| File name: | Zemana.AntiMalware.Portable.exe |
| Full analysis: | https://app.any.run/tasks/c524b8c1-5103-43df-af2a-8b927af8b51c |
| Verdict: | Malicious activity |
| Analysis date: | August 31, 2018, 13:05:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D40BCD0501C7C9CDE26F7A5DC08E68F3 |
| SHA1: | 6236E23BEBC3AFCD5C31835433B8787CFEA64A68 |
| SHA256: | FC7AB9C7052D14306124E4C8735387D774749679113CF507F49AA9FB467CB589 |
| SSDEEP: | 196608:aX41Px1UjhSh5XcSMZFcEPF8FF1kFTv8dcwCDeJBuLRpB+UjfFY2R6Z/YzU:aiwS4SMQE0dOsuV2UjtY2seU |
| .scr | | | Windows screen saver (60.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (20.8) |
| .exe | | | Generic Win/DOS Executable (9.2) |
| .exe | | | DOS Executable Generic (9.2) |
| .vxd | | | VXD Driver (0.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:08:09 19:20:38+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 5 |
| CodeSize: | 7786496 |
| InitializedDataSize: | 7057408 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2ff4 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.74.0.150 |
| ProductVersionNumber: | 2.74.0.150 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Copyright 2017. |
| FileDescription: | ZAM |
| LegalCopyright: | Copyright 2017. All rights reserved. |
| ProductName: | ZAM |
| ProductVersion: | 2.74.0.150 |
| FileVersion: | 2.74.0.150 |
| InternalName: | ZAM |
| OriginalFileName: | ZAM.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3384 | "C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Portable.exe" | C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Portable.exe | — | explorer.exe | |||||||||||
User: admin Company: Copyright 2017. Integrity Level: MEDIUM Description: ZAM Exit code: 3221226540 Version: 2.74.0.150 Modules
| |||||||||||||||
| 3880 | "C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Portable.exe" | C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Portable.exe | explorer.exe | ||||||||||||
User: admin Company: Copyright 2017. Integrity Level: HIGH Description: ZAM Exit code: 0 Version: 2.74.0.150 Modules
| |||||||||||||||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion |
| Operation: | write | Name: | CUID |
Value: 122F47044D0197891995B5 | |||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK |
| Operation: | write | Name: | CUID |
Value: 122F47044D0197891995B5 | |||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK |
| Operation: | write | Name: | PermanentPartnerID |
Value: 187 | |||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK |
| Operation: | write | Name: | ZAMPartnerID |
Value: 187 | |||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK |
| Operation: | write | Name: | ZAMSubPartnerID |
Value: 0 | |||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK |
| Operation: | write | Name: | ZAMDownloadID |
Value: 77648 | |||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CrashControl |
| Operation: | write | Name: | CrashDumpEnabled |
Value: 3 | |||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_CURRENT_USER\Software\Zemana\AntiMalware |
| Operation: | write | Name: | LastExtractedLangs |
Value: 2.74.187.150 | |||
| (PID) Process: | (3880) Zemana.AntiMalware.Portable.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ZAM\Instances |
| Operation: | write | Name: | DefaultInstance |
Value: ZAMDefaultFilter | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Users\admin\AppData\Local\Temp\{2B3F4F41-285C-4525-BDE5-AD9E585E9F2C}.cat | — | |
MD5:— | SHA256:— | |||
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Bengali.ini | text | |
MD5:AF91551DEFE493099DFB8237DAE400CB | SHA256:D71B80CC9F28D9533B966FD9D35F71183820F99C1AB6C8ABDAC56D849170CA29 | |||
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\nedb.zdb_config.ini | text | |
MD5:D4E58D17C47FBCAF08896CD43BD14749 | SHA256:9139F0BD888DDF21ADCC16A1991ACB352E811D55C418AF523F4067C8FF1C4A81 | |||
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\nedb.zdb | text | |
MD5:FBE3214EE90F0620B1DAAAEA12D1E36F | SHA256:CF568A5B194FCEC94B21D370571D01173C7F2F516106C9BA2A8EEB19F618A345 | |||
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Arabic.ini | text | |
MD5:FF846CB61A628FC102E029FF24F484CF | SHA256:7FC11749581EB9498DC914699EDB02C1945BF066495F771541040B0B25A0B5BB | |||
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Bosnian.ini | text | |
MD5:017CE35CE3E37E39B52879F1DE5BE40C | SHA256:98B3C9377540C20C2A13D75E40B8C772C0A70CDBB61BCAB4CADCE94BD992BB6A | |||
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Windows\System32\drivers\zamguard32.sys | executable | |
MD5:06897B431C07886454E0681723DD53E6 | SHA256:AB2632A4D93A7F3B7598C06A9FDC773A1B1B69A7DD926BDB7CF578992628E9DD | |||
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Albanian.ini | text | |
MD5:D446492265AFB1AC5D91CE352A3EC5F9 | SHA256:0C68AC63CC677B8D71B4D60A3800190466D82F6AEA524634CD3266667C3F2EFB | |||
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Bulgarian.ini | text | |
MD5:BEF43CBEE6A0600022C5B2A7E494C99F | SHA256:D8566EE7727A6AC9BFF9D1C14B04509F81B4952D4AC052C39E6CAFC7962D0241 | |||
| 3880 | Zemana.AntiMalware.Portable.exe | C:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Dutch.ini | text | |
MD5:9D975D528D2667EB2F934AD3FFD768DD | SHA256:01EDDCC6F166E74B6A76C5ACEA61F63A20F7B9F383E76B5B5618759AECB3ADB7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3880 | Zemana.AntiMalware.Portable.exe | GET | — | 168.62.20.37:80 | http://zamcloud.zemana.com/api/sym/33C3093D09017CFE2E219F2472BFF6EB/E8DEB8BCE841AC92057E0844D47C3E1B | US | — | — | whitelisted |
3880 | Zemana.AntiMalware.Portable.exe | GET | 200 | 45.79.153.218:80 | http://dl12.zemana.com/CacheControl.bin | US | text | 12 b | whitelisted |
3880 | Zemana.AntiMalware.Portable.exe | POST | 200 | 168.62.20.37:80 | http://zamcloud.zemana.com/api/client/settings/122F47044D0197891995B5/2/187/2074150 | US | text | 1.41 Kb | whitelisted |
3880 | Zemana.AntiMalware.Portable.exe | GET | 200 | 168.62.20.37:80 | http://zamcloud.zemana.com/api/sym/144BD78C6103C8616DE047B3532142DB/38A360764C04E69544CEAB86175CD5D0 | US | text | 172 b | whitelisted |
3880 | Zemana.AntiMalware.Portable.exe | POST | 200 | 168.62.20.37:80 | http://zamcloud.zemana.com/api/miniport | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3880 | Zemana.AntiMalware.Portable.exe | 45.79.153.218:80 | dl12.zemana.com | Linode, LLC | US | suspicious |
3880 | Zemana.AntiMalware.Portable.exe | 168.62.20.37:80 | zamcloud.zemana.com | Microsoft Corporation | US | whitelisted |
3880 | Zemana.AntiMalware.Portable.exe | 208.67.220.220:53 | — | OpenDNS, LLC | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
dl12.zemana.com |
| whitelisted |
zamcloud.zemana.com |
| whitelisted |