File name:

CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.zip

Full analysis: https://app.any.run/tasks/ae5e7f93-760c-4fda-87ba-7c81ac712598
Verdict: Malicious activity
Analysis date: November 24, 2025, 15:53:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
delphi
upx
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

EF0F71C3C760E946A350CC05C73C2811

SHA1:

EF90524D352420E7AE1D00CC886B55BE6AFF95E4

SHA256:

F0483568DA2BA31B9CC3866C770B7C9D760ACDAECA80B203B01C388E1DD2F8D9

SSDEEP:

98304:YSwQKnHlXTnZcCfhBkollR/3GC70aE+wt/ZPd62Vd9OdJWSsb7bZgnS/qqaK/7iP:loV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2916)
    • Changes the autorun value in the registry

      • zanhh.exe (PID: 1160)
      • zanhh.exe (PID: 2292)
  • SUSPICIOUS

    • Reads the Internet Settings

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
      • zanhh.exe (PID: 2328)
    • Reads settings of System Certificates

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
    • Potential Corporate Privacy Violation

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
    • There is functionality for taking screenshot (YARA)

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
      • zanhh.exe (PID: 2328)
      • zanhh.exe (PID: 1160)
      • zanhh.exe (PID: 2292)
    • Reads security settings of Internet Explorer

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
      • zanhh.exe (PID: 2328)
    • Executable content was dropped or overwritten

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
    • Application launched itself

      • zanhh.exe (PID: 2328)
  • INFO

    • Reads the machine GUID from the registry

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
      • zanhh.exe (PID: 2292)
      • zanhh.exe (PID: 1160)
    • Checks supported languages

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
      • zanhh.exe (PID: 2328)
      • zanhh.exe (PID: 2292)
      • zanhh.exe (PID: 1160)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2916)
    • Reads the computer name

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
      • zanhh.exe (PID: 2292)
      • zanhh.exe (PID: 2328)
      • zanhh.exe (PID: 1160)
    • The sample compiled with english language support

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
    • Application launched itself

      • msedge.exe (PID: 3312)
    • Create files in a temporary directory

      • zanhh.exe (PID: 1160)
    • Launching a file from a Registry key

      • zanhh.exe (PID: 2292)
      • zanhh.exe (PID: 1160)
    • Compiled with Borland Delphi (YARA)

      • _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe (PID: 952)
    • UPX packer has been detected

      • zanhh.exe (PID: 1160)
      • zanhh.exe (PID: 2328)
      • zanhh.exe (PID: 2292)
    • Creates files or folders in the user directory

      • zanhh.exe (PID: 2292)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2025:11:19 15:54:32
ZipCRC: 0xaf4ef830
ZipCompressedSize: 66759
ZipUncompressedSize: 180736
ZipFileName: _CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
26
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs _convite-confirma-hp00-gt65_yh00-00358237577646664214.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs zanhh.exe no specs zanhh.exe zanhh.exe msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
344"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --mojo-platform-channel-handle=5032 --field-trial-handle=1336,i,11696588319150710502,17499649140539986377,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
584"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=5848 --field-trial-handle=1336,i,11696588319150710502,17499649140539986377,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
952"C:\Users\admin\Desktop\_CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe" C:\Users\admin\Desktop\_CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\_convite-confirma-hp00-gt65_yh00-00358237577646664214.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1160"C:\DISKDRIVER\zanhh.exe" /KC:\DISKDRIVER\zanhh.exe
zanhh.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\diskdriver\zanhh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\glu32.dll
c:\windows\system32\opengl32.dll
1920"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=5336 --field-trial-handle=1336,i,11696588319150710502,17499649140539986377,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2108"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1632 --field-trial-handle=1336,i,11696588319150710502,17499649140539986377,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2292"C:\DISKDRIVER\zanhh.exe" /GC:\DISKDRIVER\zanhh.exe
zanhh.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\diskdriver\zanhh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\glu32.dll
c:\windows\system32\opengl32.dll
2328"C:\DISKDRIVER\zanhh.exe" C:\DISKDRIVER\zanhh.exe_CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\diskdriver\zanhh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\glu32.dll
c:\windows\system32\opengl32.dll
2524"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1564 --field-trial-handle=1336,i,11696588319150710502,17499649140539986377,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2540"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=5820 --field-trial-handle=1336,i,11696588319150710502,17499649140539986377,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
9 537
Read events
9 024
Write events
490
Delete events
23

Modification events

(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.zip
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
24
Suspicious files
162
Text files
127
Unknown types
0

Dropped files

PID
Process
Filename
Type
3312msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF685cc.TMP
MD5:
SHA256:
3312msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.28542\-=- -=- -text
MD5:EBEFA959C0AE77A562DAE2A1CDA457EA
SHA256:CC03BF77747D295B9CA4887725FE903E153BFDA57443C2B3C5CF0516582BADD0
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.28542\-=-text
MD5:A2CAF0A0145DFEE51FD91CD58DBE7421
SHA256:9074A1110CD12A651BE9393A0EC43612F5BFDA0EF6EE9B943D30FBAB10809051
3312msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF6861a.TMP
MD5:
SHA256:
3312msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.28542\_CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exeexecutable
MD5:82F40686EB49850D3833AB1EE10346A4
SHA256:2BA1F4D1997F03C07D6E34A0CB4CEE395F8A427FEF01286BCF9B18BCCBA6E791
3312msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF686e6.TMP
MD5:
SHA256:
3312msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
3136msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pma~RF681c5.TMPbinary
MD5:C612E96CBFAC63232FC2062E15600FB1
SHA256:DB3C05D5EC0B6719A73E7F0BE84BCE9342772DA70567E7CE08CF6573480B38FF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
49
DNS requests
50
Threats
3

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
whitelisted
952
_CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe
162.125.66.18:443
www.dropbox.com
DROPBOX
DE
whitelisted
952
_CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe
162.125.66.15:443
ucabc7dbcda4b6a62f1c79348cda.dl.dropboxusercontent.com
DROPBOX
DE
whitelisted
2760
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2760
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2760
msedge.exe
172.64.146.215:443
www.linkedin.com
CLOUDFLARENET
US
whitelisted
3312
msedge.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
www.dropbox.com
  • 162.125.66.18
whitelisted
ucabc7dbcda4b6a62f1c79348cda.dl.dropboxusercontent.com
  • 162.125.66.15
unknown
config.edge.skype.com
  • 150.171.22.17
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
www.linkedin.com
  • 172.64.146.215
  • 104.18.41.41
whitelisted
static.licdn.com
  • 172.64.154.50
  • 104.18.33.206
whitelisted
www.bing.com
  • 2.16.241.221
  • 2.16.241.219
  • 2.16.241.222
  • 2.16.241.218
  • 2.16.241.206
  • 2.16.241.214
  • 2.16.241.204
  • 2.16.241.205
  • 2.16.241.200
  • 184.86.251.25
  • 184.86.251.4
  • 184.86.251.10
  • 184.86.251.14
  • 184.86.251.8
  • 184.86.251.15
  • 184.86.251.27
  • 184.86.251.12
  • 2.16.204.146
  • 2.16.204.136
  • 2.16.204.143
  • 2.16.204.138
  • 2.16.204.141
  • 2.16.204.142
  • 2.16.204.145
  • 2.16.204.137
  • 2.16.204.139
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
platform.linkedin.com
  • 172.64.154.50
  • 104.18.33.206
whitelisted

Threats

PID
Process
Class
Message
952
_CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe
Potential Corporate Privacy Violation
ET INFO Dropbox.com Offsite File Backup in Use
952
_CONVITE-CONFIRMA-HP00-GT65_YH00-00358237577646664214.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
No debug info