File name:

ZAZTools 1.27c.exe

Full analysis: https://app.any.run/tasks/fef3ce47-830a-457d-8410-6aeea3947d75
Verdict: Malicious activity
Analysis date: March 24, 2024, 19:34:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

11E95DADE7B88B5AA91886A979852BDB

SHA1:

AADA2690B12EDDD1899DB0B8D00FCAB708FA122E

SHA256:

E5ADF69659232969E36D776BFA824D8BBFBC1F47E57DB9D4C29FC2DE14CA83EB

SSDEEP:

98304:t+cD4dnXGt0VOC2gX0z9iK4L8GLOzDbElvILayOsN8TMe0KMdEb2QtWudNjfC0TF:ZHZpI5V

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ZAZTools 1.27c.exe (PID: 3500)
      • ZAZTools 1.27c.exe (PID: 1656)
      • ZAZTools 1.27c.tmp (PID: 2152)
    • Creates a writable file in the system directory

      • ZAZTools 1.27c.tmp (PID: 2152)
    • Registers / Runs the DLL via REGSVR32.EXE

      • ZAZTools 1.27c.tmp (PID: 2152)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ZAZTools 1.27c.exe (PID: 3500)
      • ZAZTools 1.27c.exe (PID: 1656)
      • ZAZTools 1.27c.tmp (PID: 2152)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 1808)
      • regsvr32.exe (PID: 1576)
      • regsvr32.exe (PID: 1352)
      • regsvr32.exe (PID: 2832)
      • regsvr32.exe (PID: 2432)
      • regsvr32.exe (PID: 1556)
      • regsvr32.exe (PID: 2484)
      • regsvr32.exe (PID: 980)
      • regsvr32.exe (PID: 2888)
      • regsvr32.exe (PID: 2576)
      • regsvr32.exe (PID: 3540)
      • regsvr32.exe (PID: 3544)
      • regsvr32.exe (PID: 2564)
      • regsvr32.exe (PID: 1368)
      • regsvr32.exe (PID: 2728)
      • regsvr32.exe (PID: 2260)
    • Process drops legitimate windows executable

      • ZAZTools 1.27c.tmp (PID: 2152)
    • Reads the Windows owner or organization settings

      • ZAZTools 1.27c.tmp (PID: 2152)
    • Non-standard symbols in registry

      • ZAZTools 1.27c.tmp (PID: 2152)
  • INFO

    • Checks supported languages

      • ZAZTools 1.27c.exe (PID: 3500)
      • ZAZTools 1.27c.tmp (PID: 4008)
      • ZAZTools 1.27c.exe (PID: 1656)
      • ZAZTools 1.27c.tmp (PID: 2152)
      • CSM.exe (PID: 764)
      • Paths.exe (PID: 1796)
      • TSM.exe (PID: 2028)
      • Paths.exe (PID: 1172)
    • Reads the computer name

      • ZAZTools 1.27c.tmp (PID: 4008)
      • ZAZTools 1.27c.tmp (PID: 2152)
      • Paths.exe (PID: 1172)
      • Paths.exe (PID: 1796)
    • Create files in a temporary directory

      • ZAZTools 1.27c.exe (PID: 3500)
      • ZAZTools 1.27c.exe (PID: 1656)
      • Paths.exe (PID: 1796)
      • Paths.exe (PID: 1172)
    • Creates files in the program directory

      • ZAZTools 1.27c.tmp (PID: 2152)
      • TSM.exe (PID: 2028)
    • Manual execution by a user

      • CSM.exe (PID: 764)
      • CSM.exe (PID: 968)
      • TSM.exe (PID: 3260)
      • TSM.exe (PID: 2028)
    • Creates a software uninstall entry

      • ZAZTools 1.27c.tmp (PID: 2152)
    • Reads the machine GUID from the registry

      • Paths.exe (PID: 1796)
      • Paths.exe (PID: 1172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 68608
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: ZaZ
FileDescription: ZaZ GP4 Tools Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: ZaZ GP4 Tools
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
29
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start zaztools 1.27c.exe zaztools 1.27c.tmp no specs zaztools 1.27c.exe zaztools 1.27c.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs csm.exe no specs csm.exe paths.exe no specs tsm.exe no specs tsm.exe paths.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Program Files\ZaZ GP4 Tools\CSM.exe" C:\Program Files\ZaZ GP4 Tools\CSM.exe
explorer.exe
User:
admin
Company:
ZaZ
Integrity Level:
HIGH
Exit code:
0
Version:
0.03.0003
Modules
Images
c:\program files\zaz gp4 tools\csm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
968"C:\Program Files\ZaZ GP4 Tools\CSM.exe" C:\Program Files\ZaZ GP4 Tools\CSM.exeexplorer.exe
User:
admin
Company:
ZaZ
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
0.03.0003
Modules
Images
c:\program files\zaz gp4 tools\csm.exe
c:\windows\system32\ntdll.dll
980"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\ZaZ GP4 Tools\DLL\csmsgrid.ocx"C:\Windows\System32\regsvr32.exeZAZTools 1.27c.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1172"C:\Program Files\ZaZ GP4 Tools\paths.exe" /start="C:\Program Files\ZaZ GP4 Tools\TSM.exe"C:\Program Files\ZaZ GP4 Tools\Paths.exeTSM.exe
User:
admin
Company:
ZaZ
Integrity Level:
HIGH
Exit code:
0
Version:
0.00.0074
Modules
Images
c:\program files\zaz gp4 tools\paths.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1352"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\ZaZ GP4 Tools\DLL\csmodcl.ocx"C:\Windows\System32\regsvr32.exeZAZTools 1.27c.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1368"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\ZaZ GP4 Tools\DLL\csmprogbar.ocx"C:\Windows\System32\regsvr32.exeZAZTools 1.27c.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1556"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\ZaZ GP4 Tools\DLL\csmtreeview.ocx"C:\Windows\System32\regsvr32.exeZAZTools 1.27c.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1576"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\ZaZ GP4 Tools\DLL\csmimglst.ocx"C:\Windows\System32\regsvr32.exeZAZTools 1.27c.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1656"C:\Users\admin\AppData\Local\Temp\ZAZTools 1.27c.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\ZAZTools 1.27c.exe
ZAZTools 1.27c.tmp
User:
admin
Company:
ZaZ
Integrity Level:
HIGH
Description:
ZaZ GP4 Tools Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\zaztools 1.27c.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1796"C:\Program Files\ZaZ GP4 Tools\paths.exe" /start="C:\Program Files\ZaZ GP4 Tools\CSM.exe"C:\Program Files\ZaZ GP4 Tools\Paths.exeCSM.exe
User:
admin
Company:
ZaZ
Integrity Level:
HIGH
Exit code:
0
Version:
0.00.0074
Modules
Images
c:\program files\zaz gp4 tools\paths.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
19 277
Read events
18 851
Write events
407
Delete events
19

Modification events

(PID) Process:(2152) ZAZTools 1.27c.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
680800009A36D157227EDA01
(PID) Process:(2152) ZAZTools 1.27c.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
000F84B602135D872D2ADE1DFDD703EAB3983E33774F5E9A06C7AB77C8D6B551
(PID) Process:(2152) ZAZTools 1.27c.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2152) ZAZTools 1.27c.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\ZaZ GP4 Tools\CSM.exe
(PID) Process:(2152) ZAZTools 1.27c.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
BE054102DCC98EC5141C69529B7511585D000F25E39B0A60B6D3D9A67ED48515
(PID) Process:(1992) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E61B1B13-5FA6-431E-9CE7-2DC61F882BDB}\TypeLib
Operation:writeName:Version
Value:
2.1
(PID) Process:(1992) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{406E6D79-9147-4291-B9B2-0B1E86FC553D}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(2832) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7D1CDCB4-257A-4120-B229-C4D16B441048}\TypeLib
Operation:writeName:Version
Value:
2.0
(PID) Process:(2832) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6A372764-BD39-43C9-8528-40BC91E6D0BF}\TypeLib
Operation:writeName:Version
Value:
2.0
(PID) Process:(2832) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{78E8F17D-3CD6-4F3C-A8D8-54F0F231DACE}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
Executable files
88
Suspicious files
33
Text files
38
Unknown types
14

Dropped files

PID
Process
Filename
Type
2152ZAZTools 1.27c.tmpC:\Program Files\ZaZ GP4 Tools\unins000.exeexecutable
MD5:E277B0866D099668BFC91A2B94059654
SHA256:24DB10428CD9A4D1E027AD5746EF12A23C4EC7BF5FA45BB9D67021DAA4005B3E
2152ZAZTools 1.27c.tmpC:\Program Files\ZaZ GP4 Tools\is-FCLEN.tmpexecutable
MD5:E277B0866D099668BFC91A2B94059654
SHA256:24DB10428CD9A4D1E027AD5746EF12A23C4EC7BF5FA45BB9D67021DAA4005B3E
2152ZAZTools 1.27c.tmpC:\Program Files\ZaZ GP4 Tools\is-R8598.tmpexecutable
MD5:B7F4A22CF27A1DB5C901F80DF8C7908E
SHA256:AF32494A2A47EA196CD3427426329CD1955D16E0A72D2E5FB3B37651CE0E2F75
1656ZAZTools 1.27c.exeC:\Users\admin\AppData\Local\Temp\is-M7EPV.tmp\ZAZTools 1.27c.tmpexecutable
MD5:BDEFDD24472D2F23881C02C87C36BF17
SHA256:EC98CD9E5B649FEF1E5580D0238731A0C725480BC5C64135B44E20D17DEDC509
2152ZAZTools 1.27c.tmpC:\Program Files\ZaZ GP4 Tools\is-KB80G.tmpexecutable
MD5:F4C6754236EE24BF48887F464DF46F9A
SHA256:AF2D5298F68DAD552627D16B8CF2B356064C51FEB72681B82ED9B01C5BA8D270
2152ZAZTools 1.27c.tmpC:\Program Files\ZaZ GP4 Tools\csmcore.exeexecutable
MD5:26D83018B9436302D447E75D9349E061
SHA256:08038589E2A7D9E0E391F058D84394598CD5BFA5C8C006B71419D46A4EDC8E02
2152ZAZTools 1.27c.tmpC:\Program Files\ZaZ GP4 Tools\is-CQMKT.tmpexecutable
MD5:F78319D13EF8B63149F7CF59EAC57767
SHA256:1DC065B1BEDEFF6A3D07837F37BD5377A275FEB2A7831D253FB534F031D2A6C0
2152ZAZTools 1.27c.tmpC:\Program Files\ZaZ GP4 Tools\TSM.exeexecutable
MD5:F78319D13EF8B63149F7CF59EAC57767
SHA256:1DC065B1BEDEFF6A3D07837F37BD5377A275FEB2A7831D253FB534F031D2A6C0
2152ZAZTools 1.27c.tmpC:\Program Files\ZaZ GP4 Tools\tsmcore.exeexecutable
MD5:79659ABF5536805BFEC50F9FE90223FE
SHA256:0128A40010A7ADF8971D84902225F28781204D3C3348D852A440382E26249FA3
2152ZAZTools 1.27c.tmpC:\Program Files\ZaZ GP4 Tools\is-JVV1U.tmpexecutable
MD5:82DB765C17A7096EF1013F586AD2E423
SHA256:AD030197B9DDE45B43631822178BDC7BF6BB51FF33EF1C3A865A2D7ED3DAC200
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info