Suspicious activity by Zotero application
Hello,
This looks like a really useful application that some of our clients would like us to install.
But when I run the application through a forensic scan it shows malware like techniques and communication back to server all over the RIPE network. Some of the servers have been identified as hosting malware.
Can someone explain this application behavior before we can consider installing it?
Thank you!
https://www.hybrid-analysis.com/sample/aa7ea299fae7670640ca5344a75f036fad9ef324a457365d3b55dab8619ba573/5c4f85c17ca3e1215c3ec5e8
This looks like a really useful application that some of our clients would like us to install.
But when I run the application through a forensic scan it shows malware like techniques and communication back to server all over the RIPE network. Some of the servers have been identified as hosting malware.
Can someone explain this application behavior before we can consider installing it?
Thank you!
https://www.hybrid-analysis.com/sample/aa7ea299fae7670640ca5344a75f036fad9ef324a457365d3b55dab8619ba573/5c4f85c17ca3e1215c3ec5e8
The Zotero application makes requests to zotero.org domains, third-party services such as Crossref and Library of Congress for retrieving metadata, and sites that you save from, as explained in our privacy policy.
I put the installer link into the Hybrid Analysis scan: https://www.zotero.org/download/client/dl?channel=release&platform=win32&version=5.0.60
The scanner downloads the installer, runs the installation, and monitors the activity of the application during install and after.
Here is that scan:
https://www.hybrid-analysis.com/sample/8aeec60b7d2962ddd688f16a05b1908da5ee419a761f01516b5f43181278c9c2/5c4fbca57ca3e126cd5c8143
It sends data out to a RIPE IP 88.198.200.74 It queries RDP info. It changes proxy settings. Opens MountPointManager. Loads this API SetKernelObjectSecurity.
Just curious on why it's doing some of these things.
Thanks!
The iexplore.exe requests — to zotero.org, Google (for reCAPTCHA), MyFonts, and Akamai — are from the Zotero start page, as you can see in the screenshot.
The rest is just standard stuff that's done by Firefox, on which Zotero is based, and you'd see similar results for the Firefox installer, which this site also marks as malicious. The exact results would depend on the version, but Firefox, like any browser, is a huge, complex piece of software, and a scan like this isn't going to return meaningful results.
The only changes Zotero makes to your system are registering itself for some common bibliographic file formats such as RIS and installing the word processor plugin.