URL:

https://dpdhl.zoom.us/j/98351661914?pwd=Vi93cXdIYUI2cHBFMTVlSlZyTGthdz09

Full analysis: https://app.any.run/tasks/5648febe-e228-4767-98d1-71f8536bcf23
Verdict: Malicious activity
Analysis date: December 01, 2020, 08:24:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

6BAC9AE2EFC6A4FC35944D74377CECB5

SHA1:

A16E05AE39F851603F699B93AE8E530FAC3859EE

SHA256:

B4C23F6F6D617FA86E01870E30355B8C8870C0DAA25425C7B11C42B8CA8D9571

SSDEEP:

3:N8NZmLQNMQplE0B26U1JpxepVc:27MQplEW7UDfwc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
    • Application was dropped or rewritten from another process

      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
      • Installer.exe (PID: 1760)
      • Installer.exe (PID: 2568)
      • Zoom.exe (PID: 448)
      • Zoom.exe (PID: 3228)
      • zm44DF.tmp (PID: 2504)
    • Loads dropped or rewritten executable

      • Installer.exe (PID: 1760)
      • Zoom.exe (PID: 448)
      • Zoom.exe (PID: 3228)
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • chrome.exe (PID: 2640)
      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
      • Installer.exe (PID: 1760)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2640)
      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
      • Installer.exe (PID: 1760)
    • Adds / modifies Windows certificates

      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
    • Creates files in the user directory

      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
      • Zoom.exe (PID: 448)
      • Zoom.exe (PID: 3228)
      • Installer.exe (PID: 1760)
    • Drops a file with a compile date too recent

      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
      • Installer.exe (PID: 1760)
    • Changes IE settings (feature browser emulation)

      • Installer.exe (PID: 1760)
    • Modifies the open verb of a shell class

      • Installer.exe (PID: 1760)
    • Starts application with an unusual extension

      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
    • Application launched itself

      • Zoom.exe (PID: 448)
      • Installer.exe (PID: 1760)
    • Creates a software uninstall entry

      • Installer.exe (PID: 1760)
    • Drops a file with too old compile date

      • Installer.exe (PID: 1760)
    • Starts itself from another location

      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
  • INFO

    • Reads the hosts file

      • chrome.exe (PID: 2640)
      • chrome.exe (PID: 1080)
    • Application launched itself

      • chrome.exe (PID: 2640)
    • Dropped object may contain Bitcoin addresses

      • Installer.exe (PID: 1760)
    • Reads settings of System Certificates

      • Installer.exe (PID: 1760)
      • Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe (PID: 856)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
18
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs zoom_cm_fbebz8z9vvrzo4_mrtq3yzreodvbsko12p5f7pczghke6bglbfyz@eycwjy3if3cyuuqr_k796e7770d9338016_.exe chrome.exe no specs installer.exe installer.exe zoom.exe zm44df.tmp no specs zoom.exe

Process information

PID
CMD
Path
Indicators
Parent process
448"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe" "--url=zoommtg://win.launch?h.domain=zoom.us&h.path=join&stype=0&zc=0&action=join&confno=98351661914"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Meetings
Exit code:
0
Version:
5,4,58891,1115
Modules
Images
c:\users\admin\appdata\roaming\zoom\bin\zoom.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\zoom\bin\dllsafecheck.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
856"C:\Users\admin\Downloads\Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe" C:\Users\admin\Downloads\Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe
chrome.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Opener
Exit code:
0
Version:
5,0,26188,0601
Modules
Images
c:\users\admin\downloads\zoom_cm_fbebz8z9vvrzo4_mrtq3yzreodvbsko12p5f7pczghke6bglbfyz@eycwjy3if3cyuuqr_k796e7770d9338016_.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
924"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1008,18278771730369731740,13124697746291414453,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=1886893473644223407 --mojo-platform-channel-handle=1072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1080"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1008,18278771730369731740,13124697746291414453,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=1102403421940857661 --mojo-platform-channel-handle=1488 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1136"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2660 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1344"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1008,18278771730369731740,13124697746291414453,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9764964706999915748 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2148 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1760"C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe" ZInstaller --conf.mode=silent --ipc_wnd=131440C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe
Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Installer
Exit code:
0
Version:
5,4,58891,1115
Modules
Images
c:\users\admin\appdata\roaming\zoom\zoomdownload\installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1924"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1008,18278771730369731740,13124697746291414453,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=6568280915004988424 --mojo-platform-channel-handle=1028 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2504"C:\Users\admin\AppData\Local\Temp\zm44DF.tmp" -DAF8C715436E44649F1312698287E6A5=C:\Users\admin\Downloads\Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exeC:\Users\admin\AppData\Local\Temp\zm44DF.tmpZoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Opener
Exit code:
0
Version:
5,0,26188,0601
Modules
Images
c:\users\admin\appdata\local\temp\zm44df.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
2508"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1008,18278771730369731740,13124697746291414453,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=15324072375100115300 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2172 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
2 268
Read events
2 083
Write events
177
Delete events
8

Modification events

(PID) Process:(2640) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2640) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2640) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2640) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2640) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1136) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:2640-13251284705768750
Value:
259
(PID) Process:(2640) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2640) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2640) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3252-13245750958665039
Value:
0
(PID) Process:(2640) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
155
Suspicious files
40
Text files
83
Unknown types
4

Dropped files

PID
Process
Filename
Type
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5FC5FDE2-A50.pma
MD5:
SHA256:
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old
MD5:
SHA256:
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RF1541d5.TMP
MD5:
SHA256:
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\1b93b14e-3da9-4d47-a939-4f97570e7641.tmp
MD5:
SHA256:
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp
MD5:
SHA256:
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF1541b6.TMPtext
MD5:
SHA256:
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.oldtext
MD5:
SHA256:
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.oldtext
MD5:
SHA256:
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
2640chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF15437b.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
29
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
856
Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe
GET
200
23.51.123.27:80
http://s.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEGMYDTj7gJd4qdA1oxYY%2BEA%3D
NL
der
1.71 Kb
shared
856
Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAyO4MkNaokViAQGHuJB%2Ba8%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
chrome.exe
52.202.62.232:443
dpdhl.zoom.us
Amazon.com, Inc.
US
suspicious
1080
chrome.exe
65.9.68.77:443
static.ada.support
AT&T Services, Inc.
US
unknown
1080
chrome.exe
65.9.68.80:443
zoom.ada.support
AT&T Services, Inc.
US
unknown
856
Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe
52.202.62.232:443
dpdhl.zoom.us
Amazon.com, Inc.
US
suspicious
1080
chrome.exe
3.80.20.234:443
nws.zoom.us
US
unknown
1080
chrome.exe
65.9.70.66:443
d24cgw3uvb9a9h.cloudfront.net
AT&T Services, Inc.
US
unknown
856
Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
856
Zoom_cm_fbebz8Z9vvrZo4_mRtq3yZREOdVbsko12P5F7PczGhKe6bgLBFYZ@eYcwJy3if3CyUUqr_k796e7770d9338016_.exe
143.204.89.64:443
d11yldzmag5yn.cloudfront.net
US
suspicious
448
Zoom.exe
147.124.97.30:3478
Albion College
US
unknown
1080
chrome.exe
64.233.165.139:443
clients4.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
dpdhl.zoom.us
  • 52.202.62.232
suspicious
accounts.google.com
  • 172.217.168.13
shared
static.ada.support
  • 65.9.68.77
  • 65.9.68.72
  • 65.9.68.28
  • 65.9.68.102
whitelisted
safebrowsing.googleapis.com
  • 216.58.206.10
whitelisted
d24cgw3uvb9a9h.cloudfront.net
  • 65.9.70.66
  • 65.9.70.123
  • 65.9.70.82
  • 65.9.70.45
shared
rollout.ada.support
  • 65.9.68.66
  • 65.9.68.125
  • 65.9.68.71
  • 65.9.68.27
shared
zoom.ada.support
  • 65.9.68.80
  • 65.9.68.12
  • 65.9.68.27
  • 65.9.68.73
whitelisted
www.dpdhl.com
  • 104.109.81.4
unknown
nws.zoom.us
  • 3.80.20.234
whitelisted
sb-ssl.google.com
  • 172.217.16.174
whitelisted

Threats

No threats detected
Process
Message
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\zoom_install_src
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\zoom_install_src
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\uninstall
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\bin
Installer.exe
Installer.exe
[CZoomProductPathHelper::RecursiveRemoveDirA] Path is: