File name:

Unconfirmed 902518.crdownload

Full analysis: https://app.any.run/tasks/671cc81e-19b5-4178-a6f1-c8e896d397c9
Verdict: Malicious activity
Analysis date: October 20, 2024, 23:16:09
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BC48CB98D8F2DACCA97A2EB72F4275CB

SHA1:

CD3DD263FC37C8C7BEB1393A654B400F2F531F1C

SHA256:

C18FB46AFA17AD8578D1EDD4AA6A89B42F381CA7998A4E5A096643E0F2721C49

SSDEEP:

3072:mUGN8U00oL0pMQPmcDgbt6RbMMlLDYthINgsVHRjb:mUS03wpfPm1b8RbMMRqI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
    • Executable content was dropped or overwritten

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
      • Installer.exe (PID: 7156)
      • Zoom.exe (PID: 6296)
    • Process drops legitimate windows executable

      • Installer.exe (PID: 7156)
    • Checks Windows Trust Settings

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
    • The process drops C-runtime libraries

      • Installer.exe (PID: 7156)
    • The process creates files with name similar to system file names

      • Installer.exe (PID: 7156)
    • Starts itself from another location

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
    • Starts application with an unusual extension

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
    • Application launched itself

      • Installer.exe (PID: 7156)
      • Zoom.exe (PID: 6296)
  • INFO

    • Create files in a temporary directory

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
    • Reads the computer name

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
      • Installer.exe (PID: 7156)
    • Creates files or folders in the user directory

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
      • Installer.exe (PID: 7156)
    • Reads the machine GUID from the registry

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
      • Installer.exe (PID: 7156)
    • Checks proxy server information

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
    • Checks supported languages

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
      • Installer.exe (PID: 7156)
    • Process checks computer location settings

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
    • The process uses the downloaded file

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
    • Reads the software policy settings

      • Unconfirmed 902518.crdownload.exe (PID: 6216)
    • Sends debugging messages

      • Installer.exe (PID: 7156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:26 05:23:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 70656
InitializedDataSize: 44032
UninitializedDataSize: -
EntryPoint: 0x6be0
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 6.1.10.43
ProductVersionNumber: 6.1.10.43
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: Zoom Opener
CompanyName: Zoom Video Communications, Inc.
FileDescription: Zoom Opener
FileVersion: 6,1,10,43
InternalName: Zoom Opener
LegalCopyright: © Zoom Video Communications, Inc. All rights reserved.
LegalTrademarks: Zoom Opener
OriginalFileName: Zoom Opener
ProductName: Zoom Opener
ProductVersion: 6,1,10,43
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start unconfirmed 902518.crdownload.exe installer.exe sppextcomobj.exe no specs slui.exe no specs installer.exe zoom.exe zm4838.tmp no specs zoom.exe

Process information

PID
CMD
Path
Indicators
Parent process
4232"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe" --action=joinbyno --runaszvideo=TRUE C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
Zoom.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Meetings
Version:
6,2,3,47507
Modules
Images
c:\users\admin\appdata\roaming\zoom\bin\zoom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\users\admin\appdata\roaming\zoom\bin\cmmlib.dll
4812"C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe" /addfwexception --bin_home="C:\Users\admin\AppData\Roaming\Zoom\bin"C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe
Installer.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
HIGH
Description:
Zoom Installer
Exit code:
0
Version:
6,2,3,47507
Modules
Images
c:\users\admin\appdata\roaming\zoom\zoomdownload\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6216"C:\Users\admin\AppData\Local\Temp\Unconfirmed 902518.crdownload.exe" C:\Users\admin\AppData\Local\Temp\Unconfirmed 902518.crdownload.exe
explorer.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Opener
Exit code:
0
Version:
6,1,10,43
Modules
Images
c:\users\admin\appdata\local\temp\unconfirmed 902518.crdownload.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6288C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6292"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6296"C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe" "--url=zoommtg://win.launch?h.domain=zoom.us&h.path=join&action=join&confno="C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
Unconfirmed 902518.crdownload.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Meetings
Version:
6,2,3,47507
Modules
Images
c:\users\admin\appdata\roaming\zoom\bin\zoom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
6564"C:\Users\admin\AppData\Local\Temp\zm4838.tmp" -DAF8C715436E44649F1312698287E6A5=C:\Users\admin\AppData\Local\Temp\Unconfirmed 902518.crdownload.exeC:\Users\admin\AppData\Local\Temp\zm4838.tmpUnconfirmed 902518.crdownload.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Opener
Exit code:
0
Version:
6,1,10,43
Modules
Images
c:\users\admin\appdata\local\temp\zm4838.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
7156"C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe" ZInstaller --conf.mode=silent --ipc_wnd=262728C:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exe
Unconfirmed 902518.crdownload.exe
User:
admin
Company:
Zoom Video Communications, Inc.
Integrity Level:
MEDIUM
Description:
Zoom Installer
Exit code:
0
Version:
6,2,3,47507
Modules
Images
c:\users\admin\appdata\roaming\zoom\zoomdownload\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
Total events
18 770
Read events
18 666
Write events
78
Delete events
26

Modification events

(PID) Process:(6216) Unconfirmed 902518.crdownload.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6216) Unconfirmed 902518.crdownload.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6216) Unconfirmed 902518.crdownload.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7156) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe
(PID) Process:(7156) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:DisplayName
Value:
Zoom Workplace
(PID) Process:(7156) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:DisplayVersion
Value:
6.2.3 (47507)
(PID) Process:(7156) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:HelpLink
Value:
https://support.zoom.us/home
(PID) Process:(7156) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:URLInfoAbout
Value:
https://zoom.us
(PID) Process:(7156) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:URLUpdateInfo
Value:
https://zoom.us
(PID) Process:(7156) Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoomUMX
Operation:writeName:Publisher
Value:
Zoom Video Communications, Inc.
Executable files
253
Suspicious files
214
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
6216Unconfirmed 902518.crdownload.exeC:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Zoom.msi
MD5:
SHA256:
6216Unconfirmed 902518.crdownload.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cder
MD5:C321F1C7215459541829F055E4DF1594
SHA256:E3AED728513B8F30BA5F4B1AEF3984AF5BBFDB40A6A64B028A81478B2A12D0FD
7156Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\clap-high.pcmbinary
MD5:C32F95839557340B4B4197A68847CA1D
SHA256:0A16435CB3F7B8B1787476575AD646361E6FB4C07587DF874940413DE004DD08
7156Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\duilib_license.txttext
MD5:7FAEC2006BB231D14B794A9F31769448
SHA256:7ED2ACCA31A243BA107D8C12FDDECD52462FD326D3D2C73B04D4CF10C76765FF
7156Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\crashrpt_lang.initext
MD5:FCF61AED8F093BFCF571CDD8F8162A05
SHA256:1F5B45A5411F7FC71B9DA789D6D1EAD8AD30551FBEA7BBB40FC7EA576D581ABB
7156Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\dingdong.pcmbinary
MD5:54511224E61E71D2915FF67E57DCB268
SHA256:7AADF0E317831D287B51E41992B43F0F381AE48A312CB77A426EEB3B6129D6D7
7156Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\clap-medium.pcmbinary
MD5:AA93AB138EC89CF7CFB8B4B0EA8990A6
SHA256:D754FC9D9378772B7A17A53E6598C9CFE4A0F3EC492F0ED30241020562F58509
7156Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\archival.pcmbinary
MD5:2DA32E501E9720B40D438FF7352A5573
SHA256:5E7D1491E7D6969EB67646F87AB2DBF0FF1D1CB4F5CF631128A305E2B67D4A1B
6216Unconfirmed 902518.crdownload.exeC:\Users\admin\AppData\Roaming\Zoom\ZoomDownload\Installer.exeexecutable
MD5:97F9E69D58C37809BBF69D1E9DA9AD7A
SHA256:52BA24DC0905BC7D12F9D776E2DB0F67129E6AE7E40B8B261D957F0EB8EC1E3C
7156Installer.exeC:\Users\admin\AppData\Roaming\Zoom\zoom_install_src\dingdong1.pcmbinary
MD5:8FE86D9E8AA5C709BB0563243172E580
SHA256:2FBBB9AE6A463B360E1459BEE558DAFA8D864DB2423F0FE4D2C56D22C3F3A5A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
73
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6216
Unconfirmed 902518.crdownload.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
whitelisted
6376
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6944
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6208
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6208
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6680
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2.23.209.140:443
www.bing.com
Akamai International B.V.
GB
whitelisted
7044
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6216
Unconfirmed 902518.crdownload.exe
170.114.52.2:443
zoom.us
US
whitelisted
170.114.52.2:443
zoom.us
US
whitelisted
170.114.45.1:443
cdn.zoom.us
Cloudflare London, LLC
US
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
www.bing.com
  • 2.23.209.140
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.149
  • 2.23.209.182
whitelisted
google.com
  • 172.217.16.142
whitelisted
zoom.us
  • 170.114.52.2
whitelisted
cdn.zoom.us
  • 170.114.45.1
  • 170.114.46.1
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.4
  • 20.190.159.2
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.23
  • 40.126.31.71
whitelisted
th.bing.com
  • 2.23.209.182
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.130
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted

Threats

No threats detected
Process
Message
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\zoom_install_src
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\tmp_uninstall
Installer.exe
Installer.exe
[ProductPathHelper::RecursiveRemoveDirA] Path is:
Installer.exe
C:\Users\admin\AppData\Roaming\Zoom\tmp_bin
Installer.exe
Installer.exe
C:\Users\Public\Desktop\Adobe Acrobat.lnk