File name:

Zemana.AntiMalware.Portable.exe

Full analysis: https://app.any.run/tasks/c524b8c1-5103-43df-af2a-8b927af8b51c
Verdict: Malicious activity
Analysis date: August 31, 2018, 13:05:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D40BCD0501C7C9CDE26F7A5DC08E68F3

SHA1:

6236E23BEBC3AFCD5C31835433B8787CFEA64A68

SHA256:

FC7AB9C7052D14306124E4C8735387D774749679113CF507F49AA9FB467CB589

SSDEEP:

196608:aX41Px1UjhSh5XcSMZFcEPF8FF1kFTv8dcwCDeJBuLRpB+UjfFY2R6Z/YzU:aiwS4SMQE0dOsuV2UjtY2seU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the Windows directory

      • Zemana.AntiMalware.Portable.exe (PID: 3880)
    • Creates files in the driver directory

      • Zemana.AntiMalware.Portable.exe (PID: 3880)
    • Executable content was dropped or overwritten

      • Zemana.AntiMalware.Portable.exe (PID: 3880)
    • Reads CPU info

      • Zemana.AntiMalware.Portable.exe (PID: 3880)
    • Reads internet explorer settings

      • Zemana.AntiMalware.Portable.exe (PID: 3880)
    • Creates or modifies windows services

      • Zemana.AntiMalware.Portable.exe (PID: 3880)
  • INFO

    • Dropped object may contain URL's

      • Zemana.AntiMalware.Portable.exe (PID: 3880)
    • Dropped object may contain Bitcoin addresses

      • Zemana.AntiMalware.Portable.exe (PID: 3880)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.scr | Windows screen saver (60.5)
.exe | Win32 Executable (generic) (20.8)
.exe | Generic Win/DOS Executable (9.2)
.exe | DOS Executable Generic (9.2)
.vxd | VXD Driver (0.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:08:09 19:20:38+02:00
PEType: PE32
LinkerVersion: 5
CodeSize: 7786496
InitializedDataSize: 7057408
UninitializedDataSize: -
EntryPoint: 0x2ff4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.74.0.150
ProductVersionNumber: 2.74.0.150
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Copyright 2017.
FileDescription: ZAM
LegalCopyright: Copyright 2017. All rights reserved.
ProductName: ZAM
ProductVersion: 2.74.0.150
FileVersion: 2.74.0.150
InternalName: ZAM
OriginalFileName: ZAM.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start zemana.antimalware.portable.exe zemana.antimalware.portable.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3384"C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Portable.exe" C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Portable.exeexplorer.exe
User:
admin
Company:
Copyright 2017.
Integrity Level:
MEDIUM
Description:
ZAM
Exit code:
3221226540
Version:
2.74.0.150
Modules
Images
c:\users\admin\appdata\local\temp\zemana.antimalware.portable.exe
c:\systemroot\system32\ntdll.dll
3880"C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Portable.exe" C:\Users\admin\AppData\Local\Temp\Zemana.AntiMalware.Portable.exe
explorer.exe
User:
admin
Company:
Copyright 2017.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Version:
2.74.0.150
Modules
Images
c:\users\admin\appdata\local\temp\zemana.antimalware.portable.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
Total events
277
Read events
229
Write events
47
Delete events
1

Modification events

(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
Operation:writeName:CUID
Value:
122F47044D0197891995B5
(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:CUID
Value:
122F47044D0197891995B5
(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:PermanentPartnerID
Value:
187
(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMPartnerID
Value:
187
(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMSubPartnerID
Value:
0
(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMDownloadID
Value:
77648
(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CrashControl
Operation:writeName:CrashDumpEnabled
Value:
3
(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_CURRENT_USER\Software\Zemana\AntiMalware
Operation:writeName:LastExtractedLangs
Value:
2.74.187.150
(PID) Process:(3880) Zemana.AntiMalware.Portable.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ZAM\Instances
Operation:writeName:DefaultInstance
Value:
ZAMDefaultFilter
Executable files
2
Suspicious files
34
Text files
47
Unknown types
1

Dropped files

PID
Process
Filename
Type
3880Zemana.AntiMalware.Portable.exeC:\Users\admin\AppData\Local\Temp\{2B3F4F41-285C-4525-BDE5-AD9E585E9F2C}.cat
MD5:
SHA256:
3880Zemana.AntiMalware.Portable.exeC:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Bengali.initext
MD5:AF91551DEFE493099DFB8237DAE400CB
SHA256:D71B80CC9F28D9533B966FD9D35F71183820F99C1AB6C8ABDAC56D849170CA29
3880Zemana.AntiMalware.Portable.exeC:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\nedb.zdb_config.initext
MD5:D4E58D17C47FBCAF08896CD43BD14749
SHA256:9139F0BD888DDF21ADCC16A1991ACB352E811D55C418AF523F4067C8FF1C4A81
3880Zemana.AntiMalware.Portable.exeC:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\nedb.zdbtext
MD5:FBE3214EE90F0620B1DAAAEA12D1E36F
SHA256:CF568A5B194FCEC94B21D370571D01173C7F2F516106C9BA2A8EEB19F618A345
3880Zemana.AntiMalware.Portable.exeC:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Arabic.initext
MD5:FF846CB61A628FC102E029FF24F484CF
SHA256:7FC11749581EB9498DC914699EDB02C1945BF066495F771541040B0B25A0B5BB
3880Zemana.AntiMalware.Portable.exeC:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Bosnian.initext
MD5:017CE35CE3E37E39B52879F1DE5BE40C
SHA256:98B3C9377540C20C2A13D75E40B8C772C0A70CDBB61BCAB4CADCE94BD992BB6A
3880Zemana.AntiMalware.Portable.exeC:\Windows\System32\drivers\zamguard32.sysexecutable
MD5:06897B431C07886454E0681723DD53E6
SHA256:AB2632A4D93A7F3B7598C06A9FDC773A1B1B69A7DD926BDB7CF578992628E9DD
3880Zemana.AntiMalware.Portable.exeC:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Albanian.initext
MD5:D446492265AFB1AC5D91CE352A3EC5F9
SHA256:0C68AC63CC677B8D71B4D60A3800190466D82F6AEA524634CD3266667C3F2EFB
3880Zemana.AntiMalware.Portable.exeC:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Bulgarian.initext
MD5:BEF43CBEE6A0600022C5B2A7E494C99F
SHA256:D8566EE7727A6AC9BFF9D1C14B04509F81B4952D4AC052C39E6CAFC7962D0241
3880Zemana.AntiMalware.Portable.exeC:\Users\admin\AppData\Local\Zemana\Zemana AntiMalware\lang\Dutch.initext
MD5:9D975D528D2667EB2F934AD3FFD768DD
SHA256:01EDDCC6F166E74B6A76C5ACEA61F63A20F7B9F383E76B5B5618759AECB3ADB7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
7
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3880
Zemana.AntiMalware.Portable.exe
GET
168.62.20.37:80
http://zamcloud.zemana.com/api/sym/33C3093D09017CFE2E219F2472BFF6EB/E8DEB8BCE841AC92057E0844D47C3E1B
US
whitelisted
3880
Zemana.AntiMalware.Portable.exe
GET
200
45.79.153.218:80
http://dl12.zemana.com/CacheControl.bin
US
text
12 b
whitelisted
3880
Zemana.AntiMalware.Portable.exe
POST
200
168.62.20.37:80
http://zamcloud.zemana.com/api/client/settings/122F47044D0197891995B5/2/187/2074150
US
text
1.41 Kb
whitelisted
3880
Zemana.AntiMalware.Portable.exe
GET
200
168.62.20.37:80
http://zamcloud.zemana.com/api/sym/144BD78C6103C8616DE047B3532142DB/38A360764C04E69544CEAB86175CD5D0
US
text
172 b
whitelisted
3880
Zemana.AntiMalware.Portable.exe
POST
200
168.62.20.37:80
http://zamcloud.zemana.com/api/miniport
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3880
Zemana.AntiMalware.Portable.exe
45.79.153.218:80
dl12.zemana.com
Linode, LLC
US
suspicious
3880
Zemana.AntiMalware.Portable.exe
168.62.20.37:80
zamcloud.zemana.com
Microsoft Corporation
US
whitelisted
3880
Zemana.AntiMalware.Portable.exe
208.67.220.220:53
OpenDNS, LLC
US
suspicious

DNS requests

Domain
IP
Reputation
dl12.zemana.com
  • 45.79.153.218
whitelisted
zamcloud.zemana.com
  • 168.62.20.37
whitelisted

Threats

No threats detected
No debug info