Edit tour

Windows Analysis Report
Zscaler-windows-4.4.0.309-installer-x64.exe

Overview

General Information

Sample name:Zscaler-windows-4.4.0.309-installer-x64.exe
Analysis ID:1554237
MD5:37d6c75390d283f47665db629ebaa626
SHA1:7eaeba97bba91b0c1fcfda9538ced8b813676514
SHA256:bb7f812a83fbbde43ff81b0349dc59b06a226765333817c7157593494fa5e65c
Infos:

Detection

Score:26
Range:0 - 100
Whitelisted:false
Confidence:40%

Compliance

Score:65
Range:0 - 100

Signatures

Changes security center settings (notifications, updates, antivirus, firewall)
Query firmware table information (likely to detect VMs)
Registers a service to start in safe boot mode
Adds / modifies Windows certificates
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains capabilities to detect virtual machines
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates driver files
Creates files inside the system directory
Creates or modifies windows services
Drops PE files
Drops certificate files (DER)
Drops files with a non-matching file extension (content does not match file extension)
Enables driver privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Queries information about the installed CPU (vendor, model number etc)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Queries time zone information
Sigma detected: Suspicious Copy From or To System Directory
Stores large binary data to the registry

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • Zscaler-windows-4.4.0.309-installer-x64.exe (PID: 7048 cmdline: "C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe" MD5: 37D6C75390D283F47665DB629EBAA626)
    • dllhost.exe (PID: 6916 cmdline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} MD5: 08EB78E5BE019DF044C26B14703BD1FA)
    • cmd.exe (PID: 6692 cmdline: C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc"" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 6696 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • ZSAService.exe (PID: 1092 cmdline: "C:\Program Files\Zscaler\ZSAService\ZSAService.exe" -pushCert MD5: BA783DEC4A0BBBA3619648B2853D68F1)
    • ZSAHelper.exe (PID: 6728 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setRecoveryMode MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 6508 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATrayManager MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 7136 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATunnel MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 6936 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAService MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 6876 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAUpdater MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 4540 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAUpm MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 3424 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATray MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 1816 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAHelper MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 1428 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAMTAuthApp MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 3364 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZEPInstaller MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 6916 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZEPService MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 6604 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZDPInstaller MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 408 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSACli MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 5464 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSFFutil MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 1788 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --migrateConfigFiles MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 6748 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --updatePrevInstallerHash MD5: F9BB669A809694C1E085E963610A4866)
  • svchost.exe (PID: 7124 cmdline: C:\Windows\System32\svchost.exe -k NetworkService -p MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • SgrmBroker.exe (PID: 6352 cmdline: C:\Windows\system32\SgrmBroker.exe MD5: 3BA1A18A0DC30A0545E7765CB97D8E63)
  • svchost.exe (PID: 7160 cmdline: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • svchost.exe (PID: 1540 cmdline: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
    • MpCmdRun.exe (PID: 2196 cmdline: "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable MD5: B3676839B2EE96983F9ED735CD044159)
      • conhost.exe (PID: 3632 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • svchost.exe (PID: 5868 cmdline: C:\Windows\system32\svchost.exe -k UnistackSvcGroup MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • ZSAService.exe (PID: 3720 cmdline: "C:\Program Files\Zscaler\ZSAService\ZSAService.exe" MD5: BA783DEC4A0BBBA3619648B2853D68F1)
    • sc.exe (PID: 3224 cmdline: C:\Windows\System32\sc.exe stop ZSAUpm MD5: 3FB5CF71F7E7EB49790CB0E663434D80)
      • conhost.exe (PID: 1904 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • ZSATrayManager.exe (PID: 2120 cmdline: "C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exe" MD5: 90AFC50FD2BB415992B218E20BB303F2)
    • ZSATray.exe (PID: 3484 cmdline: ZSATray.exe MD5: 70271880E4C851B68574F76962C01D1E)
  • Zscaler-windows-4.4.0.309-installer-x64.exe (PID: 3724 cmdline: "C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe" MD5: 37D6C75390D283F47665DB629EBAA626)
  • Zscaler-windows-4.4.0.309-installer-x64.exe (PID: 5612 cmdline: "C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe" MD5: 37D6C75390D283F47665DB629EBAA626)
    • fsutil.exe (PID: 6744 cmdline: C:\Windows\System32\fsutil.exe reparsepoint query C:\ProgramData\Zscaler MD5: DE00EDA7134D3365E6074700E3008CAD)
    • ZSAHelper.exe (PID: 6372 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --isInstallerPasswordConfigured 2 0 MD5: F9BB669A809694C1E085E963610A4866)
    • ZSAHelper.exe (PID: 6560 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --installerDisableAntiTampering 2 0 MD5: F9BB669A809694C1E085E963610A4866)
    • cmd.exe (PID: 2852 cmdline: C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc"" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 4580 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • ZSAHelper.exe (PID: 1100 cmdline: "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --markStop 2 0 MD5: F9BB669A809694C1E085E963610A4866)
  • cleanup
No yara matches
Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, Tim Shelton (HAWK.IO), Nasreddine Bencherchali (Nextron Systems): Data: Command: C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc"", CommandLine: C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc"", CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: "C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe", ParentImage: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe, ParentProcessId: 7048, ParentProcessName: Zscaler-windows-4.4.0.309-installer-x64.exe, ProcessCommandLine: C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc"", ProcessId: 6692, ProcessName: cmd.exe
Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k NetworkService -p, CommandLine: C:\Windows\System32\svchost.exe -k NetworkService -p, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 656, ProcessCommandLine: C:\Windows\System32\svchost.exe -k NetworkService -p, ProcessId: 7124, ProcessName: svchost.exe
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION ZSATray.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION ZSAMTAuthApp.exe
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION ZSATray.exe

Compliance

barindex
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Config
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Config\Backup
Source: C:\Windows\System32\cmd.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Zscaler-windows-4.4.0.309-installer-x64.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\rollbackBackupDirectory
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATunnel
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAHelper
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAService
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\lib
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\Npcap
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\PacParser
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\PacParser\x64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\TAPDriver
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\TAPDriver\x64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\WebView2
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAUpdater
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATrayManager
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACredentialProviders
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACredentialProviders\ARM64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZEPInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACli
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Wpf.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\WebView2Loader.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources\ZscalerAppSplash.png
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssutil3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\smime3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ZSFFutil.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources\ZscalerApp.ico
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources\ZscalerApp.png
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources\ZscalerAppTop.png
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\Npcap\Libpcap-License.txt
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\Npcap\WinPcap-License-And-Acknowledgements.txt
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nspr-LICENSE
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nss-COPYING
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plc4.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plds4.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Core.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\Newtonsoft.Json.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\ZSAMTAuthApp.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\ZSATray.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATunnel\ZSATunnel.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAService\ZSAService.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\lib\ZSAAuth.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\lib\ZSALogger.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\lib\ZSATrayHelper.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\Npcap\npcap-1.78-oem.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\PacParser\x64\pacparser.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\PacParser\x64\PacparserV8.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\TAPDriver\x64\Zscaler-Network-Adapter-Win10-1.0.2.0.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\WebView2\MicrosoftEdgeWebview2Setup.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\freebl3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nspr4.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nss3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssckbi.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\softokn3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\sqlite3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ssl3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAUpdater\ZSAUpdater.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACredentialProviders\ZSACredentialProvider.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACredentialProviders\ARM64\ZSACredentialProvider.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZEPInstaller\ZEPInstaller.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACli\ZSACli.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\uninstall.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\uninstbr.000
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\uninstall.dat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\uninstall.dat.new
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\tclEA5B.tmp
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\Zscaler-installLog.log
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Config\Backup
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Config\Backup\Zscaler-windows-4.4.0.309-installer-x64.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zscaler
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\installbuilder_installer.log
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAInstaller\Zscaler-installLog.log
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\installbuilder_installer_5612.log
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\Npcap\Libpcap-License.txt
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\Npcap\WinPcap-License-And-Acknowledgements.txt
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: certificate valid
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.catJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.catJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.catJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.catJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.catJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Windows\System32\ZSACredentialProvider.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess token adjusted: Load Driver
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: Number of sections : 12 > 10
Source: classification engineClassification label: sus26.evad.winEXE@67/122@0/0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeFile created: C:\Users\user\AppData\Local\Zscaler\ZSATray_2024-11-12-08-20-51.606816.log
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:3632:120:WilError_03
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeMutant created: NULL
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4580:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6696:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:1904:120:WilError_03
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeMutant created: \Sessions\1\BaseNamedObjects\Global itrockSingleInstanceCheck
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : Select * From Win32_Process Where ParentProcessId = 3484
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile read: C:\Program Files\desktop.ini
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile read: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
Source: unknownProcess created: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe"
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc""
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc""
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAService\ZSAService.exe "C:\Program Files\Zscaler\ZSAService\ZSAService.exe" -pushCert
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setRecoveryMode
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATrayManager
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATunnel
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAService
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAUpdater
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAUpm
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATray
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAHelper
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAMTAuthApp
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZEPInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZEPService
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZDPInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSACli
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSFFutil
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --migrateConfigFiles
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --updatePrevInstallerHash
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p
Source: unknownProcess created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k UnistackSvcGroup
Source: unknownProcess created: C:\Program Files\Zscaler\ZSAService\ZSAService.exe "C:\Program Files\Zscaler\ZSAService\ZSAService.exe"
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeProcess created: C:\Windows\System32\sc.exe C:\Windows\System32\sc.exe stop ZSAUpm
Source: C:\Windows\System32\sc.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exe "C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exe"
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAService\ZSAService.exe "C:\Program Files\Zscaler\ZSAService\ZSAService.exe" -pushCert
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setRecoveryMode
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATrayManager
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATunnel
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAService
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAUpdater
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAUpm
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATray
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAHelper
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAMTAuthApp
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZEPInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZDPInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSACli
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSFFutil
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --migrateConfigFiles
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --updatePrevInstallerHash
Source: unknownProcess created: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe"
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess created: C:\Program Files\Zscaler\ZSATray\ZSATray.exe ZSATray.exe
Source: unknownProcess created: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe"
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\fsutil.exe C:\Windows\System32\fsutil.exe reparsepoint query C:\ProgramData\Zscaler
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --isInstallerPasswordConfigured 2 0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --installerDisableAntiTampering 2 0
Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc""
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --markStop 2 0
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeProcess created: C:\Windows\System32\sc.exe C:\Windows\System32\sc.exe stop ZSAUpm
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess created: C:\Program Files\Zscaler\ZSATray\ZSATray.exe ZSATray.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\fsutil.exe C:\Windows\System32\fsutil.exe reparsepoint query C:\ProgramData\Zscaler
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --isInstallerPasswordConfigured 2 0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --installerDisableAntiTampering 2 0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc""
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --markStop 2 0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: netapi32.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: pdh.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: winmm.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: mpr.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: version.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: powrprof.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: secur32.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: userenv.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: srvcli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: samcli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wkscli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: logoncli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: netutils.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: sspicli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: umpdc.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wsock32.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wldp.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: profapi.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: textinputframework.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: textshaping.dll
Source: C:\Windows\System32\cmd.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: apphelp.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: propsys.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: linkinfo.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: ntshrui.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: cscapi.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: dlnashext.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wpdshext.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: storsvc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: devobj.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fltlib.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bcd.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wer.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: storageusage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: aphostservice.dll
Source: C:\Windows\System32\svchost.exeSection loaded: networkhelper.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userdataplatformhelperutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mccspal.dll
Source: C:\Windows\System32\svchost.exeSection loaded: syncutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: syncutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vaultcli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dmcfgutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wintypes.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dmcmnutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dmxmlhelputils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dll
Source: C:\Windows\System32\svchost.exeSection loaded: inproclogger.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dll
Source: C:\Windows\System32\svchost.exeSection loaded: windows.networking.connectivity.dll
Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dll
Source: C:\Windows\System32\svchost.exeSection loaded: synccontroller.dll
Source: C:\Windows\System32\svchost.exeSection loaded: pimstore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: aphostclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: accountaccessor.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dsclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exeSection loaded: systemeventsbrokerclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userdatalanguageutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mccsengineshared.dll
Source: C:\Windows\System32\svchost.exeSection loaded: pimstore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cemapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userdatatypehelperutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: phoneutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: dbghelp.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: userenv.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: version.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: dbgcore.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: msasn1.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: windows.storage.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: wldp.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: profapi.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: ntmarta.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: powrprof.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: umpdc.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: winsta.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: cryptsp.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: rsaenh.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: cryptbase.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: gpapi.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: cryptnet.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: netapi32.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: netutils.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: wkscli.dll
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeSection loaded: srvcli.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: wevtapi.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: userenv.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: version.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: ncrypt.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: dbghelp.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: netapi32.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: winhttp.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: rasapi32.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: wininet.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: rasman.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: dbgcore.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: dsreg.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: netutils.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: cryptsp.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: samcli.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: msasn1.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: ntasn1.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: windows.storage.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: wldp.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: profapi.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: ntmarta.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: powrprof.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: umpdc.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: winsta.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: sspicli.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: winbrand.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: wbemcomn.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: amsi.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: mswsock.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: winnsi.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: dhcpcsvc6.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: dhcpcsvc.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: wkscli.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: srvcli.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: rsaenh.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: cryptbase.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: iertutil.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: gpapi.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: cryptnet.dll
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSection loaded: apphelp.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: mpclient.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: secur32.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sspicli.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: version.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: msasn1.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: userenv.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: gpapi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wbemcomn.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: amsi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: profapi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wscapi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: urlmon.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: iertutil.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: srvcli.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: netutils.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: slc.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sppc.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: netapi32.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: pdh.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: winmm.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: mpr.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: version.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: powrprof.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: secur32.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: userenv.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: srvcli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: samcli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wkscli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: logoncli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: netutils.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: sspicli.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: umpdc.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wsock32.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wldp.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: profapi.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: textinputframework.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeSection loaded: textshaping.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: mscoree.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: version.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: uxtheme.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: cryptsp.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: rsaenh.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: cryptbase.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dwrite.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: msvcp140_clr0400.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: windows.storage.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: wldp.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: profapi.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: userenv.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: ncrypt.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dbghelp.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: netapi32.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dbgcore.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: netutils.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: samcli.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dsreg.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: msasn1.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: ntasn1.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: gpapi.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: cryptnet.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: urlmon.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: iertutil.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: srvcli.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: windowscodecs.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dwmapi.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: d3d9.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: d3d10warp.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: wbemcomn.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: amsi.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: textshaping.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dnsapi.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dhcpcsvc6.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dhcpcsvc.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: winnsi.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: winsta.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: powrprof.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: umpdc.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dataexchange.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: d3d11.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dcomp.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dxgi.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: twinapi.appcore.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: resourcepolicyclient.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: dxcore.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: mswsock.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: uiautomationcore.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: propsys.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: textinputframework.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: coreuicomponents.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: coremessaging.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: ntmarta.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: wintypes.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: wintypes.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: wintypes.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: msctfui.dll
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeSection loaded: d3dcompiler_47.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: userenv.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: version.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: windows.storage.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: wldp.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: profapi.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\cmd.exeSection loaded: ntmarta.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: userenv.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: version.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: windows.storage.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: wldp.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: profapi.dll
Source: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Config
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Config\Backup
Source: C:\Windows\System32\cmd.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Zscaler-windows-4.4.0.309-installer-x64.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\rollbackBackupDirectory
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATunnel
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAHelper
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAService
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\lib
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\Npcap
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\PacParser
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\PacParser\x64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\TAPDriver
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\TAPDriver\x64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\WebView2
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAUpdater
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATrayManager
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACredentialProviders
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACredentialProviders\ARM64
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZEPInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACli
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Wpf.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\WebView2Loader.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources\ZscalerAppSplash.png
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssutil3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\smime3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ZSFFutil.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.sys
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources\ZscalerApp.ico
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources\ZscalerApp.png
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\resources\ZscalerAppTop.png
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\Npcap\Libpcap-License.txt
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\Npcap\WinPcap-License-And-Acknowledgements.txt
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nspr-LICENSE
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nss-COPYING
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plc4.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plds4.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.cat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.inf
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Core.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\Newtonsoft.Json.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\ZSAMTAuthApp.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATray\ZSATray.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATunnel\ZSATunnel.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAService\ZSAService.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\lib\ZSAAuth.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\lib\ZSALogger.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\Common\lib\ZSATrayHelper.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\Npcap\npcap-1.78-oem.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\PacParser\x64\pacparser.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\PacParser\x64\PacparserV8.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\TAPDriver\x64\Zscaler-Network-Adapter-Win10-1.0.2.0.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\WebView2\MicrosoftEdgeWebview2Setup.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\freebl3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nspr4.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nss3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssckbi.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\softokn3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\sqlite3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ssl3.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAUpdater\ZSAUpdater.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACredentialProviders\ZSACredentialProvider.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACredentialProviders\ARM64\ZSACredentialProvider.dll
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZEPInstaller\ZEPInstaller.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSACli\ZSACli.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\uninstall.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\uninstbr.000
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\uninstall.dat
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\uninstall.dat.new
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\tclEA5B.tmp
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\ZSAInstaller\Zscaler-installLog.log
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Config\Backup
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDirectory created: C:\Program Files\Zscaler\RevertZcc\Config\Backup\Zscaler-windows-4.4.0.309-installer-x64.exe
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zscaler
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: certificate valid
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic file information: File size 62101792 > 1048576
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x1f4200
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: 0xA4F8A4E0 [Sat Sep 15 05:49:20 2057 UTC]
Source: Zscaler-windows-4.4.0.309-installer-x64.exeStatic PE information: section name: .xdata
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\TAPDriver\x64\Zscaler-Network-Adapter-Win10-1.0.2.0.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ssl3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR3B5F830D2BB11E2B.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSACredentialProviders\ARM64\ZSACredentialProvider.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSATunnel\ZSATunnel.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR35615B2F934939A3.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\PacParser\x64\pacparser.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nspr4.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nss3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAService\ZSAService.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR622C137B951D933C.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssutil3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\Npcap\npcap-1.78-oem.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSATray\ZSAMTAuthApp.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\smime3.dllJump to dropped file
Source: C:\Windows\System32\cmd.exeFile created: C:\Program Files\Zscaler\RevertZcc\Zscaler-windows-4.4.0.309-installer-x64.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSATray\WebView2Loader.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAUpdater\ZSAUpdater.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR21F29831012E61DD.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSATray\ZSATray.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRA018BDF1AB2F73A8.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D736031D18236EB.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2D2C719D21C20E27.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRE029A274AC39924C.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\freebl3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSACli\ZSACli.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR36228A1AD3752AD1.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D69E23D81E01402.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSACredentialProviders\ZSACredentialProvider.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plc4.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2BF1381B13B7213D.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\WebView2\MicrosoftEdgeWebview2Setup.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plds4.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSATray\Newtonsoft.Json.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1310716922C20F10.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR34729C2D5264F725.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssckbi.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\sqlite3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2E61BD27E2AF2DF3.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Wpf.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\PacParser\x64\PacparserV8.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\Common\lib\ZSALogger.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR33B1514629514031.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\Common\lib\ZSATrayHelper.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ZSFFutil.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAInstaller\uninstbr.000Jump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\Common\lib\ZSAAuth.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\softokn3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZEPInstaller\ZEPInstaller.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAInstaller\uninstbr.000Jump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\installbuilder_installer.log
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ZSAInstaller\Zscaler-installLog.log
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Users\user\AppData\Local\Temp\installbuilder_installer_5612.log
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\Npcap\Libpcap-License.txt
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeFile created: C:\Program Files\Zscaler\ThirdParty\Npcap\WinPcap-License-And-Acknowledgements.txt

Boot Survival

barindex
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry value created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\ZSAService NULL
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZSAService
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeProcess created: C:\Windows\System32\sc.exe C:\Windows\System32\sc.exe stop ZSAUpm
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 Blob
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeProcess information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSystem information queried: FirmwareTableInformation
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSystem information queried: FirmwareTableInformation
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSystem information queried: FirmwareTableInformation
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeSystem information queried: FirmwareTableInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeMemory allocated: 15269EB0000 memory reserve | memory write watch
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeMemory allocated: 1526BA70000 memory reserve | memory write watch
Source: C:\Windows\System32\svchost.exeFile opened / queried: SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeThread delayed: delay time: 922337203685477
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeThread delayed: delay time: 922337203685477
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeWindow / User API: threadDelayed 3422
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeWindow / User API: threadDelayed 862
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\TAPDriver\x64\Zscaler-Network-Adapter-Win10-1.0.2.0.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ssl3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR3B5F830D2BB11E2B.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSACredentialProviders\ARM64\ZSACredentialProvider.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSATunnel\ZSATunnel.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR35615B2F934939A3.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\PacParser\x64\pacparser.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nspr4.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nss3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR622C137B951D933C.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssutil3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\Npcap\npcap-1.78-oem.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSATray\ZSAMTAuthApp.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\smime3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSATray\WebView2Loader.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSAUpdater\ZSAUpdater.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR21F29831012E61DD.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRA018BDF1AB2F73A8.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D736031D18236EB.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2D2C719D21C20E27.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRE029A274AC39924C.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\freebl3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSACli\ZSACli.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D69E23D81E01402.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR36228A1AD3752AD1.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSACredentialProviders\ZSACredentialProvider.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plc4.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2BF1381B13B7213D.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\WebView2\MicrosoftEdgeWebview2Setup.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plds4.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSATray\Newtonsoft.Json.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1310716922C20F10.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR34729C2D5264F725.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\sqlite3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssckbi.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2E61BD27E2AF2DF3.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\PacParser\x64\PacparserV8.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Wpf.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\Common\lib\ZSALogger.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.sysJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR33B1514629514031.tmpJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\Common\lib\ZSATrayHelper.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ZSFFutil.exeJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZSAInstaller\uninstbr.000Jump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\Common\lib\ZSAAuth.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\softokn3.dllJump to dropped file
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeDropped PE file which has not been started: C:\Program Files\Zscaler\ZEPInstaller\ZEPInstaller.exeJump to dropped file
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exe TID: 3636Thread sleep time: -30000s >= -30000s
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exe TID: 4588Thread sleep count: 3422 > 30
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exe TID: 5144Thread sleep count: 862 > 30
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exe TID: 4124Thread sleep count: 110 > 30
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exe TID: 4572Thread sleep time: -6456360425798339s >= -30000s
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exe TID: 3340Thread sleep time: -1844674407370954s >= -30000s
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exe TID: 4840Thread sleep count: 126 > 30
Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
Source: C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\Windows\System32 FullSizeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeThread delayed: delay time: 922337203685477
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeThread delayed: delay time: 922337203685477
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess information queried: ProcessInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeMemory allocated: page read and write | page guard
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc""
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAService\ZSAService.exe "C:\Program Files\Zscaler\ZSAService\ZSAService.exe" -pushCert
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setRecoveryMode
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATrayManager
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATunnel
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAService
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAUpdater
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAUpm
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSATray
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAHelper
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSAMTAuthApp
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZEPInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZDPInstaller
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSACli
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --setPreferSystem32Mitigation ZSFFutil
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --migrateConfigFiles
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --updatePrevInstallerHash
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeProcess created: C:\Windows\System32\sc.exe C:\Windows\System32\sc.exe stop ZSAUpm
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\fsutil.exe C:\Windows\System32\fsutil.exe reparsepoint query C:\ProgramData\Zscaler
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --isInstallerPasswordConfigured 2 0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --installerDisableAntiTampering 2 0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /s /c " copy C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe "C:\Program Files\Zscaler\RevertZcc""
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeProcess created: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe "C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe" --markStop 2 0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR21F29831012E61DD.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR21F29831012E61DD.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR36228A1AD3752AD1.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR36228A1AD3752AD1.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRE029A274AC39924C.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRE029A274AC39924C.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1310716922C20F10.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1310716922C20F10.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR622C137B951D933C.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR622C137B951D933C.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRA018BDF1AB2F73A8.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRA018BDF1AB2F73A8.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR33B1514629514031.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR33B1514629514031.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2BF1381B13B7213D.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2BF1381B13B7213D.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR34729C2D5264F725.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR34729C2D5264F725.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2E61BD27E2AF2DF3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2E61BD27E2AF2DF3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2D2C719D21C20E27.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2D2C719D21C20E27.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D736031D18236EB.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR35615B2F934939A3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR35615B2F934939A3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR3B5F830D2BB11E2B.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D69E23D81E01402.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D69E23D81E01402.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR3B5F830D2BB11E2B.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D736031D18236EB.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAWFPDriver VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAWFPDriver VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACredentialProviders VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Wpf.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Wpf.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Wpf.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\WebView2Loader.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\WebView2Loader.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\WebView2Loader.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common\resources\ZscalerAppSplash.png VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common\resources\ZscalerAppSplash.png VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssutil3.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssutil3.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssutil3.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\smime3.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\smime3.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ZSFFutil.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ZSFFutil.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ZSFFutil.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.sys VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.sys VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.sys VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.sys VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.sys VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.sys VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.sys VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.sys VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.sys VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common\resources\ZscalerApp.ico VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common\resources\ZscalerApp.ico VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common\resources\ZscalerApp.png VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common\resources\ZscalerApp.png VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common\resources\ZscalerAppTop.png VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\Npcap\Libpcap-License.txt VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\Npcap\Libpcap-License.txt VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\Npcap\WinPcap-License-And-Acknowledgements.txt VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nspr-LICENSE VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plc4.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plc4.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plc4.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plds4.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plds4.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plds4.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.cat VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.cat VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.cat VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.cat VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.cat VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.inf VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.inf VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.cat VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.cat VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.inf VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Core.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATunnel\ZSATunnel.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATunnel\ZSATunnel.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAService\ZSAService.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\Common\lib\ZSAAuth.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\Npcap\npcap-1.78-oem.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ThirdParty\PacParser\x64\pacparser.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAUpdater\ZSAUpdater.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACredentialProviders\ZSACredentialProvider.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACredentialProviders\ARM64\ZSACredentialProvider.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACredentialProviders\ARM64\ZSACredentialProvider.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACredentialProviders\ARM64\ZSACredentialProvider.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZEPInstaller\ZEPInstaller.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZEPInstaller\ZEPInstaller.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZEPInstaller\ZEPInstaller.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACli\ZSACli.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACli\ZSACli.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACli\ZSACli.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller\uninstall.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ProgramData VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ProgramData\Microsoft VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ProgramData\Microsoft\Windows VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ProgramData\Microsoft\Windows\Start Menu VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Windows\System32 VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Windows\System32 VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Windows\System32 VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACredentialProviders\ZSACredentialProvider.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Windows\System32 VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSACredentialProviders\ZSACredentialProvider.dll VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ProgramData VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\ZSATray.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zscaler\Zscaler.lnk VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller\uninstall.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zscaler\Uninstall Zscaler.lnk VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller\uninstall.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller\uninstall.dat VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller\uninstall.dat.new VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller\uninstall.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller\uninstbr.000 VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller\uninstall.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\ZSAInstaller\rollbackBackupDirectory VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1310716922C20F10.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D736031D18236EB.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR21F29831012E61DD.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2D2C719D21C20E27.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR33B1514629514031.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR34729C2D5264F725.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR3B5F830D2BB11E2B.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BR622C137B951D933C.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRA018BDF1AB2F73A8.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL00001b88\BRE029A274AC39924C.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\installbuilder_installer.log VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR3D5D26A2F537918F.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR3D5D26A2F537918F.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR2581D71E82E62FE1.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR2581D71E82E62FE1.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1C118539B1771501.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1C118539B1771501.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1BE1312BF36218F2.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1BE1312BF36218F2.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1512E01121629831.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1512E01121629831.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR4723D3BE92952072.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR4723D3BE92952072.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1B51A011F3665910.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1B51A011F3665910.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1932335C2A2266D3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1932335C2A2266D3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR3B73E734724039B3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR3B73E734724039B3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR3CD9E232401952A3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR3CD9E232401952A3.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1CE3A726A2157234.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1CE3A726A2157234.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1D43911EB9F1D12B.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR2C1A1118D63B024A.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR2C1A1118D63B024A.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR2A62C52E11E0260D.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR31B20E2F01943092.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR31B20E2F01943092.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR2A62C52E11E0260D.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\BRL000015ec\BR1D43911EB9F1D12B.tmp VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup\Zscaler-windows-4.4.0.309-installer-x64.exe VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Config\Backup VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeQueries volume information: C:\Program Files\Zscaler\RevertZcc\Zscaler-windows-4.4.0.309-installer-x64.exe.bak VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\ZSATray.exe VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Program Files\Zscaler\ZSATray\Newtonsoft.Json.dll VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userbrii.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userbrili.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userbrib.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userbriz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userFR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userFI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userFB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userST.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userSTI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userSTB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\userSTBI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeKey value queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation Bias
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Windows\System32\svchost.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center cval
Source: C:\Program Files\Zscaler\ZSAService\ZSAService.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 Blob
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA &apos;AntiVirusProduct&apos; OR TargetInstance ISA &apos;FirewallProduct&apos; OR TargetInstance ISA &apos;AntiSpywareProduct&apos;
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA &apos;AntiVirusProduct&apos; OR TargetInstance ISA &apos;FirewallProduct&apos; OR TargetInstance ISA &apos;AntiSpywareProduct&apos;
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA &apos;AntiVirusProduct&apos; OR TargetInstance ISA &apos;FirewallProduct&apos; OR TargetInstance ISA &apos;AntiSpywareProduct&apos;
Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA &apos;AntiVirusProduct&apos; OR TargetInstance ISA &apos;FirewallProduct&apos; OR TargetInstance ISA &apos;AntiSpywareProduct&apos;
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA &apos;AntiVirusProduct&apos; OR TargetInstance ISA &apos;FirewallProduct&apos; OR TargetInstance ISA &apos;AntiSpywareProduct&apos;
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA &apos;AntiVirusProduct&apos; OR TargetInstance ISA &apos;FirewallProduct&apos; OR TargetInstance ISA &apos;AntiSpywareProduct&apos;
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA &apos;AntiVirusProduct&apos; OR TargetInstance ISA &apos;FirewallProduct&apos; OR TargetInstance ISA &apos;AntiSpywareProduct&apos;
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Source: C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Source: C:\Program Files\Zscaler\ZSATray\ZSATray.exeRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts21
Windows Management Instrumentation
22
Windows Service
22
Windows Service
23
Masquerading
OS Credential Dumping1
System Time Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts1
Service Execution
1
Scripting
11
Process Injection
11
Modify Registry
LSASS Memory13
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Registry Run Keys / Startup Folder
1
Registry Run Keys / Startup Folder
111
Disable or Modify Tools
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCron1
LSASS Driver
1
LSASS Driver
151
Virtualization/Sandbox Evasion
NTDS151
Virtualization/Sandbox Evasion
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchd1
DLL Side-Loading
1
DLL Side-Loading
11
Process Injection
LSA Secrets1
Application Window Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Timestomp
Cached Domain Credentials1
File and Directory Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
DLL Side-Loading
DCSync44
System Information Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Zscaler-windows-4.4.0.309-installer-x64.exe0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1310716922C20F10.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D69E23D81E01402.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR1D736031D18236EB.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR21F29831012E61DD.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2BF1381B13B7213D.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2D2C719D21C20E27.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR2E61BD27E2AF2DF3.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR33B1514629514031.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR34729C2D5264F725.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR35615B2F934939A3.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR36228A1AD3752AD1.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR3B5F830D2BB11E2B.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BR622C137B951D933C.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BRA018BDF1AB2F73A8.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\BRL00001b88\BRE029A274AC39924C.tmp0%ReversingLabs
C:\Program Files\Zscaler\Common\lib\ZSAAuth.dll0%ReversingLabs
C:\Program Files\Zscaler\Common\lib\ZSALogger.dll0%ReversingLabs
C:\Program Files\Zscaler\Common\lib\ZSATrayHelper.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\Npcap\npcap-1.78-oem.exe0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\PacParser\x64\PacparserV8.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\PacParser\x64\pacparser.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\TAPDriver\x64\Zscaler-Network-Adapter-Win10-1.0.2.0.exe0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\WebView2\MicrosoftEdgeWebview2Setup.exe0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ZSFFutil.exe0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\freebl3.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nspr4.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nss3.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssckbi.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\nssutil3.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plc4.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\plds4.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\smime3.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\softokn3.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\sqlite3.dll0%ReversingLabs
C:\Program Files\Zscaler\ThirdParty\ZSFFUtil\x64\ssl3.dll0%ReversingLabs
C:\Program Files\Zscaler\ZEPInstaller\ZEPInstaller.exe0%ReversingLabs
C:\Program Files\Zscaler\ZSACli\ZSACli.exe0%ReversingLabs
C:\Program Files\Zscaler\ZSACredentialProviders\ARM64\ZSACredentialProvider.dll0%ReversingLabs
C:\Program Files\Zscaler\ZSACredentialProviders\ZSACredentialProvider.dll0%ReversingLabs
C:\Program Files\Zscaler\ZSAFilterDriver\win10\amd64\zapprd.sys0%ReversingLabs
C:\Program Files\Zscaler\ZSAFilterDriver\win10\arm64\zapprd.sys0%ReversingLabs
C:\Program Files\Zscaler\ZSAFilterDriver\win10\i386\zapprd.sys0%ReversingLabs
C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe0%ReversingLabs
C:\Program Files\Zscaler\ZSAInstaller\uninstbr.0000%ReversingLabs
C:\Program Files\Zscaler\ZSAService\ZSAService.exe0%ReversingLabs
C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exe0%ReversingLabs
C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Core.dll0%ReversingLabs
C:\Program Files\Zscaler\ZSATray\Microsoft.Web.WebView2.Wpf.dll0%ReversingLabs
C:\Program Files\Zscaler\ZSATray\WebView2Loader.dll0%ReversingLabs
C:\Program Files\Zscaler\ZSATray\ZSAMTAuthApp.exe0%ReversingLabs
C:\Program Files\Zscaler\ZSATray\ZSATray.exe0%ReversingLabs
C:\Program Files\Zscaler\ZSATunnel\ZSATunnel.exe0%ReversingLabs
C:\Program Files\Zscaler\ZSAUpdater\ZSAUpdater.exe0%ReversingLabs
C:\Program Files\Zscaler\ZSAWFPDriver\amd64\zsawdrv.sys0%ReversingLabs
C:\Program Files\Zscaler\ZSAWFPDriver\arm64\zsawdrv.sys0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1554237
Start date and time:2024-11-12 09:19:00 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:46
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:1
Technologies:
  • EGA enabled
Analysis Mode:stream
Sample name:Zscaler-windows-4.4.0.309-installer-x64.exe
Detection:SUS
Classification:sus26.evad.winEXE@67/122@0/0
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, SgrmBroker.exe, svchost.exe
  • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
  • Report size getting too big, too many NtOpenFile calls found.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtSetInformationFile calls found.
  • Timeout during stream target processing, analysis might miss dynamic analysis data
  • VT rate limit hit for: Zscaler-windows-4.4.0.309-installer-x64.exe
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):8067976
Entropy (8bit):6.484358089216621
Encrypted:false
SSDEEP:
MD5:24025FF3F98BF6E40FBE2B2AE8560487
SHA1:72796EDF2A2B3618A50469E8DD6AD76EBECBFAF5
SHA-256:0CACE7CC92FA6E84E6B0D09A49CE22CB4A2474EB3FFB6BFB43F397AF96CFF27F
SHA-512:8FACB96B8862201D2D100949504E7BA0408B0E1790E6B1D56D12E947A6043CA784C5C049DEE3386027DA21490B228C0C08C8DD28C40F62D49CB60165428EE27E
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$.......,...h...h...h......e............|.l...:..a..........h...L.............w......O...:..L...:.......I......i......O...h..........Z......i.....D.i...h.,.i......i...Richh...........PE..d.....qf.........." .....,R..6).....`w?........@..............................{.......{...`A........................................0^n......fn.......{......@u.t]....z..%... {.|... .b.T...................x.b.(....w_..............PR......Zn.@....................text....3Q......4Q................. ..`fipstx.......PQ......8Q............. ..`.rdata..BI...PR..J...0R.............@..@.data........n..(...zn.............@....pdata..t]...@u..^....t.............@..@.didat..H.....y.......y.............@...fipsro..0.....y.......y.............@..@fipsda...u...`z..v....y.............@...fipsrd..`+....z..,....z.............@..@.rsrc.........{......Fz.............@..@.reloc..|.... {.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):1284488
Entropy (8bit):6.27927342560963
Encrypted:false
SSDEEP:
MD5:EAA527D684D05E3E449BEB6C60D3FE12
SHA1:E9C3DFD0CA10366D3FA727DBEA8B924CD18A8EF8
SHA-256:33EC8401350A5B047982AC779E9B69883AA33F6B32B2C065DD4DE88B745A9A00
SHA-512:1EC90B688782A90E68E7FD210A25E29903AB331FDE6492EAC56E8E2E034E347FFA0FBF0D3092E4797D07468EB878421BF2A23BA4921B08955462AFC5506BEEFF
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$........mI...'..'..'..j$..'..j#..'..j".,.'......'..d$..'.=e"...'.=e#..'..d"...'..d#..'..j&..'..&.G.'.=e...'.=e'..'.=e...'.....'.=e%..'.Rich..'.........................PE..d...X.qf.........." ................P................................................|....`A.........................................U.......W..d............... ....t...%......d....H..p....................I..(....H...............................................text.............................. ..`.rdata..............................@..@.data........p...^...P..............@....pdata.. ...........................@..@.rsrc................P..............@..@.reloc..d............V..............@..B................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):7477128
Entropy (8bit):6.495909738221805
Encrypted:false
SSDEEP:
MD5:21EF951A23F3BC0543EDF44DF6F7C5FC
SHA1:C92DB73CFEFD82D8EB3426E854052C93C94F0BC2
SHA-256:DA444D4F4F47184CC1F2EAFE429B63451F30DDFF9355E76AA8851951DB30D688
SHA-512:BD9A5B2182EB622F0D2E4067A37CCFA513B838E74E94A77556770A8D2ACA614952EC351CC47B47ADE7914E413A564E84DD1E1D528DDA21B7BB1E2837B2BFC363
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$.........................8...m.h......................[.......X.....X...............y..................#...X......X.....X.P....8...X.....Rich..........PE..d....qf.........." ......K..p&.......5.......................................r.......r...`A..........................................e.<....e.......r.h....pl..2....q..%... r.d... .[.T...................x.[.(....,Y...............L.......e.@....................text.....J.......J................. ..`fipstx........K.......J............. ..`.rdata........L.......K.............@..@.data...$.....e.......e.............@....pdata...2...pl..4....k.............@..@.didat..H.....p.......p.............@...fipsrd..`+....p..,....p.............@..@fipsda..(u....p..v....p.............@...fipsro......pq.......p.............@..@.rsrc...h.....r......Dq.............@..@.reloc..d.... r.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
Category:dropped
Size (bytes):32038
Entropy (8bit):2.504856956832959
Encrypted:false
SSDEEP:
MD5:E7F64900C568F83EF1420E0FF84324E0
SHA1:7E7629FDD21A507268BE3F69688F2649F2E446F3
SHA-256:7A56C8062BDF15AD41867DF0DA024BF63915A51BDBCF6D1F6D5F8CE161FCF95A
SHA-512:0AC6BA8C32D33B4AF3CFB419872FE3E2C28BBCFC3C7DF30090F3A78572BC1C8A9F4880C68B1228C8772C1EA4ABB9C82DAD4D31CF93F68563E4DEA3580359C615
Malicious:false
Reputation:unknown
Preview:............ .h...F... .... .........00.... ..%..V...@@.... .(B...:..(....... ..... .....@........................................................................................................................................................................................................................................_..o..............s.....................!........W.....................................1...........G..S..........................k...........................}.........................................q..........................................................c.....g..A............w.....................................................).............................}.....)..?..).................E....................'..............................................)................./..........................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
Category:dropped
Size (bytes):4148
Entropy (8bit):7.7451714323559875
Encrypted:false
SSDEEP:
MD5:C06BE6F670CA74CA544D6DCF7CE1042C
SHA1:339BA72BA6CBDD8BCEE5A0299FCE8D937A703365
SHA-256:C33F6E3F09B5374FE9E7BA5E6CEF8194F7F8E8CAF2B7598DBE4832294ABE767A
SHA-512:9A11FE77181D4A91016A6F623E9A44F49067C630E4147D876C324EB6B17261689304E3342AD412732960942E710BB2FDA7ACDB29D3A185E60DA7B9C0937E2343
Malicious:false
Reputation:unknown
Preview:.PNG........IHDR..............>a.....tEXtSoftware.Adobe ImageReadyq.e<....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c014 79.156797, 2014/08/20-09:53:02 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmpMM:OriginalDocumentID="uuid:5D20892493BFDB11914A8590D31508C8" xmpMM:DocumentID="xmp.did:D73D36FAE53811E496F4946D1F195FDE" xmpMM:InstanceID="xmp.iid:D73D36F9E53811E496F4946D1F195FDE" xmp:CreatorTool="Adobe Illustrator CC 2014 (Macintosh)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:f697779e-7c75-4b96-8763-01f6302ac78c" stRef:documentID="xmp.did:f697779e-7c75-4b96-8763-01f6302ac78c"/> <dc:title> <rdf:Alt> <rdf:li xml:lang="x-default">Print</
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
Category:dropped
Size (bytes):54184
Entropy (8bit):4.4186481019580075
Encrypted:false
SSDEEP:
MD5:94DAC91DEBF537E46EDC126D0495C8F3
SHA1:B7FF881553389FEFDD1E5B5405D911009EF67AA9
SHA-256:40DB3B085EC60070ACDBF38560B99125EAB9FA496BD66A094D29426A19EEC115
SHA-512:08EE77140AB49D999F67D7AFF7C13CF09621E398335D7235F80EA388E5E0827471837269E33A9F4575CE181E0C5C7026EA9DCB6278D48121840A0F4E4EAAB6C3
Malicious:false
Reputation:unknown
Preview:.PNG........IHDR..............>a.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
Category:dropped
Size (bytes):2427
Entropy (8bit):7.408817381297061
Encrypted:false
SSDEEP:
MD5:9E746B898B3DA77E1321E5E35A3C4869
SHA1:2D937677EE38973016532EF1ACB3DD9AA2EA14B6
SHA-256:5214615E4FCB61514A48CF746E5CF645BDB674A0681F3BA49EFFD2B8DEBB1F39
SHA-512:E82B7274C0D39BDE68465CB16DBBACB54DAE336CFBEDCD63AF3B2AF88B6AC84C043028D8D26B5DE4690E4914CDA6DDC185895422F3B80D99B99A1C1B5ED15532
Malicious:false
Reputation:unknown
Preview:.PNG........IHDR...@...@......iq.....tEXtSoftware.Adobe ImageReadyq.e<....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c014 79.156797, 2014/08/20-09:53:02 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmpMM:OriginalDocumentID="uuid:5D20892493BFDB11914A8590D31508C8" xmpMM:DocumentID="xmp.did:475FFAA0DB2611E4876F9E7D749D4744" xmpMM:InstanceID="xmp.iid:475FFA9FDB2611E4876F9E7D749D4744" xmp:CreatorTool="Adobe Illustrator CC 2014 (Macintosh)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:c14e8da7-3a30-415d-915f-6bbba99eae8c" stRef:documentID="xmp.did:c14e8da7-3a30-415d-915f-6bbba99eae8c"/> <dc:title> <rdf:Alt> <rdf:li xml:lang="x-default">Print</
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:37D6C75390D283F47665DB629EBAA626
SHA1:7EAEBA97BBA91B0C1FCFDA9538CED8B813676514
SHA-256:BB7F812A83FBBDE43FF81B0349DC59B06A226765333817C7157593494FA5E65C
SHA-512:653C7FF79F977320F353ABD7B301D8059C18358DB6F2EE20DEBAB5FBB92C67AC05D693A5963A98079DCAF3FC2ECAF78D27F2888F13BDE40BA6F9BDB45E1C0ED5
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.......................B...,-..@............@...............................-.....M\....@... ......................................@*.n....P*..O....*.x.....'.8....s...%...p-. `.......................... .*.(....................b*..............................text....A.......B..................`.P`.data........`.......F..............@.p..rdata.......`"..0...@".............@.p@.pdata..8.....'......p'.............@.0@.xdata...Q....(..R...x(.............@.0@.bss.....?....*.......................p..edata..n....@*.......).............@.0@.idata...O...P*..P....).............@.0..CRT....h.....*.......*.............@.@..tls....h.....*.......*.............@.`..rsrc...x.....*...... *.............@.0..reloc.. `...p-..b....,.............@.0B................................................................................................................................
Process:C:\Windows\System32\cmd.exe
File Type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):62101792
Entropy (8bit):7.979928611768417
Encrypted:false
SSDEEP:
MD5:37D6C75390D283F47665DB629EBAA626
SHA1:7EAEBA97BBA91B0C1FCFDA9538CED8B813676514
SHA-256:BB7F812A83FBBDE43FF81B0349DC59B06A226765333817C7157593494FA5E65C
SHA-512:653C7FF79F977320F353ABD7B301D8059C18358DB6F2EE20DEBAB5FBB92C67AC05D693A5963A98079DCAF3FC2ECAF78D27F2888F13BDE40BA6F9BDB45E1C0ED5
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.......................B...,-..@............@...............................-.....M\....@... ......................................@*.n....P*..O....*.x.....'.8....s...%...p-. `.......................... .*.(....................b*..............................text....A.......B..................`.P`.data........`.......F..............@.p..rdata.......`"..0...@".............@.p@.pdata..8.....'......p'.............@.0@.xdata...Q....(..R...x(.............@.0@.bss.....?....*.......................p..edata..n....@*.......).............@.0@.idata...O...P*..P....).............@.0..CRT....h.....*.......*.............@.@..tls....h.....*.......*.............@.`..rsrc...x.....*...... *.............@.0..reloc.. `...p-..b....,.............@.0B................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:37D6C75390D283F47665DB629EBAA626
SHA1:7EAEBA97BBA91B0C1FCFDA9538CED8B813676514
SHA-256:BB7F812A83FBBDE43FF81B0349DC59B06A226765333817C7157593494FA5E65C
SHA-512:653C7FF79F977320F353ABD7B301D8059C18358DB6F2EE20DEBAB5FBB92C67AC05D693A5963A98079DCAF3FC2ECAF78D27F2888F13BDE40BA6F9BDB45E1C0ED5
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.......................B...,-..@............@...............................-.....M\....@... ......................................@*.n....P*..O....*.x.....'.8....s...%...p-. `.......................... .*.(....................b*..............................text....A.......B..................`.P`.data........`.......F..............@.p..rdata.......`"..0...@".............@.p@.pdata..8.....'......p'.............@.0@.xdata...Q....(..R...x(.............@.0@.bss.....?....*.......................p..edata..n....@*.......).............@.0@.idata...O...P*..P....).............@.0..CRT....h.....*.......*.............@.@..tls....h.....*.......*.............@.`..rsrc...x.....*...... *.............@.0..reloc.. `...p-..b....,.............@.0B................................................................................................................................
Process:C:\Windows\System32\cmd.exe
File Type:ASCII text, with CRLF line terminators
Category:modified
Size (bytes):26
Entropy (8bit):3.95006375643621
Encrypted:false
SSDEEP:
MD5:187F488E27DB4AF347237FE461A079AD
SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
Malicious:false
Reputation:unknown
Preview:[ZoneTransfer]....ZoneId=0
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):1175
Entropy (8bit):4.9143475318935215
Encrypted:false
SSDEEP:
MD5:1675D1BAFFA7CAFC27D8463B229D47E4
SHA1:595B76F017A67904523B6BC9811FDD90665A4287
SHA-256:D71E1CC78A905FA01E255381FEC90E6A5D3ECAEF8EC3C3ADB13B5D38ADC50E37
SHA-512:4DED377F56672D00A31F6C82D3E8D59C304AF2F1AD8907D3209C27660E87326B246813666F08532BFA1F63ED3629A15CE7993D3AF20B3DE06080749805010186
Malicious:false
Reputation:unknown
Preview:Npcap incorporates the multi-platform Libpcap packet capturing..software (http://www.tcpdump.org/). Libpcap is under the 3-clause..BSD-style open source license reproduced below. This allows for free..redistribution and use in other softare. Npcap itself is NOT under..this license.....License: BSD....Redistribution and use in source and binary forms, with or without..modification, are permitted provided that the following conditions..are met:.... 1. Redistributions of source code must retain the above copyright.. notice, this list of conditions and the following disclaimer... 2. Redistributions in binary form must reproduce the above copyright.. notice, this list of conditions and the following disclaimer in.. the documentation and/or other materials provided with the.. distribution... 3. The names of the authors may not be used to endorse or promote.. products derived from this software without specific prior.. written permission.....THIS SOFTWARE IS PROVI
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:Unicode text, UTF-8 text, with very long lines (755), with CRLF line terminators
Category:dropped
Size (bytes):13650
Entropy (8bit):5.173819734234075
Encrypted:false
SSDEEP:
MD5:88E03F685CA21FD5964FAFB04D23C1FD
SHA1:760E91558C98D162C78E948E2B95536012BF399D
SHA-256:614F0362650CEC33543706004C22B2FCF3C07CF914FF766F996060E8CBC2FDC8
SHA-512:3ADDF1BEBCE52134B05DAE12A29B75BCAA73DCEE19AD0B60014AB48BEDD7D21060AEEB231E603692AA00B8882FEAED724F8D66B71B2FF9532AAE6C70C430B920
Malicious:false
Reputation:unknown
Preview:Since Npcap is based on WinPcap (which is based on code from various other contributors), we're including this..WinPcap-License-And-Acknowledgement.txt which is straight from the WinPcap project. It explains the copyright and..credits for WinPcap, but keep in mind that the Npcap copyright is different. See the LICENSE file in this directory..for the Npcap license.....[From https://www.winpcap.org/misc/copyright.htm 2016/03/11]....Copyright (c) 1999 - 2005 NetGroup, Politecnico di Torino (Italy)...Copyright (c) 2005 - 2010 CACE Technologies, Davis (userfornia)...All rights reserved.....Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:....1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. ..2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
Category:dropped
Size (bytes):1171688
Entropy (8bit):7.9802269148005704
Encrypted:false
SSDEEP:
MD5:D2163AD38CC1421C971533A1C273E2C4
SHA1:629F91116A895AEAA86BD762B0833B0EC6B1C0D4
SHA-256:F00E775B1CFDCAE3DB4214DF358A9407D007B44094C1168A95D6DA92C47C65A9
SHA-512:D3AC8D171F7C341D2693A086452405D098DCC0B9A59E76FB68D6BB04D5B4B3B121BA094163BBF460ECFC6AD04DBB84EF74703B66951F2979FAA796740F6892E3
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1(..PF..PF..PF.*_...PF..PG.APF.*_...PF.sv..PF..V@..PF.Rich.PF.........PE..L.....`.................n...T......Y:............@..........................0.......*....@..............................................D...............M...........................................................................................text...sm.......n.................. ..`.rdata...............r..............@..@.data....-..........................@....ndata...................................rsrc....D.......F..................@..@................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):18804536
Entropy (8bit):6.524975001157171
Encrypted:false
SSDEEP:
MD5:7E165B774A2BC4D884C671867DCC19C1
SHA1:E2CB573D0B51AF9383678B6F72512574BA3DEEFB
SHA-256:DE1288A10201803B2695B91F1032E0E1E34D799C4D4290B49EBF948C02DD591C
SHA-512:C3A765F83176DD2E67668F9870AD6C7C7B7646D37E20C80FA92ECFAF9EA7BEAE1C76B1C9589DEF5ADAC00817A0F0C2A84C5A7F70B3CCD219140744EE1F798192
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........kv....D...D...D.r.E...D.r.E...D.r.E...D...E...D...E...D...E4..D.u.D...D.u.E...D.u.E...D.u.E...D.r.E...D...Dv..D...E...D...E...D...D...D...E...DRich...D........PE..d...TS.e.........." ...%....../.....H.........................................!...........`.........................................@^......,a..x.....!......@..........8#....!........p.......................(...`...@............................................text...l........................... ..`.rdata..............................@..@.data...d............b..............@....pdata.......@.......x..............@..@_RDATA..\..... ...... ..............@..@.rsrc.........!......"..............@..@.reloc.......!......$..............@..B........................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):1163880
Entropy (8bit):5.850610991200503
Encrypted:false
SSDEEP:
MD5:F7DDCBEB3B353757B4A82D69A414E541
SHA1:2C7462B6C15E3F7801F1197FFB2551723D72A299
SHA-256:319209EE2D2995163BFD64837EAB53BFB30FF40678B9C2B884A33CDFC64DDEBD
SHA-512:EE6B1AC55056EFED408D1C76A04A754DD57276EE16E4124F1008E215BD41082894777A7893387BCD74D24A0E0C9C9D87BFD08D37D7DB0F329698825220C2BC22
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...}w.c..........& ...(.....J................;j.....................................m....`... .........................................\w...................@...S..0...8$..................................`...(...................(................................text...............................`..`.data....b.......d..................@....rdata..@....0......................@..@/4...........0......................@....pdata...S...@...T..................@..@.xdata..8S.......T...^..............@..@.bss.....................................edata..\w.......x..................@..@.idata...............*..............@....CRT....X............8..............@....tls.................:..............@....reloc...............<..............@..B/14..................P..............@..B/29......<.......>...R..............@..B/41..........0......................@..B/55.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64, for MS Windows, Nullsoft Installer self-extracting archive
Category:dropped
Size (bytes):639072
Entropy (8bit):7.880836649810277
Encrypted:false
SSDEEP:
MD5:6B4BC12DF160979A8C8263B98EBBC2B3
SHA1:3942AE45679A6D298F534245AAEAAF5A65CEF502
SHA-256:2D1E207A836D6450FAE69237D5C12882FE33F48E61BB81768F4EFEF0FCD4E709
SHA-512:11C1EFB8820921266CE0B111AEAB6B07E2D1AB6C6139BBD609323FE7C13E267C9591F1C463100F08A6EBEF01DF37DD1CB017A331A4BE596C465030ADB9C1BB4D
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........ (.AF..AF..AF..'B..AF..'@..AF..'G..AF..AG..AF..(B..AF..(...AF..(D..AF.Rich.AF.........PE..d...Q.#d..........#..........$......l>.........@.....................................O....`.................................................L........0..........`.......P#..............................................................@............................text....~.......................... ..`.rdata..@ ......."..................@..@.data...............................@....pdata..`...........................@..@.ndata...p...............................rsrc........0......................@..@........................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):1601904
Entropy (8bit):7.928613727185149
Encrypted:false
SSDEEP:
MD5:4B9CB01CEDBF0453BC9A0D402F41CD4B
SHA1:2835C85C6971430CED8FFD2E6F2052180A268722
SHA-256:677AB2A0A906D74B9D6609187BF7944C53B6E1281C40F456C142FDED02EB90FA
SHA-512:70CD81DC45F6B0878CCAD410A2E3777AFAA7EEBAB063BB21334A098012C8139F328129799FEC3483E12F0DF2DD5ECD5F79AD7E7EE293B4FA79B825C71EDA669F
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......d..[ e.. e.. e..4...+e..4....e..B...1e..B...4e......-e..B....e..4...3e..4...!e..4...-e.. e...e....@.!e.. e(.ve......!e..Rich e..................PE..L....(.c.....................t...... }............@..........................p............@..................................?..x.......................pS...P.. ....1..p....................1..........@...............H...T>..`....................text...*........................... ..`.rdata..............................@..@.data...,....P.......8..............@....didat..,....p.......B..............@....rsrc................D..............@..@.reloc.. ....P......................@..B................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (console) x86-64, for MS Windows
Category:dropped
Size (bytes):218680
Entropy (8bit):6.35409297179342
Encrypted:false
SSDEEP:
MD5:8C6E1938D11DF88CFC5A528B1C644C68
SHA1:C0342CE229B34446A8659769D6CE52153280BCE8
SHA-256:A61E184C0D3FC6918E724F20C68D445E08B8B9BA899C3F1451D789F85770C851
SHA-512:02E291BA9AEF1BB739392EB08AB3A5C87621E55BC344121F249F460F6217FA049CEA5F076935433C43EDD9CC08F3CEB0CF5DD5654CB76A20D76DC21FAF6F1C7C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......F................s.....P......g........'.....P......P......P................A.........................Rich............PE..d...>..c.........."..........X.................@..........................................`.....................................................h....p.......P..L....2..8$......d.......T............................................................................text............................... ..`.rdata..............................@..@.data....'... ......................@....pdata..L....P......................@..@.rsrc........p.......,..............@..@.reloc..d...........................@..B................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):815672
Entropy (8bit):6.628524732421309
Encrypted:false
SSDEEP:
MD5:E05C6F324198860C093C33F10AFF8A97
SHA1:F54F14AA2CB21ADD781565282BB92FC6EE1446F1
SHA-256:B2CD08C0EA9C8571855D3CC42DE23C388B82983978E907A0FFF1442E4EA066D7
SHA-512:A425E5198857F89DC1132FD5059BD9BCB38CD1418B16CB60E39BE781CBCFB764872D605C5E08F23CFDF48D65C02C38E5B4B48BCE7AA0B9535EA9766E66163266
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........d.........}......m...?.+.....m....m....m....l....c.........l....l.....l....l......l...Rich...........PE..d...,..c.........." .........~.......................................................x....`.............................................P....................p...@...N..8$......|.......T........................... ................0...............................text...S........................... ..`.rdata.......0......................@..@.data....N... ......................@....pdata...@...p...B..................@..@.rsrc................H..............@..@.reloc..|............J..............@..B................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):17099
Entropy (8bit):4.589578253764449
Encrypted:false
SSDEEP:
MD5:CFD7D66D2864C38232EC1EF20B27C13A
SHA1:9CF097120D3D9EEA0E9790D7D44AE80E6231A35A
SHA-256:CDE215E5B42363EB28CA2462C4558FF4807B38F383C537624C31E44657AC58F4
SHA-512:4F3D2BA0A66B0044FC29E477326B50E63F1B5252DC0CF9950A41ACF9462357CD4A703CE4CE0306D3CA0A74D21E16BAB632958AF544059AB7E7E34F9CE82A8D7F
Malicious:false
Reputation:unknown
Preview:Mozilla Public License Version 2.0..==================================....1. Definitions..--------------....1.1. "Contributor".. means each individual or legal entity that creates, contributes to.. the creation of, or owns Covered Software.....1.2. "Contributor Version".. means the combination of the Contributions of others (if any) used.. by a Contributor and that particular Contributor's Contribution.....1.3. "Contribution".. means Covered Software of a particular Contributor.....1.4. "Covered Software".. means Source Code Form to which the initial Contributor has attached.. the notice in Exhibit A, the Executable Form of such Source Code.. Form, and Modifications of such Source Code Form, in each case.. including portions thereof.....1.5. "Incompatible With Secondary Licenses".. means.... (a) that the initial Contributor has attached the notice described.. in Exhibit B to the Covered Software; or.... (b) that the Covered Software was made a
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):313912
Entropy (8bit):6.062387036633833
Encrypted:false
SSDEEP:
MD5:5D3B7B04719E9C1038A117C779E96CD7
SHA1:69BAFC71BA6887C6CC771CAE23D9F37D04356FA2
SHA-256:905F2E7057999BB546A07EB12E0386CCA818DFAE2BC018F70C21204B6161D14B
SHA-512:A14115114FCE26FF53ADF54C053EF8CAC4E3A37FF007325C62D929EBEA53231FF31B2E21D6734E51EF5F508BA8E4077E2DE53E4C087386E727C0A988FC614EAD
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......S..............p....E.....!$....E.....E.....E......r............]..................Rich...................PE..d.....c.........." ......... ...................................................... ....`.........................................P8..t,...d..@...............L&......8$...........+..T...........................p+..................P............................text............................... ..`.rdata..............................@..@.data...P"...........f..............@....pdata..L&.......(...t..............@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):18503
Entropy (8bit):4.602916384645227
Encrypted:false
SSDEEP:
MD5:BDDEDB773E17C5704ACA39EAC9F71FA4
SHA1:0C3529CB8DA338AB8BABC78B039F1F7D841F6EF8
SHA-256:8D795AEAC957C8B6556B2ACA5E0A5A8B0B3254365D488BC62E280CB3255D441A
SHA-512:E8FAC311334B505886E65CF2804223D1304C0A5E72F5E1BF8A09F9E76221B597696E762E613438D0286EA45FF57B22A29944E3BDA6198996EC4F1215B505FC14
Malicious:false
Reputation:unknown
Preview:NSS is available under the Mozilla Public License, version 2, a copy of which..is below.....Note on GPL Compatibility..-------------------------....The MPL 2, section 3.3, permits you to combine NSS with code under the GNU..General Public License (GPL) version 2, or any later version of that..license, to make a Larger Work, and distribute the result under the GPL...The only condition is that you must also make NSS, and any changes you..have made to it, available to recipients under the terms of the MPL 2 also.....Anyone who receives the combined code from you does not have to continue..to dual licence in this way, and may, if they wish, distribute under the..terms of either of the two licences - either the MPL alone or the GPL..alone. However, we discourage people from distributing copies of NSS under..the GPL alone, because it means that any improvements they make cannot be..reincorporated into the main version of NSS. There is never a need to do..this for license compatibility reason
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):681016
Entropy (8bit):6.3886073642424135
Encrypted:false
SSDEEP:
MD5:A2E7F1EE61772728DD62846716B7D648
SHA1:D7301402A8520B2FB57AED02998E2119D1336CE4
SHA-256:069870711FCB32D34E551965E1E878D5194A711987AEBF5F55C7EC559ADFCCF6
SHA-512:61AEF2EC1F3D45F8A72C77C8DA5917F9E9E8995AC24D299CD4B2C6F7058E1E95091A2EB94083FB250753C0B23F1A16C61E9515F477E27DF6EF479A84D9BF5E66
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........3.I.]^I.]^I.]^@..^C.]^..\_K.]^,.\_J.]^..X_E.]^..Y_A.]^..^_J.]^..\_A.]^I.\^|.]^..Y_..]^..]_H.]^..^H.]^..__H.]^RichI.]^........PE..d...6..c.........." .....z..........T...............................................Cs....`..............................................p...........`...............@..8$...p.......A..T............................A...............................................text....x.......z.................. ..`.rdata..&........ ...~..............@..@.data...............................@....pdata..............................@..@.rsrc........`.......8..............@..@.reloc.......p.......:..............@..B................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):443448
Entropy (8bit):6.37753044434251
Encrypted:false
SSDEEP:
MD5:4164B7A423BAF7BCD839D3DE98F6C413
SHA1:CAAC9C687A90C516B88FAF2FECE580EEE31697F8
SHA-256:2F5CA3EE805760F136E84A3081FD2B371B2EF6BA0AE79832A3AE3AA2EC28BEDF
SHA-512:15A03B4ED0CECECE2236E74F3EB3A61F995BC3E18497D5D30A6E938CB3625371AE84F0FDA924D7BACF95FBE7ED3C48BE255ECE23AF80ACF2FB00E226A98F9950
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........HD$.)*w.)*w.)*w.Q.w.)*w.A+v.)*w.O+v.)*w.A/v.)*w.A.v.)*w.A)v.)*w.@+v.)*w.)+w.)*w.@.v.)*w.@*v.)*w.@.w.)*w.@(v.)*wRich.)*w................PE..d...9..c.........." .................................................................I....`.........................................p...P...............................8$.......(......T............................................0...............................text............................... ..`.rdata.......0......................@..@.data..............................@....pdata...............b..............@..@.rsrc................t..............@..@.reloc...(.......*...v..............@..B........................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):190520
Entropy (8bit):6.331568372115623
Encrypted:false
SSDEEP:
MD5:66B1DA60E5F9ECB94E8BBBABA67F312E
SHA1:06B71BCBAF0D8946D943A7786BA86B2BF5DFC159
SHA-256:73F4696A58A7EBE7CB58EF72628D102D8360257E4EDB1F559581C2C6ED092380
SHA-512:C2A0B79A62033CF0746DEA0A5B16B593981D6F13A09AC8A6AE243C882CE7707307AC85BCB9A3ACE4AA6B802689C23F0E91FAA99868433F3BFFCC37A48D52BA4D
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........v............oI............q.....$............................~.............~......~......~%.....~.....Rich............................PE..d......c.........." .....f...f......T.....................................................`.............................................<.......................x.......8$...........W..T............................W...............................................text....d.......f.................. ..`.rdata...-...........j..............@..@.data...............................@....pdata..x...........................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):32312
Entropy (8bit):6.394152708740677
Encrypted:false
SSDEEP:
MD5:086A9AF14F66BE19045FCAC136BC65D2
SHA1:8DF41BF78CBFB390B1EA542143664A612F419594
SHA-256:0E680DB178BE3E10801A3F4B57A17D953528D78378AE088F91B0E8D21635C602
SHA-512:A9B71B23755F08D26B8400257EB747B4D9439D7411A19CB811F163D91514D8C706EA9E3CA774FDB2431D782A9717BC51DA2460A4CE4F917D6062B641B04F8224
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Vz..Vz..Vz.._...Pz......Tz..3...Tz......\z......Qz......Wz......Uz..Vz..yz......Xz......Wz....q.Wz......Wz..RichVz..................PE..d.....c.........." .....4...".......:....................................................`.........................................@\.......`.......................Z..8$......,....U..T...........................PV...............P..x............................text....3.......4.................. ..`.rdata.......P.......8..............@..@.data...(....p.......N..............@....pdata...............P..............@..@.rsrc................T..............@..@.reloc..,............X..............@..B........................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):27192
Entropy (8bit):6.336451818181687
Encrypted:false
SSDEEP:
MD5:1770D3370480CB896B177441D03C797D
SHA1:5093CB797CE1B7EA536C36540BDA2210779A3FFF
SHA-256:4FB56BF12DD3BF5C2A82ECCE8FD3590C5C15B674AF4925718BE6D240D22116AD
SHA-512:A763FF708E30522DF9F7A247D40728FDC35BA3E2B218470474914C14C8C5E107B440F2D5B39F14D4AA3F4402B3C0FCD41EDCFF8C05498728ED48C4A57B8702E0
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}...9..B9..B9..B0.(B;..Bk.C;..B\.C;..Bk.C3..Bk.C>..Bk.C8..B..C:..B9..B...B..C:..B..C8..B..DB8..B..C8..BRich9..B........PE..d.....c.........." .....$..........8)....................................................`.........................................pJ..,....M..d............p.......F..8$......4...@D..T............................D...............@...............................text...S".......$.................. ..`.rdata.......@.......(..............@..@.data...8....`.......:..............@....pdata.......p.......<..............@..@.rsrc................@..............@..@.reloc..4............D..............@..B................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):178232
Entropy (8bit):6.1729749326752765
Encrypted:false
SSDEEP:
MD5:E0CCF29A98EBB0108E6B901B44F67AA8
SHA1:581823A5C0EC39FD7B9348E62344D0EAAFAC0C69
SHA-256:DE42806070E446DD2C530212DAA7FBB297B487347428AE0195C34E4CE8FDA1DC
SHA-512:C28CAF0C2C970D447DEB87ADB0B16FE6BA6BA605C62A8817CE23B15A7E043C96DA194784D50F59E93F02B95C82EB66FEF99E9D22CDE91C7F210348813D9C8D17
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........MM..,#.,#.,#.T..,#..D".,#..J".,#..D&.,#..D'.,#..D .,#..E".,#.,".O,#..E'.,#..E#.,#..E..,#..E!.,#.Rich.,#.........................PE..d...9..c.........." ................T...............................................g.....`.........................................P?......LY...................(......8$..............T............................................................................text............................... ..`.rdata..^...........................@..@.data...H............b..............@....pdata...(.......*...f..............@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):326200
Entropy (8bit):6.409587385550177
Encrypted:false
SSDEEP:
MD5:DE7505EB9884AE038AFD529CC2149582
SHA1:C5946D52912D61BD843CCEFEC5CC241B46453F43
SHA-256:63A623E9DA3FDB71C60040B6004320F0D7B3734D6F07C170F5D92DF5D5627CB3
SHA-512:B864DA5B08F094AEB7EAAC3861F3CB9C9FC062D68FC40CD8D62CD5B0E4DE83048624BD70CD9FE9784020DC41A31136BD17999A80DCEF826BC70CD5C90F2DB62E
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........p...#...#...#.O#...#..."...#..."...#..."...#..."...#..."...#M.."...#...#D..#M.."...#M.."...#M.##...#M.."...#Rich...#................PE..d...2..c.........." .........@......T........................................ ......I.....`..........................................}..P....~..@...............8=......8$......@.......T...........................@................................................text...s........................... ..`.rdata..0...........................@..@.data...............................@....pdata..8=.......>..................@..@.rsrc...............................@..@.reloc..@...........................@..B........................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):936504
Entropy (8bit):6.515127046470251
Encrypted:false
SSDEEP:
MD5:4E31AC2DC4E3BE97B6E3CE8F6030FD0B
SHA1:240980A21C04C9381DE857E6CE4B89A80B542A02
SHA-256:8D3FBBCC17AAD5903D222040482878773F409E7F6C7DC80B424D3138DFE8DE59
SHA-512:C592198FCCEECCC08E69F021268D1FFB2D1BA51B3C6906236433FE8E7B70152621547C42845C9CF5ECBEFBF050CB6DC6B3D6A60CDBE4BD3B7ED38919C23F5BC5
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......f!.."@."@."@.+8|.*@.p(. @.p(..@.p(.*@.p(.!@.G&.!@."@.O@.).#@.).#@.).#@.Rich"@.........................PE..d......c.........." ................D........................................`............`.........................................P;..<#...^.......@...............&..8$...P..t...0...T...............................................h............................text............................... ..`.rdata..^...........................@..@.data....=...p...4...\..............@....pdata..............................@..@.rsrc........@......................@..@.reloc..t....P......................@..B................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):406072
Entropy (8bit):6.388632247404637
Encrypted:false
SSDEEP:
MD5:9D8A9480953EFFEF0EAB1B3550409A99
SHA1:64EDA50A880FA94FA39F11D038DC5A11A5C08A91
SHA-256:6532E93FDCDA87A0C8D6815F14FC8CA365F7E86364A07E7AD2A19E28EABD3F7A
SHA-512:DA61C724353C35F5CE94B06801C682AA51BFB12529ACEED0ED7D24AA4FEB2F0549BF33FC0079EAD08A170E952E46C1151B58DE29F69CA32647CE34F2FF57CDFA
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......'.Hc...c...c...j.\.e...1...a.......`...1...h...1...k...1...`.......k...c...G.......H.......b.....0.b.......b...Richc...........................PE..d...9..c.........." .....^..........T........................................`......=+....`.........................................P...|...........@...........B......8$...P...... /..T............................/...............p..h............................text...c\.......^.................. ..`.rdata...U...p...V...b..............@..@.data...............................@....pdata...B.......D..................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):6207368
Entropy (8bit):7.636749765782432
Encrypted:false
SSDEEP:
MD5:D9AE1ABA82F5AE0BEE922C34BCA5B685
SHA1:16E20142C89A3D0A3EB646BDC2E31C3C4C1334CB
SHA-256:E9A68380428C7C58C21D7A8CEBBCD7A794880BC85941BBFCE4D190C1F9E370F0
SHA-512:B6880CD66027B58FD1633B7A12A1C5CD4DFB9DD1B600536DA6F6E7005B0F067527B7C0D99B278C452A748008C34A9A5CA2B34F63EBE657556C21C7095DC257D9
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......f..................]...........^.. ... ^...@.. ........................^.....x.^...@.................................d.^.W.... ^.X.............^..%....^...................................................... ............... ..H............text.....].. ....]................. ..`.rsrc...X.... ^.......].............@..@.reloc........^.......^.............@..B..................^.....H.......l9..(A......3....z...]..........................................0..%.........&(....~....(......r...p(....(....&*....0..e...........(....,.....+....,....I(.....r...p......%........(........%...rA..p......%...o.....(..........+..*...........=>.!.....0...........r...p......%......(..........(.....(........(.........,....i......,....].(...........,..r...p(...+(........9.."...r...p......%...o.....(.........r5..p(...+(.......+..*......*.Fp.".....0..x...........(.........,.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (console) x86-64, for MS Windows
Category:dropped
Size (bytes):3456392
Entropy (8bit):6.348224858118605
Encrypted:false
SSDEEP:
MD5:C3E158FC16E8AAF2BDF8CF73140C5C67
SHA1:69BC5E72D9E9C930710B6206EA948B4F000AAC2E
SHA-256:833CC2B77815FA472AA7C5D0611D646613F3712EF60422D3B44D916ED0DA043B
SHA-512:A52F59F216E91E2DB261C53D208A8C21296647971BB47A55C0FF31F77B97DD6F21AD5195603985864B04C9A2D7CABF923E0782F5192644217057DB3D1954ABD7
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$........Uj..4...4...4...R...4...R...4...R..x4..o]...4..o]...4..Z...4...\..N4...\...4...\...4...R...4...R...4...4...5..o]...4..o]...4...4...4..o]...4..Rich.4..........................PE..d....qf..........".......#..........S.........@..............................5.......5...`.................................................$.0......@4...... 2.......4..%....4..?...[+.T...................0]+.(...0\+...............#..............................text.....#.......#................. ..`.rdata...,....#.......#.............@..@.data.........1.......0.............@....pdata....... 2.......1.............@..@.rsrc........@4.......3.............@..@.reloc...?....4..@...X4.............@..B................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) Aarch64, for MS Windows
Category:dropped
Size (bytes):3444104
Entropy (8bit):5.89292298812713
Encrypted:false
SSDEEP:
MD5:E796C98F624A25591894E0C2BCC1C1DE
SHA1:DC0B9F3D46EFCA90A0A0E5DEB2DD8C06F5FAC40A
SHA-256:F76957262E363E0F5247EB6A7BF1CF22618E178A6374F5E75A32A311D2F42653
SHA-512:A447B8FD79DAA2A42243AE13C0D2FB302AAB4A97F81783FCA5E659A064FCAB91E04D75DC9AD7C776D13D4797F87BC7357BDF8F0541AED1C7F016EAEC12F83FB7
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$........................).....<..................9....................9..........................9......9......9.......l....9......Rich............................PE..d....qf.........." ......$.........@.........................................4.......4...`A........................................0)/.x....)/.@.....1...... 0.8e...h4..%....4..'...*.T...................P.*.(...P.*...............$..............................text.....$.......$................. ..`.rdata...]....$..^....$.............@..@.data...D....P/......:/.............@....pdata..8e... 0..f..../.............@..@.rsrc.........1......:1.............@..@.reloc...'....4..(...@4.............@..B................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):3102088
Entropy (8bit):6.307831784402097
Encrypted:false
SSDEEP:
MD5:9D7AB651EBA49866DCD20CFA938C97FB
SHA1:816EF3ABB4F4A16C300284D090BE2094A48BF0B6
SHA-256:9125A194A07D812BE7653A3D7647880FF779D8902DEFC7404866519A5891E8EB
SHA-512:A3E900AEBD11A7118E06BE1F56B4EE0CE1D24103AED70CFD6095CCF25363E930273347B72FCF3145E8C80D5129489CA03EA3FF900D323C3F52619A0FA937BB9C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.......7...s.{.s.{.s.{...x.x.{...~..{..8..p.{.!.x.z.{.....n.{.!.~..{.!...P.{...r.y.{.....n.{...}.r.{...z.l.{.s.z.g.{...~...{...{.r.{...r.{.s..r.{...y.r.{.Richs.{.........PE..d...o.qf.........." .....&...6................................................/.....H./...`A..........................................).x.....).@....`,.......*......0/..%...p/.$+...i$.T...................Pk$.(...Pj$..............@...............................text....$.......&.................. ..`.rdata..Pb...@...d...*..............@..@.data.........).......).............@....pdata........*......**.............@..@.rsrc........`,.......+.............@..@.reloc..$+...p/..,..../.............@..B........................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:data
Category:dropped
Size (bytes):12162
Entropy (8bit):7.293890803747961
Encrypted:false
SSDEEP:
MD5:08FDB033450CDFB0E554ED184559B422
SHA1:FB56BC20719E10383DB763F455B9233BF5DDE6B4
SHA-256:3632A5F1132C569B16BDC8262F1EE70E6BA3A8BB66030F82A20D961B5181C9E4
SHA-512:DB2782C679251A7226BAA7E8BD18BCEF001A9F01151BCEE4F2E4E82A19ED95D4A9D794F0BC3B024B9141E390FF594FF94EC92368C457B8B208E759A4066A337F
Malicious:false
Reputation:unknown
Preview:0./~..*.H......../o0./k...1.0...`.H.e......0.....+.....7......0...0...+.....7.........(..M...*......230622213915Z0...+.....7.....0..G0..........)........CW1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...i.n.f...0....:........;..dXs..D..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...s.y.s...0... k......4..&j.M.....7.H...^7.r..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...i.n.f...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... k......4..&j.M.....7.H...^7.r..0.... .=....}-D.V....E.a.B/....S...V.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...s.y.s...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... .=....}-D.V....E.a.B/....S...V...E0..A0....+.....7......0.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:Windows setup INFormation
Category:dropped
Size (bytes):2778
Entropy (8bit):5.052072729086147
Encrypted:false
SSDEEP:
MD5:3C1A6520F3C779DE66EC05C9F99485BD
SHA1:02070082EC0129CE8AE5A8B4AEC0E315EDE54357
SHA-256:6BC6E4DB09F4D2349512266A0D4DF0DEC615F237B94807EDC9A25E3714729094
SHA-512:098C4D03D9730724C50D02BC8BCB182BDCC5C3CBFEBE4A1BB4508FEF53A732F43504F49ACB90D52BE278E32C38B69748268F836EB3881BE325C1E5D64B4BB94C
Malicious:false
Reputation:unknown
Preview:;-------------------------------------------------------------------------..; zapprd.INF -- Zscaler NDIS LWF driver..;..; Copyright (c) Zscaler Inc. All rights reserved...;-------------------------------------------------------------------------..[version]..Signature .= "$Windows NT$"..Class .= NetService..ClassGUID .= {4D36E974-E325-11CE-BFC1-08002BE10318}..Provider .= %Ntkr%..CatalogFile = zapprd.cat..PnpLockdown = 1..DriverVer = 06/22/2023,3.4.0.0....[Manufacturer]..%Ntkr%=Ntkr,NTx86,NTia64,NTamd64,NTARM64....[Ntkr.NTx86]..%zapprd_Desc%=Install, zs_zapprd....[Ntkr.NTia64]..%zapprd_Desc%=Install, zs_zapprd....[Ntkr.NTamd64]..%zapprd_Desc%=Install, zs_zapprd....[Ntkr.NTARM64]..%zapprd_Desc%=Install, zs_zapprd....;-------------------------------------------------------------------------..; Installation Section..;-------------------------------------------------------------------------..[Install]..AddReg=Inst_Ndi..Characteristics=0x40008..NetCfgInstanceId="{0014E1B1-5DFF-4BD7
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):52224
Entropy (8bit):6.4301128849703835
Encrypted:false
SSDEEP:
MD5:C6FB212118EF67278EAC9DABBF562ADE
SHA1:637FA7DA8C342915D7F68989668017064745FACA
SHA-256:9DD49A112515D42D1622E2EAB33B6F58638D3DE53C083574CA3EA3707C8E2FDA
SHA-512:E74A99C6820F497B773CC0EE9FDA653C419B583E64F1C4ADF919E4A377A284D6A5C0B89FC6F2C5D3192B1D1C1EF78488A212DB64184432D8E0DDF31F51B7E718
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........j.K..x...x...x...y...x..oy...x..o|...x..o{...x.#b|...x.#b....x.#bz...x.Rich..x.........................PE..d......d.........."............................@.....................................j....`A................................................X...<........................(......(...0...8...........................p...................@............................text...rn.......p.................. ..h.rdata...............t..............@..H.data...............................@....pdata..............................@..HPAGE....6........................... ..`INIT....4........................... ..b.rsrc...............................@..B.reloc..(...........................@..B........................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:data
Category:dropped
Size (bytes):12162
Entropy (8bit):7.294613038823455
Encrypted:false
SSDEEP:
MD5:BE1EDD959359DD6C8EC84B566D9F58EC
SHA1:6C38394F929EFCC70C59A70514BE5BA062B40721
SHA-256:B1BC5CED3A4D3D255DF9691BF4CF60CDF26F88996A9818BD10EE93E08A3283AC
SHA-512:83480D0541FDB37C9AB9B638D26759C5B3EC534755654575045FAD6A9C485D78AE8BDCD7CE24106FB868158FA8E13ED16C7D7C2D1AF416B13630E7A2F4C300A1
Malicious:false
Reputation:unknown
Preview:0./~..*.H......../o0./k...1.0...`.H.e......0.....+.....7......0...0...+.....7.........J..N..A.5`.4..230622213915Z0...+.....7.....0..G0..........)........CW1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...i.n.f...0.... .....?..$...W...,....g.O...01..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...s.y.s...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... .....?..$...W...,....g.O...00......./E......c...FZ.!.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...s.y.s...0... k......4..&j.M.....7.H...^7.r..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...i.n.f...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... k......4..&j.M.....7.H...^7.r.....E0..A0....+.....7......0.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (native) Aarch64, for MS Windows
Category:dropped
Size (bytes):53760
Entropy (8bit):6.50230837922353
Encrypted:false
SSDEEP:
MD5:F77155FAE3E8EFCE5D6FC85478D6D80E
SHA1:13F02688635E849FD2D6A624E1DEB44AEC829D0E
SHA-256:34904D9AD42E6DBDEDDED02136476446A81FC4B7F94F7001DE6D11E6DBAD5EF1
SHA-512:CBD75BFD377468F46AAAF8FC652DEC827F3A5CEF8D2907D5E5AA887FE7861E150AB678BF066B969D81CCBDC6B815E9667E15E2311E1366D4D3AA863D299C807D
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............................................B.....B.)....B.....Rich...................PE..d......d.........."................. ..........@....................................t?....`A......... ..........................................P........................(.......... ...8...........................`...................P............................text....y.......z.................. ..h.rdata...............~..............@..H.data...............................@....pdata..............................@..HPAGE................................ ..`INIT................................ ..b.rsrc...............................@..B.reloc..............................@..B................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:data
Category:dropped
Size (bytes):12160
Entropy (8bit):7.297321994130019
Encrypted:false
SSDEEP:
MD5:5500D1FA00EC5A7C5E94CF068DD163DD
SHA1:A8CA4456DE29805209473EF057C6EF42C7E44DAB
SHA-256:8ED39D88D8C314F35786B71E49C041BE45C6075F44703515DA4C91AFBEE598D5
SHA-512:F1B043A57F7B43989B5E4ACD6F1BE56281C9BA282B57B18CCA79F81255AD2FBBC0A39F986FBE0F85BF6D88E70F9D59E755E1F835F66E128F42A50DEC0E3121BA
Malicious:false
Reputation:unknown
Preview:0./|..*.H......../m0./i...1.0...`.H.e......0.....+.....7......0...0...+.....7.....5...C_.G...h.....230622213915Z0...+.....7.....0..G0..........)........CW1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...i.n.f...0....a.d.M....r.T.....B.m1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...s.y.s...0... k......4..&j.M.....7.H...^7.r..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...i.n.f...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... k......4..&j.M.....7.H...^7.r..0.... .@?.>]....p....^.\..._...3>.*...1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...08..+.....7...1*0(...F.i.l.e........z.a.p.p.r.d...s.y.s...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... .@?.>]....p....^.\..._...3>.*......C0..?0....+.....7......0.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):44032
Entropy (8bit):6.819618701343495
Encrypted:false
SSDEEP:
MD5:F54E61896615395DE82972EBE3D6474C
SHA1:3BFE7B816C2023F0AAA81E2A0EAA05155A928953
SHA-256:58B22F2D84AFA3755F86A1B3817B4CFEE6470589283D97F7F8E2915BBE247BC1
SHA-512:2A6FAD7853B97CF505709FBC063CD3D8DC008EBECEA30D990AA7553F90E86C40D76C374236B8BE9FF6473E38459B1A870A7A4C9E4861D7487BFEB6D32F986000
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......*...n...n...n...n...%......i......m......i......`.....D.o......o...Richn...................PE..L......d.................n.......... ........p....@.......................................@A................................l...P........................(..........Pr..8............................r...............p..8............................text...H[.......\.................. ..h.rdata.......p.......`..............@..H.data................f..............@...PAGE.................h.............. ..`INIT....x............j.............. ..b.rsrc................z..............@..B.reloc...............~..............@..B........................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):4093320
Entropy (8bit):6.602195145313947
Encrypted:false
SSDEEP:
MD5:F9BB669A809694C1E085E963610A4866
SHA1:02A34B9B17F8FF0D50E7947645ED251C30F970E2
SHA-256:F621BA017658918E18C58B24A7676FD9846D0FE90F729377C37BCF92A4F74AC7
SHA-512:D560965099A9D6F74D89B75CC00F13F4D9F2333D87C4104DD60379497B47539CB359203CD84E2C18549BB4F7AD4700B2970E6BD3E43323A86C4686E21E036778
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$........~.....@...@...@.y.A...@.y.An..@;.@@...@.w.A...@.w.A...@...@...@.v.A]..@.v.A...@.v.A...@.w.A...@.w.A1..@.y.A...@.y.A...@.y.A...@...@t..@.v.A...@.vx@...@...@...@.v.A...@Rich...@........PE..d....qf..........".......%....................@............................. ?.....z.>...`...................................................4.......>.......:......P>..%....>.d.....0.p...................@.0.(...P./...............%.......4.@....................text.....$.......$................. ..`fipstx........$.......$............. ..`.rdata........%.......%.............@..@.data.........4.......4.............@....pdata........:......,:.............@..@.didat..H.....<.......<.............@...fipsrd..`+....<..,....<.............@..@fipsda..(u....<..v...4<.............@...fipsro......`=.......<.............@..@.rsrc.........>......J=.............@..@.reloc..d.....>.......=.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:B3D62A19C2166086556804FB7659651F
SHA1:360ABB68EADD31598DE6ECF3D9A091BEC0F7C942
SHA-256:A674A23D330EE55E21A84911A650D9EEFD8944AC285599ED1EB2302646B4E5C8
SHA-512:D073C481A65B686B6AE5CA9B2C706FB5B7239AD9D2807DE19A36F9A6C1700576FAEA0472047D2CD06459C7320C8F0489D1FF957CE949BFD3D31E460003D38E85
Malicious:false
Reputation:unknown
Preview:Log started 11/12/2024 at 03:19:43..Preferred installation mode : win32..Trying to init installer in mode win32..Mode win32 successfully initialized..[03:19:46] Windows OS Name: Windows 10..[03:19:46] Windows OS Version: 10.0..[03:19:46] WindowsBuildNumber: 19045..[03:19:46] Installer PID: 7048..[03:19:46] Package Version: 4.4.0.309..[03:19:46] Package Architecture: x64..[03:19:46] Installed Package Version: 0.0.0.0..[03:19:46] Installed Package Architecture: 0..[03:19:46] Installed Package Location: ***unknown variable installedlocation***..[03:19:46] Processor_architecture: AMD64..[03:19:46] Package Version Split: 4.4.0.309..[03:19:46] Installed Version Split: 0.0.0.0..[03:19:46] isDowngrade: false..[03:19:46] is32to64bitUpgrade: false..[03:19:46] 3.4 autoUpgrade scenario check: Skipping as installed version is 0.0.x..[03:19:46] enableFipsOld: ***unknown variable enablefipsold***, Zscaler-windows-4.4.0.309-installer-x64.exe..[03:19:46] enableFips: 0..[03:19:46] Installed version of Z
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:ECA7B648F8E2456ADF905BBBF5AC0DE9
SHA1:3D818C4039E40FE046EEF4B620FC938E3DCDAD89
SHA-256:62266BE8FFE098FF509E595CA55E50F1C82586D844CC4A0E589665ED1499BD3B
SHA-512:99FCAD59D30C788BA1E61A2C30D7EB171E1D338626D4EEABC57FF65F16A665077739568C0BF9C7AD118A3992316D7D59D81F64E0627CA0A058A7FA849BDA458D
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.......................B...,-..@............@...............................-.....5Zr...@... ......................................@*.n....P*..O....*.x.....'.8....:q..%...p-. `.......................... .*.(....................b*..............................text....A.......B..................`.P`.data........`.......F..............@.p..rdata.......`"..0...@".............@.p@.pdata..8.....'......p'.............@.0@.xdata...Q....(..R...x(.............@.0@.bss.....?....*.......................p..edata..n....@*.......).............@.0@.idata...O...P*..P....).............@.0..CRT....h.....*.......*.............@.@..tls....h.....*.......*.............@.`..rsrc...x.....*...... *.............@.0..reloc.. `...p-..b....,.............@.0B................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:data
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:2CF484F2EB1EB50BF4F1F5711DE27A2D
SHA1:E20E3CEC57328F9CAC295BB0FF7D325081BC0138
SHA-256:929228ED11F36D0452C1DA4D118E11D05D7C15DBA22046FD9EAD57962AFC1D69
SHA-512:99A9E29F1AC766606921B6EAE086BBCA7A2229560D3B6CDAB54B372767838D8E031831231A902C1976C8212CD20B4C6B424994B3ABCE0AAF2B44091A94FC5B95
Malicious:false
Reputation:unknown
Preview:..]mo.H........I[.K.U.A..7..UO.*......!9r..~..z...Pc.c..~.}..........iB..>>.l.....{Mo..my..%i;...)...E...{d..#....j...ql..........hiI....Y.M<.o.55..+...PR8.....Q..3Sz..;...dI}..K.Bg"G...G8.)......!g.zP..}U.v..y.|SI.7t.$c.P.f..A"37..(...q.M..t5..c..h,......=.{..p..wM.wJ.L..n..).8....\.<#..e..W..6u...=..X.m..zU.[.`{.6.H=...@.v.l..(`e.........'..DF.q............z...s.>b..&.e.=K.C..}.b.xD.qn ^.}..../8.....#.....lw....9]....e..:.....;.l.....<>. .j.L.[S.....0....CPb.GP.x.U.c...*.q.....U..|.SR.tS..8_UF..3.'JfW.:z.^..//#.r.W.Z..c(R?..].....i:./....u.(+.SoV.%.A.yT....Q......w*Z....eVf.;pG..V..... .....)$...{Cy......8x#>.wl+/....c....A=.w.c....y.").7....[>ky.v.(/....}...s9;.9j.z:.`.P.Ps0jU.Pxr.U?]Z.8....T.5..Q,.CMY.>.TU.C9.J..{.53.p.xY-g\,[\l....Z.elN.../a.y..J\GKo..X.._.P. ..1a-...B....*.#..".f.v..\:....`tWe32N.........K.Y&.v2......Q.>..Qfm.....io..d......\Vax.R6..0..G..._*..._.4.#....N[.c..x}m..7..zW...2`)lW.R1.. >@........f ..bKpu.D6.Tw.sn..(
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:data
Category:dropped
Size (bytes):37274
Entropy (8bit):7.993026153130452
Encrypted:true
SSDEEP:
MD5:2CF484F2EB1EB50BF4F1F5711DE27A2D
SHA1:E20E3CEC57328F9CAC295BB0FF7D325081BC0138
SHA-256:929228ED11F36D0452C1DA4D118E11D05D7C15DBA22046FD9EAD57962AFC1D69
SHA-512:99A9E29F1AC766606921B6EAE086BBCA7A2229560D3B6CDAB54B372767838D8E031831231A902C1976C8212CD20B4C6B424994B3ABCE0AAF2B44091A94FC5B95
Malicious:false
Reputation:unknown
Preview:..]mo.H........I[.K.U.A..7..UO.*......!9r..~..z...Pc.c..~.}..........iB..>>.l.....{Mo..my..%i;...)...E...{d..#....j...ql..........hiI....Y.M<.o.55..+...PR8.....Q..3Sz..;...dI}..K.Bg"G...G8.)......!g.zP..}U.v..y.|SI.7t.$c.P.f..A"37..(...q.M..t5..c..h,......=.{..p..wM.wJ.L..n..).8....\.<#..e..W..6u...=..X.m..zU.[.`{.6.H=...@.v.l..(`e.........'..DF.q............z...s.>b..&.e.=K.C..}.b.xD.qn ^.}..../8.....#.....lw....9]....e..:.....;.l.....<>. .j.L.[S.....0....CPb.GP.x.U.c...*.q.....U..|.SR.tS..8_UF..3.'JfW.:z.^..//#.r.W.Z..c(R?..].....i:./....u.(+.SoV.%.A.yT....Q......w*Z....eVf.;pG..V..... .....)$...{Cy......8x#>.wl+/....c....A=.w.c....y.").7....[>ky.v.(/....}...s9;.9j.z:.`.P.Ps0jU.Pxr.U?]Z.8....T.5..Q,.CMY.>.TU.C9.J..{.53.p.xY-g\,[\l....Z.elN.../a.y..J\GKo..X.._.P. ..1a-...B....*.#..".f.v..\:....`tWe32N.........K.Y&.v2......Q.>..Qfm.....io..d......\Vax.R6..0..G..._*..._.4.#....N[.c..x}m..7..zW...2`)lW.R1.. >@........f ..bKpu.D6.Tw.sn..(
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:ECA7B648F8E2456ADF905BBBF5AC0DE9
SHA1:3D818C4039E40FE046EEF4B620FC938E3DCDAD89
SHA-256:62266BE8FFE098FF509E595CA55E50F1C82586D844CC4A0E589665ED1499BD3B
SHA-512:99FCAD59D30C788BA1E61A2C30D7EB171E1D338626D4EEABC57FF65F16A665077739568C0BF9C7AD118A3992316D7D59D81F64E0627CA0A058A7FA849BDA458D
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.......................B...,-..@............@...............................-.....5Zr...@... ......................................@*.n....P*..O....*.x.....'.8....:q..%...p-. `.......................... .*.(....................b*..............................text....A.......B..................`.P`.data........`.......F..............@.p..rdata.......`"..0...@".............@.p@.pdata..8.....'......p'.............@.0@.xdata...Q....(..R...x(.............@.0@.bss.....?....*.......................p..edata..n....@*.......).............@.0@.idata...O...P*..P....).............@.0..CRT....h.....*.......*.............@.@..tls....h.....*.......*.............@.`..rsrc...x.....*...... *.............@.0..reloc.. `...p-..b....,.............@.0B................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Category:modified
Size (bytes):7430168
Entropy (8bit):7.508473504134782
Encrypted:false
SSDEEP:
MD5:ECA7B648F8E2456ADF905BBBF5AC0DE9
SHA1:3D818C4039E40FE046EEF4B620FC938E3DCDAD89
SHA-256:62266BE8FFE098FF509E595CA55E50F1C82586D844CC4A0E589665ED1499BD3B
SHA-512:99FCAD59D30C788BA1E61A2C30D7EB171E1D338626D4EEABC57FF65F16A665077739568C0BF9C7AD118A3992316D7D59D81F64E0627CA0A058A7FA849BDA458D
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.......................B...,-..@............@...............................-.....5Zr...@... ......................................@*.n....P*..O....*.x.....'.8....:q..%...p-. `.......................... .*.(....................b*..............................text....A.......B..................`.P`.data........`.......F..............@.p..rdata.......`"..0...@".............@.p@.pdata..8.....'......p'.............@.0@.xdata...Q....(..R...x(.............@.0@.bss.....?....*.......................p..edata..n....@*.......).............@.0@.idata...O...P*..P....).............@.0..CRT....h.....*.......*.............@.@..tls....h.....*.......*.............@.`..rsrc...x.....*...... *.............@.0..reloc.. `...p-..b....,.............@.0B................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):5597576
Entropy (8bit):6.534543708175984
Encrypted:false
SSDEEP:
MD5:BA783DEC4A0BBBA3619648B2853D68F1
SHA1:F02BD85CB52D24560F18C545C9B6D0499BCFE7E1
SHA-256:09942DC5C675A134DD6AADCBBC8F47F27883089AD436FC27A77654111197F5A5
SHA-512:4FB82F67D3E54277013BA31840BCCC57B58F67BFB2B1A2A8D4970C0C4B62A448068F9AD0B4C42AEB872D00BFE6EF8824D28C515EAEC62DE300402117CD17FA59
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$.......Y.0..O^..O^..O^.x)]..O^.x)[..O^....O^.O']..O^.{'Z.qO^..O^.9O^..&Z..N^..&Z..O^.O'Z.;O^..&[.^N^.O'[..O^.x)Y..O^.x)Z.8O^.x)X..O^.x)_.:O^..O_..N^..&W.RO^..&...O^..O..O^..&\..O^.Rich.O^.........PE..d...A.qf..........".......4... .......(........@..............................V.......U...`..................................................?J.,.....T.......P......DU..%...pU.....P.B.p.....................B.(.....@...............5......=J.@....................text...L.3.......3................. ..`fipstx........4.......3............. ..`.rdata..`k....5..l....4.............@..@.data....k...pJ......XJ.............@....pdata........P......HP.............@..@.didat........S.......R.............@...fipsro........S.......R.............@..@fipsda...u...0T..v....S.............@...fipsrd..`+....T..,....S.............@..@.rsrc.........T......&T.............@..@.reloc.......pU.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):14265224
Entropy (8bit):6.373361109565878
Encrypted:false
SSDEEP:
MD5:90AFC50FD2BB415992B218E20BB303F2
SHA1:436E0D842782C562F8BA8568654EA6B4B0E7B8B2
SHA-256:0025AF04768024740939E122D10435E9ADE67BE82DF7276D7F42E340D5F6D2FC
SHA-512:B1F7E5C5B3D3334FD07ACF1D133AF622C0CE387EF77B5AE38370D0D230625A4B56BA4F36863245237F9315FA5C4223CC59C04152B3A4A5850F0400D5EBF52D3D
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$.........q.........................k......................A...'..........................................-...............................................3...........................Rich............PE..d.....qf..........".........fI.......G........@..........................................`.......................................................... .......`...H.......%......D......T...................X..(...p..................@...x...`....................text...|.......................... ..`fipstx............................. ..`.rdata..\.6......6................@..@.data....@..........................@....pdata...H...`...J...v..............@..@.didat..............................@...fipsro..0...........................@..@fipsda...u...p...v...d..............@...fipsrd..`+.......,..................@..@.rsrc........ ......................@..@.reloc..D.......
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):428424
Entropy (8bit):5.597313009388592
Encrypted:false
SSDEEP:
MD5:EAB68876AD66EECB7A4D1C6E356F8A33
SHA1:28BCB922503F6808CDDC2ED5A53BA6BBC31D15D3
SHA-256:5B1F9471AE84FDB7B8FF5BD63899925526FF66C191A49D3013B46A2B115939A1
SHA-512:B3E23EE4EA43CC500BB66D6CBB2A19FA8270224AAE5E9B9942FE3DEBA1CACD53DF4EA03264436D1210A44103389EB49ECC5145C1DF1FCBC3C7FC5804997D1366
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....W.c.........." ..0..\...........{... ........... ...............................J....`.................................4{..O....................d...%...........y............................................... ............... ..H............text....[... ...\.................. ..`.rsrc................^..............@..@.reloc...............b..............@..B................h{......H...............................|y.......................................0..G.........((...}.......}.......}.......}.......}......|......(...+..|....(*...*..0..I..........(!....o.....8..o+... .@..3.r...p.s,...z.z..o+... ....3.r}..p.s,...z.z*........................,.......0../........{....- ..{....t....}.......r...p.s-...z.{....*................."..}....*....0../........{....- ..{....t....}.......ry..p.s-...z.{....*................."..}....*....0../........{....- ..{....t....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):43400
Entropy (8bit):6.319951294962853
Encrypted:false
SSDEEP:
MD5:E7FC0D5075ADA3E8BBFEF06D91864CDA
SHA1:3E972BFB82BA5964EF6949D79B07B0A2AD1469E7
SHA-256:B68BED24C7AAC3B8FCA391AAEE2B1A95AF09078813CDB7A128570E00F50D1A15
SHA-512:49015CE9CAD4B9D4F0934832E6E3F99BBCC70060C10E4C18307C079A1E12DF9E16F0F002AF9455F518FD922110CB0E1436C679D0B3C025E1BEA1DDAB553EDCD1
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..|............... ........... ....................................`.....................................O........................%.............8............................................ ............... ..H............text....z... ...|.................. ..`.rsrc................~..............@..@.reloc..............................@..B.......................H........@..dU..............@...L.........................................(....*F.~....(....tT...*6.~.....(....*F.~....(....tT...*6.~.....(....*F.~....(....tT...*6.~.....(....*F.~....(....tT...*6.~.....(....*F.~....(....tT...*6.~.....(....*F.~....(.........*J.~..........(....*6.t.....}....*..0..d........{....-K.(....-..(....-..(....-..(....,+..(.....(.....(.....(.......s....(....}.....{....%-.&.(...+*.0..C..........(....-..(.......(....,'.o.......(....o......(.......(....o ..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):703880
Entropy (8bit):5.950486269814407
Encrypted:false
SSDEEP:
MD5:2FBBF09F6E5CB97A7C48320A8828C7D9
SHA1:3170E93B1EE4112FBDCA76B89FEEB2E7D31E654A
SHA-256:4CDFB75C336A81555E0548F1B633A921CA15777E4C20AE0080D726E5CDBDC49B
SHA-512:F7C122572F3B5542D22591AD8AD29F5098C24FDBD40A2DC6658ABE45595CE35F5040306DFF83FAA11B505C03035815AA7AF3AB81225F2E6F730596641EA0F043
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0.................. ........... ..............................7.....`.....................................O........................%.............T............................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B.......................H........{...,..................d.........................................(....*..(....*^.(...........%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*..{....*..(....*..(....*:.(......}....*..{....*.(.........*....}.....(......{.....X.....}....*..0...........-.~....*.~....X....b...aX...X...X.+....b...aX...X...2.....cY.....cY....cY...{...._..{........+,..{^....3...{]......(....,...{]...*..{_.......-..*...0...........-.r...ps....z.o......-.~....*.~....X...+....b..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):158088
Entropy (8bit):6.1738076161951065
Encrypted:false
SSDEEP:
MD5:673A9182E1113A0C388CE33BC11D6BAA
SHA1:54C4BBBF53962172030230C776BFB4A1688481B6
SHA-256:D414FB0D8C4369D788F045E8B45487749C75513867580AB3BAF31AE655E1C8B1
SHA-512:8446C4C71DC7A5EEC447E60D7176E62BA8C0670F2B0A933C705B7C6F77A6614B28A3E547869468128117FA1F9E647CAD6A7A61C5424D4832BAC4286E7C63399B
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...6..c.........." .....B..........`D..............................................Zb....`A....................................................(............@.......D...%..........4...T.......................(....a..8.......................`....................text...5A.......B.................. ..`.rdata.......`.......F..............@..@.data........ ......................@....pdata.......@......................@..@.00cfg..(....`......................@..@.gxfg...p....p......................@..@.retplne\................................tls.................0..............@....voltbl.D............2.................._RDATA...............4..............@..@.rsrc................6..............@..@.reloc...............<..............@..B........................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):1223048
Entropy (8bit):5.099887432387854
Encrypted:false
SSDEEP:
MD5:C111AC1B829634076F00F5ED09C314E1
SHA1:B05FBF897F7C0B4F087ED919EC7AF9C673D211B3
SHA-256:AB34914270E21C9A610DA71FB6868D4B1302E35D984AF29D4DC9FF23A1088E47
SHA-512:5FF8CCBB20E4C2377E2C8C04A61001E1F2D543E58674BE5916C230A5969871152DF2A50E5A65794B0A3794252B0A16812E2EC24DF46535F9E43E7D5EAB3B880C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................."...0.................. .....@..... ..............................Ah....`...@......@............... ...................................................%..........h...8............................................................ ..H............text...^.... ...................... ..`.rsrc...............................@..@........................................H.......8n..p.......j....F..............................................Br...p(....(....*....0...............(.....(......( ...*.(....(!...*..(....*..(....*..(....*..(....*&...(....*...0..D.......r...p.r...p..(....-...( ....o!... _|..1... _|..o"........(#.....&..*........@@........($...*N~....,.(....*(....*N~....,.(....*(....*V~....,..(....*.(....*V~....,..(....*.(....*V~....,..(....*.(....*V~....,..(....*.(....*V~....,..(....*.(....*V~....,..(....*.(....*f~....,....(....*...(....*..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):2098568
Entropy (8bit):6.752490969459485
Encrypted:false
SSDEEP:
MD5:70271880E4C851B68574F76962C01D1E
SHA1:3C64C2548A9E42A1D85ED1808E26BF85694D719D
SHA-256:BA32E520B1504A81C5DA99B1D12C124FE820CB425EC40DD8261F40D61491BF9A
SHA-512:3485AA411448AEAD077FC84DF1332129EF49ED6EB5D1F5794D965CD2438E1ED35FFFBF47E077A92C2A484F3C1B873F8059F7DD3EA9E9D9C635E9D746335F0F11
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....qf.........."...0..*............... .....@..... ....................... ......\ ...`...@......@............... ...............................`...................%..........TG............................................................... ..H............text....(... ...*.................. ..`.rsrc........`.......,..............@..@........................................H.......HS..L.......O........R............................................{....*...Y...(+.....Y...(,...-..+..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(-...*...0..{........r...p}.....r...p}.....r...p}......}.....r...p}.....(-....r...p(.....r%..p(.....r-..p(......(......(......(.....r=..p(....*..0..w........r...p}.....r...p}.....r...p}......}.....r...p}.....(-.....(.....r%..p(.....r-..p(......(......(......(.....r=..p(....*..{....*N..}.....ri..p(....*..{....*N..}.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):14296456
Entropy (8bit):6.380717279569214
Encrypted:false
SSDEEP:
MD5:BB0F61FD41D8E04D0A0CCD8488A6F9A5
SHA1:414F23871EB8D74172C4BBB568101B2B2ABB2920
SHA-256:0236EE3305B2F40F217FC2D5CA6CD9CB88EC343838AAFEBBF523514C25FAA94D
SHA-512:9DD86C85ABDF58C3D9032D43023C12E75C8480D519C033B5AD3074B3CE28B4B4FD5471AA09B8E6CB31E3FA88CA85A6D41EC2C01CB97978E2AE3CCCABDEC40B70
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$.......13~.uR..uR..uR...4..xR...4...R...;..cR...:...R..uR..QR...;...S...;..jR...;..4S.....qR..':..|R..':..SR..':...R...4..tR...4..QR...4..vR...4..\R..uR..'P...;...R...;.tR..uR..tR...;..tR..RichuR..PE..d.....qf.........."......V....I.....0.O........@....................................v.....`..........................................................@..8................%..........@...T.......................(....................p......h........................text....].......^.................. ..`fipstx.......p.......b.............. ..`.rdata...W8..p...X8..Z..............@..@.data....,..........................@....pdata..............................@..@.didat...............j..............@...fipsro..0............n..............@..@fipsda...u.......v..................@...fipsrd..`+.......,..................@..@.rsrc...8....@......................@..@.reloc..........
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):5170568
Entropy (8bit):6.558664016414744
Encrypted:false
SSDEEP:
MD5:DE0FDEEF39389B9F61A11AF935706E91
SHA1:E4CBC11B03B02AA893DC470FF7F35F1073AC54F2
SHA-256:87C6B20ECE0BA3F824D02464CDA788D5085CE5CAFCAA3BBDCE4172063F330335
SHA-512:D295833282AD8B9705A9CC06EC5268C2C33092B13F1D53BC177957D169D73E2551504EBE650E405BCC5D32AEB01E3ECFBC363351D06AC5C801F7425A7C7FF82F
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$.......>...zk..zk..zk......wk......k....?.~k..(...sk.......k..zk..^k......j......ek......Sj..(...\k..(....k......{k......dk......{k......]k..zk..j......Jk......{k..zko.{k......{k..Richzk..........PE..d.....qf..........".......1...........%........@..............................O.....D.N...`..................................................:D......`N.......J..a....N..%....N.....F>.p....................G>.(.....<...............1......8D.@....................text.....0.......0................. ..`fipstx........0.......0............. ..`.rdata........1.......1.............@..@.data...\&...`D......JD.............@....pdata...a....J..b....J.............@..@.didat........M......jL.............@...fipsro........M......lL.............@..@fipsda...u....M..v....M.............@...fipsrd..`+...0N..,....M.............@..@.rsrc........`N.......M.............@..@.reloc.......N.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:data
Category:dropped
Size (bytes):12154
Entropy (8bit):7.3051965934360865
Encrypted:false
SSDEEP:
MD5:CD6F7579BE34643F373497D3B623789C
SHA1:12C399FE299592DDB83B6077872755EE714D4CF5
SHA-256:AEF646FF4C05FA2D244657C79A1F9B8E32E95799B49FDABB8EE68184444B7F65
SHA-512:BD5FC82CE5FF4A5533AEA66F339DDB5C07EDB39DB352E907AB35B3A6867B0DB29515065EA8933C5291711049C8183A8C06DBCE95293709A12E13239DEA96B3F6
Malicious:false
Reputation:unknown
Preview:0./v..*.H......../g0./c...1.0...`.H.e......0.....+.....7......0...0...+.....7.....@..l,&.L..........240112043117Z0...+.....7.....0..P0.......u....:q.L|...T;1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0:..+.....7...1,0*...F.i.l.e........z.s.a.w.d.r.v...s.y.s...0.... g..b..........D.....5.ElQ...1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0:..+.....7...1,0*...F.i.l.e........z.s.a.w.d.r.v...i.n.f...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... g..b..........D.....5.ElQ...0.......oM.L.T.."@..N_t..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0:..+.....7...1,0*...F.i.l.e........z.s.a.w.d.r.v...i.n.f...0.... .&7ufn...e......B..'..Gn&hTg..t*1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0:..+.....7...1,0*...F.i.l.e........z.s.a.w.d.r.v...s.y.s...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... .&7ufn...e......B..'..Gn&hTg..t*....0...0....+.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:Windows setup INFormation
Category:dropped
Size (bytes):1729
Entropy (8bit):4.596333213391172
Encrypted:false
SSDEEP:
MD5:B16404C255F1DA9EB98627D8762C5B55
SHA1:81FF0A6F4DD14CFC54E8C22240F7C54E5F740B91
SHA-256:67CEDF62A9DEB6EE8914F8AF0FB8FCC944E2ABBE9AA90BAF359D456C51F11FC7
SHA-512:9405AA5072959C2F648CD004B01EF2784581963C61DC2EB901CE2A9A94600BCCBEE88C3A1332317552187D791463FD0058577AF9BEFF8A822203CDCA7ADF12AB
Malicious:false
Reputation:unknown
Preview:;;;..;;;..;;; Abstract:..;;; Zsawdrv Callout driver install configuration...;;;....[Version].. Signature = "$Windows NT$".. Class = WFPCALLOUTS.. ClassGuid = {57465043-616C-6C6F-7574-5F636C617373}.. Provider = %ProviderString%.. CatalogFile = zsawdrv.cat.. DriverVer = 01/11/2024,1.2.2.1.. ..[SourceDisksNames].. 1 = %zsawdrvDisk%,,,""....[SourceDisksFiles].. zsawdrv.sys = 1,,....[DestinationDirs].. DefaultDestDir = 12 ; %WinDir%\System32\Drivers.. zsawdrv.DriverFiles = 12 ; %WinDir%\System32\Drivers....[DefaultInstall.NTamd64].. OptionDesc = %zsawdrvServiceDesc%.. CopyFiles = zsawdrv.DriverFiles....[DefaultInstall.NTamd64.Services].. AddService = %zsawdrvServiceName%,,zsawdrv.Service....[zsawdrv.DriverFiles].. zsawdrv.sys,,,0x00000040 ; COPYFLG_OVERWRITE_OLDER_ONLY....[zsawdrv.Service]..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):84520
Entropy (8bit):6.499439738934567
Encrypted:false
SSDEEP:
MD5:56841C7DF8002B52052B76F03E19A7F4
SHA1:217554A452695C877A857C51787CF4C317EA73C6
SHA-256:C019FA970595C35F949973DA3AAB507921065F0CE2C64CF88836F05CD180BD15
SHA-512:59EBC7A00162C4D836384C54F97C49CFC6C04D1C5CB411164BAF0EF5EDFE5DBDE33F62199F6C09C4056A82E7DB0EC91BC7E0D0289905539A2BAD108B9BA1C1CE
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........................................................q...........Rich...........................PE..d...u..e.........."..........0......`B.........@.....................................\.....A.................................................C..P....`..........8...."..((...p..4.......8...........................................................................text...mt.......v.................. ..h.rdata..d............z..............@..H.data...h...........................@....pdata..8...........................@..HPAGE.....d.......f.................. ..`INIT.........@...................... ..b.rsrc........`......................@..B.reloc..4....p....... ..............@..B................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:data
Category:dropped
Size (bytes):12154
Entropy (8bit):7.295964622651444
Encrypted:false
SSDEEP:
MD5:4FC0A5BC47E1751F8478F3B5D1FD2C6A
SHA1:553D734A7281905DEFE5D49A53EB1150C59FAFF8
SHA-256:E7660167A0607D6B698BB5E09B58FD4E86D73822A0F1E6D53D5DDC0E95964473
SHA-512:188C95C609C6221E557395940B3CE3A1DF032EB401E1FDA89630732370A22F01B5934C2F503E6C39702FE2ED0BEB8315980520A533677CBC511FFDDEAE80F840
Malicious:false
Reputation:unknown
Preview:0./v..*.H......../g0./c...1.0...`.H.e......0.....+.....7......0...0...+.....7.......rv.:D...!.....240112043117Z0...+.....7.....0..P0.... P.q..Qx...^7jjx.WV.M.1...,V.B1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0:..+.....7...1,0*...F.i.l.e........z.s.a.w.d.r.v...i.n.f...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... P.q..Qx...^7jjx.WV.M.1...,V.B0....Z..2.#8.........6..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0:..+.....7...1,0*...F.i.l.e........z.s.a.w.d.r.v...s.y.s...0.....$.q.......8$u/.'[.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0:..+.....7...1,0*...F.i.l.e........z.s.a.w.d.r.v...i.n.f...0.... ..?$..K.....s|...T.....K...e1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0:..+.....7...1,0*...F.i.l.e........z.s.a.w.d.r.v...s.y.s...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... ..?$..K.....s|...T.....K...e....0...0....+.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:Windows setup INFormation
Category:dropped
Size (bytes):1729
Entropy (8bit):4.602615955303984
Encrypted:false
SSDEEP:
MD5:9595E1F8AB611AF24D800656DCC32EB5
SHA1:8324FE71079F8ECF1B17A63824752FA2275BC9B2
SHA-256:50EDAB71E080517886F59E5E376A6A78895756114DE731D28199D72C56EE8742
SHA-512:D68BDDC2784A86774B3A8E776E2B57D0CA02FEF43FC634B68BA7267470F9AE0AA36977B365087F5AE82CA6F138912D94B94B8AB45CF81D63FBBC7A3E6C499BF3
Malicious:false
Reputation:unknown
Preview:;;;..;;;..;;; Abstract:..;;; Zsawdrv Callout driver install configuration...;;;....[Version].. Signature = "$Windows NT$".. Class = WFPCALLOUTS.. ClassGuid = {57465043-616C-6C6F-7574-5F636C617373}.. Provider = %ProviderString%.. CatalogFile = zsawdrv.cat.. DriverVer = 01/11/2024,1.2.2.1.. ..[SourceDisksNames].. 1 = %zsawdrvDisk%,,,""....[SourceDisksFiles].. zsawdrv.sys = 1,,....[DestinationDirs].. DefaultDestDir = 12 ; %WinDir%\System32\Drivers.. zsawdrv.DriverFiles = 12 ; %WinDir%\System32\Drivers....[DefaultInstall.NTARM64].. OptionDesc = %zsawdrvServiceDesc%.. CopyFiles = zsawdrv.DriverFiles....[DefaultInstall.NTARM64.Services].. AddService = %zsawdrvServiceName%,,zsawdrv.Service....[zsawdrv.DriverFiles].. zsawdrv.sys,,,0x00000040 ; COPYFLG_OVERWRITE_OLDER_ONLY....[zsawdrv.Service]..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (native) Aarch64, for MS Windows
Category:dropped
Size (bytes):88616
Entropy (8bit):6.43588505006247
Encrypted:false
SSDEEP:
MD5:0B49B4CB4ACD7ACD032B78F31AD2F538
SHA1:C7AB7775488B495A6964D2300540147181A7634B
SHA-256:35AC2662648BE896E0650256D44478A628ECF80420762603DF35B5384B94F192
SHA-512:96AEAD0444E653C325B086FAE1A437D6A515331FA856B5CF0A9BB84735D74E1953AA6D0337285875C6902E1E266ECBCE463526D7045EFF864B5118E6C5974312
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...............................................P....P.A.....P......Rich............PE..d...~..e..........".........."......pR.........@.....................................;.....A......... ...................................... S..d....p..........H....2..((......0...@...8............................................................................text...D........................... ..h.rdata..............................@..H.data...D...........................@....pdata..H...........................@..HPAGE....@q.......r.................. ..`INIT....L....P...................... ..b.rsrc........p.......,..............@..B.reloc..0............0..............@..B................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Tue Nov 12 07:19:57 2024, mtime=Tue Nov 12 07:19:57 2024, atime=Tue Nov 12 07:19:57 2024, length=0, window=hide
Category:dropped
Size (bytes):2107
Entropy (8bit):3.523690619659061
Encrypted:false
SSDEEP:
MD5:6486F7B03D7018E5CAB60B4283673FCB
SHA1:CC10975114642D6DA622D067CD4AF5E826FD9220
SHA-256:9F9AD55E2CDD2BC8B2DD2610C6A6C95124203C56ED968F86BDC5E066BA2FCED8
SHA-512:856E27AC449795C8BB1752C54252F53D9026C3768DA8C7C0FB3074428505731CB384542B79FA25B12D29F22B0A99283ABD13A52A5155E95F25FDF529A8CF90D3
Malicious:false
Reputation:unknown
Preview:L..................F.`.. ...A1%..4..A1%..4..A1%..4...............................P.O. .:i.....+00.../C:\.....................1.....lYxB..PROGRA~1..t......O.IlYxB....B...............J.....?...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....V.1.....lYzB..Zscaler.@......lYxBlYzB..........................D..Z.s.c.a.l.e.r.....b.1.....lY}B..ZSAINS~1..J......lYzBlY}B............................!.Z.S.A.I.n.s.t.a.l.l.e.r.....h.2.....lY}B .UNINST~1.EXE..L......lY}BlY}B............................!.u.n.i.n.s.t.a.l.l...e.x.e.......b...............-.......a...........+,.......C:\Program Files\Zscaler\ZSAInstaller\uninstall.exe....U.n.i.n.s.t.a.l.l. .Z.s.c.a.l.e.r.3.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.Z.s.c.a.l.e.r.\.Z.S.A.I.n.s.t.a.l.l.e.r.\.u.n.i.n.s.t.a.l.l...e.x.e.%.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.Z.s.c.a.l.e.r.\.Z.S.A.I.n.s.t.a.l.l.e.r.0.C.:./.P.R.O.G.R.A.~.1./.Z.s.c.a.l.e.r./.C.o.m.m.o.n./.R.E.S.O.U.R.~.1./.Z.S.C.A.L.E.~.1...I.C.O.........%SystemDrive%/PROGRA~1/Zsca
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Nov 12 07:19:52 2024, mtime=Tue Jun 18 15:21:12 2024, atime=Tue Jun 18 15:21:12 2024, length=2098568, window=hide
Category:dropped
Size (bytes):2058
Entropy (8bit):3.54094167118616
Encrypted:false
SSDEEP:
MD5:C9EC8B44D7190DF3C9F5CA08E6C26337
SHA1:F91A18A311B9BD330D493DE1C5BBBDB2BB525346
SHA-256:7FF1FAB65D2BCE8C3F75F3CD46D13D5797C42D3C929AE43305039F5B18980FDF
SHA-512:05F060E211DE3919B7FA5A342FF7A65260BC49183E590D0F75D3766F5D4B3E7EC0ECC4BDA2B99C6DA1EDB66ECC24759C2673872310DD9C7F06786E959738F7A2
Malicious:false
Reputation:unknown
Preview:L..................F.@.. ..._...4.................. ..........................P.O. .:i.....+00.../C:\.....................1.....lYxB..PROGRA~1..t......O.IlYxB....B...............J.....?...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....V.1.....lYzB..Zscaler.@......lYxBlYzB..........................D..Z.s.c.a.l.e.r.....V.1.....lY{B..ZSATray.@......lYzBlY{B..............................Z.S.A.T.r.a.y.....b.2... ..X.. .ZSATray.exe.H......lY{B.X.......Z........................Z.S.A.T.r.a.y...e.x.e.......[...............-.......Z...........+,.......C:\Program Files\Zscaler\ZSATray\ZSATray.exe....Z.s.c.a.l.e.r.,.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.Z.s.c.a.l.e.r.\.Z.S.A.T.r.a.y.\.Z.S.A.T.r.a.y...e.x.e. .C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.Z.s.c.a.l.e.r.\.Z.S.A.T.r.a.y...-.s.h.o.r.t.c.u.t.0.C.:./.P.R.O.G.R.A.~.1./.Z.s.c.a.l.e.r./.C.o.m.m.o.n./.R.E.S.O.U.R.~.1./.Z.S.C.A.L.E.~.1...I.C.O.........%SystemDrive%/PROGRA~1/Zscaler/Common/RESOUR~1/ZSCALE~1.ICO.................
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):1392
Entropy (8bit):5.245002290220922
Encrypted:false
SSDEEP:
MD5:F45722620D6DA9ACE759F4ECF1D2BE2D
SHA1:7E5A6683AFAFBF5A3AF8676A4336E6E06A542604
SHA-256:6E5F5A0B2EB5F40EBB099D5AAB3E1112583CC4C68ABC638184081C053AE991D4
SHA-512:F278E1BB58C574EE225164FCF01FB91FD5CBE898CC39CD4D1EBC37F935E54A6D2ACF0F69E816C9C186B550548040F7724DAF7F482F636C93A89EC6764EFF654E
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:00.199584(-0500)[6728:3436] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:00.199584(-0500)[6728:3436] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:00.199584(-0500)[6728:3436] INF ZSAHelper Architecture: x64..2024-11-12 08:20:00.199584(-0500)[6728:3436] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:00.199584(-0500)[6728:3436] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:00.199584(-0500)[6728:3436] INF Performing op: --setRecoveryMode..2024-11-12 08:20:00.199584(-0500)[6728:3436] DBG ZEPSdk: ZSetPermissions not initialized..2024-11-12 08:20:00.199584(-0500)[6728:3436] ERR ZEP: Failed to set permissions..2024-11-12 08:20:00.199584(-0500)[6728:3436] DBG ZEPSdk: ZSetPermissions not initialized..2024-11-12 08:20:00.199584(-0500)[6728:3436] ERR ZEP: Failed to set permissions..2024-11-12 08:20:00.19958
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.201350645134959
Encrypted:false
SSDEEP:
MD5:3E9993FFD5A845DE98856EA1AD9F1885
SHA1:A4641545FE033A8B1E088E8FDEF8F3B1A26BB831
SHA-256:5D2629EC5FD989CC96E60A022A86EBDC5B9DE5D24282F7733A3E7DAD89254AC3
SHA-512:F5A7AC33800AAD7C2227862B0DFAE5166CF9468A3646830FFDDC44E0ED659906DE296420C14638C794A2660464F639AA9BC964AE977B8C251A822D13EEC846DC
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:00.915409(-0500)[6508:6520] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:00.915409(-0500)[6508:6520] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:00.915409(-0500)[6508:6520] INF ZSAHelper Architecture: x64..2024-11-12 08:20:00.915409(-0500)[6508:6520] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:00.915409(-0500)[6508:6520] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:00.915409(-0500)[6508:6520] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:00.915409(-0500)[6508:6520] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:00.915409(-0500)[6508:6520] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.2201847145097515
Encrypted:false
SSDEEP:
MD5:83F8113DB1F216B2EA54F12B5F7F5A56
SHA1:6C98C10E5EB0C3489C0C0C3226BC24CC688231FB
SHA-256:8765F96D38E34923913C8C2232889A9C3878D35FE133B3C444C28AD03E581FC8
SHA-512:EB661AD820C28FF7FEA0A7F6955C584ED215E525C8433B489E3D617961D38B53D7EE395E3417EC5054AC0C51B63B46B89EC69B42D78ED3F7A55C8B01EAA0A307
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:01.555240(-0500)[7136:7140] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:01.555240(-0500)[7136:7140] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:01.555240(-0500)[7136:7140] INF ZSAHelper Architecture: x64..2024-11-12 08:20:01.555240(-0500)[7136:7140] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:01.555240(-0500)[7136:7140] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:01.571251(-0500)[7136:7140] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:01.571251(-0500)[7136:7140] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:01.571251(-0500)[7136:7140] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.245503820747641
Encrypted:false
SSDEEP:
MD5:D34E7911909A452BB31189E36E3044D5
SHA1:1D27B820EDB9B3E562C414342A7C61353657A9CB
SHA-256:65106D39ACE81FCBE1BBF0CA13496DA47CBA722FD83AE9370926CB2EDE12DC3A
SHA-512:0191DF6D9DEF64F1C1F6165EC6400434B9699818B1BAE71B316EA88374A0922928367382BB8DE089851F242C5C795D40F45509071427BA846F08C8B120A99A01
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:02.193509(-0500)[6936:3028] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:02.193509(-0500)[6936:3028] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:02.193509(-0500)[6936:3028] INF ZSAHelper Architecture: x64..2024-11-12 08:20:02.193509(-0500)[6936:3028] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:02.193509(-0500)[6936:3028] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:02.193509(-0500)[6936:3028] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:02.193509(-0500)[6936:3028] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:02.193509(-0500)[6936:3028] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.243570865595894
Encrypted:false
SSDEEP:
MD5:D6E614AC93C1790C521DFDBD5F9921F0
SHA1:23AF3B7850226ADF066A7559B4B8B7836845809D
SHA-256:13E9EA868C68BA9C4D13E71A9AEA9851D8BF2FA4EE454700D1D91885684B600A
SHA-512:66595489F092097215F2E2ABA5387916DBA1AD55BBEBB4C3B17EB4B136B9823959B0D30F166DB2839AE6E178264BE29668DC64D26F5C8CF08A8516DEF5317187
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:02.927218(-0500)[6876:4480] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:02.927218(-0500)[6876:4480] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:02.927218(-0500)[6876:4480] INF ZSAHelper Architecture: x64..2024-11-12 08:20:02.927218(-0500)[6876:4480] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:02.927218(-0500)[6876:4480] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:02.927218(-0500)[6876:4480] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:02.927218(-0500)[6876:4480] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:02.927218(-0500)[6876:4480] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):1007
Entropy (8bit):5.2085965737393565
Encrypted:false
SSDEEP:
MD5:093F5A1A367B23214CBBCBD7602346DA
SHA1:31C081557F4F06244D440A404B57763BEC702A06
SHA-256:02DAEC3A05879BD1205989C8463DE41B63408E5CF4D82300317C61AEBCCC86DD
SHA-512:09D5B39338C02B2AB99861CA4C78646E89800D9099A20B9E29BEE7EA158989DAEDD79492BDFA19BBFFC8FCECA7D938731EA896DB37D441C8AB7EBFB1E70E97FC
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:03.565937(-0500)[4540:1100] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:03.565937(-0500)[4540:1100] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:03.565937(-0500)[4540:1100] INF ZSAHelper Architecture: x64..2024-11-12 08:20:03.565937(-0500)[4540:1100] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:03.565937(-0500)[4540:1100] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:03.565937(-0500)[4540:1100] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:03.565937(-0500)[4540:1100] ERR Failed to open service: 1060..2024-11-12 08:20:03.565937(-0500)[4540:1100] INF Service: ZSAUpm, isServiceInstalled: 0..2024-11-12 08:20:03.565937(-0500)[4540:1100] DBG setPreferSystem32Mitigation: Ignoring for UPM as it is not installed..2024-11-12 08:20:03.565937(-0500)[4540:1100] INF ZSAHelper return co
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.206264256324166
Encrypted:false
SSDEEP:
MD5:F0228EACEBC6E2B0AF6B343CBB9F2AA3
SHA1:86EC18B8FBE60E76B4877043B40B8E62F5994996
SHA-256:78B7A5761BADEE23B6978236FCFFE3DB1732DA03C49E8D3FA8B93C9DC91C5F0E
SHA-512:11091C1B06F5CBF5D66938C260E3F31945F5CFB0934896491F5235BCF6B207FD4282DC60105D22782DC62DB8D253B518B39635CCFA8815B581AE1D3AC6397074
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:04.221237(-0500)[3424:5380] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:04.221237(-0500)[3424:5380] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:04.221237(-0500)[3424:5380] INF ZSAHelper Architecture: x64..2024-11-12 08:20:04.221237(-0500)[3424:5380] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:04.221237(-0500)[3424:5380] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:04.221237(-0500)[3424:5380] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:04.221237(-0500)[3424:5380] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:04.221237(-0500)[3424:5380] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.283576963269671
Encrypted:false
SSDEEP:
MD5:7F939739079B6C0039A101FFA51F3357
SHA1:2C543DBB750D066EBE368C80F8AC9719BDFB2CD0
SHA-256:0A041E0BACA2039A4A99451F559B5FEF61BA742E764DF8D1CDAD4FC980CCA15C
SHA-512:29F15E52AC0B09B40686F2F241C7727C427035C2020A18843A7015A432847C97513FE90CE47FEC1AD50CE3A174E1D44C548297D392418BCB50911BBCDDAEB0EF
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:04.859784(-0500)[1816:5316] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:04.859784(-0500)[1816:5316] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:04.859784(-0500)[1816:5316] INF ZSAHelper Architecture: x64..2024-11-12 08:20:04.859784(-0500)[1816:5316] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:04.859784(-0500)[1816:5316] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:04.859784(-0500)[1816:5316] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:04.859784(-0500)[1816:5316] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:04.859784(-0500)[1816:5316] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.23475468739117
Encrypted:false
SSDEEP:
MD5:F975C9B0A94886C7A985EB1E97DA0ABF
SHA1:91DCD7CD6041CF2D997E6FC92D9FAB140EBFDA18
SHA-256:6AAAC70EEB3E42FD5E2369F0F483BE4C4F7E7869AFE937647C3F448A78C7EA67
SHA-512:67B600FF9C41FF37AADEC06C12C67A0279D65165BDFE5F007BE009114134401331A9552C8770E48B505CC9EBE7EB62FCDF1EEC99D5EB89A8CA109FA9BED0A294
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:05.531131(-0500)[1428:1764] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:05.531131(-0500)[1428:1764] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:05.531131(-0500)[1428:1764] INF ZSAHelper Architecture: x64..2024-11-12 08:20:05.531131(-0500)[1428:1764] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:05.531131(-0500)[1428:1764] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:05.531131(-0500)[1428:1764] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:05.531131(-0500)[1428:1764] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:05.531131(-0500)[1428:1764] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.266635584270209
Encrypted:false
SSDEEP:
MD5:19D759249725E0249C0CD8D454E0DEE8
SHA1:743922A822867D044150A380C55842AD3A4E3B01
SHA-256:CD464B3602E2E28CED4286FC1F39782AFEF995C2933AAEF87F4D13028DBCB53B
SHA-512:112DD3DFB57CD745CBB900D71142D8B8EB0244B63A664D4EE993AA5CBE8649EAC727F8228957D20F559A14952CDCB451E4A6FA8B5943AFF4BEF689DCF3EE19E1
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:06.187285(-0500)[3364:7016] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:06.187285(-0500)[3364:7016] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:06.187285(-0500)[3364:7016] INF ZSAHelper Architecture: x64..2024-11-12 08:20:06.187285(-0500)[3364:7016] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:06.187285(-0500)[3364:7016] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:06.187285(-0500)[3364:7016] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:06.187285(-0500)[3364:7016] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:06.187285(-0500)[3364:7016] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.227268594310068
Encrypted:false
SSDEEP:
MD5:6707B7E20E55C713F75B5DA98E055893
SHA1:7A1ACF1DACF23EA30C98F0AEBA4C58CADDC59310
SHA-256:6D3E63C0B825F0A77E744AC15335E92297BFAD10B0AF567832313CA4B927EC0F
SHA-512:314FA155885275DE9D510DB51F22249ACE4C3C8B54B79A3B38ECC1ED12D517A6ADD2B1CEEB8DA2CECF424C318ACC1A511DCB526C0947FA7DBAED0EF54769B5A5
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:06.825582(-0500)[6916:2460] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:06.825582(-0500)[6916:2460] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:06.825582(-0500)[6916:2460] INF ZSAHelper Architecture: x64..2024-11-12 08:20:06.825582(-0500)[6916:2460] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:06.825582(-0500)[6916:2460] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:06.825582(-0500)[6916:2460] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:06.825582(-0500)[6916:2460] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:06.825582(-0500)[6916:2460] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.272789814752671
Encrypted:false
SSDEEP:
MD5:A0D2FC1783FC6CBBFCE20AA33A7CA42D
SHA1:48EC69D36229F13B9F1C6C845BC39DE06AC0EC59
SHA-256:E37BE14175AB90C0D0420C0E52B7515306331CB7CC5A10DBEB7F9D32F04D81B5
SHA-512:5E1B7E53F55EA65C84F3A37437254A991B7377863B2D9DFFDA7AF0FBFA6DD719A708DEB0D46CCE816D8FB61C4B1EC9C8113CD04B8A50BC27A8B63BCBF8B9E62B
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:07.479736(-0500)[6604:4132] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:07.479736(-0500)[6604:4132] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:07.479736(-0500)[6604:4132] INF ZSAHelper Architecture: x64..2024-11-12 08:20:07.479736(-0500)[6604:4132] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:07.479736(-0500)[6604:4132] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:07.479736(-0500)[6604:4132] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:07.479736(-0500)[6604:4132] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:07.479736(-0500)[6604:4132] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):815
Entropy (8bit):5.193595045158872
Encrypted:false
SSDEEP:
MD5:41BEC4D0413B3CEA044A843A7764190A
SHA1:A016DD244C6F889C09B59BC81975C764555517CA
SHA-256:E870D448C1CDD5C6683E30BBB1B21284F0E19EB03A97C4ED3DBF880E64D0F937
SHA-512:81485585F4DCF49DAC81384D5017E7754A67B0283A4993ADEBCDBEA4DE6174414D86ACEE83F1E4017636C2017544E2C1849DF0BDF6E823E1ABBA46FE0F905979
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:08.130891(-0500)[408:2920] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:08.130891(-0500)[408:2920] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:08.130891(-0500)[408:2920] INF ZSAHelper Architecture: x64..2024-11-12 08:20:08.130891(-0500)[408:2920] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:08.130891(-0500)[408:2920] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:08.130891(-0500)[408:2920] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:08.130891(-0500)[408:2920] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:08.130891(-0500)[408:2920] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):823
Entropy (8bit):5.264417411122777
Encrypted:false
SSDEEP:
MD5:D0BD10C4C5A6305708360306316FBBC7
SHA1:805B5DF9EB682F2404D3E716D9550DB8E6778C73
SHA-256:E05D8E25939D8432D17A01BBDEC4E1916CAAF5960F088C618B7A11D8F1939192
SHA-512:F6384F32CC30823882ED6BA3C197AB0A5E746D116DD871F530B9BE695B300EBF8E09543973D0AA52DD9CB6B52B5989759F44A1F50CE95B65CD740073E1CC6942
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:08.786609(-0500)[5464:5940] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:08.786609(-0500)[5464:5940] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:08.786609(-0500)[5464:5940] INF ZSAHelper Architecture: x64..2024-11-12 08:20:08.786609(-0500)[5464:5940] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:08.786609(-0500)[5464:5940] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:08.786609(-0500)[5464:5940] INF Performing op: --setPreferSystem32Mitigation..2024-11-12 08:20:08.786609(-0500)[5464:5940] DBG setPreferSystem32Mitigation: Value set successfully...2024-11-12 08:20:08.786609(-0500)[5464:5940] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):704
Entropy (8bit):5.2027287484835325
Encrypted:false
SSDEEP:
MD5:4540F276CF813B3C7303E44FAB426558
SHA1:3D951F294F15381EE52F6E11B1A60DB42C039A5C
SHA-256:1B5BD96025265BE71CBBD7B5DFE13F1371B6184F49224F7096F29AE5C9E05607
SHA-512:109A8DD26128623A173741C4B77BC23927E1E993C48323E12375542A6D02FECC99D85C981A90C324A0313211E10782F865E3332054288C5B4EEBB3E3CBA746E3
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:09.695508(-0500)[1788:400] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:09.695508(-0500)[1788:400] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:09.695508(-0500)[1788:400] INF ZSAHelper Architecture: x64..2024-11-12 08:20:09.695508(-0500)[1788:400] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:09.695508(-0500)[1788:400] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:09.695508(-0500)[1788:400] INF Performing op: --migrateConfigFiles..2024-11-12 08:20:09.695508(-0500)[1788:400] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):1360
Entropy (8bit):5.329260278753852
Encrypted:false
SSDEEP:
MD5:D67F399745AC8B05C71A28D77C59885B
SHA1:9E784A06D7A8C341566C5A8FCD5559B99EE1EAC5
SHA-256:C82605FB89B0AE77FC2C1FE0DA3C0A2DF75C9964FDA9512888F8C0210F65FBDA
SHA-512:C33895CBCA4905339BC2DB432DDF08CFBE06B7F293A76A520E38C586C8CA161C8EBA5CE42B019A5183254EAEB512F74CA302539F6D68DB5A9C8D651FBD3BBDB7
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:20:10.351785(-0500)[6748:6696] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:10.351785(-0500)[6748:6696] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:20:10.351785(-0500)[6748:6696] INF ZSAHelper Architecture: x64..2024-11-12 08:20:10.351785(-0500)[6748:6696] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:10.351785(-0500)[6748:6696] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:10.351785(-0500)[6748:6696] INF Performing op: --updatePrevInstallerHash..2024-11-12 08:20:10.351785(-0500)[6748:6696] INF Finding version for file: C:\Program Files\Zscaler\RevertZcc\Zscaler-windows-4.4.0.309-installer-x64.exe..2024-11-12 08:20:10.366784(-0500)[6748:6696] INF ZccRevert, Found installer: Zscaler-windows-4.4.0.309-installer-x64.exe with version: 4.4.0.309..2024-11-12 08:20:10.366784(-0500)[6748:6696] DBG ZccRevert
Process:C:\Program Files\Zscaler\ZSAService\ZSAService.exe
File Type:ASCII text, with CRLF, CR line terminators
Category:modified
Size (bytes):36749
Entropy (8bit):5.363199175281254
Encrypted:false
SSDEEP:
MD5:B374C8E6ADECF9FA5A043C2B7D13FDB5
SHA1:1EF2F1C1001FB1B7C34AC7EC50A1E02EA54737E3
SHA-256:C26850A5F38CDE6C888C0CF6F14A008FCDFA110E8D9FE3AE3AAE53DA282565FB
SHA-512:AFE466F026A92AB84CD14C22C43592A094A762E130F9AFF49CEB9466E3E6961EF36483EDB1BAE4F9E47452573EAC1302A182D15C0EF80726E7195CA076E816A5
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:32.122547(-0500)[3720:1656] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:32.122547(-0500)[3720:1656] INF ZSAService App Version: 4.4.0.309..2024-11-12 08:20:32.122547(-0500)[3720:1656] INF ZSAService Architecture: x64..2024-11-12 08:20:32.122547(-0500)[3720:1656] INF ZSAService GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:32.122547(-0500)[3720:1656] INF UPM Hard Protocol Version: 28..2024-11-12 08:20:32.122547(-0500)[3720:1656] INF UPM Soft Protocol Version: 900..2024-11-12 08:20:32.122547(-0500)[3720:1656] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:32.122547(-0500)[3720:744] INF ZSAServiceBase::serviceMain: registering for power events..2024-11-12 08:20:32.122547(-0500)[3720:744] INF ZSAServiceBase::serviceMain: registered for suspend-resume, power & battery notifications..2024-11-12 08:20:32.122547(-0500)[3720:744] INF ZSAServiceB
Process:C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):42
Entropy (8bit):3.778640339187872
Encrypted:false
SSDEEP:
MD5:82F0FCC6B95C6E2082A548E7337FD924
SHA1:761016C4716A997CD4984385F967D16405E17B2E
SHA-256:3F47177EC0AA8E9055BEA827E42E4ED0F888AAE767F1620B458786240E7145CA
SHA-512:E0D9F65E7291ADCD0D1EABE46673F878749EC80411952DD1D73753B6F8C0E0E5CC5F8D0F8FC26F1C571ED793DD1DBC7E16440487A9B9DC0B10575B2DC8E038B9
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:21:16.605109.4.4.0.309.x64..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):895
Entropy (8bit):5.243371303248458
Encrypted:false
SSDEEP:
MD5:F548A42E09C118B7EA1D534D7177B86E
SHA1:4F628ECBC5426449083A77873A4BA26A9353E09A
SHA-256:A4DE430DBF03956A92EF32653529C3333A80D5C9905D3BD28038A98D7C2025B5
SHA-512:BAE3C33EFED0B65CD60DEFECA41F32FC3C343A88D459305D346BC139C2D8A798B4F9C31CA1C2960445CC6CA17B4616BF6CF2EB6506ABD623E17EDA1F8E29764A
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:21:03.474438(-0500)[6372:4212] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:21:03.474438(-0500)[6372:4212] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:21:03.474438(-0500)[6372:4212] INF ZSAHelper Architecture: x64..2024-11-12 08:21:03.474438(-0500)[6372:4212] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:21:03.474438(-0500)[6372:4212] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:21:03.474438(-0500)[6372:4212] INF Performing op: --isInstallerPasswordConfigured..2024-11-12 08:21:07.327424(-0500)[6372:4212] DBG ZSAServiceRpcClient::sendCommandToService: 2..2024-11-12 08:21:07.327424(-0500)[6372:4212] INF Uninstall password is empty..2024-11-12 08:21:07.327424(-0500)[6372:4212] INF ZSAHelper return code: 2..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):945
Entropy (8bit):5.222692724325866
Encrypted:false
SSDEEP:
MD5:C10C6BC8B9557C8E3860C6339A726E13
SHA1:B30394F5899E4A8D6A7261389A41292D16A3266A
SHA-256:B3839748A19627F6BDBBA7E0B9DFCC7DE2F2C7C3B55D16A538F4F3E021080E4C
SHA-512:DAFFAE7F21D70D7E150FAC37E32224A567D6C3891EDB501D2B06C448023FF59C76703229006E59D188A9075A31E3A7776291E481A3166F34573D1B5CBCFC43C6
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:21:08.061017(-0500)[6560:6860] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:21:08.061017(-0500)[6560:6860] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:21:08.061017(-0500)[6560:6860] INF ZSAHelper Architecture: x64..2024-11-12 08:21:08.061017(-0500)[6560:6860] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:21:08.061017(-0500)[6560:6860] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:21:08.061017(-0500)[6560:6860] INF Performing op: --installerDisableAntiTampering..2024-11-12 08:21:10.038002(-0500)[6560:6860] DBG ZSAServiceRpcClient::sendCommandToService: 1..2024-11-12 08:21:10.038002(-0500)[6560:6860] DBG [ZEP][installerDisableAntiTampering], Anti tampering is turned off by policy...2024-11-12 08:21:10.038002(-0500)[6560:6860] INF ZSAHelper return code: 0..
Process:C:\Program Files\Zscaler\ZSAHelper\ZSAHelper.exe
File Type:ASCII text, with CRLF, CR line terminators
Category:dropped
Size (bytes):2831
Entropy (8bit):5.223619777147774
Encrypted:false
SSDEEP:
MD5:8B3B10EE7B28E28EE67BF7B1142450F2
SHA1:A41D3D979E755CC66FA209DF55CF1024CF74852D
SHA-256:4A58F85E9AD03BA09E4F967F29DC0460100FF7E45D62602E7D20EF6AB307A729
SHA-512:8084A4324A96FCF26F47055B887E6EA6A967D23B658B44F048F22E627EBD40B1CB653669074E0DAD24F99AC6A0E155DDC24CE92B6783CEF27E23954FD983B376
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:21:13.993352(-0500)[1100:6192] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:21:13.993352(-0500)[1100:6192] INF ZSAHelper App Version: 4.4.0.309..2024-11-12 08:21:13.993352(-0500)[1100:6192] INF ZSAHelper Architecture: x64..2024-11-12 08:21:13.993352(-0500)[1100:6192] INF ZSAHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:21:13.993352(-0500)[1100:6192] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:21:13.993352(-0500)[1100:6192] INF Performing op: --markStop..2024-11-12 08:21:14.807355(-0500)[1100:6192] DBG ZSAServiceRpcClient::sendCommandToService: 0..2024-11-12 08:21:14.807355(-0500)[1100:6192] DBG [MarkStop] Password validated successfully, marking services stoppable...2024-11-12 08:21:14.807355(-0500)[1100:6192] INF sendUserCommand: Start! ServiceName: [ZSAService], Code: [1]..2024-11-12 08:21:14.807355(-0500)[1100:6192] I
Process:C:\Program Files\Zscaler\ZSATrayManager\ZSATrayManager.exe
File Type:ASCII text, with very long lines (2601), with CRLF, CR line terminators
Category:modified
Size (bytes):56927
Entropy (8bit):5.475125525992774
Encrypted:false
SSDEEP:
MD5:4D1343795EAC57BCCC5144F551B7B6AE
SHA1:8F07B46F1F5C3A4721724AE7351868FA681AB618
SHA-256:3547BBB6E4C9883E28D2C6CFFCAEA58098CBECDB663C9059DFF3BF896F417C0E
SHA-512:A7211E297729920E01AEB6D98183E463FDB3650E5BA9FD693FEC127731FA31A258696434D2741F454BDD656790CFFFC12FD6FAD595067E70A8A0F8A20B427916
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:43.444116(-0500)[2120:2268] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:43.444116(-0500)[2120:2268] INF ZSATrayManager Version: 4.4.0.309..2024-11-12 08:20:43.444116(-0500)[2120:2268] INF ZSATrayManager Architecture: x64..2024-11-12 08:20:43.444116(-0500)[2120:2268] INF UPM Hard Protocol Version: 28..2024-11-12 08:20:43.444116(-0500)[2120:2268] INF UPM Soft Protocol Version: 900..2024-11-12 08:20:43.444116(-0500)[2120:2268] INF GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:43.444116(-0500)[2120:2268] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:43.444116(-0500)[2120:3052] INF ZSAServiceBase::serviceMain: registering for power events..2024-11-12 08:20:43.444116(-0500)[2120:3052] INF ZSAServiceBase::serviceMain: registered for suspend-resume, power & battery notifications..2024-11-12 08:20:43.444116(-0500)[2120:3052] INF ZSAServiceBase:
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):14
Entropy (8bit):2.9852281360342516
Encrypted:false
SSDEEP:
MD5:6DEDF3959B0887F8EF855AE5FE4F7856
SHA1:EE8A32768AE3D54DD15CC6E7FF7D1EE9B6362561
SHA-256:D34C048CE472164CB4DE0F4ABE4D95347BB004606AFD2905304A584543866EB1
SHA-512:4685E4420BD8BD295156EA354AC7E947F577AC279A601F780746C91745853D30B853F801590C59A82D66F2AFCEFA27F5726BE8E7C1CBA356D4BBB81AE85EE114
Malicious:false
Reputation:unknown
Preview:Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):112
Entropy (8bit):5.197961177183742
Encrypted:false
SSDEEP:
MD5:419D2439AC7FDD85791F95FA344B3A08
SHA1:54923119D0B7A3F8555B69C4165F127E7BEDDF18
SHA-256:A3D8F01C406F163ADD026F65FE187D8D3826081EEC6F48D339526ABAAB2468FC
SHA-512:1F165D5B1DE6B243C012C47E082393E4CF390E67E59CECD676A3AD4ADE5EFA3C79CB0E7B6CFCAC31002D49DE1D49267857B65EE1EFDEB088F0BDD22BD80B5BB8
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:19:58.619595(-0500)[1092:5992] ERR SID not matching with SECURITY_LOCAL_SYSTEM_RID..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.255140715771935
Encrypted:false
SSDEEP:
MD5:FA3673AADEE44068911811B7D23D32CF
SHA1:E9C68B977EF7C1194756B768501D26820D884945
SHA-256:5ED5860A3ECDE8DA481A297806DEAE4543EFAD459F678F5B6C8033AFC940BB4B
SHA-512:E31EDD455773D25AF6744B9A59EE93D8042548925C6FBAC335E22EB6639A7779B9C9BF2E84626E1967F40C2863B6061EF1A17B1DBBD2A4E51B800CA16467AEEF
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:00.199584(-0500)[6728:3436] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.179116638192036
Encrypted:false
SSDEEP:
MD5:54AC6CB41ED86CA73480F45720C3F4B6
SHA1:0665D102E20C683A422EFFA10D24FCF8E9C4F8B9
SHA-256:535B4E319A044FA2099EE488D38779262E75DF27EDD0832B035B6994F561E93B
SHA-512:BCA8A3CEC038C9ACF370C610F3F749578E8716C4B77F80EB6D5F2E64A51A0E97AB64319917A351AE906CDFE9566B97BEB5F22E8E7EC989508CB3105738380DD4
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:00.915409(-0500)[6508:6520] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.198872761134696
Encrypted:false
SSDEEP:
MD5:45D46AA5FC37B9A5A296C7A19E2A9676
SHA1:44A2D9422593C821E7A195EC93E5EDD398DA8D0C
SHA-256:58ECC7CEAB8495D9FC67A732D86FAD815FFDDBA96964EB2C3958AD7FD3AA3A78
SHA-512:7F45B0CC0988A1F76C185A96300CC0DCECF03A73BB074D5F8E7018C6322D1677AD96AEFDC020E9333B57D8A1AB34C4D5A4F66F59D97AC37AE76DC87D526D95C8
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:01.555240(-0500)[7136:7140] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.214710203874619
Encrypted:false
SSDEEP:
MD5:9CDEA6B402AC1AF6D45E6F0A7030DC0B
SHA1:8A41489BE8BA53C16ECCDE0014985363978148CA
SHA-256:F931DFE85A15C1AED05BAD85DEE947B1019A67DD523E64DFA44FA27411F111A1
SHA-512:757A8A29FAE9B46F82E58EF6032456A095583F3CB631B51623DCED6261D5804E4BC98B83BA299879E9CD9E5B05613F021CBD5F60CD02C905632704FB9CE2DC97
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:02.193509(-0500)[6936:3028] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.208259882477937
Encrypted:false
SSDEEP:
MD5:453C1AC16CBB7FA85056FDE5EBB14F77
SHA1:B6ABA30FC9719768D2821B34DF685839FA852402
SHA-256:8C889A90110CA282CF7AD9C9760DABDA0031D0CBAF7B4B91BCE7636E0843886A
SHA-512:8E0811421D7115B1E90F6031C329A12472BC751DE70746B496AB3217572C9BBEF12A751910311ABED06FD4820052D99678CE7BDE6164C109465FFFEACC8E81BC
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:02.927218(-0500)[6876:4480] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.2177231437037115
Encrypted:false
SSDEEP:
MD5:2D7DDBA1DFFF43CACA177FFD54C6FC13
SHA1:595A3E45A5FB2BB51A2D82DAA9BCE861F4119F68
SHA-256:3B64F4288529650A93AED92E395D49EB021BCC22B0F7E0F9E0581B960FA8E9B6
SHA-512:71376EEC66967BC0C38F8497EE1F7A2B2C3F84264350438F5D91B6A4984309143C94C091148B161CB50E86C9A4C4350EA07214DBDAD803AA42A858B22C4E9768
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:03.565937(-0500)[4540:1100] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.180809427853811
Encrypted:false
SSDEEP:
MD5:1AE2E8AF1A92BB0547C10069D39C9F03
SHA1:E18032EC3B78805B4EE852D5B54E00BC4CB9EABF
SHA-256:1DC91A34710AA5A4451A548D2D4978D0A16C365BF9737D6215CC71EE57EA7E8D
SHA-512:3B93139C0E6A72F7FC71ED5C47A8A83856A4F9371432F9ACDA6B8EB7A4CC563287F6A93F5CC09243B710700E4E72DE8E3BBFC668BAA0624D2D6BBE684A8F101F
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:04.221237(-0500)[3424:5380] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.247497534385025
Encrypted:false
SSDEEP:
MD5:FA1FAF5DBC34A3F069B8CB802503FC43
SHA1:8361A529A80C63950FD9A6B625D9585B7870F3C2
SHA-256:DBD015C47748FE807F1D338B5C1F10F5923399DA295AF60C357761EF051994E0
SHA-512:E58C083EC299C3F5F0A403EAE9ACBF779700C764B374797A030E67BCACB365F05FFB6562C7A5CBAF0DCC0B1E010B7D07699DF5B4B6977274CD79A586E8A1CAF2
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:04.859784(-0500)[1816:5316] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.181554597892684
Encrypted:false
SSDEEP:
MD5:C1C3C27E40B901CF7093CA6E6A2A8F30
SHA1:B5BDAA74ECAB4F1D8F396CADEADC000CFC3B31E9
SHA-256:47603362CC46319E0276C540B572A74D580EBB452D229EED1414D1662BDA0CA7
SHA-512:16F76E24FCEDA7D46384776D96888AA6576F5DDC6A294CAC635E22B22FC6D27827DA7A0F2C0A42B50D96FF9EAE4F7668668C1796D1C7C251BC5558B30BE7843A
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:05.515140(-0500)[1428:1764] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.213343158485633
Encrypted:false
SSDEEP:
MD5:ECE1AC4F49128D82827BB7F28B865252
SHA1:3F2BD09300810677D3716A7CE7F9F3BBAFF57C10
SHA-256:EDC645D462B6893760F9ED5E63CE7C93FEF724335787E2147D94875A82E923CD
SHA-512:96910AF51C4687D917D2F69A4890F47589498F4716BDB24A52ADC3A86B78506D441876CA24946B2FF32552AE30345C0C5AF980EC0239C62EA89695586299A9F5
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:06.171281(-0500)[3364:7016] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.191563594586038
Encrypted:false
SSDEEP:
MD5:45CFF5F459A8508AD300727E267853E0
SHA1:D317B6419ABC931A6D84022BB20AF5E86B37D34D
SHA-256:55E830BBBBF05D2FBCEBE922B01FCEF27F6A18D1AE3141D5751206A4F14FB65C
SHA-512:5C77680DCF09FEA27200F4010123C1812963F46FC71A83349DFC12C810A8B7B565E4522BF921794369B1C0DE39A3670F7500795540873F7BD23063789253A995
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:06.825582(-0500)[6916:2460] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.243019503650722
Encrypted:false
SSDEEP:
MD5:E1188B7D145B805C0DBF7C8B5D7F6A4F
SHA1:453C2CBB67B4C6B82F8FE997C94444EAF2427326
SHA-256:138F2BDA5D0AAF5255560BAC24FA03B4E45F521BAD9381ACAD7C9CC237E10E2A
SHA-512:4383C0A8E40535BA1E010FFB176DF10228F32DE2C79D65EE99E6E65F2C96126DA325DE69869C3E94B3D078BCB3530CA6809FFDFFC274E64F2195A4DA65EF8B35
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:07.479736(-0500)[6604:4132] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):164
Entropy (8bit):5.163614180732414
Encrypted:false
SSDEEP:
MD5:B54E6D40463FB1CCB19C98BB799E2936
SHA1:FD6A8FDE9E233A4AF725513EB304001477DA96F0
SHA-256:B2340506A75641BC870F4F24310892F25892A22A3AFEC362B1C2B21493104F9A
SHA-512:1C09CDE454D41A925A263F3960D3AE4AE43C17FC6BEFF6BFB10C57BA03A8BB9FB061720C81472D0E8B6213D6ECC19CBD0BBAC164BE2A01B4D31BAB7D133F22D6
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:08.130891(-0500)[408:2920] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.230056076454252
Encrypted:false
SSDEEP:
MD5:E87DBEC5AC82F6D9270ACF6D22EC013D
SHA1:089A122F4F3BECB3E5389C6F6734167403F08029
SHA-256:6FDE19D927234A8208039DA202B97B68E068358996A8F265DD08529BAB75530F
SHA-512:7AB4257240982E45447C3511195F34646BF0492C64D0986049009E0A59A8D6AB810388C180959A9CCAD640362526C51F0F84D249DAA0955D64EB264655052482
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:08.786609(-0500)[5464:5940] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):164
Entropy (8bit):5.2056666011729
Encrypted:false
SSDEEP:
MD5:C4C9A5BCD3567988EF71F02854214BC2
SHA1:0FCB65609B8172F2AA013F20BE28F7FE2BE5B994
SHA-256:04E15DDE0513A6D5C5A0432C1195AD4E34539DDCCA78CEC5AD9CEA7F651136F5
SHA-512:C057E46F4277B4783E941F3F364645AED217162AC89FF7A78307FAC0D935264B781F950D1EF2007F898B3F508DA43AD13255E008792E97A6AF26100713F2ECFD
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:09.695508(-0500)[1788:400] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):165
Entropy (8bit):5.259013501232844
Encrypted:false
SSDEEP:
MD5:BFA65329C4664014788F2B4B5D9A734F
SHA1:BD8D32E0852E19BAF16D17B6B9BA0B2D56F46AEC
SHA-256:A7E828347056E307E05EA7C4367C4318C41C2A0AFF729D0A39E143B6D15DD0B1
SHA-512:661DD081C1ED6C1D7E1DB9CC18B72732924B1B5E53BD3D0C629622265DF51173C4E7ECE34843506A8AA792028570A2BA4FF0A44B8AE2A415E84654622E92F0F7
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:10.351785(-0500)[6748:6696] ERR ZSARegistryInterfaceImpl::getValue: failed for Registry: SOFTWARE\Zscaler Inc.\Zscaler\SID, Error: 2..Stderr reset..
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):60462
Entropy (8bit):5.101194912004142
Encrypted:false
SSDEEP:
MD5:F62DD6CE51E19349EC1D1F2E88C4EF4D
SHA1:60BD29538B4FECAF527BA8B7D92B7F32D2E72DDB
SHA-256:BE88244DA9FAAA6636A9D2F4C4249C08066A0B48359690B9B27A2B9ED47E093D
SHA-512:BA68A59427EC252B895E1C3D6879E0C7A010893D23B5A8687CE86D738FAAEC1367F73ABBCF63FB8CE8B95D32AFA3049CD59F22F0BC5A2FF2A3B123A54FE02012
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....Q\....O.....& .....@...,................hf.............................P.......p........ ........................................./.......................................x........................... ...(.......................p............................text....?.......@.................. .P`.data........P.......F..............@.p..rdata.......`.......H..............@.p@.pdata...............Z..............@.0@.xdata...............^..............@.0@.bss....0.............................p..edata../............b..............@.0@.idata...............d..............@.0..CRT....X............l..............@.@..tls....h............n..............@.`..reloc..x............p..............@.0B/4......P............r..............@.PB/19..................t..............@..B/31.......... ......................@..B/45..........0......................@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):128664
Entropy (8bit):5.914596539398763
Encrypted:false
SSDEEP:
MD5:053A60F34C75CA0A4A821B46EAE86D31
SHA1:EBCF9F84A393969655969C248C2D572D7A05541C
SHA-256:683F19A461948F4CCA2FBECE26949B34D6347DFF279EFECE983B9F64A868422C
SHA-512:346C989EF320079B5978678264059AD9E545081DDED233D10DCA73A72906FA01DF30A3C96F6D319EFCEA64C198EF409748E511DAB8A4D43E1FA7AF50ED3F0256
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...o.Q\.p........& .........z.................f.............................0................ .........................................i.......|............`.............................................. ...(...................................................text............................... .P`.data...............................@.`..rdata..0W.......X..................@.p@.pdata.......`.......:..............@.0@.xdata.......p.......B..............@.0@.bss..................................p..edata..i............J..............@.0@.idata..|............L..............@.0..CRT....X............T..............@.@..tls....h............V..............@.`..reloc...............X..............@.0B/4......P............Z..............@.PB/19..................\..............@..B/31..................j..............@..B/45..................l..............@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):55263
Entropy (8bit):4.928828205790685
Encrypted:false
SSDEEP:
MD5:2C8F6A964CA7761122F7DA22042462F4
SHA1:290E48BF0F83B3F3832F69BB1EA0637ED4D8CCCA
SHA-256:9D6F2629AA5978DD6B87FE9BCE77A5CF0135B8DA2980A050579EB4E23A92F8FA
SHA-512:88C49DBC5A5CCE28FC61689B953E091DC5114196A9CE5977DE1BC1EA916333D73A13D06ABB56B7AFD88F6C4F80953A2B9B720CD79E773A1246D44B37EAE4CBF8
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....Q\.v..G.....& .....4...&.................c.............................@................ .........................................l.......h............p..................t........................... ...(.......................`............................text....3.......4.................. .P`.data........P.......:..............@.p..rdata..@....`.......<..............@.P@.pdata.......p.......H..............@.0@.xdata...............L..............@.0@.bss..................................p..edata..l............P..............@.0@.idata..h............R..............@.0..CRT....X............Z..............@.@..tls....h............\..............@.`..reloc..t............^..............@.0B/4......P............`..............@.PB/19..................b..............@..B/31..................p..............@..B/45.......... .......r..............@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):131145
Entropy (8bit):5.193951180687598
Encrypted:false
SSDEEP:
MD5:1EBC6771762F78019131C13039E82932
SHA1:37C57DBDCE9530F5E1F230C211BEE78A6C1A9927
SHA-256:1EFA623B990D8505F01D4AFD67B7E1E5BDECC03420B730CD3C85CD4A84BDF001
SHA-512:069B9ED6427951383B86AAB3ED0DE05D102B2A6E30AFB18BC875B59EFD2F9D44CD85109D6C316C01C25D92F454385CC67CC6B1E48D5E79C2EE387951D81486F0
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......d.~........& .....B...,.................b.............................`............@... .........................................g................................................................... ...(.......................H............................text....A.......B.................. .P`.data...P....`.......H..............@.p..rdata.......p.......L..............@.`@.pdata...............X..............@.0@.xdata...............\..............@.0@.bss..................................p..edata..g............`..............@.0@.idata...............b..............@.0..CRT....X............n..............@.@..tls....h............p..............@.`..reloc...............r..............@.0B/4...................t..............@..B/19..................x..............@..B/31.....K...........................@..B/45..................$..............@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):18944
Entropy (8bit):5.006005905937146
Encrypted:false
SSDEEP:
MD5:6D2C718C3059CEAA7B90919E6725A09A
SHA1:489967F8FE2B9021A891112754B840FE7DC71D13
SHA-256:2CA70BC6394EE1B299A8CF1FE28E95C7D68B765E1828DB1B651A7A62ACAE5356
SHA-512:37547E9C6080D0DCB3EA23D9C856CE689997275B40D72BF9FD7C7C165E8CEE4AFE2EBE52E052C5F8BFC3E618391425219E9681191EE6F650444EBD643CB5A50D
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....$...F.................p....................................y7....`... .........................................I....................`..d...............l........................... ...(...................................................text...h#.......$..................`.P`.data...h....@.......(..............@.P..rdata.......P.......*..............@.P@.pdata..d....`.......4..............@.0@.xdata.......p.......8..............@.0@.bss....`.............................`..edata..I............:..............@.0@.idata...............<..............@.0..CRT....X............D..............@.@..tls....h............F..............@.`..reloc..l............H..............@.0B........................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):183734
Entropy (8bit):5.623100191295644
Encrypted:false
SSDEEP:
MD5:79B690260195499E756CEE3DBE0CB1E2
SHA1:2D1C8918C67EBD63136D71B6AA0217E4B63FFAD6
SHA-256:3ED71920D5D23234F694BD2CD73BA3B477E2BD899BF695CA328CA66615271285
SHA-512:6246273E0D155F2820353FC376255EF2A51514BA062044EF6AA100A513CD2768B9E8841A6885180F0E4200E9D2947B29B2248D212DC39E32AEA4906501C3CE6F
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...>..d.B........& .........@.................n............................. ............@... ......................................p..w....................@.............................................. ...(...................................................text............................... .P`.data...............................@.p..rdata..0.... ......................@.P@.pdata.......@......................@.0@.xdata.......P......................@.0@.bss....0....`........................p..edata..w....p.......(..............@.0@.idata...............*..............@.0..CRT....X............2..............@.@..tls....h............4..............@.`..reloc...............6..............@.0B/4...................8..............@..B/19..................<..............@..B/31.....K....p......................@..B/45.................................@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):98608
Entropy (8bit):5.526395383526755
Encrypted:false
SSDEEP:
MD5:9B299884420745D80C70BBA6B8A7F05A
SHA1:195423185A7776E072A65FBABAE868C15F7B2F56
SHA-256:9426E96A97F41645FAB524385A852687792F99B505554B6B9809ED99451B2399
SHA-512:ED839DC1B6EF53F3663B6055FB2869A522600B2AF8D8A800958DDB531154F4E9A3F1733F32DFF5511A22FE01525191C8683519CBDCEDEC138B1BCF3425F2155B
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....Q\....0.....& .........P.................f............................................. .............................................. ..................x............P.............................. @..(....................!..x............................text............................... .P`.data...............................@.p..rdata.. ...........................@.P@.pdata..x...........................@.0@.xdata..............................@.0@.bss..................................p..edata..............................@.0@.idata....... ......................@.0..CRT....X....0......................@.@..tls....h....@......................@.`..reloc.......P......................@.0B/4......P....`......................@.PB/19..........p......................@..B/31.................................@..B/45.................................@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):241448
Entropy (8bit):5.119290538404736
Encrypted:false
SSDEEP:
MD5:51C675FC1EF0A62322052D3E86567C06
SHA1:E295D0B668105D81F9180EF1056D0528E4B2116A
SHA-256:AAA3D7E589E9BE1911EEE5974AFA68C64AF1BBD5E039FF6A82A15C2B54C0F9F0
SHA-512:A352E82DB5C930C73165A48337AE51ACDA7EBD393B8B0B57D03D2E1B5057C41C26B1F321759B7BC521166890853ECDAD7B37531212243AD86E181E2252A3B78D
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...~.Q\..........& ....."....................Xl.............................................. .........................................]....................................0..h........................... ..(.......................`............................text.... .......".................. .P`.data...P....@.......(..............@.P..rdata...m...P...n...*..............@.P@.pdata..............................@.0@.xdata..............................@.0@.bss..................................p..edata..]...........................@.0@.idata..............................@.0..CRT....X...........................@.@..tls....h.... ......................@.`..reloc..h....0......................@.0B/4......P....@......................@.PB/19..........P......................@..B/31..........`......................@..B/45..........p......................@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):19456
Entropy (8bit):4.855136950572863
Encrypted:false
SSDEEP:
MD5:A56543B9CD3AA403311B49189D25851E
SHA1:BD2609D35D4A967FE23EF4092B1DAA6F74A858AD
SHA-256:034756F772399552CD33605A189EE0E45D7947860E0D83EC12AA6DA1A5A42054
SHA-512:2237F493D70799675AE0E395F551B6CD46FF4789E46E2453C48FEDE07B7623B4B8111904D6FA139C204EEA4405B5FD5812B0A91F27374219B721339149C25EDF
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...Q..]...........".....&...".................l.............................................. ..............................................................`..p...............d........................... ...(.......................H............................text....$.......&.................. .P`.data........@.......*..............@.`..rdata..0....P.......,..............@.p@.pdata..p....`.......4..............@.0@.xdata.......p.......8..............@.0@.bss..................................p..edata...............<..............@.0@.idata...............>..............@.0..CRT....X............F..............@.@..tls....h............H..............@.`..reloc..d............J..............@.0B........................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):54306
Entropy (8bit):4.798541373874198
Encrypted:false
SSDEEP:
MD5:4640FD47F64BB72CB34DBAFEE65DBDDE
SHA1:508C8713E06BA55588D41918C5A99308CB4B37A0
SHA-256:F02C4352EA80E1B476EB4754455AE684EFB4289D95EDF925E38BD3789F6EAD49
SHA-512:DE2D05EA66AB37B7120CDE8F4AEB79C6365430BD94F56B07019451E1329F8F3A2674AF9ED6677B8ADE59FA2185C6A48EAEAD47091EDC8284E686260C69544A4C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....Q\.p..].....& .....,...(.................c.............................@................ .........................................c.......,............`.............................................. ...(.......................P............................text...0*.......,.................. .P`.data...`....@.......2..............@.P..rdata.......P.......4..............@.p@.pdata.......`.......B..............@.0@.xdata..t....p.......F..............@.0@.bss..................................p..edata..c............J..............@.0@.idata..,............L..............@.0..CRT....X............T..............@.@..tls....h............V..............@.`..reloc...............X..............@.0B/4......P............Z..............@.PB/19..................\..............@..B/31..................j..............@..B/45.......... .......l..............@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):365056
Entropy (8bit):6.18264633495016
Encrypted:false
SSDEEP:
MD5:C3C4F3FE90E3B3B02BEA0E8DA3447ED2
SHA1:7AC0F54119D2273A2CD261F1FE6C5667E9C486DF
SHA-256:3524EC77985E390ACF9D07D81B1B44305165D711BBCA770F7458EA0A78751F82
SHA-512:0E24C9394C635A3F1671A297F97B613E6936CD8F862A214125D3456324A18668AE138D5C4FDE036F55E2B13B158E4CEBC53F78153862A008B1AE747EAB228A60
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&pq.b...b...b.....b.`.....d.S...b.........r._.....e.c.....c.c.....g.c...Richb...........................PE..d...)U.N.........." ................@...............................................................................................py......./..........H............................5............................................... ..h............................text............................... ..`.rdata..;e... ...f..................@..@.data................l..............@....pdata...............p..............@..@.rsrc...H...........................@..@.reloc..$...........................@..B........................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):223794
Entropy (8bit):5.987297584654645
Encrypted:false
SSDEEP:
MD5:7190ECF05EC3B297D6DED3E204399E95
SHA1:5C085CBBBCC8686266ACFB318E75A38794625E88
SHA-256:49E2C502923DE5F89958DE86F1CC6F91E7DDAFE46D0F81BFB51A669627650E6E
SHA-512:4E12ADCAAEBDC08E06270437DD4EBF33C4AECD5B6CCE7245BF12B0303C809465D75D5B319FB262A807CF9A5CB99D808E466FC30B19D88DDCF2B3F0B9C9F74881
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...z.Q\..........& ...........................j....................................Z......... .........................................g....................................0.............................. ..(....................................................text...P........................... .P`.data........ ......................@.P..rdata...P...0...R..................@.p@.pdata...............\..............@.0@.xdata...............p..............@.0@.bss..................................p..edata..g...........................@.0@.idata..............................@.0..CRT....X...........................@.@..tls....h.... ......................@.`..reloc.......0......................@.0B/4......P....@......................@.PB/19..........P......................@..B/31..........`......................@..B/45..........p......................@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):202816
Entropy (8bit):5.710869134395079
Encrypted:false
SSDEEP:
MD5:78B6849A39C4B2767F15F427ADF6032C
SHA1:9B721D2FC6676381BF7A857412DA97A40BC3D1BD
SHA-256:99C45F2615AF1B1CA375528CE70D5D50F4F9A160A139A2C2B5A8685C51638465
SHA-512:A0377CA1138AF2526AB14054D092584E2195DF90C39F6275EAB7F80FBF0639DD4318418DC18A7C0F495DC93D40882B2398D460C96ECCC3B71F8FE10FA0AC491F
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...L..d....$.....& .........n.................q.............................@......n......... ..............................................................`..P........................................... ...(.......................x............................text............................... .P`.data........ ......................@.p..rdata...$...0...&...&..............@.p@.pdata..P....`.......L..............@.0@.xdata.......p.......X..............@.0@.bss..................................p..edata...............f..............@.0@.idata...............v..............@.0..CRT....X............~..............@.@..tls....h...........................@.`..reloc..............................@.0B/4..................................@..B/19.....Q...........................@..B/31.................................@..B/45.....W............0..............@..B/57.....
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):525312
Entropy (8bit):6.326337067953554
Encrypted:false
SSDEEP:
MD5:5FBC6BD806A8A6C460FACEEEA73BD7F7
SHA1:4D1586A9631A72C3E1D75FB3C385DBD278804665
SHA-256:8033D1B3AF84D47D275E022608DA35BAAC16CF40D9607CA026A47B6CD65E6A97
SHA-512:4C51F9F331AC15206942E13504334B4C3549888519388607C44B617A68A9095114B0E6127E82B84170445DF06260CC62308BC197B90CFB95AF18D7CB6D413195
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....$....... .............g.....................................q........ ......................................@..=....P..4...............\...............,........................... p..(....................R..X............................text....#.......$.................. .P`.data....A...@...B...(..............@.p..rdata...8.......:...j..............@.p@.pdata..\........ ..................@.0@.xdata..`!......."..................@.0@.bss......... ........................p..edata..=....@......................@.0@.idata..4....P......................@.0..CRT....X....`......................@.@..tls....h....p......................@.`..reloc..,...........................@.0B........................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):2882876
Entropy (8bit):5.997730582092785
Encrypted:false
SSDEEP:
MD5:A3F40A0E5DB219350A381015AEB90B19
SHA1:835BFC9A8C125EB235B230630D54E72FB2515592
SHA-256:086F4C38C0ABDBC15B1755A1D422CD1B5490241A070BB208B7E9B5300927369B
SHA-512:3053E5F387BF8963359B236F8CF12C0FAAD589C014504C9F04F44311EFB17BA206E53F3545F1B8333C85B4823DA3EF5B194BAA197ABF08E3DD41A59249219552
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........+.......&"..........+..L............pj.............................P,.......,...@... .......................................+.M.....+.............. (.\.............+.h_.......................... .+.(...................H.+..............................text...............................`.P`.data... ...........................@.p..rdata.. ............z..............@.p@.pdata..\.... (.......'.............@.0@.xdata..t.....).......).............@.0@.bss.....J...P+.......................p..edata..M.....+......(+.............@.0@.idata........+......*+.............@.0..CRT....X.....+......D+.............@.@..tls....h.....+......F+.............@.`..reloc..h_....+..`...H+.............@.0B........................................................................................................................................................................
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):16561
Entropy (8bit):5.3333822922807474
Encrypted:false
SSDEEP:
MD5:B3D62A19C2166086556804FB7659651F
SHA1:360ABB68EADD31598DE6ECF3D9A091BEC0F7C942
SHA-256:A674A23D330EE55E21A84911A650D9EEFD8944AC285599ED1EB2302646B4E5C8
SHA-512:D073C481A65B686B6AE5CA9B2C706FB5B7239AD9D2807DE19A36F9A6C1700576FAEA0472047D2CD06459C7320C8F0489D1FF957CE949BFD3D31E460003D38E85
Malicious:false
Reputation:unknown
Preview:Log started 11/12/2024 at 03:19:43..Preferred installation mode : win32..Trying to init installer in mode win32..Mode win32 successfully initialized..[03:19:46] Windows OS Name: Windows 10..[03:19:46] Windows OS Version: 10.0..[03:19:46] WindowsBuildNumber: 19045..[03:19:46] Installer PID: 7048..[03:19:46] Package Version: 4.4.0.309..[03:19:46] Package Architecture: x64..[03:19:46] Installed Package Version: 0.0.0.0..[03:19:46] Installed Package Architecture: 0..[03:19:46] Installed Package Location: ***unknown variable installedlocation***..[03:19:46] Processor_architecture: AMD64..[03:19:46] Package Version Split: 4.4.0.309..[03:19:46] Installed Version Split: 0.0.0.0..[03:19:46] isDowngrade: false..[03:19:46] is32to64bitUpgrade: false..[03:19:46] 3.4 autoUpgrade scenario check: Skipping as installed version is 0.0.x..[03:19:46] enableFipsOld: ***unknown variable enablefipsold***, Zscaler-windows-4.4.0.309-installer-x64.exe..[03:19:46] enableFips: 0..[03:19:46] Installed version of Z
Process:C:\Program Files\Zscaler\ZSAService\ZSAService.exe
File Type:ASCII text, with very long lines (375), with CRLF line terminators
Category:dropped
Size (bytes):3073
Entropy (8bit):5.405726802361476
Encrypted:false
SSDEEP:
MD5:CEABE65F734311E546E10935FB592D0E
SHA1:89F7D98F7DB832476699BB797DFCBDA8630F8D1C
SHA-256:DC5B613A161CECE6B4F71E097B1309360DACA250AF4B3BDFBA17EB1ED19549F8
SHA-512:542D7F7428A78AE24CA9C4A5C4922101BC2F2A6555DC99D86A6610ED083808456F3496536BF95529AAA737B838D3B6650C2D90FBF2F82284EC9CBA7CD8E48E85
Malicious:false
Reputation:unknown
Preview:Redirected stderr..2024-11-12 08:19:58.619595(-0500)[1092:5992] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:19:58.619595(-0500)[1092:5992] INF ZSAService App Version: 4.4.0.309..2024-11-12 08:19:58.619595(-0500)[1092:5992] INF ZSAService Architecture: x64..2024-11-12 08:19:58.619595(-0500)[1092:5992] INF ZSAService GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:19:58.619595(-0500)[1092:5992] INF UPM Hard Protocol Version: 28..2024-11-12 08:19:58.619595(-0500)[1092:5992] INF UPM Soft Protocol Version: 900..2024-11-12 08:19:58.619595(-0500)[1092:5992] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:19:58.619595(-0500)[1092:5992] INF Performing op: -pushCert..2024-11-12 08:19:58.619595(-0500)[1092:5992] INF Installing Zscaler driver certificate..2024-11-12 08:19:58.745576(-0500)[1092:5992] INF Certificate Info: serialNumber: 0DA893C39FF930AEA038A0EDB1B42176, issuer:
Process:C:\Program Files\Zscaler\ZSATray\ZSATray.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):3742
Entropy (8bit):5.381227381904072
Encrypted:false
SSDEEP:
MD5:062DCF9CAC41646B0948CD3C553F3E59
SHA1:B8E665056F673226613EA2959F5D45391E4C5D5E
SHA-256:5323C5F39D3F30475301883959F1C19BD08C1FCF3CB8004AC0706CC5C553B993
SHA-512:F83ADE0B8722ABDBD937D681AEA4BBEAC345FBBF9018A0DB3D343DEBBD71F2AE770BF37605E3CD51612C21003B885217E20CE21578DD3BC9292B0120E1008AEB
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:51.622839(-0500)[3484:6140] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:51.622839(-0500)[3484:6140] INF ZSATrayHelper App Version: 4.4.0.309..2024-11-12 08:20:51.622839(-0500)[3484:6140] INF ZSATrayHelper Architecture: x64..2024-11-12 08:20:51.622839(-0500)[3484:6140] INF ZSATrayHelper GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:51.622839(-0500)[3484:6140] INF x64 BINARY (Supports both gov and commercial clouds)..2024-11-12 08:20:51.846819(-0500)[3484:6140] INF Security: checking signature of ZSAService..2024-11-12 08:20:51.846819(-0500)[3484:6140] DBG Security: trying to start a Zscaler service: 'ZSAService', install location and checking signature.....2024-11-12 08:20:51.846819(-0500)[3484:6140] DBG Security: binary path: 'C:\Program Files\Zscaler\ZSAService\ZSAService.exe'..2024-11-12 08:20:51.846819(-0500)[3484:6140] DBG Security: verifying the install path.
Process:C:\Program Files\Zscaler\ZSATray\ZSATray.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):6072
Entropy (8bit):5.349944429939185
Encrypted:false
SSDEEP:
MD5:11D46D9FBFC8A4758456DD4B60AC1D52
SHA1:00AE4F7D10971F00FFC0C7D031B5D344CDC70ED7
SHA-256:452B4DC048DD291819C42F2E08B84DB12897F4A28ECAF490BC20FED3242F5C06
SHA-512:3C1C3833A294D627AFBC7D89B4C80894217F2A34B4FCBFA2FB58BE41168160831C1B34691FA8E0A26C61E1EAC66F21FBBD95E030CF23A7B5D96B4E9AFAE7CBA5
Malicious:false
Reputation:unknown
Preview:2024-11-12 08:20:51.606816(-0500)[3484:6140] INF Timezone: Eastern Standard Time, Offset: -18000, Standard Name: Eastern Standard Time, UTC Offset: -18000..2024-11-12 08:20:51.622839(-0500)[3484:6140] INF ZSATray App Version: 4.4.0.309..2024-11-12 08:20:51.622839(-0500)[3484:6140] INF ZSATray Architecture: x64..2024-11-12 08:20:51.622839(-0500)[3484:6140] INF ZSATray GIT Hash: 5e97356fc940f673806db24755bb01fd2aadf371..2024-11-12 08:20:51.942827(-0500)[3484:6140] INF Main service already running..2024-11-12 08:20:53.042824(-0500)[3484:6140] INF Starting RPC server..2024-11-12 08:20:53.058831(-0500)[3484:6140] INF ZSATray RPC server started..2024-11-12 08:20:53.074821(-0500)[3484:6140] INF Sending process Id: 3484..2024-11-12 08:20:56.046819(-0500)[3484:6140] INF sendZSATrayManagerCommandHelper retVal: STATUS_SUCCESS..2024-11-12 08:20:56.046819(-0500)[3484:6140] INF Process Id sent..2024-11-12 08:20:56.253825(-0500)[3484:6140] INF sendZSATrayManagerCommandHelper retVal: STATUS_SUCCESS..2
Process:C:\Program Files\Windows Defender\MpCmdRun.exe
File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:modified
Size (bytes):4926
Entropy (8bit):3.2468645971038192
Encrypted:false
SSDEEP:
MD5:9BF983DACDEBC9BB173634F9D92F6A40
SHA1:6E0AD885D86C6E93EE103B21FF408C43B8A95EA3
SHA-256:72B5B17293787412D3C1854FCD39D0C148CA48302C040860DF05D52112DB9094
SHA-512:E5B626E64D04E41D51DEE3806415D8FE24597DDE8E182EC19472DB557FCD15D20EE5AB1C1D36370C16BA92B82C9D7352646C1B56CE1E50472B1367E284142481
Malicious:false
Reputation:unknown
Preview:..........-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....M.p.C.m.d.R.u.n.:. .C.o.m.m.a.n.d. .L.i.n.e.:. .".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.m.p.c.m.d.r.u.n...e.x.e.". .-.w.d.e.n.a.b.l.e..... .S.t.a.r.t. .T.i.m.e.:. .. F.r.i. .. O.c.t. .. 0.6. .. 2.0.2.3. .1.1.:.3.5.:.2.9.........M.p.E.n.s.u.r.e.P.r.o.c.e.s.s.M.i.t.i.g.a.t.i.o.n.P.o.l.i.c.y.:. .h.r. .=. .0.x.1.....W.D.E.n.a.b.l.e.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .W.S.C. .S.t.a.t.e. .I.n.f.o. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .A.n.t.i.V.i.r.u.s.P.r.o.d.u.c.t. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....d.i.s.p.l.a.y.N.a.m.e. .=. .[.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.].....p.a.t.h.T.o.S.i.g.n.e.d.P.r.o.d.u.c.t.E.x.e. .=. .[.w.i.n.d.o.w.s.d.
Process:C:\Users\user\Desktop\Zscaler-windows-4.4.0.309-installer-x64.exe
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:9D7AB651EBA49866DCD20CFA938C97FB
SHA1:816EF3ABB4F4A16C300284D090BE2094A48BF0B6
SHA-256:9125A194A07D812BE7653A3D7647880FF779D8902DEFC7404866519A5891E8EB
SHA-512:A3E900AEBD11A7118E06BE1F56B4EE0CE1D24103AED70CFD6095CCF25363E930273347B72FCF3145E8C80D5129489CA03EA3FF900D323C3F52619A0FA937BB9C
Malicious:false
Reputation:unknown
Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.......7...s.{.s.{.s.{...x.x.{...~..{..8..p.{.!.x.z.{.....n.{.!.~..{.!...P.{...r.y.{.....n.{...}.r.{...z.l.{.s.z.g.{...~...{...{.r.{...r.{.s..r.{...y.r.{.Richs.{.........PE..d...o.qf.........." .....&...6................................................/.....H./...`A..........................................).x.....).@....`,.......*......0/..%...p/.$+...i$.T...................Pk$.(...Pj$..............@...............................text....$.......&.................. ..`.rdata..Pb...@...d...*..............@..@.data.........).......).............@....pdata........*......**.............@..@.rsrc........`,.......+.............@..@.reloc..$+...p/..,..../.............@..B........................................................................................................................................................................................................
File type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Entropy (8bit):7.979928611768417
TrID:
  • Win64 Executable (generic) (12005/4) 74.95%
  • Generic Win/DOS Executable (2004/3) 12.51%
  • DOS Executable Generic (2002/1) 12.50%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.04%
File name:Zscaler-windows-4.4.0.309-installer-x64.exe
File size:62'101'792 bytes
MD5:37d6c75390d283f47665db629ebaa626
SHA1:7eaeba97bba91b0c1fcfda9538ced8b813676514
SHA256:bb7f812a83fbbde43ff81b0349dc59b06a226765333817c7157593494fa5e65c
SHA512:653c7ff79f977320f353abd7b301d8059c18358db6f2ee20debab5fbb92c67ac05d693a5963a98079dcaf3fc2ecaf78d27f2888f13bde40ba6f9bdb45e1c0ed5
SSDEEP:1572864:MkNFDhIBK4Ju+NgGA8A3sDJenIUPn5q+ewSs1AoKFbD17:MkNJIzA3kQPn5qwF4l
TLSH:0AD73313D2A210ECC967C17483A7E272B971BC6811307EAF1560FB312F76D919B6E62D
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........................B...,-..@............@...............................-.....M\....@... ............................
Icon Hash:8f0375c2d96d259e
Entrypoint:0x4014d0
Entrypoint Section:.text
Digitally signed:true
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, DEBUG_STRIPPED
DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH
Time Stamp:0xA4F8A4E0 [Sat Sep 15 05:49:20 2057 UTC]
TLS Callbacks:0x5e7cc0
CLR (.Net) Version:
OS Version Major:4
OS Version Minor:0
File Version Major:4
File Version Minor:0
Subsystem Version Major:4
Subsystem Version Minor:0
Import Hash:8c6e3a20ed69c3cf0fd555f92863226b
Signature Valid:true
Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
Signature Validation Error:The operation completed successfully
Error Number:0
Not Before, Not After
  • 19/09/2023 20:00:00 14/07/2026 19:59:59
Subject Chain
  • CN="Zscaler, Inc.", O="Zscaler, Inc.", L=San Jose, S=California, C=US, SERIALNUMBER=4431830, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US
Version:3
Thumbprint MD5:343B234595B99143D2004F638ED19655
Thumbprint SHA-1:E0D9E7B346F24BB06B8E37C8AA2BAA9A0FB16DB3
Thumbprint SHA-256:A29E78E3E6B0525F29F4E521CA58AAAAA8988E90121CAF762638CDAC9B34F36A
Serial:0E138B65C32AD225E42025C5DEB716BC
Instruction
dec eax
sub esp, 28h
dec eax
mov eax, dword ptr [002708C5h]
mov dword ptr [eax], 00000001h
call 00007FD85549752Fh
call 00007FD8552B0C2Ah
nop
nop
dec eax
add esp, 28h
ret
nop word ptr [eax+eax+00000000h]
dec eax
sub esp, 28h
dec eax
mov eax, dword ptr [00270895h]
mov dword ptr [eax], 00000000h
call 00007FD8554974FFh
call 00007FD8552B0BFAh
nop
nop
dec eax
add esp, 28h
ret
nop
nop
nop
nop
nop
nop
nop
nop
nop
nop
nop
nop
nop
nop
mov eax, 00000001h
ret
nop word ptr [eax+eax+00000000h]
push ebx
dec eax
sub esp, 20h
dec eax
mov ebx, ecx
dec eax
mov ecx, dword ptr [ecx+40h]
dec eax
test ecx, ecx
je 00007FD8552B0F67h
call 00007FD85541D70Fh
mov edx, dword ptr [ebx+0Ch]
dec eax
mov ecx, dword ptr [ebx]
dec eax
mov dword ptr [ebx+40h], 00000000h
dec eax
add esp, 20h
pop ebx
jmp 00007FD8553E8E67h
nop
push edi
push esi
push ebx
dec eax
sub esp, 20h
dec eax
mov esi, ecx
dec eax
mov ecx, dword ptr [ecx+18h]
dec eax
mov edi, edx
call 00007FD855400E6Fh
add dword ptr [eax], 01h
dec eax
mov ecx, dword ptr [esi+10h]
dec ecx
mov eax, edi
dec eax
mov edx, eax
dec eax
mov ebx, eax
call 00007FD8552B0F6Ah
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x2a40000x6e.edata
IMAGE_DIRECTORY_ENTRY_IMPORT0x2a50000x4fa8.idata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x2ac0000x2ad78.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x2790000x10638.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x3b373980x2588
IMAGE_DIRECTORY_ENTRY_BASERELOC0x2d70000x6020.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x2ab0200x28.tls
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x2a629c0x1198.idata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x1f41b00x1f420024e911cd2d0d9f0eac7191a1fb21f508False0.5090397322544364data6.229728054867929IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.data0x1f60000x2f9800x2fa00fb52a6367249b9b92154ad60f58ca502False0.13543204560367453dBase III DBT, version number 0, next free block index 10, 1st item "set ::tclKitMkCounter 0"1.7694251031892874IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rdata0x2260000x52ea00x530000b7754b5ea5475777098cbdd6afb8578False0.33064288403614456data5.351728215353662IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
.pdata0x2790000x106380x10800364490ce09c9dde46a825e8ac3d38889False0.5196792140151515data6.165787204861382IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
.xdata0x28a0000x151b40x152000b57031d6c802f58ce1f297c80b90acdFalse0.20305565828402367data4.889247057922903IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
.bss0x2a00000x3f000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.edata0x2a40000x6e0x200765d4d21df1a3050120e3f894e1a03b0False0.19140625data1.3728070899138527IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
.idata0x2a50000x4fa80x50005e8b685053b954081aa3b939d4272081False0.280224609375data4.706020366802908IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.CRT0x2aa0000x680x2008a4f0845d0fd2bed5b84f8f582c9d9fbFalse0.07421875data0.2804011676589459IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.tls0x2ab0000x680x20091d4f699db3f59565e721047890d7f91False0.060546875data0.2044881574398449IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc0x2ac0000x2ad780x2ae007aa7880eec20fa71d41869618406399eFalse0.06780133928571429data2.071592022842992IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.reloc0x2d70000x60200x6200f9a340b111cbe0c630bdaa38c543fcfbFalse0.2861926020408163data5.426028697049459IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_CURSOR0x2ae5e80x134dataEnglishUnited States0.37662337662337664
RT_CURSOR0x2ae71c0x134dataEnglishUnited States0.3961038961038961
RT_CURSOR0x2ae8500x134dataEnglishUnited States0.2694805194805195
RT_CURSOR0x2ae9840x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.24675324675324675
RT_CURSOR0x2aeab80x134dataEnglishUnited States0.25
RT_CURSOR0x2aebec0x134dataEnglishUnited States0.2694805194805195
RT_CURSOR0x2aed200x134dataEnglishUnited States0.32142857142857145
RT_CURSOR0x2aee540x134dataEnglishUnited States0.3246753246753247
RT_CURSOR0x2aef880x134dataEnglishUnited States0.30844155844155846
RT_CURSOR0x2af0bc0x134dataEnglishUnited States0.19480519480519481
RT_CURSOR0x2af1f00x134dataEnglishUnited States0.2694805194805195
RT_CURSOR0x2af3240x134dataEnglishUnited States0.2857142857142857
RT_CURSOR0x2af4580x134dataEnglishUnited States0.3344155844155844
RT_CURSOR0x2af58c0x134dataEnglishUnited States0.45454545454545453
RT_CURSOR0x2af6c00x134dataEnglishUnited States0.3181818181818182
RT_CURSOR0x2af7f40x134dataEnglishUnited States0.2077922077922078
RT_CURSOR0x2af9280x134dataEnglishUnited States0.39935064935064934
RT_CURSOR0x2afa5c0x134dataEnglishUnited States0.17857142857142858
RT_CURSOR0x2afb900x134dataEnglishUnited States0.37012987012987014
RT_CURSOR0x2afcc40x134dataEnglishUnited States0.22402597402597402
RT_CURSOR0x2afdf80x134dataEnglishUnited States0.21428571428571427
RT_CURSOR0x2aff2c0x134dataEnglishUnited States0.33766233766233766
RT_CURSOR0x2b00600x134dataEnglishUnited States0.37987012987012986
RT_CURSOR0x2b01940x134dataEnglishUnited States0.37662337662337664
RT_CURSOR0x2b02c80x134dataEnglishUnited States0.3409090909090909
RT_CURSOR0x2b03fc0x134dataEnglishUnited States0.4090909090909091
RT_CURSOR0x2b05300x134dataEnglishUnited States0.37662337662337664
RT_CURSOR0x2b06640x134dataEnglishUnited States0.3181818181818182
RT_CURSOR0x2b07980x134dataEnglishUnited States0.4155844155844156
RT_CURSOR0x2b08cc0x134dataEnglishUnited States0.38311688311688313
RT_CURSOR0x2b0a000x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"EnglishUnited States0.44155844155844154
RT_CURSOR0x2b0b340x134dataEnglishUnited States0.41233766233766234
RT_CURSOR0x2b0c680x134dataEnglishUnited States0.21428571428571427
RT_CURSOR0x2b0d9c0x134dataEnglishUnited States0.3116883116883117
RT_CURSOR0x2b0ed00x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.33766233766233766
RT_CURSOR0x2b10040x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.3051948051948052
RT_CURSOR0x2b11380x134dataEnglishUnited States0.19480519480519481
RT_CURSOR0x2b126c0x134dataEnglishUnited States0.21428571428571427
RT_CURSOR0x2b13a00x134Targa image data - Mono - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.19480519480519481
RT_CURSOR0x2b14d40x134Targa image data - Mono - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.19155844155844157
RT_CURSOR0x2b16080x134dataEnglishUnited States0.4383116883116883
RT_CURSOR0x2b173c0x134dataEnglishUnited States0.21428571428571427
RT_CURSOR0x2b18700x134dataEnglishUnited States0.33766233766233766
RT_CURSOR0x2b19a40x134dataEnglishUnited States0.37987012987012986
RT_CURSOR0x2b1ad80x134dataEnglishUnited States0.4318181818181818
RT_CURSOR0x2b1c0c0x134dataEnglishUnited States0.18506493506493507
RT_CURSOR0x2b1d400x134dataEnglishUnited States0.37662337662337664
RT_CURSOR0x2b1e740x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.35064935064935066
RT_CURSOR0x2b1fa80x134dataEnglishUnited States0.2922077922077922
RT_CURSOR0x2b20dc0x134dataEnglishUnited States0.19480519480519481
RT_CURSOR0x2b22100x134dataEnglishUnited States0.19805194805194806
RT_CURSOR0x2b23440x134dataEnglishUnited States0.2824675324675325
RT_CURSOR0x2b24780x134dataEnglishUnited States0.32142857142857145
RT_CURSOR0x2b25ac0x134dataEnglishUnited States0.262987012987013
RT_CURSOR0x2b26e00x134dataEnglishUnited States0.288961038961039
RT_CURSOR0x2b28140x134dataEnglishUnited States0.2435064935064935
RT_CURSOR0x2b29480x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.2435064935064935
RT_CURSOR0x2b2a7c0x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.24675324675324675
RT_CURSOR0x2b2bb00x134dataEnglishUnited States0.3116883116883117
RT_CURSOR0x2b2ce40x134dataEnglishUnited States0.36038961038961037
RT_CURSOR0x2b2e180x134dataEnglishUnited States0.32792207792207795
RT_CURSOR0x2b2f4c0x134dataEnglishUnited States0.37337662337662336
RT_CURSOR0x2b30800x134dataEnglishUnited States0.2597402597402597
RT_CURSOR0x2b31b40x134dataEnglishUnited States0.4512987012987013
RT_CURSOR0x2b32e80x134dataEnglishUnited States0.36688311688311687
RT_CURSOR0x2b341c0x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.18831168831168832
RT_CURSOR0x2b35500x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.38311688311688313
RT_CURSOR0x2b36840x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.3181818181818182
RT_CURSOR0x2b37b80x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.32142857142857145
RT_CURSOR0x2b38ec0x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.30194805194805197
RT_CURSOR0x2b3a200x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.19480519480519481
RT_CURSOR0x2b3b540x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.3409090909090909
RT_CURSOR0x2b3c880x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.18831168831168832
RT_CURSOR0x2b3dbc0x134dataEnglishUnited States0.3246753246753247
RT_CURSOR0x2b3ef00x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.18831168831168832
RT_CURSOR0x2b40240x134dataEnglishUnited States0.288961038961039
RT_CURSOR0x2b41580x134dataEnglishUnited States0.24025974025974026
RT_CURSOR0x2b428c0x134dataEnglishUnited States0.12012987012987013
RT_BITMAP0x2b43c00x340Device independent bitmap graphic, 52 x 26 x 4, image size 728EnglishUnited States0.40625
RT_ICON0x2b47000x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States0.062529522909778
RT_ICON0x2b89280x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.13215767634854772
RT_ICON0x2baed00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.12148217636022514
RT_ICON0x2bbf780x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.22074468085106383
RT_DIALOG0x2bc3e00x23adataEnglishUnited States0.5421052631578948
RT_GROUP_CURSOR0x2bc61a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
RT_GROUP_CURSOR0x2bc62e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc6420x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc6560x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc66a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc67e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc6920x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc6a60x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc6ba0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc6ce0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc6e20x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc6f60x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc70a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc71e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc7320x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc7460x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc75a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc76e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc7820x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc7960x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc7aa0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc7be0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc7d20x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc7e60x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc7fa0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc80e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc8220x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc8360x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc84a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc85e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc8720x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
RT_GROUP_CURSOR0x2bc8860x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc89a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc8ae0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc8c20x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc8d60x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc8ea0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc8fe0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc9120x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc9260x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc93a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc94e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc9620x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc9760x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc98a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc99e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc9b20x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc9c60x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc9da0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bc9ee0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bca020x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bca160x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bca2a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bca3e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bca520x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bca660x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bca7a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bca8e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcaa20x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcab60x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcaca0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcade0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcaf20x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcb060x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
RT_GROUP_CURSOR0x2bcb1a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcb2e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcb420x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcb560x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcb6a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcb7e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcb920x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcba60x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcbba0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcbce0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcbe20x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcbf60x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_CURSOR0x2bcc0a0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
RT_GROUP_CURSOR0x2bcc1e0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
RT_GROUP_ICON0x2bcc320x3edataEnglishUnited States0.8387096774193549
RT_VERSION0x2bcc700x310dataEnglishUnited States0.45535714285714285
RT_MANIFEST0x2bcf800x79fXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.38185545873910814
RT_MANIFEST0x2bd71f0x79fXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.38185545873910814
DLLImport
ADVAPI32.dllConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorOwner, GetSidIdentifierAuthority, GetUserNameA, GetUserNameW, InitializeSecurityDescriptor, RegCloseKey, RegOpenKeyExA, RegOpenKeyExW, RegQueryValueExA
COMCTL32.dllInitCommonControlsEx
comdlg32.dllChooseColorA, CommDlgExtendedError, GetOpenFileNameA, GetOpenFileNameW, GetSaveFileNameA, GetSaveFileNameW
GDI32.dllArc, BitBlt, Chord, CombineRgn, CreateBitmap, CreateCompatibleBitmap, CreateCompatibleDC, CreateDCA, CreateDIBSection, CreateDIBitmap, CreateFontIndirectA, CreateFontIndirectW, CreatePalette, CreatePatternBrush, CreatePen, CreateRectRgn, CreateRectRgnIndirect, CreateSolidBrush, DPtoLP, DeleteDC, DeleteObject, EnumFontFamiliesA, EnumFontFamiliesW, ExtCreatePen, ExtTextOutA, GetBkMode, GetCharWidthA, GetCharWidthW, GetDIBits, GetDeviceCaps, GetFontData, GetMapMode, GetNearestColor, GetNearestPaletteIndex, GetObjectA, GetPaletteEntries, GetPixel, GetRgnBox, GetStockObject, GetTextCharset, GetTextExtentPoint32A, GetTextExtentPoint32W, GetTextExtentPointA, GetTextFaceA, GetTextFaceW, GetTextMetricsA, OffsetClipRgn, PatBlt, Pie, Polygon, Polyline, RealizePalette, RectInRegion, Rectangle, ResizePalette, SelectClipRgn, SelectObject, SelectPalette, SetBkColor, SetBkMode, SetBrushOrgEx, SetMapMode, SetPaletteEntries, SetPolyFillMode, SetROP2, SetRectRgn, SetTextAlign, SetTextColor, StretchDIBits, TextOutA, TextOutW, TranslateCharsetInfo, UpdateColors
IMM32.dllImmGetCompositionStringA, ImmGetCompositionStringW, ImmGetContext, ImmReleaseContext, ImmSetCompositionWindow
KERNEL32.dllBuildCommDCBA, BuildCommDCBW, ClearCommError, CloseHandle, CopyFileA, CopyFileW, CreateDirectoryA, CreateDirectoryW, CreateEventA, CreateFileA, CreateFileMappingA, CreateFileW, CreatePipe, CreateProcessA, CreateProcessW, CreateSemaphoreW, CreateThread, DeleteCriticalSection, DeleteFileA, DeleteFileW, DeviceIoControl, DuplicateHandle, EnterCriticalSection, EscapeCommFunction, ExitProcess, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW, FindResourceA, FlushFileBuffers, FormatMessageA, FreeLibrary, GetACP, GetCommModemStatus, GetCommState, GetComputerNameA, GetComputerNameW, GetConsoleCP, GetConsoleMode, GetCurrentDirectoryA, GetCurrentDirectoryW, GetCurrentProcess, GetCurrentProcessId, GetCurrentThread, GetCurrentThreadId, GetEnvironmentVariableW, GetExitCodeProcess, GetExitCodeThread, GetFileAttributesA, GetFileAttributesW, GetFileInformationByHandle, GetFileType, GetFullPathNameA, GetFullPathNameW, GetLastError, GetLocaleInfoA, GetLogicalDriveStringsA, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleA, GetModuleHandleW, GetOverlappedResult, GetPrivateProfileStringA, GetProcAddress, GetProcessHeap, GetShortPathNameA, GetShortPathNameW, GetStartupInfoA, GetStdHandle, GetSystemDirectoryW, GetSystemInfo, GetSystemTimeAsFileTime, GetTempFileNameA, GetTempFileNameW, GetTempPathA, GetTempPathW, GetTickCount, GetTimeZoneInformation, GetVersion, GetVersionExA, GetVolumeInformationA, GetVolumeInformationW, GetWindowsDirectoryA, GetWindowsDirectoryW, GlobalAlloc, GlobalLock, GlobalUnlock, HeapAlloc, HeapFree, InitializeCriticalSection, IsDBCSLeadByte, LeaveCriticalSection, LoadLibraryA, LoadLibraryExA, LoadLibraryExW, LoadResource, LocalFree, LockResource, MapViewOfFile, MoveFileA, MoveFileW, MulDiv, MultiByteToWideChar, OutputDebugStringA, PeekConsoleInputA, PeekNamedPipe, PurgeComm, QueryPerformanceCounter, QueryPerformanceFrequency, RaiseException, ReadConsoleA, ReadConsoleW, ReadFile, ReleaseSemaphore, RemoveDirectoryA, RemoveDirectoryW, ResetEvent, RtlAddFunctionTable, RtlCaptureContext, RtlLookupFunctionEntry, RtlUnwindEx, RtlVirtualUnwind, SearchPathA, SearchPathW, SetCommState, SetCommTimeouts, SetConsoleMode, SetCurrentDirectoryA, SetCurrentDirectoryW, SetEndOfFile, SetEnvironmentVariableW, SetErrorMode, SetEvent, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime, SetHandleInformation, SetLastError, SetThreadPriority, SetUnhandledExceptionFilter, SetupComm, Sleep, TerminateProcess, TerminateThread, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, UnhandledExceptionFilter, UnmapViewOfFile, VirtualProtect, VirtualQuery, WaitForMultipleObjects, WaitForSingleObject, WaitForSingleObjectEx, WideCharToMultiByte, WriteConsoleA, WriteConsoleW, WriteFile, lstrcpyA, lstrcpyW, lstrcpynA, lstrlenA, lstrlenW
msvcrt.dll__C_specific_handler, __argc, __argv, __dllonexit, __getmainargs, __initenv, __iob_func, __lconv_init, __set_app_type, __setusermatherr, _acmdln, _amsg_exit, _beginthreadex, _cexit, _ctime64, _endthreadex, _environ, _errno, _fdopen, _fileno, _fmode, _ftime64, _get_osfhandle, _gmtime64, _initterm, _localtime64, _lock, _mktime64, _onexit, _open, _stricmp, _strnicmp, _strtoi64, _time64, _unlock, _vsnwprintf, _wcsicmp, _wopen, abort, acos, asin, atan, atan2, atoi, calloc, cosh, exit, fclose, ferror, fflush, fprintf, fputc, fputs, fread, free, frexp, fseek, ftell, fwrite, getenv, isalnum, isalpha, islower, isprint, isspace, isupper, isxdigit, localeconv, log10, malloc, memcmp, memcpy, memmove, memset, printf, puts, qsort, rand_s, realloc, setlocale, signal, sinh, sprintf, sscanf, strcat, strchr, strcmp, strcpy, strcspn, strerror, strlen, strncmp, strncpy, strpbrk, strrchr, strspn, strstr, strtol, strtoul, tan, tanh, tolower, toupper, vfprintf, vsprintf, wcschr, wcscmp, wcscpy, wcslen, wcsncmp, wcsncpy, _timezone, _hypot, _write, _tzset, _strnicmp, _stricmp, _strdup, _putenv, _isatty, _getpid
ole32.dllCreateBindCtx, CreateErrorInfo, CreateFileMoniker, GetRunningObjectTable, SetErrorInfo
OLEAUT32.dllSysAllocString, SysFreeString, VariantChangeType, VariantClear, VariantInit
SHELL32.dllSHBrowseForFolderA, SHBrowseForFolderW, SHGetDesktopFolder, SHGetMalloc, SHGetPathFromIDListA, SHGetPathFromIDListW
USER32.dllAdjustWindowRectEx, BeginPaint, CallNextHookEx, CallWindowProcA, CallWindowProcW, CharLowerA, CharLowerW, ClientToScreen, CloseClipboard, CreateCaret, CreateIconFromResource, CreateIconIndirect, CreateMenu, CreatePopupMenu, CreateWindowExA, CreateWindowExW, DefWindowProcA, DefWindowProcW, DestroyCaret, DestroyIcon, DestroyMenu, DestroyWindow, DispatchMessageA, DrawEdge, DrawFocusRect, DrawFrameControl, DrawMenuBar, EmptyClipboard, EnableWindow, EndPaint, EnumWindows, FillRect, GetAsyncKeyState, GetCapture, GetClassLongPtrA, GetClientRect, GetClipboardData, GetClipboardOwner, GetCursorPos, GetDC, GetDesktopWindow, GetFocus, GetForegroundWindow, GetKeyState, GetKeyboardLayout, GetMenuCheckMarkDimensions, GetMenuItemCount, GetMessageA, GetMessagePos, GetParent, GetSysColor, GetSysColorBrush, GetSystemMenu, GetSystemMetrics, GetWindow, GetWindowLongPtrA, GetWindowPlacement, GetWindowRect, GetWindowTextA, GetWindowTextW, InsertMenuA, InsertMenuW, InvalidateRect, IsClipboardFormatAvailable, IsIconic, IsWindow, IsWindowVisible, IsZoomed, KillTimer, LoadBitmapA, LoadCursorA, LoadCursorFromFileA, LoadIconA, MapVirtualKeyA, MessageBeep, MessageBoxA, MessageBoxW, MoveWindow, MsgWaitForMultipleObjectsEx, OpenClipboard, PeekMessageA, PostMessageA, PostQuitMessage, RegisterClassA, RegisterClassExA, RegisterClassW, ReleaseCapture, ReleaseDC, RemoveMenu, ScreenToClient, ScrollWindowEx, SendInput, SendMessageA, SendMessageW, SetActiveWindow, SetCapture, SetCaretPos, SetClassLongPtrA, SetClipboardData, SetCursor, SetCursorPos, SetFocus, SetForegroundWindow, SetMenu, SetParent, SetScrollInfo, SetTimer, SetWindowLongPtrA, SetWindowLongPtrW, SetWindowPos, SetWindowTextA, SetWindowTextW, SetWindowsHookExA, ShowWindow, SystemParametersInfoA, ToAscii, TrackPopupMenu, TranslateMessage, UnhookWindowsHookEx, UnregisterClassA, UpdateWindow, VkKeyScanA, WaitForInputIdle, WindowFromPoint, wsprintfA, wsprintfW
WS2_32.dllWSAAsyncSelect, WSACleanup, WSAGetLastError, WSAStartup, accept, bind, closesocket, connect, gethostbyaddr, gethostbyname, gethostname, getpeername, getservbyname, getsockname, getsockopt, htons, inet_addr, inet_ntoa, ioctlsocket, listen, ntohs, recv, select, send, setsockopt, socket
NameOrdinalAddress
TclKit_AppInit10x403310
TclKit_SetKitPath20x403670
Language of compilation systemCountry where language is spokenMap
EnglishUnited States