File name:

ZipSoft.exe

Full analysis: https://app.any.run/tasks/eb15066d-5f49-4b76-ad73-57fcb470ebf8
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 16, 2025, 07:04:13
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

33B6BB65EF9087F7D62CF5A01CC3B863

SHA1:

6BFE8074F98E2CC0C9A182417F01A02D90118CB6

SHA256:

BE79146A6B2AD73AF155836449FF0A1DC1A69483D5DDA3F1A8B6BB8867B6E8B4

SSDEEP:

24576:XhXlRauLC50SBffyyyyyyyyyyyyK7VVgoTF3B9jV6XfE3Fzv6qlUqT:XhXlLCucyyyyyyyyyyyyK7V62F3B9jV9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 7212)
    • Actions looks like stealing of personal data

      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 7212)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Executable content was dropped or overwritten

      • ZipSoft.exe (PID: 7400)
      • OperaSetup.exe (PID: 7988)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • setup.exe (PID: 6068)
      • OperaGXSetup.exe (PID: 8108)
      • setup.exe (PID: 7212)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 4776)
      • setup.exe (PID: 6988)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 6712)
      • setup.exe (PID: 2108)
      • 7z2409-x64.exe (PID: 4428)
    • Drops 7-zip archiver for unpacking

      • ZipSoft.exe (PID: 7400)
      • 7z2409-x64.exe (PID: 4428)
    • Application launched itself

      • setup.exe (PID: 8052)
      • setup.exe (PID: 7212)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 6712)
    • Starts itself from another location

      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
    • Potential Corporate Privacy Violation

      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Process requests binary or script from the Internet

      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Starts POWERSHELL.EXE for commands execution

      • ZipSoft.exe (PID: 7400)
    • Creates a software uninstall entry

      • 7z2409-x64.exe (PID: 4428)
    • Creates/Modifies COM task schedule object

      • 7z2409-x64.exe (PID: 4428)
  • INFO

    • Reads the computer name

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 7212)
      • setup.exe (PID: 6404)
      • 7zFM.exe (PID: 812)
      • 7z2409-x64.exe (PID: 4428)
      • setup.exe (PID: 6712)
    • Checks supported languages

      • ZipSoft.exe (PID: 7400)
      • OperaSetup.exe (PID: 7988)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • OperaGXSetup.exe (PID: 8108)
      • setup.exe (PID: 6068)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 7212)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 4776)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 6988)
      • setup.exe (PID: 6712)
      • 7zFM.exe (PID: 812)
      • 7z2409-x64.exe (PID: 4428)
      • setup.exe (PID: 2108)
    • Reads the machine GUID from the registry

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Disables trace logs

      • ZipSoft.exe (PID: 7400)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Create files in a temporary directory

      • ZipSoft.exe (PID: 7400)
      • OperaSetup.exe (PID: 7988)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • OperaGXSetup.exe (PID: 8108)
      • setup.exe (PID: 6068)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 7212)
      • setup.exe (PID: 4776)
      • setup.exe (PID: 6988)
      • setup.exe (PID: 6712)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 2108)
    • Reads the software policy settings

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
    • Checks proxy server information

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • The sample compiled with english language support

      • OperaSetup.exe (PID: 7988)
      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • OperaGXSetup.exe (PID: 8108)
      • setup.exe (PID: 6068)
      • setup.exe (PID: 7212)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 4776)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 6988)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 6712)
      • setup.exe (PID: 2108)
      • 7z2409-x64.exe (PID: 4428)
    • Process checks computer location settings

      • ZipSoft.exe (PID: 7400)
    • Creates files or folders in the user directory

      • setup.exe (PID: 8084)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 4776)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 6404)
    • Creates files in the program directory

      • 7z2409-x64.exe (PID: 4428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2077:10:12 02:36:29+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 1038848
InitializedDataSize: 7680
UninitializedDataSize: -
EntryPoint: 0xff7c2
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.7.0
ProductVersionNumber: 2.0.7.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Install any useful software with a single click
CompanyName: ROSTPAY LTD
FileDescription: ZipSoft
FileVersion: 2.0.7.0
InternalName: ZipSoft.exe
LegalCopyright: © ROSTPAY LTD. All rights reserved.
LegalTrademarks: -
OriginalFileName: ZipSoft.exe
ProductName: ZipSoft
ProductVersion: 2.0.7.0
AssemblyVersion: 2.0.7.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
22
Malicious processes
7
Suspicious processes
3

Behavior graph

Click at the process to see the details
start zipsoft.exe sppextcomobj.exe no specs slui.exe no specs operasetup.exe setup.exe setup.exe operagxsetup.exe setup.exe 901f10a0-3786-461e-af7e-5ae443cd02d2.exe 7z2409-x64.exe setup.exe setup.exe setup.exe setup.exe setup.exe setup.exe setup.exe powershell.exe no specs conhost.exe no specs 7zfm.exe no specs svchost.exe zipsoft.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
812"C:\Program Files\7-Zip\7zFM.exe" C:\Program Files\7-Zip\7zFM.exepowershell.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip File Manager
Exit code:
0
Version:
24.09
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
2108C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=117.0.5408.213 --initial-client-data=0x28c,0x290,0x2a0,0x268,0x2a4,0x7ffc861916f8,0x7ffc86191704,0x7ffc86191710C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera GX Installer
Version:
117.0.5408.213
Modules
Images
c:\users\admin\appdata\local\temp\7zscaf2fa71\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
4108"C:\Users\admin\AppData\Local\Temp\901f10a0-3786-461e-af7e-5ae443cd02d2.exe" /sC:\Users\admin\AppData\Local\Temp\901f10a0-3786-461e-af7e-5ae443cd02d2.exe
ZipSoft.exe
User:
admin
Company:
Qihoo 360 Technology Co. Ltd.
Integrity Level:
HIGH
Description:
360 Total Security Online Installer
Version:
6, 6, 0, 1060
Modules
Images
c:\users\admin\appdata\local\temp\901f10a0-3786-461e-af7e-5ae443cd02d2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
4428"C:\Users\admin\AppData\Local\Temp\ZipSoft\7z2409-x64.exe" /SC:\Users\admin\AppData\Local\Temp\ZipSoft\7z2409-x64.exe
ZipSoft.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Installer
Exit code:
0
Version:
24.09
Modules
Images
c:\users\admin\appdata\local\temp\zipsoft\7z2409-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4776C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=117.0.5408.213 --initial-client-data=0x294,0x298,0x29c,0x270,0x2a0,0x7ffc878216f8,0x7ffc87821704,0x7ffc87821710C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera GX Installer
Version:
117.0.5408.213
Modules
Images
c:\users\admin\appdata\local\temp\7zscaf2fa71\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5260\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5400"powershell.exe" /command "start shell:'appsfolder\{6D809377-6AF0-444B-8957-A3773F02200E}\7-Zip\7zFM.exe'"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeZipSoft.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
6068"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
118.0.5461.41
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6404C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe --silent --allusers=0 --server-tracking-blob=NDA1N2VlYjg3MzdlNGM4NjljYWMyMmJmMTZlZjYxMDIzZTI5NmVhMzBiNWRhNmY0NTU3ZGQyM2E1OTAyYWIwZDp7ImNvdW50cnkiOiJERSIsImVkaXRpb24iOiJzdGQtMiIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFHWFNldHVwLmV4ZSIsInByb2R1Y3QiOiJvcGVyYV9neCIsInF1ZXJ5IjoiL29wZXJhX2d4L3N0YWJsZS9lZGl0aW9uL3N0ZC0yP3V0bV9zb3VyY2U9UFdOZ2FtZXMmdXRtX21lZGl1bT1wYSZ1dG1fY2FtcGFpZ249UFdOX0RFX1BCNV85NDE2XzM4NDkmdXRtX2lkPTkwOWNlNjljZWRkYjQ0YzFiM2Y1OWJmNDUwMTQwOTZiIiwidGltZXN0YW1wIjoiMTc0NDc4NzA3OC4wOTk0IiwidXNlcmFnZW50IjoiWmlwU29mdFdyYXBwZXIvMi4wLjcuMCAxMC4wL3g2NCIsInV0bSI6eyJjYW1wYWlnbiI6IlBXTl9ERV9QQjVfOTQxNl8zODQ5IiwiaWQiOiI5MDljZTY5Y2VkZGI0NGMxYjNmNTliZjQ1MDE0MDk2YiIsIm1lZGl1bSI6InBhIiwic291cmNlIjoiUFdOZ2FtZXMifSwidXVpZCI6IjY3OTk4OTMxLTA1NTktNDEwZi1iZDEwLTA5YTUzZGYwY2ZiZSJ9C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe
OperaGXSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera GX Installer
Version:
117.0.5408.213
Modules
Images
c:\users\admin\appdata\local\temp\7zscaf2fa71\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
11 334
Read events
11 252
Write events
78
Delete events
4

Modification events

(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
29
Suspicious files
22
Text files
99
Unknown types
0

Dropped files

PID
Process
Filename
Type
7400ZipSoft.exeC:\Users\admin\AppData\Local\Temp\ZipSoft\7z2409-x64.exeexecutable
MD5:6C73CC4C494BE8F4E680DE1A20262C8A
SHA256:BDD1A33DE78618D16EE4CE148B849932C05D0015491C34887846D431D29F308E
7988OperaSetup.exeC:\Users\admin\AppData\Local\Temp\7zS43F3D380\setup.exeexecutable
MD5:53966124DB88689E3C0836C5BC5508B6
SHA256:346E414427D9352F6049EFFB479566D6F262372873F1EBB2EF5D6BFD5A8CD052
8084setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2504160704396618084.dllexecutable
MD5:83EB2F48045104FE716F0308EB7AEC4C
SHA256:0CABD4D09D54B363C97B27D4DEF1DB5CB184F9B3AC129856DD4B71C17F986F21
7400ZipSoft.exeC:\Users\admin\AppData\Local\Temp\OperaGXSetup.exeexecutable
MD5:8FAA19A7573EF5D07BFF297388942F42
SHA256:FDFA76D22E13251ABDEAFC8BBA80148CE0EB93A9F3215EADBF9E2A5D0CC7B7E3
8052setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2504160704393298052.dllexecutable
MD5:83EB2F48045104FE716F0308EB7AEC4C
SHA256:0CABD4D09D54B363C97B27D4DEF1DB5CB184F9B3AC129856DD4B71C17F986F21
8052setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeexecutable
MD5:53966124DB88689E3C0836C5BC5508B6
SHA256:346E414427D9352F6049EFFB479566D6F262372873F1EBB2EF5D6BFD5A8CD052
6068setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2504160704409586068.dllexecutable
MD5:83EB2F48045104FE716F0308EB7AEC4C
SHA256:0CABD4D09D54B363C97B27D4DEF1DB5CB184F9B3AC129856DD4B71C17F986F21
44287z2409-x64.exeC:\Program Files\7-Zip\Lang\ast.txttext
MD5:1CF6411FF9154A34AFB512901BA3EE02
SHA256:F5F2174DAF36E65790C7F0E9A4496B12E14816DAD2EE5B1D48A52307076BE35F
44287z2409-x64.exeC:\Program Files\7-Zip\descript.iontext
MD5:EB7E322BDC62614E49DED60E0FB23845
SHA256:1DA513F5A4E8018B9AE143884EB3EAF72454B606FD51F2401B7CFD9BE4DBBF4F
44287z2409-x64.exeC:\Program Files\7-Zip\Lang\af.txttext
MD5:DF216FAE5B13D3C3AFE87E405FD34B97
SHA256:9CF684EA88EA5A479F510750E4089AEE60BBB2452AA85285312BAFCC02C10A34
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
71
DNS requests
36
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
8052
setup.exe
GET
200
142.250.186.35:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
8052
setup.exe
GET
200
142.250.186.35:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
104.192.108.17:80
http://int.down.360safe.com/totalsecurity/360TS_Setup_11.0.0.1185.exe
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
200
108.138.24.16:80
http://sd.p.360safe.com/FA1A0875EF2B3DDC65617C494EA48F451559B187.trt
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
200
151.236.71.147:80
http://iup.360safe.com/iv3/pc/360safe/360TS_Setup_For_Mini_Rel.cab
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
104.192.108.17:80
http://int.down.360safe.com/totalsecurity/360TS_Setup_11.0.0.1185.exe
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
200
18.184.178.29:80
http://s.360safe.com/360ts/mini_inst.htm?ver=6.6.0.1060&pid=WW.AZLP.CPI20240305&os=10.0&mid=80342cb959da2233832ae840f019ccba&state=153
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
200
18.184.178.29:80
http://s.360safe.com/safei18n/dimana.htm?lr=1&mid=80342cb959da2233832ae840f019ccba&mod=360Installer.exe&ph=02a8342074eb25c8adb2d135e2bab7e5&p2p=1&t_id=360TS_Setup_For_Mini.cab&tads=656&tdl=656&tds=645&terr=0&tes=Status|1,ErrorCode|0,DnCount|5,HttpNum|1,DnFailCount|5,FStatus|1,P2SS|656,P2PS|0,PDMode|2&tfl=656&tp=t&tst=1&ttdl=656&ttm=1016&ttup=120&vh=1.3.0.1361&vp=1.3.0.1320&softname=360TS
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
104.192.108.21:80
http://int.down.360safe.com/totalsecurity/360TS_Setup_11.0.0.1185.exe
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
7400
ZipSoft.exe
188.130.153.32:443
api.zip-soft.net
Rostpay Ltd
RU
suspicious
7400
ZipSoft.exe
188.130.153.33:443
api.zip-soft.net
Rostpay Ltd
RU
suspicious
6544
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.49
whitelisted
api.zip-soft.net
  • 188.130.153.32
  • 188.130.153.33
unknown
api.az-partners.net
  • 188.130.153.33
  • 188.130.153.32
unknown
login.live.com
  • 40.126.32.68
  • 20.190.160.130
  • 20.190.160.67
  • 40.126.32.138
  • 40.126.32.140
  • 20.190.160.5
  • 20.190.160.4
  • 20.190.160.132
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
www.zip-soft.net
  • 188.130.153.33
  • 188.130.153.32
unknown
7-zip.org
  • 49.12.202.237
unknown
free.360totalsecurity.com
  • 151.236.71.147
whitelisted

Threats

PID
Process
Class
Message
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
Misc activity
ET INFO Packed Executable Download
No debug info