575908759735061 --mojo-platform-channel-handle=1036 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
75.0.3770.100
3448"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1032,8207175108809653409,16631101827843906530,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=4494551327747998712 --mojo-platform-channel-handle=1524 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
75.0.3770.100
3988"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1032,8207175108809653409,16631101827843906530,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5616588213300589087 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2264 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
75.0.3770.100
2640"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1032,8207175108809653409,16631101827843906530,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2974802966630564456 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2272 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
75.0.3770.100
1840"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1032,8207175108809653409,16631101827843906530,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11967828329400331436 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2528 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
1692"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1032,8207175108809653409,16631101827843906530,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=14663709241828823876 --mojo-platform-channel-handle=4184 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
3464"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1032,8207175108809653409,16631101827843906530,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=11158912489941517945 --mojo-platform-channel-handle=4416 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Total events
7 279
Read events
1 997
Write events
0
Delete events
0

Modification events

No data
Executable files
58
Suspicious files
57
Text files
251
Unknown types
14

Dropped files

PID
Process
Filename
Type
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5E827A33-B14.pma
MD5:
SHA256:
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old
MD5:
SHA256:
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old
MD5:
SHA256:
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old
MD5:
SHA256:
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RFa66c01.TMP
MD5:
SHA256:
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\a97f6b34-167b-4767-b9bf-8b31af00e426.tmp
MD5:
SHA256:
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000028.dbtmp
MD5:
SHA256:
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RFa66c20.TMPtext
MD5:33B05E8AC9C178C58ED3321F496588C0
SHA256:2CDF6A09638A0B563EA2672D6926210771902E0A9203FE15D2857FC4EB954CDE
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old~RFa66c9d.TMPtext
MD5:FC9FFE77348619CC285333DFF5E1D5D1
SHA256:7CB9B3575330B3D776A21EB7A7407E34F013A0975B7418DA11B5C85DEC91D1F3
2836chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Tabsbinary
MD5:702AEC53DCDCFEA33C4BE3D2F888473E
SHA256:D16286D6EE0EB33E7907EE4FCB8FDB6B5A54E5A56BFAF99A9C2451D239BC9765
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
38
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3984
Zoom_2283cff74d52b2a6.exe
GET
200
23.37.43.27:80
http://s.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEGMYDTj7gJd4qdA1oxYY%2BEA%3D
NL
der
1.71 Kb
shared
3984
Zoom_2283cff74d52b2a6.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAyO4MkNaokViAQGHuJB%2Ba8%3D
US
der
471 b
whitelisted
3448
chrome.exe
GET
302
216.58.207.78:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx
US
html
517 b
whitelisted
3448
chrome.exe
GET
302
216.58.207.78:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx
US
html
522 b
whitelisted
3448
chrome.exe
GET
200
173.194.151.108:80
http://r6---sn-4g5e6ne6.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&mh=QJ&mip=92.118.13.5&mm=28&mn=sn-4g5e6ne6&ms=nvh&mt=1585609211&mv=m&mvi=5&pl=25&shardbypass=yes
US
crx
293 Kb
whitelisted
3448
chrome.exe
GET
200
74.125.11.26:80
http://r4---sn-4g5ednee.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mh=bs&mip=92.118.13.5&mm=28&mn=sn-4g5ednee&ms=nvh&mt=1585609211&mv=m&mvi=3&pl=25&shardbypass=yes
US
crx
862 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3448
chrome.exe
172.217.21.206:443
clients4.google.com
Google Inc.
US
whitelisted
3448
chrome.exe
3.235.71.132:443
zoom.us
US
unknown
3448
chrome.exe
13.35.254.162:443
d24cgw3uvb9a9h.cloudfront.net
US
unknown
3448
chrome.exe
172.217.22.77:443
accounts.google.com
Google Inc.
US
whitelisted
3448
chrome.exe
172.217.16.142:443
www.google-analytics.com
Google Inc.
US
whitelisted
3448
chrome.exe
172.217.21.232:443
www.googletagmanager.com
Google Inc.
US
whitelisted
3448
chrome.exe
216.58.207.67:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
216.58.208.36:443
www.google.com
Google Inc.
US
whitelisted
3448
chrome.exe
52.202.62.237:443
launcher.zoom.us
Amazon.com, Inc.
US
unknown
3448
chrome.exe
104.16.54.111:443
zoomus.zendesk.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
zoom.us
  • 3.235.71.132
whitelisted
clientservices.googleapis.com
  • 216.58.207.67
whitelisted
accounts.google.com
  • 172.217.22.77
shared
clients4.google.com
  • 172.217.21.206
whitelisted
d24cgw3uvb9a9h.cloudfront.net
  • 13.35.254.162
  • 13.35.254.53
  • 13.35.254.41
  • 13.35.254.48
shared
www.google-analytics.com
  • 172.217.16.142
whitelisted
www.googletagmanager.com
  • 172.217.21.232
whitelisted
clients1.google.com
  • 172.217.21.206
whitelisted
www.google.com
  • 216.58.208.36
whitelisted
assets.zendesk.com
  • 104.18.71.113
  • 104.18.70.113
  • 104.18.73.113
  • 104.18.72.113
  • 104.18.74.113
whitelisted

Threats

PID
Process
Class
Message
3448
chrome.exe
Generic Protocol Command Decode
SURICATA STREAM ESTABLISHED invalid ack
3448
chrome.exe
Generic Protocol Command Decode
SURICATA STREAM Packet with invalid ack
Process
Message
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\zoom_install_src
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\zoom_install_src
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\uninstall
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\bin
Installer.exe
Installer.exe
[CZoomProductPathHelper::RecursiveRemoveDirA] Path is: