| File name: | ZoomInfoContactContributor-57-3.exe |
| Full analysis: | https://app.any.run/tasks/9d75db2d-1526-4322-8be0-c6e606fdcec6 |
| Verdict: | Malicious activity |
| Analysis date: | October 31, 2023, 03:05:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 0C4CBC3957BD9651AF06F76AD32B1FA2 |
| SHA1: | A0C2D8CDFC71545623EA01D143F213AD66499F35 |
| SHA256: | C5CCC464818ECCA316D98C67A79FC51192835CBC1EBA3060A22537D0382EEB41 |
| SSDEEP: | 3072:FHonJ5U5TPVobeaOETMsfKnFgem6Nh2/Qz1Kz+Rd4CYM:FHoPUlPeDOETMXiYQB8d4CY |
| .exe | | | NSIS - Nullsoft Scriptable Install System (94.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.5) |
| .exe | | | Generic Win/DOS Executable (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:12:05 23:50:52+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 164864 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x30fa |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.57 |
| ProductVersionNumber: | 2.0.0.57 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | ASCII |
| FileDescription: | - |
| FileVersion: | 57 |
| LegalCopyright: | (c) Zoom Information, Inc. |
| ProductName: | ZoomInfo Contact Contributor |
| ProductVersion: | 57 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\ZoomInfoCEUtility\launch.bat"" | C:\Windows\System32\cmd.exe | — | ZoomInfoContactContributor-57-3.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1032 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2252 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1244 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1244 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1244 | "C:\Windows\system32\notepad.exe" C:\Users\admin\AppData\Local\ZoomInfoCEUtility\launch.bat | C:\Windows\System32\notepad.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1620 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3956 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1648 | "C:\Users\admin\AppData\Local\ZoomInfoCEUtility\2258\coordinator.exe" | C:\Users\admin\AppData\Local\ZoomInfoCEUtility\2258\coordinator.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2128 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1460 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2296 | "C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2812 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3220 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2860 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2284 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: On | |||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: On | |||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: On | |||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: On | |||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: On | |||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: On | |||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: On | |||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: On | |||
| (PID) Process: | (4076) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1055 |
Value: On | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4076 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVR45FB.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 4076 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst | — | |
MD5:— | SHA256:— | |||
| 3328 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVR66F0.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3820 | ZoomInfoContactContributor-57-3.exe | C:\Users\admin\AppData\Local\ZoomInfoCEUtility\ZoomInfo_Grow.zip | — | |
MD5:— | SHA256:— | |||
| 3820 | ZoomInfoContactContributor-57-3.exe | C:\Users\admin\AppData\Local\Temp\nsoB053.tmp\nsDialogs.dll | executable | |
MD5:C10E04DD4AD4277D5ADC951BB331C777 | SHA256:E31AD6C6E82E603378CB6B80E67D0E0DCD9CF384E1199AC5A65CB4935680021A | |||
| 3820 | ZoomInfoContactContributor-57-3.exe | C:\Users\admin\AppData\Local\Temp\nsoB053.tmp\GetVersion.dll | executable | |
MD5:2E2412281A205ED8D53AAFB3EF770A2D | SHA256:DB09ADB6E17B6A0B31823802431FF5209018EE8C77A193AC8077E42E5F15FB00 | |||
| 3820 | ZoomInfoContactContributor-57-3.exe | C:\Users\admin\AppData\Local\Temp\fccoordinator.tmp | text | |
MD5:11FA8A81C1DE99D4C03F433A9C1C6505 | SHA256:CA77688E75B0088ECEE17258959ECF7FAD24C77BCA9DB0183671144B383E6FE1 | |||
| 3820 | ZoomInfoContactContributor-57-3.exe | C:\Users\admin\AppData\Local\Temp\nsoB053.tmp\FindProcDLL.dll | executable | |
MD5:83CD62EAB980E3D64C131799608C8371 | SHA256:A6122E80F1C51DC72770B4F56C7C482F7A9571143FBF83B19C4D141D0CB19294 | |||
| 4076 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\mso480F.tmp | html | |
MD5:A8934077843220A8E31367C7BBE15E6C | SHA256:A2DB0201D36F07F3F99D1ADF8B8EAFB9CF9BB803D024FCC9327B77AF56346861 | |||
| 4076 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{6B7F08BB-0D35-42F8-8996-E4B265053B78}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.png | image | |
MD5:4C61C12EDBC453D7AE184976E95258E1 | SHA256:296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3820 | ZoomInfoContactContributor-57-3.exe | GET | 302 | 216.58.213.115:80 | http://cswapper.freshcontacts.com/client/download2?client_version=57&client_id={A1CF6C7A-BFA7-4AE5-AAB9-0B3E769D0A79}&outlook_bitness=32&reachout=true&appid=3 | unknown | — | — | unknown |
3912 | msedge.exe | GET | 302 | 142.250.187.147:80 | http://cswapper.freshcontacts.com/client/installsuccess?client_version=57&os_version=Windows%206.1%20Service%20Pack%201%207601%2032%20[%20]&outlook_version=14&outlook_bitness=32&autostart=1&client_id={A1CF6C7A-BFA7-4AE5-AAB9-0B3E769D0A79}&reachout=true&appid=3 | unknown | — | — | unknown |
3820 | ZoomInfoContactContributor-57-3.exe | GET | 200 | 142.251.140.91:80 | http://storage.googleapis.com/coordinator-packages-public/swapper-2258.zip | unknown | compressed | 89.7 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4076 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3820 | ZoomInfoContactContributor-57-3.exe | 216.58.213.115:80 | cswapper.freshcontacts.com | GOOGLE | US | unknown |
3820 | ZoomInfoContactContributor-57-3.exe | 142.251.140.91:80 | storage.googleapis.com | GOOGLE | US | unknown |
3912 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3520 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3912 | msedge.exe | 142.250.187.147:80 | cswapper.freshcontacts.com | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
config.messenger.msn.com |
| whitelisted |
cswapper.freshcontacts.com |
| whitelisted |
storage.googleapis.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
data-edge.smartscreen.microsoft.com |
| whitelisted |
www.zoominfo.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.zoominfo.com |
| unknown |