File name:

ZoraraB.exe

Full analysis: https://app.any.run/tasks/6d971eaf-6466-4e94-a4c4-16e2528f59e5
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 26, 2025, 18:39:09
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
trox
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 6 sections
MD5:

884C97680495567E6BCA7BE899567062

SHA1:

7E7026F24FB04AE6830391E1C9AC702DF4213199

SHA256:

F518D247CC80F0B26DC462C3D31FE5533701429310386C9F1F27EC7EB54AFE97

SSDEEP:

98304:GN9lDzIIGKyBJ4GiDEa35Yj0sWIDJIpYpzqr7jinoRWD0br9tV6xDLnTlcWP6PM3:iVmXqMSL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • TROX has been detected

      • ZoraraB.exe (PID: 7152)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ZoraraB.exe (PID: 7152)
      • WebView2Runtime.exe (PID: 2552)
      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • MicrosoftEdgeWebview_X64_132.0.2957.115.exe (PID: 7768)
      • setup.exe (PID: 7840)
      • ZoraraB.exe (PID: 4776)
      • vc_redist.x64.exe (PID: 4120)
      • vc_redist.x64.exe (PID: 5416)
    • Process drops python dynamic module

      • ZoraraB.exe (PID: 7152)
    • The process drops C-runtime libraries

      • ZoraraB.exe (PID: 7152)
    • Process drops legitimate windows executable

      • ZoraraB.exe (PID: 7152)
      • WebView2Runtime.exe (PID: 2552)
      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • MicrosoftEdgeWebview_X64_132.0.2957.115.exe (PID: 7768)
      • setup.exe (PID: 7840)
      • ZoraraB.exe (PID: 4776)
      • vc_redist.x64.exe (PID: 4120)
      • vc_redist.x64.exe (PID: 5416)
    • Loads Python modules

      • ZoraraB.exe (PID: 4776)
    • Starts a Microsoft application from unusual location

      • WebView2Runtime.exe (PID: 2552)
      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • vc_redist.x64.exe (PID: 4120)
      • vc_redist.x64.exe (PID: 5416)
      • VC_redist.x64.exe (PID: 976)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7576)
      • MicrosoftEdgeUpdate.exe (PID: 7524)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7436)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • MicrosoftEdgeUpdate.exe (PID: 7344)
      • vc_redist.x64.exe (PID: 5416)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • vc_redist.x64.exe (PID: 5416)
    • Application launched itself

      • MicrosoftEdgeUpdate.exe (PID: 7344)
      • setup.exe (PID: 7840)
    • Searches for installed software

      • setup.exe (PID: 7840)
      • vc_redist.x64.exe (PID: 5416)
      • dllhost.exe (PID: 7736)
    • Creates a software uninstall entry

      • setup.exe (PID: 7840)
    • Executes as Windows Service

      • VSSVC.exe (PID: 4724)
  • INFO

    • The sample compiled with english language support

      • ZoraraB.exe (PID: 7152)
      • WebView2Runtime.exe (PID: 2552)
      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • MicrosoftEdgeWebview_X64_132.0.2957.115.exe (PID: 7768)
      • setup.exe (PID: 7840)
      • ZoraraB.exe (PID: 4776)
      • vc_redist.x64.exe (PID: 5416)
      • vc_redist.x64.exe (PID: 4120)
    • Checks supported languages

      • ZoraraB.exe (PID: 7152)
      • ZoraraB.exe (PID: 4776)
      • WebView2Runtime.exe (PID: 2552)
      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • MicrosoftEdgeUpdate.exe (PID: 7524)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7548)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7436)
      • MicrosoftEdgeUpdate.exe (PID: 7344)
      • MicrosoftEdgeWebview_X64_132.0.2957.115.exe (PID: 7768)
      • MicrosoftEdgeUpdate.exe (PID: 6808)
      • setup.exe (PID: 7840)
      • vc_redist.x64.exe (PID: 4120)
    • Reads the machine GUID from the registry

      • ZoraraB.exe (PID: 4776)
      • MicrosoftEdgeUpdate.exe (PID: 7344)
    • Create files in a temporary directory

      • ZoraraB.exe (PID: 7152)
      • ZoraraB.exe (PID: 4776)
      • WebView2Runtime.exe (PID: 2552)
      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • vc_redist.x64.exe (PID: 4120)
      • vc_redist.x64.exe (PID: 5416)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7616)
      • BackgroundTransferHost.exe (PID: 6640)
      • BackgroundTransferHost.exe (PID: 7796)
      • BackgroundTransferHost.exe (PID: 7404)
      • BackgroundTransferHost.exe (PID: 8016)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • MicrosoftEdgeUpdate.exe (PID: 1760)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7548)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7576)
      • MicrosoftEdgeUpdate.exe (PID: 7344)
      • MicrosoftEdgeWebview_X64_132.0.2957.115.exe (PID: 7768)
      • MicrosoftEdgeUpdate.exe (PID: 6808)
      • setup.exe (PID: 7840)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 7500)
      • MicrosoftEdgeUpdate.exe (PID: 7344)
      • MicrosoftEdgeWebview_X64_132.0.2957.115.exe (PID: 7768)
      • setup.exe (PID: 7864)
      • setup.exe (PID: 7840)
      • BackgroundTransferHost.exe (PID: 7616)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 1760)
      • MicrosoftEdgeUpdate.exe (PID: 6808)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 7344)
      • MicrosoftEdgeUpdate.exe (PID: 6808)
      • BackgroundTransferHost.exe (PID: 7616)
    • Checks proxy server information

      • slui.exe (PID: 7652)
      • ZoraraB.exe (PID: 4776)
      • BackgroundTransferHost.exe (PID: 7616)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:01:22 09:29:17+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 131072
InitializedDataSize: 6542848
UninitializedDataSize: -
EntryPoint: 0xc90c
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
174
Monitored processes
29
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start #TROX zorarab.exe conhost.exe no specs zorarab.exe sppextcomobj.exe no specs slui.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs webview2runtime.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs slui.exe microsoftedgewebview_x64_132.0.2957.115.exe setup.exe setup.exe no specs microsoftedgeupdate.exe vc_redist.x64.exe vc_redist.x64.exe vc_redist.x64.exe SPPSurrogate no specs vssvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
904C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
976"C:\Users\admin\AppData\Local\Temp\{B90C6FEB-2CB6-4E68-8E21-73EDCD0E09E0}\.be\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{E4F0F210-6E71-4C2F-A37A-5683A9FBD65A} {BCFF5379-1E93-41AA-9E94-28DB2E852CCB} 5416C:\Users\admin\AppData\Local\Temp\{B90C6FEB-2CB6-4E68-8E21-73EDCD0E09E0}\.be\VC_redist.x64.exe
vc_redist.x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438
Version:
14.42.34438.0
Modules
Images
c:\users\admin\appdata\local\temp\{b90c6feb-2cb6-4e68-8e21-73edcd0e09e0}\.be\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1276\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeZoraraB.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1760"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuNDMiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuNDMiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7REI1M0U4NzYtNzJCRS00MjU5LTk2N0ItQzUzNkM0N0ZBQjYwfSIgdXNlcmlkPSJ7NDYzRTg2RUUtQTI1Qy00OUYwLUE5OEUtOTE3MjhBOEFFRTE5fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9InsyMTlENjc0Ni05RjFCLTQ5OTAtQkVCNC05ODNDQjVEMjgxMUZ9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSIiLz48YXBwIGFwcGlkPSJ7RjNDNEZFMDAtRUZENS00MDNCLTk1NjktMzk4QTIwRjFCQTRBfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjE5NS40MyIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTAyNzYxODQwMDEiIGluc3RhbGxfdGltZV9tcz0iMzk2OCIvPjwvYXBwPjwvcmVxdWVzdD4C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.43
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
2236"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=false" /installsource offline /sessionid "{DB53E876-72BE-4259-967B-C536C47FAB60}" /silent /offlinedir "{77C20D7F-5E6C-46C1-B670-F5DD319CB1F0}"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.43
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
2552C:\Users\admin\AppData\Local\Temp\WebView2Runtime.exe /silent /installC:\Users\admin\AppData\Local\Temp\WebView2Runtime.exe
ZoraraB.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.195.43
Modules
Images
c:\users\admin\appdata\local\temp\webview2runtime.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4120C:\Users\admin\AppData\Local\Temp\vc_redist.x64.exe /quiet /norestartC:\Users\admin\AppData\Local\Temp\vc_redist.x64.exe
ZoraraB.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438
Version:
14.42.34438.0
Modules
Images
c:\users\admin\appdata\local\temp\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4724C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4776C:\Users\admin\Desktop\ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\ZoraraB.exe
ZoraraB.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\onefile_7152_133874879653919884\zorarab.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\onefile_7152_133874879653919884\python39.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
5416"C:\Users\admin\AppData\Local\Temp\{19C4F0B9-1F33-402E-8466-6700E2BB50DF}\.cr\vc_redist.x64.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\vc_redist.x64.exe" -burn.filehandle.attached=592 -burn.filehandle.self=704 /quiet /norestartC:\Users\admin\AppData\Local\Temp\{19C4F0B9-1F33-402E-8466-6700E2BB50DF}\.cr\vc_redist.x64.exe
vc_redist.x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438
Version:
14.42.34438.0
Modules
Images
c:\users\admin\appdata\local\temp\{19c4f0b9-1f33-402e-8466-6700e2bb50df}\.cr\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
21 178
Read events
19 398
Write events
1 704
Delete events
76

Modification events

(PID) Process:(7404) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7404) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7404) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7616) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7616) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7616) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7796) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7796) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7796) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6640) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
227
Suspicious files
15
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
7152ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\ZoraraB.exeexecutable
MD5:A5DD2C9B93007D30E8F0DF8E81D2D5C8
SHA256:B6C23EB719766EE1DF6B2438B90751A24C105DC67FA3168F4B97C131C528B7F6
7152ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\_ctypes.pydexecutable
MD5:29DA9B022C16DA461392795951CE32D9
SHA256:3B4012343EF7A266DB0B077BBB239833779192840D1E2C43DFCBC48FFD4C5372
7152ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\_bz2.pydexecutable
MD5:6C7565C1EFFFE44CB0616F5B34FAA628
SHA256:FE63361F6C439C6AA26FD795AF3FD805FF5B60B3B14F9B8C60C50A8F3449060A
7152ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\_decimal.pydexecutable
MD5:CE4DF4DFE65AB8DC7AE6FCDEBAE46112
SHA256:FFBE84F0A1EAB363CA9CF73EFB7518F2ABD52C0893C7CC63266613C930855E96
7152ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\_lzma.pydexecutable
MD5:B5355DD319FB3C122BB7BF4598AD7570
SHA256:B9BC7F1D8AA8498CB8B5DC75BB0DBB6E721B48953A3F295870938B27267FB5F5
7152ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\certifi\cacert.pemtext
MD5:52A8319281308DE49CCEF4850A7245BC
SHA256:807897254F383A27F45E44F49656F378ABAB2141EDE43A4AD3C2420A597DD23F
7152ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\libssl-1_1.dllexecutable
MD5:BC778F33480148EFA5D62B2EC85AAA7D
SHA256:9D4CF1C03629F92662FC8D7E3F1094A7FC93CB41634994464B853DF8036AF843
7616BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\868e8094-d527-4b74-9be2-3991fa38936b.down_data
MD5:
SHA256:
7152ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\libffi-7.dllexecutable
MD5:EEF7981412BE8EA459064D3090F4B3AA
SHA256:F60DD9F2FCBD495674DFC1555EFFB710EB081FC7D4CAE5FA58C438AB50405081
7152ZoraraB.exeC:\Users\admin\AppData\Local\Temp\onefile_7152_133874879653919884\vcruntime140.dllexecutable
MD5:8697C106593E93C11ADC34FAA483C4A0
SHA256:FF43E813785EE948A937B642B03050BB4B1C6A5E23049646B891A66F65D4C833
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
32
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6044
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7616
BackgroundTransferHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5956
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5956
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4776
ZoraraB.exe
2.16.168.117:443
msedge.sf.dl.delivery.mp.microsoft.com
Akamai International B.V.
RU
whitelisted
3216
svchost.exe
4.213.25.240:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6544
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2568
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6044
backgroundTaskHost.exe
20.103.156.88:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.238
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 2.16.168.117
  • 2.16.168.116
whitelisted
client.wns.windows.com
  • 4.213.25.240
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.74
  • 40.126.32.68
  • 40.126.32.138
  • 20.190.160.2
  • 20.190.160.131
  • 40.126.32.136
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
www.bing.com
  • 104.126.37.155
  • 104.126.37.144
  • 104.126.37.177
  • 104.126.37.163
  • 104.126.37.162
  • 104.126.37.153
  • 104.126.37.154
  • 104.126.37.170
  • 104.126.37.145
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

No threats detected
No debug info