File name:

zarar.exe

Full analysis: https://app.any.run/tasks/00e68dab-ad17-442c-a9e9-e4f5275cf57a
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: September 03, 2025, 16:57:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
telegram
stealer
python
auto-reg
auto-sch
pyinstaller
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 7 sections
MD5:

7D71E7AE065EC97927E28741FA1875DA

SHA1:

FCBA6E964225E67FEFDFB59D995509F056222080

SHA256:

DEA73BC90C4B854C19B4693F4E4F1BB987343CA82334499557DDFDF57B5DCDA6

SSDEEP:

393216:MEKeO/05vWJzq/qkiLz7TyzfYy3TAqOYjcNddSRN3GQfFu:MNsWJzq/ti9gkyjcHG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • zarar.exe (PID: 5564)
    • Actions looks like stealing of personal data

      • zarar.exe (PID: 5564)
    • Changes the autorun value in the registry

      • zarar.exe (PID: 5564)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 6748)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • zarar.exe (PID: 3788)
    • Process drops python dynamic module

      • zarar.exe (PID: 3788)
    • The process drops C-runtime libraries

      • zarar.exe (PID: 3788)
    • Executable content was dropped or overwritten

      • zarar.exe (PID: 3788)
    • Application launched itself

      • zarar.exe (PID: 3788)
    • Loads Python modules

      • zarar.exe (PID: 5564)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • zarar.exe (PID: 5564)
    • Starts CMD.EXE for commands execution

      • zarar.exe (PID: 5564)
  • INFO

    • Reads the computer name

      • zarar.exe (PID: 3788)
      • zarar.exe (PID: 5564)
    • The sample compiled with english language support

      • zarar.exe (PID: 3788)
    • Checks supported languages

      • zarar.exe (PID: 3788)
      • zarar.exe (PID: 5564)
    • Create files in a temporary directory

      • zarar.exe (PID: 3788)
      • zarar.exe (PID: 5564)
    • Checks proxy server information

      • zarar.exe (PID: 5564)
      • slui.exe (PID: 3160)
    • Launching a file from a Registry key

      • zarar.exe (PID: 5564)
    • Launching a file from Task Scheduler

      • cmd.exe (PID: 6748)
    • PyInstaller has been detected (YARA)

      • zarar.exe (PID: 3788)
    • Reads the software policy settings

      • slui.exe (PID: 3160)
    • Uses Task Scheduler to autorun other applications (AUTOMATE)

      • cmd.exe (PID: 2400)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:09:03 16:51:49+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 179712
InitializedDataSize: 155136
UninitializedDataSize: -
EntryPoint: 0xc650
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start zarar.exe conhost.exe no specs zarar.exe svchost.exe cmd.exe schtasks.exe no specs cmd.exe no specs schtasks.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
1592\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exezarar.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2200C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2400C:\WINDOWS\system32\cmd.exe /c "schtasks /create /tn "WindowsUpdateService7286" /tr "python \"C:\Users\admin\AppData\Local\Temp\_MEI37882\zarar.py\"" /sc onlogon /f /rl highest"C:\Windows\System32\cmd.exe
zarar.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
3160C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3788"C:\Users\admin\Desktop\zarar.exe" C:\Users\admin\Desktop\zarar.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\zarar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5236schtasks /create /tn "WindowsUpdateService7286" /tr "python \"C:\Users\admin\AppData\Local\Temp\_MEI37882\zarar.py\"" /sc onlogon /f /rl highestC:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
5564"C:\Users\admin\Desktop\zarar.exe" C:\Users\admin\Desktop\zarar.exe
zarar.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\zarar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6748C:\WINDOWS\system32\cmd.exe /c "schtasks /create /tn "SystemMaintenance1828" /tr "python \"C:\Users\admin\AppData\Local\Temp\_MEI37882\zarar.py\"" /sc daily /f /rl highest"C:\Windows\System32\cmd.exezarar.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
6812schtasks /create /tn "SystemMaintenance1828" /tr "python \"C:\Users\admin\AppData\Local\Temp\_MEI37882\zarar.py\"" /sc daily /f /rl highestC:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
4 002
Read events
4 000
Write events
2
Delete events
0

Modification events

(PID) Process:(5564) zarar.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:WindowsUpdateService2866
Value:
python "C:\Users\admin\AppData\Local\Temp\_MEI37882\zarar.py"
(PID) Process:(5564) zarar.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:WindowsUpdateService6368
Value:
python "C:\Users\admin\AppData\Local\Temp\_MEI37882\zarar.py"
Executable files
71
Suspicious files
7
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\PIL\_webp.cp312-win_amd64.pydexecutable
MD5:4B35DBBF5685D16596C5806D1F6681CE
SHA256:B279C625F07BCB2EAECC533FEA418D2A538CBFB0161F09F7D50BF484958EF343
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\PIL\_avif.cp312-win_amd64.pydexecutable
MD5:8975167CDBCA5A3E3FAB82C1F05AB4AF
SHA256:7F993AED80D4DFCBA1BAE7E307E10DA0FD42AE0FC46876032AC138EA511B55C3
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\PIL\_imaging.cp312-win_amd64.pydexecutable
MD5:FF163777A353E75B70C979BF6F296E6D
SHA256:03C6629B37D514770D33BFEB1C02179E50779AE67587310310A96B2DE5E7142A
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\_brotli.cp312-win_amd64.pydexecutable
MD5:9AD5BB6F92EE2CFD29DDE8DD4DA99EB7
SHA256:788ACBFD0EDD6CA3EF3E97A9487EEAEA86515642C71CB11BBCF25721E6573EC8
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\VCRUNTIME140_1.dllexecutable
MD5:F8DFA78045620CF8A732E67D1B1EB53D
SHA256:A113F192195F245F17389E6ECBED8005990BCB2476DDAD33F7C4C6C86327AFE5
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\Pythonwin\mfc140u.dllexecutable
MD5:84B82C149B450D3C8E0D06F09A416B5D
SHA256:1EC2A31A1302E720C799BAD2FD90CF3457C6B2A375C4B41FAEFEE1A91D92F3E0
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\PIL\_imagingtk.cp312-win_amd64.pydexecutable
MD5:20C6B702A24C6DEB1FC3EC46FD593BFF
SHA256:1ED10383313C15359172EC2F224B66537CA893F8E9AFA85355204826804BFBB3
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\PIL\_imagingcms.cp312-win_amd64.pydexecutable
MD5:0ED16735B4F5AC8DFDFF19FC0EF77BEE
SHA256:0E3DC1B806C412E07276FE4369750DE020065026258810016C1BF7ABABC93885
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\VCRUNTIME140.dllexecutable
MD5:BE8DBE2DC77EBE7F88F910C61AEC691A
SHA256:4D292623516F65C80482081E62D5DADB759DC16E851DE5DB24C3CBB57B87DB83
3788zarar.exeC:\Users\admin\AppData\Local\Temp\_MEI37882\PIL\_imagingmath.cp312-win_amd64.pydexecutable
MD5:48F8218F3FC97A3FD49A2D681416C5BE
SHA256:7807D7EF526A05768EC10087DF9A75CC58FC335EE3707B67C66C5D45FA3FE9ED
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
59
DNS requests
23
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3876
RUXIMICS.exe
GET
200
2.16.164.130:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
2.16.164.130:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
1268
svchost.exe
GET
200
2.16.164.130:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
3876
RUXIMICS.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
POST
200
20.190.159.71:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
unknown
POST
400
20.190.159.71:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
unknown
POST
400
20.190.159.0:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
unknown
POST
400
40.126.31.3:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3876
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5944
MoUsoCoreWorker.exe
2.16.164.130:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
1268
svchost.exe
2.16.164.130:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
3876
RUXIMICS.exe
2.16.164.130:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5944
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 2.16.164.130
  • 2.16.164.90
  • 2.16.164.73
  • 2.16.164.89
  • 2.16.164.66
  • 2.16.164.98
  • 2.16.164.112
  • 2.16.164.104
  • 2.16.164.120
  • 2.16.164.17
  • 2.16.164.128
  • 2.16.164.72
  • 2.16.164.25
  • 2.16.164.9
  • 2.16.164.34
  • 2.16.164.131
  • 2.16.164.24
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 40.126.32.134
  • 20.190.160.67
  • 20.190.160.65
  • 20.190.160.130
  • 20.190.160.20
  • 40.126.32.140
  • 40.126.32.138
  • 20.190.160.2
whitelisted
api.telegram.org
  • 149.154.167.220
whitelisted
api.gofile.io
  • 51.75.242.210
  • 45.112.123.126
whitelisted
upload.gofile.io
  • 45.112.123.226
  • 45.112.123.224
  • 31.14.70.248
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Misc activity
ET HUNTING Telegram API Domain in DNS Lookup
5564
zarar.exe
Misc activity
ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI)
2200
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING Online File Storage Domain in DNS Lookup (gofile .io)
5564
zarar.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
2200
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING Online File Storage Domain in DNS Lookup (gofile .io)
5564
zarar.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
5564
zarar.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
5564
zarar.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
5564
zarar.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
5564
zarar.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
No debug info