File name:

ZoraraB.exe

Full analysis: https://app.any.run/tasks/1ee2715d-8cb0-45bf-8d2d-eede83080264
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 14, 2025, 21:04:10
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
trox
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 6 sections
MD5:

884C97680495567E6BCA7BE899567062

SHA1:

7E7026F24FB04AE6830391E1C9AC702DF4213199

SHA256:

F518D247CC80F0B26DC462C3D31FE5533701429310386C9F1F27EC7EB54AFE97

SSDEEP:

98304:GN9lDzIIGKyBJ4GiDEa35Yj0sWIDJIpYpzqr7jinoRWD0br9tV6xDLnTlcWP6PM3:iVmXqMSL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • TROX has been detected

      • ZoraraB.exe (PID: 7424)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ZoraraB.exe (PID: 7424)
    • Process drops python dynamic module

      • ZoraraB.exe (PID: 7424)
    • Process drops legitimate windows executable

      • ZoraraB.exe (PID: 7424)
    • The process drops C-runtime libraries

      • ZoraraB.exe (PID: 7424)
    • Loads Python modules

      • ZoraraB.exe (PID: 7492)
  • INFO

    • Checks supported languages

      • ZoraraB.exe (PID: 7424)
      • ZoraraB.exe (PID: 7492)
    • Create files in a temporary directory

      • ZoraraB.exe (PID: 7424)
      • ZoraraB.exe (PID: 7492)
    • The sample compiled with english language support

      • ZoraraB.exe (PID: 7424)
    • Checks proxy server information

      • ZoraraB.exe (PID: 7492)
      • slui.exe (PID: 7916)
    • Reads the machine GUID from the registry

      • ZoraraB.exe (PID: 7492)
    • Reads the software policy settings

      • slui.exe (PID: 7916)
    • Reads the computer name

      • ZoraraB.exe (PID: 7492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:01:22 09:29:17+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 131072
InitializedDataSize: 6542848
UninitializedDataSize: -
EntryPoint: 0xc90c
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #TROX zorarab.exe conhost.exe no specs zorarab.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
7424"C:\Users\admin\Desktop\ZoraraB.exe" C:\Users\admin\Desktop\ZoraraB.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\zorarab.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
7432\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeZoraraB.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7492C:\Users\admin\Desktop\ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\ZoraraB.exe
ZoraraB.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\onefile_7424_133864598610404871\zorarab.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\onefile_7424_133864598610404871\python39.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
7916C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
6 584
Read events
6 584
Write events
0
Delete events
0

Modification events

No data
Executable files
21
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\ZoraraB.exeexecutable
MD5:A5DD2C9B93007D30E8F0DF8E81D2D5C8
SHA256:B6C23EB719766EE1DF6B2438B90751A24C105DC67FA3168F4B97C131C528B7F6
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_queue.pydexecutable
MD5:4AB2CEB88276EBA7E41628387EACB41E
SHA256:D82AB111224C54BAB3EEFDCFEB3BA406D74D2884518C5A2E9174E5C6101BD839
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_ctypes.pydexecutable
MD5:29DA9B022C16DA461392795951CE32D9
SHA256:3B4012343EF7A266DB0B077BBB239833779192840D1E2C43DFCBC48FFD4C5372
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_bz2.pydexecutable
MD5:6C7565C1EFFFE44CB0616F5B34FAA628
SHA256:FE63361F6C439C6AA26FD795AF3FD805FF5B60B3B14F9B8C60C50A8F3449060A
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_hashlib.pydexecutable
MD5:F377A418ADDEEB02F223F45F6F168FE6
SHA256:9551431425E9680660C6BAF7B67A262040FD2EFCEB241E4C9430560C3C1FAFAC
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\libssl-1_1.dllexecutable
MD5:BC778F33480148EFA5D62B2EC85AAA7D
SHA256:9D4CF1C03629F92662FC8D7E3F1094A7FC93CB41634994464B853DF8036AF843
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\libffi-7.dllexecutable
MD5:EEF7981412BE8EA459064D3090F4B3AA
SHA256:F60DD9F2FCBD495674DFC1555EFFB710EB081FC7D4CAE5FA58C438AB50405081
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\libcrypto-1_1.dllexecutable
MD5:CC4CBF715966CDCAD95A1E6C95592B3D
SHA256:594303E2CE6A4A02439054C84592791BF4AB0B7C12E9BBDB4B040E27251521F1
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\python39.dllexecutable
MD5:11C051F93C922D6B6B4829772F27A5BE
SHA256:0EABF135BB9492E561BBBC5602A933623C9E461ACEAF6EB1CECED635E363CD5C
7424ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7424_133864598610404871\_lzma.pydexecutable
MD5:B5355DD319FB3C122BB7BF4598AD7570
SHA256:B9BC7F1D8AA8498CB8B5DC75BB0DBB6E721B48953A3F295870938B27267FB5F5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
22
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
2.16.10.186:443
https://msedge.sf.dl.delivery.mp.microsoft.com/filestreamingservice/files/5438194f-50fd-42d4-a059-6ed4e13b4f9a/MicrosoftEdgeWebView2RuntimeInstallerX64.exe
unknown
unknown
4208
RUXIMICS.exe
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
4208
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:138
whitelisted
7492
ZoraraB.exe
2.19.11.102:443
msedge.sf.dl.delivery.mp.microsoft.com
Elisa Oyj
NL
whitelisted
4208
RUXIMICS.exe
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7272
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.23.110
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 2.19.11.102
  • 2.19.11.114
whitelisted
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info