File name:

ZipSoft.exe

Full analysis: https://app.any.run/tasks/eb15066d-5f49-4b76-ad73-57fcb470ebf8
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 16, 2025, 07:04:13
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

33B6BB65EF9087F7D62CF5A01CC3B863

SHA1:

6BFE8074F98E2CC0C9A182417F01A02D90118CB6

SHA256:

BE79146A6B2AD73AF155836449FF0A1DC1A69483D5DDA3F1A8B6BB8867B6E8B4

SSDEEP:

24576:XhXlRauLC50SBffyyyyyyyyyyyyK7VVgoTF3B9jV6XfE3Fzv6qlUqT:XhXlLCucyyyyyyyyyyyyK7V62F3B9jV9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • setup.exe (PID: 8084)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 7212)
    • Steals credentials from Web Browsers

      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 7212)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Executable content was dropped or overwritten

      • OperaSetup.exe (PID: 7988)
      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8084)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 7212)
      • OperaGXSetup.exe (PID: 8108)
      • setup.exe (PID: 6068)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 4776)
      • setup.exe (PID: 6988)
      • setup.exe (PID: 6712)
      • 7z2409-x64.exe (PID: 4428)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 2108)
    • Drops 7-zip archiver for unpacking

      • ZipSoft.exe (PID: 7400)
      • 7z2409-x64.exe (PID: 4428)
    • Application launched itself

      • setup.exe (PID: 8052)
      • setup.exe (PID: 7212)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 6712)
    • Starts itself from another location

      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
    • Potential Corporate Privacy Violation

      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Starts POWERSHELL.EXE for commands execution

      • ZipSoft.exe (PID: 7400)
    • Process requests binary or script from the Internet

      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Creates a software uninstall entry

      • 7z2409-x64.exe (PID: 4428)
    • Creates/Modifies COM task schedule object

      • 7z2409-x64.exe (PID: 4428)
  • INFO

    • Checks proxy server information

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Reads the computer name

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 7212)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 6712)
      • 7z2409-x64.exe (PID: 4428)
      • 7zFM.exe (PID: 812)
    • Reads the machine GUID from the registry

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Disables trace logs

      • ZipSoft.exe (PID: 7400)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Checks supported languages

      • ZipSoft.exe (PID: 7400)
      • OperaSetup.exe (PID: 7988)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • OperaGXSetup.exe (PID: 8108)
      • setup.exe (PID: 6068)
      • setup.exe (PID: 7212)
      • setup.exe (PID: 7276)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 4776)
      • setup.exe (PID: 6988)
      • setup.exe (PID: 6712)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 2108)
      • 7z2409-x64.exe (PID: 4428)
      • 7zFM.exe (PID: 812)
    • The sample compiled with english language support

      • OperaSetup.exe (PID: 7988)
      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • setup.exe (PID: 6068)
      • setup.exe (PID: 7212)
      • OperaGXSetup.exe (PID: 8108)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 6988)
      • setup.exe (PID: 6712)
      • setup.exe (PID: 4776)
      • setup.exe (PID: 6404)
      • 7z2409-x64.exe (PID: 4428)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 2108)
    • Create files in a temporary directory

      • OperaSetup.exe (PID: 7988)
      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 8084)
      • OperaGXSetup.exe (PID: 8108)
      • setup.exe (PID: 6404)
      • setup.exe (PID: 7212)
      • setup.exe (PID: 7276)
      • setup.exe (PID: 6068)
      • setup.exe (PID: 4776)
      • setup.exe (PID: 6988)
      • setup.exe (PID: 6712)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
      • setup.exe (PID: 2108)
    • Reads the software policy settings

      • ZipSoft.exe (PID: 7400)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 6404)
    • Creates files or folders in the user directory

      • setup.exe (PID: 8084)
      • setup.exe (PID: 8052)
      • setup.exe (PID: 4776)
      • setup.exe (PID: 6404)
      • 901f10a0-3786-461e-af7e-5ae443cd02d2.exe (PID: 4108)
    • Process checks computer location settings

      • ZipSoft.exe (PID: 7400)
    • Creates files in the program directory

      • 7z2409-x64.exe (PID: 4428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2077:10:12 02:36:29+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 1038848
InitializedDataSize: 7680
UninitializedDataSize: -
EntryPoint: 0xff7c2
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.7.0
ProductVersionNumber: 2.0.7.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Install any useful software with a single click
CompanyName: ROSTPAY LTD
FileDescription: ZipSoft
FileVersion: 2.0.7.0
InternalName: ZipSoft.exe
LegalCopyright: © ROSTPAY LTD. All rights reserved.
LegalTrademarks: -
OriginalFileName: ZipSoft.exe
ProductName: ZipSoft
ProductVersion: 2.0.7.0
AssemblyVersion: 2.0.7.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
22
Malicious processes
7
Suspicious processes
3

Behavior graph

Click at the process to see the details
start zipsoft.exe sppextcomobj.exe no specs slui.exe no specs operasetup.exe setup.exe setup.exe operagxsetup.exe setup.exe 901f10a0-3786-461e-af7e-5ae443cd02d2.exe 7z2409-x64.exe setup.exe setup.exe setup.exe setup.exe setup.exe setup.exe setup.exe powershell.exe no specs conhost.exe no specs 7zfm.exe no specs svchost.exe zipsoft.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
812"C:\Program Files\7-Zip\7zFM.exe" C:\Program Files\7-Zip\7zFM.exepowershell.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip File Manager
Exit code:
0
Version:
24.09
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
2108C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=117.0.5408.213 --initial-client-data=0x28c,0x290,0x2a0,0x268,0x2a4,0x7ffc861916f8,0x7ffc86191704,0x7ffc86191710C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera GX Installer
Version:
117.0.5408.213
Modules
Images
c:\users\admin\appdata\local\temp\7zscaf2fa71\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
4108"C:\Users\admin\AppData\Local\Temp\901f10a0-3786-461e-af7e-5ae443cd02d2.exe" /sC:\Users\admin\AppData\Local\Temp\901f10a0-3786-461e-af7e-5ae443cd02d2.exe
ZipSoft.exe
User:
admin
Company:
Qihoo 360 Technology Co. Ltd.
Integrity Level:
HIGH
Description:
360 Total Security Online Installer
Version:
6, 6, 0, 1060
Modules
Images
c:\users\admin\appdata\local\temp\901f10a0-3786-461e-af7e-5ae443cd02d2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
4428"C:\Users\admin\AppData\Local\Temp\ZipSoft\7z2409-x64.exe" /SC:\Users\admin\AppData\Local\Temp\ZipSoft\7z2409-x64.exe
ZipSoft.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Installer
Exit code:
0
Version:
24.09
Modules
Images
c:\users\admin\appdata\local\temp\zipsoft\7z2409-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4776C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=117.0.5408.213 --initial-client-data=0x294,0x298,0x29c,0x270,0x2a0,0x7ffc878216f8,0x7ffc87821704,0x7ffc87821710C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera GX Installer
Version:
117.0.5408.213
Modules
Images
c:\users\admin\appdata\local\temp\7zscaf2fa71\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5260\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5400"powershell.exe" /command "start shell:'appsfolder\{6D809377-6AF0-444B-8957-A3773F02200E}\7-Zip\7zFM.exe'"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeZipSoft.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
6068"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
118.0.5461.41
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6404C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe --silent --allusers=0 --server-tracking-blob=NDA1N2VlYjg3MzdlNGM4NjljYWMyMmJmMTZlZjYxMDIzZTI5NmVhMzBiNWRhNmY0NTU3ZGQyM2E1OTAyYWIwZDp7ImNvdW50cnkiOiJERSIsImVkaXRpb24iOiJzdGQtMiIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFHWFNldHVwLmV4ZSIsInByb2R1Y3QiOiJvcGVyYV9neCIsInF1ZXJ5IjoiL29wZXJhX2d4L3N0YWJsZS9lZGl0aW9uL3N0ZC0yP3V0bV9zb3VyY2U9UFdOZ2FtZXMmdXRtX21lZGl1bT1wYSZ1dG1fY2FtcGFpZ249UFdOX0RFX1BCNV85NDE2XzM4NDkmdXRtX2lkPTkwOWNlNjljZWRkYjQ0YzFiM2Y1OWJmNDUwMTQwOTZiIiwidGltZXN0YW1wIjoiMTc0NDc4NzA3OC4wOTk0IiwidXNlcmFnZW50IjoiWmlwU29mdFdyYXBwZXIvMi4wLjcuMCAxMC4wL3g2NCIsInV0bSI6eyJjYW1wYWlnbiI6IlBXTl9ERV9QQjVfOTQxNl8zODQ5IiwiaWQiOiI5MDljZTY5Y2VkZGI0NGMxYjNmNTliZjQ1MDE0MDk2YiIsIm1lZGl1bSI6InBhIiwic291cmNlIjoiUFdOZ2FtZXMifSwidXVpZCI6IjY3OTk4OTMxLTA1NTktNDEwZi1iZDEwLTA5YTUzZGYwY2ZiZSJ9C:\Users\admin\AppData\Local\Temp\7zSCAF2FA71\setup.exe
OperaGXSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera GX Installer
Version:
117.0.5408.213
Modules
Images
c:\users\admin\appdata\local\temp\7zscaf2fa71\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
11 334
Read events
11 252
Write events
78
Delete events
4

Modification events

(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7400) ZipSoft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\ZipSoft_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
29
Suspicious files
22
Text files
99
Unknown types
0

Dropped files

PID
Process
Filename
Type
7400ZipSoft.exeC:\Users\admin\AppData\Local\Temp\OperaGXSetup.exeexecutable
MD5:8FAA19A7573EF5D07BFF297388942F42
SHA256:FDFA76D22E13251ABDEAFC8BBA80148CE0EB93A9F3215EADBF9E2A5D0CC7B7E3
7988OperaSetup.exeC:\Users\admin\AppData\Local\Temp\7zS43F3D380\setup.exeexecutable
MD5:53966124DB88689E3C0836C5BC5508B6
SHA256:346E414427D9352F6049EFFB479566D6F262372873F1EBB2EF5D6BFD5A8CD052
7400ZipSoft.exeC:\Users\admin\AppData\Local\Temp\ZipSoft\7z2409-x64.exeexecutable
MD5:6C73CC4C494BE8F4E680DE1A20262C8A
SHA256:BDD1A33DE78618D16EE4CE148B849932C05D0015491C34887846D431D29F308E
7400ZipSoft.exeC:\Users\admin\AppData\Local\Temp\OperaSetup.exeexecutable
MD5:C9FC0ABF2DBB379E6F30CDC185DA080C
SHA256:39D49391BA9364C689995E282E652188099B338F8CA738843036A3F7E20BAB9A
44287z2409-x64.exeC:\Program Files\7-Zip\descript.iontext
MD5:EB7E322BDC62614E49DED60E0FB23845
SHA256:1DA513F5A4E8018B9AE143884EB3EAF72454B606FD51F2401B7CFD9BE4DBBF4F
44287z2409-x64.exeC:\Program Files\7-Zip\7-zip.chmbinary
MD5:A7BA50E8A23BF4A17F827C69BDB8F6AB
SHA256:94561A6DD2E91B42D566846270B9D8915C30DD9200E7AAB3A4E37547C0042491
44287z2409-x64.exeC:\Program Files\7-Zip\Lang\an.txttext
MD5:F16218139E027338A16C3199091D0600
SHA256:3AB9F7AACD38C4CDE814F86BC37EEC2B9DF8D0DDDB95FC1D09A5F5BCB11F0EEB
44287z2409-x64.exeC:\Program Files\7-Zip\History.txttext
MD5:CCAD44B829868FC155D11387F09C4F4B
SHA256:7D6A3D181B5166FFE08F2779903EDD2749C3EF78FD3C0174BDC4380F4A7511B8
44287z2409-x64.exeC:\Program Files\7-Zip\Lang\ar.txttext
MD5:5747381DC970306051432B18FB2236F2
SHA256:85A26C7B59D6D9932F71518CCD03ECEEBA42043CB1707719B72BFC348C1C1D72
8052setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeexecutable
MD5:53966124DB88689E3C0836C5BC5508B6
SHA256:346E414427D9352F6049EFFB479566D6F262372873F1EBB2EF5D6BFD5A8CD052
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
71
DNS requests
36
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
8052
setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
8052
setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEA17ZgsSl63KHstWnAbUez0%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8052
setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAsA6S1NbXMfyjBZx8seGIY%3D
unknown
whitelisted
8052
setup.exe
GET
200
142.250.186.35:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
8052
setup.exe
GET
200
142.250.186.35:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
200
151.236.71.147:80
http://iup.360safe.com/iv3/pc/360safe/360TS_Setup_For_Mini_Rel.cab
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
200
18.184.178.29:80
http://s.360safe.com/360ts/mini_inst.htm?ver=6.6.0.1060&pid=WW.AZLP.CPI20240305&os=10.0&mid=80342cb959da2233832ae840f019ccba&state=153
unknown
whitelisted
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
GET
200
18.184.178.29:80
http://s.360safe.com/safei18n/dimana.htm?lr=1&mid=80342cb959da2233832ae840f019ccba&mod=360Installer.exe&ph=02a8342074eb25c8adb2d135e2bab7e5&p2p=1&t_id=360TS_Setup_For_Mini.cab&tads=656&tdl=656&tds=645&terr=0&tes=Status|1,ErrorCode|0,DnCount|5,HttpNum|1,DnFailCount|5,FStatus|1,P2SS|656,P2PS|0,PDMode|2&tfl=656&tp=t&tst=1&ttdl=656&ttm=1016&ttup=120&vh=1.3.0.1361&vp=1.3.0.1320&softname=360TS
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
7400
ZipSoft.exe
188.130.153.32:443
api.zip-soft.net
Rostpay Ltd
RU
suspicious
7400
ZipSoft.exe
188.130.153.33:443
api.zip-soft.net
Rostpay Ltd
RU
suspicious
6544
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.49
whitelisted
api.zip-soft.net
  • 188.130.153.32
  • 188.130.153.33
unknown
api.az-partners.net
  • 188.130.153.33
  • 188.130.153.32
unknown
login.live.com
  • 40.126.32.68
  • 20.190.160.130
  • 20.190.160.67
  • 40.126.32.138
  • 40.126.32.140
  • 20.190.160.5
  • 20.190.160.4
  • 20.190.160.132
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
www.zip-soft.net
  • 188.130.153.33
  • 188.130.153.32
unknown
7-zip.org
  • 49.12.202.237
unknown
free.360totalsecurity.com
  • 151.236.71.147
whitelisted

Threats

PID
Process
Class
Message
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
4108
901f10a0-3786-461e-af7e-5ae443cd02d2.exe
Misc activity
ET INFO Packed Executable Download
No debug info