Is MarkZipInstallWizard.exe safe?
A lone bundle-installer detection is outweighed by tier-1 silence, but newness, unestablished signing, packing, and LSASS-related offensive indicators warrant caution.
Only 1 of 75 engines flagged this installer, and none of the 17 reporting tier-1 engines detected it. However, it is newly observed, its verified signer has no established history, and runtime evidence maps activity to process injection, data destruction, defense impairment, and LSASS access, making execution inadvisable without source verification.
503a1717c57bc1bdfb…a0573a3be383fcRecommended next actions
Before running
Do not run it until the source and publisher can be verified independently.
If you already ran it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the developer's official site or an official app store.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Only 1 of 75 engines flagged this installer, and none of the 17 reporting tier-1 engines detected it. However, it is newly observed, its verified signer has no established history, and runtime evidence maps activity to process injection, data destruction, defense impairment, and LSASS access, making execution inadvisable without source verification.
Malwarebytes alone reported a potentially unwanted bundle installer, while all 17 reporting tier-1 engines remained silent. That limited detection consensus is insufficient to establish a malware family and leaves substantial false-positive potential. Conversely, the completed runtime record maps activity to T1055, T1485, and T1562.001 and includes LSASS-related activity, which is atypical for an ordinary archive installer. The executable is also packed, rare and recently observed, and signed by PRIDEWAY ENTERPRISES LTD without any historical signer record. Its observed domain and IP had no cached malicious or suspicious reputation, and no malicious child or external-intelligence match was found, so the evidence remains mixed rather than conclusive.
What We Detected
Malwarebytes was the only detector among 75 engines, labeling the sample PUP.Optional.BundleInstaller. None of the 17 reporting tier-1 engines flagged it, and there is no engine family consensus. The executable carries a verified signature from PRIDEWAY ENTERPRISES LTD, but no prior signer history is available, and the file has only five submissions from three sources over eight days.
Threat Behavior
The completed sandbox record did not issue a malicious verdict, but it mapped activity to T1055 process injection, T1485 data destruction, and T1562.001 impairment of defenses. Saved process evidence also includes LSASS and svchost activity, while static analysis marks the .NET executable as likely packed. The sample contacted auth.markazipr.com and its associated IP; the completed cache lookup found no known malicious or suspicious reputation for those observed hosts. No dropped file hashes, malicious child, persistence indicator, or external-intelligence match was recorded.
What To Do Now
Do not run this installer unless its download source and publisher can be independently verified through an official channel. Keep endpoint protection enabled, and use an isolated test environment if organizational analysis is necessary.
Where this verdict could be wrong5 caveats
- All 17 reporting tier-1 engines were clean, and only Malwarebytes detected PUP.Optional.BundleInstaller.
- behaviour.hasMaliciousSandboxVerdict=false; the completed sandbox labeled its run clean, although the mapped offensive techniques remain concerning.
- contactedHosts inspected the observed domain and IP and found no cached malicious or suspicious host, but reputation-cache absence does not establish benign ownership.
- The signature for 'PRIDEWAY ENTERPRISES LTD' verifies cryptographically, although no historical signer record supports its reputation.
- CIRCL, MalwareBazaar, and YARAify returned no corroborating hits, which may reflect limited intelligence coverage for a new sample.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 1/75 engines detected the sample.
- engines.tier1Malicious=0, with all 17 reporting tier-1 engines clean.
- signing.verified=true for PRIDEWAY ENTERPRISES LTD.
- behaviour.hasMaliciousSandboxVerdict=false.
- No malicious child or external-intelligence hit was recorded.
- Runtime evidence maps activity to T1055 process injection.
- Runtime evidence maps activity to T1485 data destruction and T1562.001 defense impairment.
- Saved process activity includes LSASS, raising credential-access concerns.
- The likely packed executable contacted auth.markazipr.com.
- The verified signer has no historical sample record.
- The file is rare and was first observed only eight days ago.
Avoid installing it until the publisher and download channel are independently confirmed. Keep security protection enabled and quarantine the file if its origin cannot be verified.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 of 2 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete4 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 20MITRE ATT&CK techniques
- 12spawned processes
- 2network contacts
- 6filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
MarkZipInstallWizard.exe
503a1717c57bc1bdfb93d5a828ae5c7c6612d0b85a32bf9ab0a0573a3be383fc
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\markzip.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\services.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Roaming
C:\Users\user\AppData\Roaming
04Isolated runtime analysis
Network
Hosts contacted
- Contacted hostObserved
auth.markazipr.com
Contact observed during runtime.
05Isolated runtime analysis - Contacted hostObserved
104.18.30.213
Contact observed during runtime.
06Isolated runtime analysis - +1 more recorded observation in Analyst mode
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- auth.markazipr.com
- 104.18.30.213
- HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Tracing\markzip_RASAPI32
- HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Tracing\markzip_RASMANCS
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\markzip_RASAPI32\FileTracingMask
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\markzip_RASAPI32\ConsoleTracingMask
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\markzip_RASAPI32\MaxFileSize
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\markzip_RASAPI32\FileDirectory
- C:\Users\user\AppData\Roaming
- Local\MarkZip.InstallWizard.SetupLock
- Global\OneSettingQueryMutex+compat+encapsulation
- \Sessions\1\BaseNamedObjects\Local\MarkZip.InstallWizard.SetupLock
- \Sessions\1\BaseNamedObjects\Local\__DDrawExclMode__
- \Sessions\1\BaseNamedObjects\Local\__DDrawCheckExclMode__
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 4rule hits recorded
- 1 / 75engines flagged
- 3sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
2 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
1 of 75 antivirus engines flagged the file, including Malwarebytes.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The file has a valid code signature from PRIDEWAY ENTERPRISES LTD.
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: MarkZipInstallWizard.exe — 503a1717c57bc1bdfb93d5a828ae5c7c6612d0b85a32bf9ab0a0573a3be383fc
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\markzip.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\services.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Roaming — C:\Users\user\AppData\Roaming
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: auth.markazipr.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 104.18.30.213 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: pua
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSigned by "PRIDEWAY ENTERPRISES LTD" — short generic company CN. Paired with 1 engine hit(s); possible stolen, fraudulent, or reseller-purchased code-signing certificate.
EvidencePRIDEWAY ENTERPRISES LTDPacked PE with sandbox-observed network activity AND engine flags. Signed packed software exists legitimately, but a signed + packed + flagged binary is a signed dropper pattern.
Evidenceauth.markazipr.com
1 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
A known packer signature (UPX / Themida / VMProtect / etc.) matched this file. Packers aren't malicious on their own, but most malware uses them.
Packers compress or encrypt the executable and only unpack it at runtime. Legitimate commercial software uses them too — but if the file is also unsigned and rare, it's a strong malware signal.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 1 antivirus detection make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- MarkZipInstallWizard.exe
- Format
- Win32 EXE
- Code signing
- Signature valid: PRIDEWAY ENTERPRISES LTD
- Size
- 82.9 KB
- Last analyzed
- Oct 3, 2026, 2:16 AM UTC
503a1717c57bc1bdfb93d5a828ae5c7c6612d0b85a32bf9ab0a0573a3be383fcSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't run it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the developer's official site or an official app store.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is MarkZipInstallWizard.exe safe, or is it malware?
What is MarkZipInstallWizard.exe?
How many antivirus engines detected MarkZipInstallWizard.exe?
What should I do if I already ran MarkZipInstallWizard.exe?
How do I remove MarkZipInstallWizard.exe?
What kind of malware is MarkZipInstallWizard.exe?
Is MarkZipInstallWizard.exe digitally signed?
What is the SHA-256 hash of MarkZipInstallWizard.exe?
How up to date is this analysis of MarkZipInstallWizard.exe?
Community
Member reviews and reports for this exact file hash.