File name:

ZenTimings.exe

Full analysis: https://app.any.run/tasks/d0370e68-91de-4222-a9fb-8c2adb146d76
Verdict: Malicious activity
Analysis date: June 18, 2025, 21:01:10
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

6E166B185E0618781F4C299D1038F75D

SHA1:

33B0374BF0BD3D452CD61174A5C6CDCFEFAC6C57

SHA256:

F658D283275831771B6AE4817DDD95B17B6201738F3C2F96C36B2333E6E2C8BC

SSDEEP:

12288:SLnYGKRFQC1lCAejwBUt3LAejwBUtwAej7BGtNYh:SLnYGKRFQC1gAej1LAejSAejgYh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • ZenTimings.exe (PID: 2044)
      • ZenTimings.exe (PID: 6140)
      • ZenTimings.exe (PID: 188)
      • ZenTimings.exe (PID: 2028)
  • SUSPICIOUS

    • Executes application which crashes

      • ZenTimings.exe (PID: 188)
      • ZenTimings.exe (PID: 6140)
  • INFO

    • Reads the computer name

      • ZenTimings.exe (PID: 188)
      • ZenTimings.exe (PID: 6140)
    • Checks proxy server information

      • WerFault.exe (PID: 5600)
      • slui.exe (PID: 6700)
      • WerFault.exe (PID: 6768)
    • Checks supported languages

      • SearchApp.exe (PID: 5328)
      • ZenTimings.exe (PID: 6140)
      • ZenTimings.exe (PID: 188)
    • Process checks computer location settings

      • SearchApp.exe (PID: 5328)
    • Reads the software policy settings

      • SearchApp.exe (PID: 5328)
      • slui.exe (PID: 6700)
      • WerFault.exe (PID: 6768)
      • WerFault.exe (PID: 5600)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 5600)
      • WerFault.exe (PID: 6768)
    • Reads the machine GUID from the registry

      • SearchApp.exe (PID: 5328)
      • ZenTimings.exe (PID: 188)
      • ZenTimings.exe (PID: 6140)
    • Manual execution by a user

      • ZenTimings.exe (PID: 2028)
      • ZenTimings.exe (PID: 6140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2099:04:28 21:18:50+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 414208
InitializedDataSize: 99840
UninitializedDataSize: -
EntryPoint: 0x67186
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.35.1592.0
ProductVersionNumber: 1.35.1592.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Author: Ivan Rusanov
CompanyName: ZenTimings
FileDescription: ZenTimings
FileVersion: 1.35.1592
InternalName: ZenTimings.exe
LegalCopyright: Copyright © 2019-2025
LegalTrademarks: -
OriginalFileName: ZenTimings.exe
ProductName: ZenTimings
ProductVersion: 1.35.1592
AssemblyVersion: 1.35.1592.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
9
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
start zentimings.exe werfault.exe slui.exe rundll32.exe no specs zentimings.exe no specs zentimings.exe werfault.exe zentimings.exe no specs searchapp.exe

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Users\admin\AppData\Local\Temp\ZenTimings.exe" C:\Users\admin\AppData\Local\Temp\ZenTimings.exe
explorer.exe
User:
admin
Company:
ZenTimings
Integrity Level:
HIGH
Description:
ZenTimings
Exit code:
3762504530
Version:
1.35.1592
Modules
Images
c:\users\admin\appdata\local\temp\zentimings.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2028"C:\Users\admin\AppData\Local\Temp\ZenTimings.exe" C:\Users\admin\AppData\Local\Temp\ZenTimings.exeexplorer.exe
User:
admin
Company:
ZenTimings
Integrity Level:
MEDIUM
Description:
ZenTimings
Exit code:
3221226540
Version:
1.35.1592
Modules
Images
c:\users\admin\appdata\local\temp\zentimings.exe
c:\windows\system32\ntdll.dll
2044"C:\Users\admin\AppData\Local\Temp\ZenTimings.exe" C:\Users\admin\AppData\Local\Temp\ZenTimings.exeexplorer.exe
User:
admin
Company:
ZenTimings
Integrity Level:
MEDIUM
Description:
ZenTimings
Exit code:
3221226540
Version:
1.35.1592
Modules
Images
c:\users\admin\appdata\local\temp\zentimings.exe
c:\windows\system32\ntdll.dll
5328"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\combase.dll
5600C:\WINDOWS\system32\WerFault.exe -u -p 188 -s 1048C:\Windows\System32\WerFault.exe
ZenTimings.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
6140"C:\Users\admin\AppData\Local\Temp\ZenTimings.exe" C:\Users\admin\AppData\Local\Temp\ZenTimings.exe
explorer.exe
User:
admin
Company:
ZenTimings
Integrity Level:
HIGH
Description:
ZenTimings
Exit code:
3762504530
Version:
1.35.1592
Modules
Images
c:\users\admin\appdata\local\temp\zentimings.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6424C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6700C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6768C:\WINDOWS\system32\WerFault.exe -u -p 6140 -s 1040C:\Windows\System32\WerFault.exe
ZenTimings.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
Total events
8 977
Read events
8 952
Write events
17
Delete events
8

Modification events

(PID) Process:(5600) WerFault.exeKey:\REGISTRY\A\{aa061b4c-6bda-af01-dcfb-b3864360692e}\Root\InventoryApplicationFile
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(5600) WerFault.exeKey:\REGISTRY\A\{aa061b4c-6bda-af01-dcfb-b3864360692e}\Root\InventoryApplicationFile\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
(PID) Process:(5328) SearchApp.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.search_cw5n1h2txyewy\SOFTWARE\Microsoft\Speech_OneCore\Isolated\A1hdl50UVDh2ZbG324Nx-6fZgntcGnHOs5kHLdmaJYE\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech_OneCore\Recognizers
Operation:writeName:DefaultTokenId
Value:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Speech_OneCore\Recognizers\Tokens\MS-1033-110-WINMO-DNN
(PID) Process:(5328) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Flighting
Operation:delete valueName:CachedFeatureString
Value:
(PID) Process:(5328) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\SearchSettings
Operation:writeName:IsMSACloudSearchEnabled
Value:
0
(PID) Process:(5328) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\SearchSettings
Operation:writeName:IsAADCloudSearchEnabled
Value:
0
(PID) Process:(5328) SearchApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search
Operation:writeName:CortanaStateLastRun
Value:
3E29536800000000
(PID) Process:(5328) SearchApp.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.search_cw5n1h2txyewy\Internet Explorer\DOMStorage\bing.com
Operation:writeName:Total
Value:
1517
(PID) Process:(5328) SearchApp.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.search_cw5n1h2txyewy\Internet Explorer\DOMStorage\bing.com
Operation:writeName:Total
Value:
949
(PID) Process:(5328) SearchApp.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.search_cw5n1h2txyewy\Internet Explorer\DOMStorage\bing.com
Operation:writeName:Total
Value:
1675
Executable files
0
Suspicious files
6
Text files
5
Unknown types
6

Dropped files

PID
Process
Filename
Type
5600WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_ZenTimings.exe_5a465f6e0e0ecf3d6bc60d2fee72e262c55fdcb_24d6b90b_fb6b616b-eded-4aea-bcf6-af4c3f874387\Report.wer
MD5:
SHA256:
5600WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\ZenTimings.exe.188.dmp
MD5:
SHA256:
6768WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_ZenTimings.exe_5a465f6e0e0ecf3d6bc60d2fee72e262c55fdcb_24d6b90b_12bd4752-f65a-4f1e-b77e-31e56a938592\Report.wer
MD5:
SHA256:
6768WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\ZenTimings.exe.6140.dmp
MD5:
SHA256:
5600WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER6282.tmp.dmpdmp
MD5:D86EFA99D1F11EA168C6CD553DD79494
SHA256:AFE5521E147A82744872FCA2AA421DBD3ABAFFFF6BD5DDAA0C20D565627CCF9E
5328SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\fbaf94e759052658216786bfbabcdced1b67a5c2.tbresbinary
MD5:A7051AA96ABEBD67FE91F8335082478F
SHA256:B7BDAB58D0995CAF357188D066192EC2C71642257459E21D457F8751D9AFDC7C
5328SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:C592D3D128C13904553A89703BD35693
SHA256:4A8B320DC8C9E1400187648FF7ED411D22FFECA9EF128F3BC1912FF423BFC200
6768WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER9496.tmp.WERInternalMetadata.xmlxml
MD5:2DD6EE2A427EF8342FF235667E5136DF
SHA256:CB0BA9E278D0F4AB2E2AB871BB048B650F8434EE479FB254931DA93F11BE35FD
5328SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\ZWUI0EBX\www.bing[1].xmltext
MD5:CCC1CF951DD9D3C6BB20DAFE3DF91578
SHA256:E793F38F93D55B4CEAA7280BC3BEC2D3F8D91FD5C8D7B7E26D86562BBB5DACB9
5328SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187binary
MD5:2EACF2D4032384F7E1C6DBE4FBD00C12
SHA256:A5EEA49747C46DE0536C34EC8938480A67F2E9BA4825BCD71F3094D000EA95F7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
39
DNS requests
29
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5600
WerFault.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
868 b
whitelisted
5600
WerFault.exe
GET
200
2.18.121.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
FR
binary
825 b
whitelisted
1268
svchost.exe
GET
200
23.48.23.145:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
5848
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
3976
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
420 b
whitelisted
3976
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
868 b
whitelisted
5328
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
5328
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
DE
binary
471 b
whitelisted
2940
svchost.exe
GET
200
23.209.209.135:80
http://x1.c.lencr.org/
ID
binary
734 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5476
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5600
WerFault.exe
13.89.179.12:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5600
WerFault.exe
2.18.121.139:80
crl.microsoft.com
AKAMAI-AS
FR
whitelisted
5600
WerFault.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5848
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.142
whitelisted
watson.events.data.microsoft.com
  • 13.89.179.12
whitelisted
crl.microsoft.com
  • 2.18.121.139
  • 2.18.121.147
  • 23.48.23.145
  • 23.48.23.144
  • 23.48.23.153
  • 23.48.23.150
  • 23.48.23.143
  • 23.48.23.149
  • 23.48.23.161
  • 23.48.23.160
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.131
  • 20.190.159.75
  • 20.190.159.128
  • 20.190.159.0
  • 20.190.159.73
  • 40.126.31.0
  • 20.190.159.64
  • 40.126.31.1
  • 20.190.159.68
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.13
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted

Threats

No threats detected
No debug info