| URL: | github.com/laipeiyuanq/memz-/blob/main/MEMZ%203.0%20(1).zip | 
| Full analysis: | https://app.any.run/tasks/92560adc-80d7-46f5-b229-d75b1495ee24 | 
| Verdict: | Malicious activity | 
| Analysis date: | October 27, 2025, 18:21:26 | 
| OS: | Windows 10 Professional (build: 19044, 64 bit) | 
| Tags: | |
| Indicators: | |
| MD5: | 50B3ED0049A05886EAFB7CD40232651B | 
| SHA1: | 90E08CC9EA10B1521E7A3A25531D098853CCD9FF | 
| SHA256: | C8FB3F2AF715922B5FD067524F0F8E627852535ADE5884D8D8C1FDD1BB9242AA | 
| SSDEEP: | 3:j4d5EP7If3SERkAXVUA3V4:j4cPMfisJXVUaV4 | 
| PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1172 | "C:\Users\admin\Desktop\MEMZ 3.0\MEMZ.exe" | C:\Users\admin\Desktop\MEMZ 3.0\MEMZ.exe | — | explorer.exe | |||||||||||
| User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
 | |||||||||||||||
| 1500 | "C:\Users\admin\Desktop\MEMZ 3.0\MEMZ.exe" /watchdog | C:\Users\admin\Desktop\MEMZ 3.0\MEMZ.exe | MEMZ.exe | ||||||||||||
| User: admin Integrity Level: HIGH Modules
 | |||||||||||||||
| 1780 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 2276 -prefsLen 39191 -prefMapHandle 4152 -prefMapSize 273045 -jsInitHandle 4140 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4160 -initialChannelId {22503999-d18d-4f45-b7f5-377752a3d820} -parentPid 7616 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7616" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 11 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
| User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
 | |||||||||||||||
| 1924 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4216,i,212488927051480104,8082544972910868277,262144 --variations-seed-version --mojo-platform-channel-handle=4204 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
 | |||||||||||||||
| 2116 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=8 --always-read-main-dll --field-trial-handle=4896,i,212488927051480104,8082544972910868277,262144 --variations-seed-version --mojo-platform-channel-handle=5176 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
 | |||||||||||||||
| 2276 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
| User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
 | |||||||||||||||
| 2688 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6540,i,212488927051480104,8082544972910868277,262144 --variations-seed-version --mojo-platform-channel-handle=6000 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
 | |||||||||||||||
| 2712 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4880 -prefsLen 39191 -prefMapHandle 4784 -prefMapSize 273045 -jsInitHandle 5052 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4496 -initialChannelId {27ce65e6-5b87-4411-9583-caad391b1935} -parentPid 7616 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7616" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
| User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
 | |||||||||||||||
| 2968 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --disable-quic --flag-switches-end --do-not-de-elevate --single-argument https://google.co.ck/search?q=virus+builder+legit+free+download | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
 | |||||||||||||||
| 3064 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2264,i,212488927051480104,8082544972910868277,262144 --variations-seed-version --mojo-platform-channel-handle=2504 /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
 | |||||||||||||||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 15 | 
| Value: | |||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 14 | 
| Value: | |||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 13 | 
| Value: | |||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 12 | 
| Value: | |||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 11 | 
| Value: | |||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 10 | 
| Value: | |||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 9 | 
| Value: | |||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 8 | 
| Value: | |||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 7 | 
| Value: | |||
| (PID) Process: | (8100) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath | 
| Operation: | delete value | Name: | 6 | 
| Value: | |||
| PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7616 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
| MD5:— | SHA256:— | |||
| 7616 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.bin | binary | |
| MD5:EC428C7E4FCA7D4BB311AB82C5E0E7A4 | SHA256:09BF45113DBD56750973318B00B9455CE9F8BDCF8B11D76A5DC096EA4FB98FBB | |||
| 7616 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
| MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 7616 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.js | text | |
| MD5:89FDAD2BB592C8A08C49FC82E8E15E67 | SHA256:5C6D6A9AC3ABA09498787939D29135A6386854181E23F9F5C9244794CD8F1498 | |||
| 7616 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
| MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 7616 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
| MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 7616 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\bounce-tracking-protection.sqlite-journal | binary | |
| MD5:AD7BBEDDA5781B794284C8096BAB1911 | SHA256:06C3D0B6C87FAC5FEB826FE88A250E1D6783676705EBB3848FFDF7DCD1DD40EA | |||
| 7616 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
| MD5:89FDAD2BB592C8A08C49FC82E8E15E67 | SHA256:5C6D6A9AC3ABA09498787939D29135A6386854181E23F9F5C9244794CD8F1498 | |||
| 7616 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
| MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 7616 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
| MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation | 
|---|---|---|---|---|---|---|---|---|---|
| 7616 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown |  —  | — | whitelisted | 
| 7616 | firefox.exe | POST | 200 | 216.58.206.35:80 | http://o.pki.goog/s/wr3/25s | unknown |  —  | — | whitelisted | 
| 7616 | firefox.exe | POST | 200 | 216.58.206.35:80 | http://o.pki.goog/we2 | unknown |  —  | — | whitelisted | 
| 7616 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown |  —  | — | whitelisted | 
| 7616 | firefox.exe | POST | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/ | unknown |  —  | — | whitelisted | 
| 7616 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown |  —  | — | whitelisted | 
| 7616 | firefox.exe | POST | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/ | unknown |  —  | — | whitelisted | 
| 7616 | firefox.exe | POST | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/ | unknown |  —  | — | whitelisted | 
| 7616 | firefox.exe | POST | 200 | 216.58.206.35:80 | http://o.pki.goog/s/wr3/prs | unknown |  —  | — | whitelisted | 
| 7616 | firefox.exe | POST | 200 | 216.58.206.35:80 | http://o.pki.goog/s/wr3/prs | unknown |  —  | — | whitelisted | 
| PID | Process | IP | Domain | ASN | CN | Reputation | 
|---|---|---|---|---|---|---|
| 5488 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted | 
| 4 | System | 192.168.100.255:137 | — | — | — | whitelisted | 
| 5596 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted | 
| 2328 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted | 
| 4 | System | 192.168.100.255:138 | — | — | — | whitelisted | 
| 7616 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | whitelisted | 
| 7616 | firefox.exe | 140.82.121.3:443 | github.com | GITHUB | US | whitelisted | 
| 7616 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted | 
| 7616 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted | 
| 7616 | firefox.exe | 172.64.149.23:80 | ocsp.sectigo.com | CLOUDFLARENET | US | whitelisted | 
| Domain | IP | Reputation | 
|---|---|---|
| settings-win.data.microsoft.com | 
 | whitelisted | 
| google.com | 
 | whitelisted | 
| content-signature-2.cdn.mozilla.net | 
 | whitelisted | 
| content-signature-chains.prod.autograph.services.mozaws.net | 
 | whitelisted | 
| github.com | 
 | whitelisted | 
| detectportal.firefox.com | 
 | whitelisted | 
| prod.detectportal.prod.cloudops.mozgcp.net | 
 | whitelisted | 
| contile.services.mozilla.com | 
 | whitelisted | 
| spocs.getpocket.com | 
 | whitelisted | 
| ocsp.sectigo.com | 
 | whitelisted | 
| PID | Process | Class | Message | 
|---|---|---|---|
| 2276 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub | 
| 2276 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub | 
| 2276 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub | 
| — | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) | 
| — | — | Generic Protocol Command Decode | SURICATA HTTP request field missing colon | 
| — | — | Generic Protocol Command Decode | SURICATA HTTP URI terminated by non-compliant character | 
| — | — | Generic Protocol Command Decode | SURICATA HTTP request header invalid | 
| — | — | Generic Protocol Command Decode | SURICATA HTTP METHOD terminated by non-compliant character | 
| — | — | Not Suspicious Traffic | INFO [ANY.RUN] Websocket Upgrade Request | 
| — | — | Generic Protocol Command Decode | SURICATA HTTP request field missing colon |