File name:

ZoraraB.exe

Full analysis: https://app.any.run/tasks/1ee2715d-8cb0-45bf-8d2d-eede83080264
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 14, 2025, 21:04:10
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
trox
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 6 sections
MD5:

884C97680495567E6BCA7BE899567062

SHA1:

7E7026F24FB04AE6830391E1C9AC702DF4213199

SHA256:

F518D247CC80F0B26DC462C3D31FE5533701429310386C9F1F27EC7EB54AFE97

SSDEEP:

98304:GN9lDzIIGKyBJ4GiDEa35Yj0sWIDJIpYpzqr7jinoRWD0br9tV6xDLnTlcWP6PM3:iVmXqMSL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • TROX has been detected

      • ZoraraB.exe (PID: 7424)
  • SUSPICIOUS

    • Process drops python dynamic module

      • ZoraraB.exe (PID: 7424)
    • Loads Python modules

      • ZoraraB.exe (PID: 7492)
    • The process drops C-runtime libraries

      • ZoraraB.exe (PID: 7424)
    • Executable content was dropped or overwritten

      • ZoraraB.exe (PID: 7424)
    • Process drops legitimate windows executable

      • ZoraraB.exe (PID: 7424)
  • INFO

    • Checks supported languages

      • ZoraraB.exe (PID: 7424)
      • ZoraraB.exe (PID: 7492)
    • The sample compiled with english language support

      • ZoraraB.exe (PID: 7424)
    • Create files in a temporary directory

      • ZoraraB.exe (PID: 7424)
      • ZoraraB.exe (PID: 7492)
    • Reads the machine GUID from the registry

      • ZoraraB.exe (PID: 7492)
    • Checks proxy server information

      • ZoraraB.exe (PID: 7492)
      • slui.exe (PID: 7916)
    • Reads the software policy settings

      • slui.exe (PID: 7916)
    • Reads the computer name

      • ZoraraB.exe (PID: 7492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:01:22 09:29:17+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 131072
InitializedDataSize: 6542848
UninitializedDataSize: -
EntryPoint: 0xc90c
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #TROX zorarab.exe conhost.exe no specs zorarab.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
7424"C:\Users\admin\Desktop\ZoraraB.exe" C:\Users\admin\Desktop\ZoraraB.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\zorarab.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
7432\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeZoraraB.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7492C:\Users\admin\Desktop\ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\ZoraraB.exe
ZoraraB.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\onefile_7424_133864598610404871\zorarab.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\onefile_7424_133864598610404871\python39.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
7916C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
6 584
Read events
6 584
Write events
0
Delete events
0

Modification events

No data
Executable files
21
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_decimal.pydexecutable
MD5:CE4DF4DFE65AB8DC7AE6FCDEBAE46112
SHA256:FFBE84F0A1EAB363CA9CF73EFB7518F2ABD52C0893C7CC63266613C930855E96
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\ZoraraB.exeexecutable
MD5:A5DD2C9B93007D30E8F0DF8E81D2D5C8
SHA256:B6C23EB719766EE1DF6B2438B90751A24C105DC67FA3168F4B97C131C528B7F6
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_ssl.pydexecutable
MD5:EF4755195CC9B2FF134EA61ACDE20637
SHA256:8A86957B3496C8B679FCF22C287006108BFE0BB0AAFFEA17121C761A0744B470
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_ctypes.pydexecutable
MD5:29DA9B022C16DA461392795951CE32D9
SHA256:3B4012343EF7A266DB0B077BBB239833779192840D1E2C43DFCBC48FFD4C5372
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_bz2.pydexecutable
MD5:6C7565C1EFFFE44CB0616F5B34FAA628
SHA256:FE63361F6C439C6AA26FD795AF3FD805FF5B60B3B14F9B8C60C50A8F3449060A
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_queue.pydexecutable
MD5:4AB2CEB88276EBA7E41628387EACB41E
SHA256:D82AB111224C54BAB3EEFDCFEB3BA406D74D2884518C5A2E9174E5C6101BD839
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_socket.pydexecutable
MD5:F5DD9C5922A362321978C197D3713046
SHA256:4494992665305FC9401ED327398EE40064FE26342FE44DF11D89D2AC1CC6F626
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\libffi-7.dllexecutable
MD5:EEF7981412BE8EA459064D3090F4B3AA
SHA256:F60DD9F2FCBD495674DFC1555EFFB710EB081FC7D4CAE5FA58C438AB50405081
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\python39.dllexecutable
MD5:11C051F93C922D6B6B4829772F27A5BE
SHA256:0EABF135BB9492E561BBBC5602A933623C9E461ACEAF6EB1CECED635E363CD5C
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\python3.dllexecutable
MD5:3C88DE1EBD52E9FCB46DC44D8A123579
SHA256:2B22B6D576118C5AE98F13B75B4ACE47AB0C1F4CD3FF098C6AEE23A8A99B9A8C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
22
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
2.16.10.186:443
https://msedge.sf.dl.delivery.mp.microsoft.com/filestreamingservice/files/5438194f-50fd-42d4-a059-6ed4e13b4f9a/MicrosoftEdgeWebView2RuntimeInstallerX64.exe
unknown
4208
RUXIMICS.exe
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
4208
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:138
whitelisted
7492
ZoraraB.exe
2.19.11.102:443
msedge.sf.dl.delivery.mp.microsoft.com
Elisa Oyj
NL
whitelisted
4208
RUXIMICS.exe
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7272
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.23.110
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 2.19.11.102
  • 2.19.11.114
whitelisted
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info