File name:

MentalMentor.exe

Full analysis: https://app.any.run/tasks/8908f50f-5e35-417b-98d8-2da807f94c12
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: September 16, 2024, 21:29:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AEE4DD798DA9F13AC44FCD2EB5B6B296

SHA1:

7079918F2AE966E78F7F234C088CE1FEB7DB00B9

SHA256:

2952264B226A7F252A4195087E104E326CB2D70AE0FFB526C5051006059B0166

SSDEEP:

98304:z+cD4dndIQYaQCn0zYIShe3YC09z13z0WoJezEsvHG512Dcd2D+gsrC+x3ILB1UQ:kOIbt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • MentalMentor.tmp (PID: 2180)
    • Changes the autorun value in the registry

      • mentalmentor.exe (PID: 3964)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MentalMentor.exe (PID: 5284)
      • MentalMentor.exe (PID: 7052)
      • MentalMentor.tmp (PID: 2180)
      • 7z.exe (PID: 2588)
      • 7z.exe (PID: 2640)
      • 7z.exe (PID: 6484)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Reads security settings of Internet Explorer

      • MentalMentor.tmp (PID: 3036)
      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
    • Reads the Windows owner or organization settings

      • MentalMentor.tmp (PID: 2180)
    • Checks Windows Trust Settings

      • MentalMentor.tmp (PID: 2180)
      • net_updater32.exe (PID: 2400)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • MentalMentor.tmp (PID: 2180)
    • Detected use of alternative data streams (AltDS)

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Searches for installed software

      • MentalMentor.tmp (PID: 2180)
    • Executes as Windows Service

      • net_updater32.exe (PID: 2400)
      • WmiApSrv.exe (PID: 6188)
    • Potential Corporate Privacy Violation

      • net_updater32.exe (PID: 2400)
    • The process checks if it is being run in the virtual environment

      • net_updater32.exe (PID: 2400)
    • Adds/modifies Windows certificates

      • QtWebEngineProcess.exe (PID: 1440)
  • INFO

    • Checks supported languages

      • MentalMentor.exe (PID: 5284)
      • MentalMentor.tmp (PID: 3036)
      • MentalMentor.exe (PID: 7052)
      • MentalMentor.tmp (PID: 2180)
      • 7z.exe (PID: 2588)
      • 7z.exe (PID: 6484)
      • 7z.exe (PID: 2640)
      • luminati.exe (PID: 3984)
      • 7z.exe (PID: 6152)
      • test_wpf.exe (PID: 32)
      • net_updater32.exe (PID: 2400)
      • test_wpf.exe (PID: 2904)
      • net_updater32.exe (PID: 3332)
      • brightdata.exe (PID: 2876)
      • mentalmentor.exe (PID: 3964)
      • idle_report.exe (PID: 5376)
      • mentalmentor_crashpad_handler.exe (PID: 4644)
      • luminati.exe (PID: 1084)
      • test_wpf.exe (PID: 3448)
      • QtWebEngineProcess.exe (PID: 1440)
      • QtWebEngineProcess.exe (PID: 7072)
      • test_wpf.exe (PID: 6912)
      • luminati.exe (PID: 2108)
      • idle_report.exe (PID: 3376)
      • luminati.exe (PID: 1064)
      • test_wpf.exe (PID: 6204)
    • Reads the computer name

      • MentalMentor.tmp (PID: 3036)
      • MentalMentor.tmp (PID: 2180)
      • test_wpf.exe (PID: 32)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • test_wpf.exe (PID: 2904)
      • idle_report.exe (PID: 5376)
      • brightdata.exe (PID: 2876)
      • test_wpf.exe (PID: 3448)
      • mentalmentor.exe (PID: 3964)
      • luminati.exe (PID: 1084)
      • QtWebEngineProcess.exe (PID: 1440)
      • QtWebEngineProcess.exe (PID: 7072)
      • test_wpf.exe (PID: 6912)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
      • test_wpf.exe (PID: 6204)
      • idle_report.exe (PID: 3376)
    • Process checks computer location settings

      • MentalMentor.tmp (PID: 3036)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • QtWebEngineProcess.exe (PID: 7072)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 1064)
    • Create files in a temporary directory

      • MentalMentor.exe (PID: 5284)
      • MentalMentor.exe (PID: 7052)
      • MentalMentor.tmp (PID: 2180)
    • Reads the machine GUID from the registry

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • test_wpf.exe (PID: 32)
      • net_updater32.exe (PID: 2400)
      • test_wpf.exe (PID: 2904)
      • idle_report.exe (PID: 5376)
      • brightdata.exe (PID: 2876)
      • mentalmentor.exe (PID: 3964)
      • luminati.exe (PID: 1084)
      • test_wpf.exe (PID: 3448)
      • QtWebEngineProcess.exe (PID: 1440)
      • test_wpf.exe (PID: 6912)
      • luminati.exe (PID: 2108)
      • test_wpf.exe (PID: 6204)
      • idle_report.exe (PID: 3376)
      • luminati.exe (PID: 1064)
    • Reads the software policy settings

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • QtWebEngineProcess.exe (PID: 1440)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Checks proxy server information

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • mentalmentor.exe (PID: 3964)
      • QtWebEngineProcess.exe (PID: 1440)
    • Creates files or folders in the user directory

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • QtWebEngineProcess.exe (PID: 1440)
    • Creates a software uninstall entry

      • MentalMentor.tmp (PID: 2180)
    • Creates files in the program directory

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • brightdata.exe (PID: 2876)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • The process uses the downloaded file

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
    • Disables trace logs

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
    • Reads CPU info

      • net_updater32.exe (PID: 2400)
    • Reads the time zone

      • net_updater32.exe (PID: 2400)
    • Sends debugging messages

      • QtWebEngineProcess.exe (PID: 7072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 102400
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.0
ProductVersionNumber: 1.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mental Mentor
FileDescription: Mental Mentor Setup
FileVersion: 1.1.0
LegalCopyright: Copyright 2024 Agora International Agency
OriginalFileName: MentalMentor.exe
ProductName: Mental Mentor
ProductVersion: 1.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
171
Monitored processes
39
Malicious processes
10
Suspicious processes
1

Behavior graph

Click at the process to see the details
start mentalmentor.exe mentalmentor.tmp no specs mentalmentor.exe mentalmentor.tmp 7z.exe conhost.exe no specs 7z.exe conhost.exe no specs 7z.exe conhost.exe no specs 7z.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs luminati.exe test_wpf.exe no specs net_updater32.exe conhost.exe no specs net_updater32.exe test_wpf.exe no specs idle_report.exe no specs conhost.exe no specs brightdata.exe no specs conhost.exe no specs wmiapsrv.exe no specs mentalmentor.exe mentalmentor_crashpad_handler.exe no specs luminati.exe qtwebengineprocess.exe qtwebengineprocess.exe no specs test_wpf.exe no specs luminati.exe test_wpf.exe no specs luminati.exe test_wpf.exe no specs idle_report.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32C:\ProgramData\BrightData\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exeC:\ProgramData\BrightData\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exeluminati.exe
User:
admin
Company:
BrightData Ltd.
Integrity Level:
HIGH
Description:
test_wpf
Exit code:
0
Version:
1.429.308
Modules
Images
c:\programdata\brightdata\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1064C:\Users\admin\mentalmentor\luminati\luminati.exe is_switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
101
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1084C:\Users\admin\mentalmentor\luminati\luminati.exe is_switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
101
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1440"C:\Users\admin\mentalmentor\QtWebEngineProcess.exe" --type=utility --enable-features=AllowContentInitiatedDataUrlNavigations,TracingServiceInProcess --disable-features=BackgroundFetch,ConsolidatedMovementXY,DnsOverHttpsUpgrade,FormControlsRefresh,MojoVideoCapture,PictureInPicture,SmsReceiver,UseSkiaRenderer,WebPayments,WebUSB --lang=en-US --service-sandbox-type=network --use-gl=angle --application-name=mentalmentor --webengine-schemes=qrc:sLV --mojo-platform-channel-handle=3180 /prefetch:8C:\Users\admin\mentalmentor\QtWebEngineProcess.exe
mentalmentor.exe
User:
admin
Company:
The Qt Company Ltd.
Integrity Level:
HIGH
Description:
C++ Application Development Framework
Version:
5.15.2.0
Modules
Images
c:\users\admin\mentalmentor\qtwebengineprocess.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2008\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exebrightdata.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2108C:\Users\admin\mentalmentor\luminati\luminati.exe is_switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
101
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2144\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeidle_report.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2180"C:\Users\admin\AppData\Local\Temp\is-K3QV4.tmp\MentalMentor.tmp" /SL5="$B028C,2487297,845312,C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" /SPAWNWND=$803A4 /NOTIFYWND=$60202 C:\Users\admin\AppData\Local\Temp\is-K3QV4.tmp\MentalMentor.tmp
MentalMentor.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-k3qv4.tmp\mentalmentor.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2400"C:/Users/admin/mentalmentor/luminati/net_updater32.exe" --updater win_global_microtrading.mental_mentorC:\Users\admin\mentalmentor\luminati\net_updater32.exe
services.exe
User:
SYSTEM
Company:
BrightData Ltd.
Integrity Level:
SYSTEM
Description:
BrightData service allows free use of certain features in an app you installed
Version:
1.429.308
Modules
Images
c:\users\admin\mentalmentor\luminati\net_updater32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\wintrust.dll
c:\windows\syswow64\msvcrt.dll
2588"C:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\7z.exe" x "C:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\zip_libs.7z" -o"C:\Users\admin\mentalmentor\" * -r -aoaC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\7z.exe
MentalMentor.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\is-hf6e9.tmp\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
25 648
Read events
25 527
Write events
117
Delete events
4

Modification events

(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\mentalmentor
Operation:writeName:autostart
Value:
true
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\mentalmentor
Operation:writeName:reinstall
Value:
false
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\mentalmentor
Operation:writeName:installer
Value:
true
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:InstallLocation
Value:
C:\Users\admin\mentalmentor
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:DisplayName
Value:
Mental Mentor
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\mentalmentor\mentalmentor.exe
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:UninstallString
Value:
C:\Users\admin\mentalmentor\uninstall.exe
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:Publisher
Value:
Mental Mentor
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:URLInfoAbout
Value:
https://mmentorapp.com
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:HelpLink
Value:
https://mmentorapp.com
Executable files
56
Suspicious files
158
Text files
35
Unknown types
3

Dropped files

PID
Process
Filename
Type
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\zip_libs.7z
MD5:
SHA256:
25887z.exeC:\Users\admin\mentalmentor\resources\icudtl.dat
MD5:
SHA256:
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
7052MentalMentor.exeC:\Users\admin\AppData\Local\Temp\is-K3QV4.tmp\MentalMentor.tmpexecutable
MD5:0D041F22D598F3A63BDF0E66C448BDAB
SHA256:E6B54015C403E3016B848B18FC488D4D281A752BC9AB2A3324BA4D8EFB642563
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\mentor-inno-lib.dllexecutable
MD5:B53E08B82850626C046A5CEBD295E41C
SHA256:5120508B7CBDEE3D9C89C8ECE6E95C9BEE018C4E09F13D5E0E2F7CF99828D0C6
2180MentalMentor.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:3DFCA46E00FFA4795C72A41375F159D3
SHA256:DCBA1A505396539BAC40A7253C9F5DCCF06CBB79957E21D56305E1FC3AF5F40E
5284MentalMentor.exeC:\Users\admin\AppData\Local\Temp\is-04N1B.tmp\MentalMentor.tmpexecutable
MD5:0D041F22D598F3A63BDF0E66C448BDAB
SHA256:E6B54015C403E3016B848B18FC488D4D281A752BC9AB2A3324BA4D8EFB642563
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\idp.dllexecutable
MD5:347530853FD2439CE98BD9A4FAF643A0
SHA256:6280E78986521F8662E1408D7CFE3BAB343AA043E4FA15C8FE9B424306B194D9
2180MentalMentor.tmpC:\Users\admin\mentalmentor\settings\temp\install_configbinary
MD5:18E95DFA863592DBF829D49BA5FB124F
SHA256:FCDF47E2C55487DC993DF954A991409DA886B1CA5E87D9957931A1CD16C62601
25887z.exeC:\Users\admin\mentalmentor\resources\qtwebengine_resources.pakbinary
MD5:14F2F9BD381FB1E1E903304AF053137D
SHA256:5F96BB8B73792CCAB961DC06B1190FF2D7AA65E24BBCCD806FFFCA24140CBE9C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
96
DNS requests
44
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1440
QtWebEngineProcess.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D
unknown
whitelisted
1440
QtWebEngineProcess.exe
GET
200
142.250.186.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
2400
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4SYN8HbX1atPqRDi932Tc%3D
unknown
whitelisted
644
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2400
net_updater32.exe
GET
200
54.221.247.193:80
http://http-test1.brdtnet.com/connection/http-test1.html
unknown
unknown
2400
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
1436
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4316
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2400
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
644
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4316
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6244
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2180
MentalMentor.tmp
51.158.210.166:443
web.mymentalmentor.net
Online S.a.s.
FR
unknown
4316
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2180
MentalMentor.tmp
195.138.255.18:80
r10.o.lencr.org
AS33891 Netzbetrieb GmbH
DE
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1436
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
web.mymentalmentor.net
  • 51.158.210.166
unknown
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.104.136.2
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
r10.o.lencr.org
  • 195.138.255.18
  • 195.138.255.24
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.133
  • 20.190.160.17
  • 20.190.160.22
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.140
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

PID
Process
Class
Message
2400
net_updater32.exe
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
No debug info