| File name: | ZA_Access_My_Department.exe |
| Full analysis: | https://app.any.run/tasks/4f34c71e-6533-429c-9b3a-28adee1ae4d8 |
| Verdict: | Malicious activity |
| Analysis date: | July 09, 2021, 19:49:52 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BB50FDE19B664808B35E555CE933B8FE |
| SHA1: | 6AB02F0F81A5020195F75D6FC0D2120E4D8B9105 |
| SHA256: | EB0A175A987EF806D178EB53076873B406A267105298D91358ACC4F664A4DAEE |
| SSDEEP: | 196608:J1nq4gTRRDQb3Yn1C/2eVjpPrvbtrOY7uPSx0ORQ7BtBbwTCqjETUZcXo:D+TR9Qb3Ynk/xV1PTbtrtu6x0pjBq9 |
| .ax | | | DirectShow filter (56.9) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (7.7) |
| .exe | | | Win32 Executable (generic) (1.2) |
| .exe | | | Generic Win/DOS Executable (0.5) |
| ISInternalDescription: | InstallScript Setup Launcher Unicode |
|---|---|
| ISInternalVersion: | 24.0.573 |
| InternalBuildNumber: | 185990 |
| ProductVersion: | 1.00.0001 |
| ProductName: | Zoho Assist Unattended Agent |
| OriginalFileName: | InstallShield Setup.exe |
| LegalCopyright: | Copyright (c) 2018 Flexera. All Rights Reserved. |
| InternalName: | Setup |
| FileVersion: | 1.00.0001 |
| FileDescription: | InstallScript Setup Launcher Unicode |
| CompanyName: | ZOHO Corp |
| CharacterSet: | Unicode |
| LanguageCode: | English (U.S.) |
| FileSubtype: | - |
| ObjectFileType: | Dynamic link library |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x003f |
| ProductVersionNumber: | 1.0.1.0 |
| FileVersionNumber: | 1.0.1.0 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 5.1 |
| ImageVersion: | - |
| OSVersion: | 5.1 |
| EntryPoint: | 0x41d17 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 528896 |
| CodeSize: | 431104 |
| LinkerVersion: | 11 |
| PEType: | PE32 |
| TimeStamp: | 2018:09:20 12:18:20+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 20-Sep-2018 10:18:20 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | ZOHO Corp |
| FileDescription: | InstallScript Setup Launcher Unicode |
| FileVersion: | 1.00.0001 |
| InternalName: | Setup |
| LegalCopyright: | Copyright (c) 2018 Flexera. All Rights Reserved. |
| OriginalFilename: | InstallShield Setup.exe |
| ProductName: | Zoho Assist Unattended Agent |
| ProductVersion: | 1.00.0001 |
| Internal Build Number: | 185990 |
| ISInternalVersion: | 24.0.573 |
| ISInternalDescription: | InstallScript Setup Launcher Unicode |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000108 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 20-Sep-2018 10:18:20 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0006925F | 0x00069400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.51269 |
.rdata | 0x0006B000 | 0x00018ACC | 0x00018C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.47452 |
.data | 0x00084000 | 0x00004958 | 0x00002400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.38674 |
.rsrc | 0x00089000 | 0x0004DFC0 | 0x0004E000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.35407 |
.reloc | 0x000D7000 | 0x0001801A | 0x00018200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 2.57965 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.12073 | 803 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 4.1664 | 2440 | Latin 1 / Western European | UNKNOWN | RT_ICON |
3 | 3.86577 | 4264 | Latin 1 / Western European | UNKNOWN | RT_ICON |
4 | 3.41931 | 9640 | Latin 1 / Western European | UNKNOWN | RT_ICON |
5 | 3.3785 | 16936 | Latin 1 / Western European | UNKNOWN | RT_ICON |
69 | 3.10251 | 352 | Latin 1 / Western European | English - United States | RT_STRING |
70 | 3.14661 | 574 | Latin 1 / Western European | English - United States | RT_STRING |
71 | 3.25053 | 888 | Latin 1 / Western European | English - United States | RT_STRING |
72 | 3.13124 | 594 | Latin 1 / Western European | English - United States | RT_STRING |
73 | 3.06893 | 500 | Latin 1 / Western European | English - United States | RT_STRING |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
RPCRT4.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
VERSION.dll (delay-loaded) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1460 | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\ZA_Access_My_Department.exe -package:"C:\Users\admin\Desktop\ZA_Access_My_Department.exe" -no_selfdeleter -IS_temp -media_path:"C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\Disk1\" -tempdisk1folder:"C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\" -IS_OriginalLauncher:"C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\Disk1\ZA_Access_My_Department.exe" | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\ZA_Access_My_Department.exe | ZA_Access_My_Department.exe | ||||||||||||
User: admin Company: ZOHO Corp Integrity Level: HIGH Description: InstallScript Setup Launcher Unicode Exit code: 0 Version: 1.00.0001 Modules
| |||||||||||||||
| 1788 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\Desktop\ZA_Access_My_Department.exe.ax" | C:\Windows\system32\rundll32.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2040 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft� Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2532 | "C:\Users\admin\Desktop\ZA_Access_My_Department.exe" | C:\Users\admin\Desktop\ZA_Access_My_Department.exe | Explorer.EXE | ||||||||||||
User: admin Company: ZOHO Corp Integrity Level: HIGH Description: InstallScript Setup Launcher Unicode Exit code: 0 Version: 1.00.0001 Modules
| |||||||||||||||
| 2624 | "C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\ZohoURS.exe" -productID 1 -URS_REQUEST -wsn assist.zoho.com | C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\ZohoURS.exe | — | ZohoURSService.exe | |||||||||||
User: SYSTEM Company: Zoho Meeting Integrity Level: SYSTEM Description: Tray Exe Exit code: 0 Version: 1.0.3.19 Modules
| |||||||||||||||
| 2660 | C:\Windows\system32\cmd.exe /c C:\Users\admin\AppData\Local\Temp\{2613794A-3F9E-409E-BE02-7C2B92D4D9D3}\{CBF23981-D88F-419C-91AB-01BCC7DED2CB}\runsfx.bat "C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting" > "C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\logs\unziplog.txt" 2>&1 | C:\Windows\system32\cmd.exe | — | ZA_Access_My_Department.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2900 | "C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\ZohoURSService.exe" run -SessionType URS -productID 1 | C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\ZohoURSService.exe | services.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: Zoho Assist Exit code: 0 Version: 1.0.0.178 Modules
| |||||||||||||||
| 2940 | .\ZohoMeeting_7zip.exe -y | C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\ZohoMeeting_7zip.exe | cmd.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7z Console SFX Exit code: 0 Version: 19.00 Modules
| |||||||||||||||
| 3112 | "C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\ZohoTray.exe" -wsn assist.zoho.com -check_urs_preferences -productID 1 | C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\ZohoTray.exe | ZohoURSService.exe | ||||||||||||
User: SYSTEM Company: Zoho Meeting Integrity Level: SYSTEM Description: Tray Exe Exit code: 0 Version: 1.0.3.19 Modules
| |||||||||||||||
| 3304 | "C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\ZAService.exe" install C:\Users\admin\Desktop\ZA_Access_My_Department.exe -SessionType URS | C:\Program Files\ZohoMeeting\UnAttended\ZohoMeeting\ZAService.exe | ZA_Access_My_Department.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Zoho Assist Exit code: 0 Version: 1.0.0.178 Modules
| |||||||||||||||
| (PID) Process: | (1460) ZA_Access_My_Department.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000DE94ECB7FB74D701B405000024020000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1460) ZA_Access_My_Department.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 400000000000000038F7EEB7FB74D701B405000024020000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1460) ZA_Access_My_Department.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 67 | |||
| (PID) Process: | (1460) ZA_Access_My_Department.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000B6562FB8FB74D701B405000024020000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1460) ZA_Access_My_Department.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000010B931B8FB74D701B4050000B4090000E803000001000000000000000000000076201E0A7F8531489C9F5A77D79383CA0000000000000000 | |||
| (PID) Process: | (2040) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E0CB44B8FB74D701F807000010020000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2040) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E0CB44B8FB74D701F8070000AC090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2040) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E0CB44B8FB74D701F807000020010000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2040) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E0CB44B8FB74D701F80700000C080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2040) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000949049B8FB74D701F8070000AC090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2532 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\Disk1\layout.bin | binary | |
MD5:EC297EA4EE801BAA1ACD1547E2EA1F6D | SHA256:EB90F1564335BF3ED5A902ABCC033076A68E561B6C4D830D90A092DBC2C00BB0 | |||
| 1460 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{2613794A-3F9E-409E-BE02-7C2B92D4D9D3}\{CBF23981-D88F-419C-91AB-01BCC7DED2CB}\setC15F.tmp | binary | |
MD5:8BD3359096A4E1329D1CEC0E297BD9DC | SHA256:F3CD04BE9D82D26E8D7CCE1BEAEBC96E8469C172B4BE6FDA806767605D121EB4 | |||
| 2532 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\Disk1\data1.hdr | compressed | |
MD5:BE3429C673A6439B5D253329F5525957 | SHA256:EAEB9150DBACDC4B429A757795C695566BEB5C79EAC66181D84BDB3DA4A53139 | |||
| 1460 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{2613794A-3F9E-409E-BE02-7C2B92D4D9D3}\{CBF23981-D88F-419C-91AB-01BCC7DED2CB}\setup.inx | binary | |
MD5:8BD3359096A4E1329D1CEC0E297BD9DC | SHA256:F3CD04BE9D82D26E8D7CCE1BEAEBC96E8469C172B4BE6FDA806767605D121EB4 | |||
| 2532 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\Disk1\setup.ini | text | |
MD5:02A4B07F7D55EA899A71A953F29ED648 | SHA256:4BD271E3D60BC88DE3B9E41B586A6A6729BD6725E7235916E8FD3345873DB867 | |||
| 2532 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\setup.ini | text | |
MD5:02A4B07F7D55EA899A71A953F29ED648 | SHA256:4BD271E3D60BC88DE3B9E41B586A6A6729BD6725E7235916E8FD3345873DB867 | |||
| 2532 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\Disk1\setup.inx | binary | |
MD5:8BD3359096A4E1329D1CEC0E297BD9DC | SHA256:F3CD04BE9D82D26E8D7CCE1BEAEBC96E8469C172B4BE6FDA806767605D121EB4 | |||
| 2532 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\Disk1\ZA_Access_My_Department.exe | executable | |
MD5:0DB10D1E3FDB89770C5223EE975DB817 | SHA256:9A4C6C7B6E2B9403735EB69DD6FAD0C3CEA98A2D6C9F950022EF3CEA3E89FDFA | |||
| 2532 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\Disk1\data1.cab | compressed | |
MD5:8D5CC336353AC55648BDB730A517E68C | SHA256:C70F2512153EE89290740930E8C5B3D0CBBAC9EEF89F6FE033D03115E8E7E62E | |||
| 2532 | ZA_Access_My_Department.exe | C:\Users\admin\AppData\Local\Temp\{0EAC3D52-B901-479B-A05E-EC6FBF9D496F}\Disk1\0x0409.ini | text | |
MD5:A108F0030A2CDA00405281014F897241 | SHA256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3304 | ZAService.exe | 204.141.43.95:443 | assist.zoho.com | ZOHO | US | unknown |
2900 | ZohoURSService.exe | 204.141.43.95:443 | assist.zoho.com | ZOHO | US | unknown |
2900 | ZohoURSService.exe | 204.141.42.136:443 | us4-dms.zoho.com | ZOHO | US | unknown |
3112 | ZohoTray.exe | 204.141.43.95:443 | assist.zoho.com | ZOHO | US | unknown |
Domain | IP | Reputation |
|---|---|---|
assist.zoho.com |
| suspicious |
us4-dms.zoho.com |
| unknown |