File name:

MentalMentor.exe

Full analysis: https://app.any.run/tasks/8908f50f-5e35-417b-98d8-2da807f94c12
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: September 16, 2024, 21:29:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AEE4DD798DA9F13AC44FCD2EB5B6B296

SHA1:

7079918F2AE966E78F7F234C088CE1FEB7DB00B9

SHA256:

2952264B226A7F252A4195087E104E326CB2D70AE0FFB526C5051006059B0166

SSDEEP:

98304:z+cD4dndIQYaQCn0zYIShe3YC09z13z0WoJezEsvHG512Dcd2D+gsrC+x3ILB1UQ:kOIbt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • MentalMentor.tmp (PID: 2180)
    • Changes the autorun value in the registry

      • mentalmentor.exe (PID: 3964)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MentalMentor.exe (PID: 5284)
      • MentalMentor.exe (PID: 7052)
      • MentalMentor.tmp (PID: 2180)
      • 7z.exe (PID: 2640)
      • 7z.exe (PID: 6484)
      • 7z.exe (PID: 2588)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Reads security settings of Internet Explorer

      • MentalMentor.tmp (PID: 3036)
      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
    • Reads the Windows owner or organization settings

      • MentalMentor.tmp (PID: 2180)
    • Searches for installed software

      • MentalMentor.tmp (PID: 2180)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • MentalMentor.tmp (PID: 2180)
    • Detected use of alternative data streams (AltDS)

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Checks Windows Trust Settings

      • MentalMentor.tmp (PID: 2180)
      • net_updater32.exe (PID: 2400)
    • Executes as Windows Service

      • net_updater32.exe (PID: 2400)
      • WmiApSrv.exe (PID: 6188)
    • Potential Corporate Privacy Violation

      • net_updater32.exe (PID: 2400)
    • The process checks if it is being run in the virtual environment

      • net_updater32.exe (PID: 2400)
    • Adds/modifies Windows certificates

      • QtWebEngineProcess.exe (PID: 1440)
  • INFO

    • Checks supported languages

      • MentalMentor.exe (PID: 5284)
      • MentalMentor.tmp (PID: 3036)
      • MentalMentor.tmp (PID: 2180)
      • MentalMentor.exe (PID: 7052)
      • 7z.exe (PID: 2588)
      • luminati.exe (PID: 3984)
      • 7z.exe (PID: 6484)
      • 7z.exe (PID: 6152)
      • 7z.exe (PID: 2640)
      • test_wpf.exe (PID: 32)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • test_wpf.exe (PID: 2904)
      • idle_report.exe (PID: 5376)
      • brightdata.exe (PID: 2876)
      • mentalmentor.exe (PID: 3964)
      • mentalmentor_crashpad_handler.exe (PID: 4644)
      • luminati.exe (PID: 1084)
      • QtWebEngineProcess.exe (PID: 1440)
      • test_wpf.exe (PID: 3448)
      • QtWebEngineProcess.exe (PID: 7072)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
      • test_wpf.exe (PID: 6204)
      • idle_report.exe (PID: 3376)
      • test_wpf.exe (PID: 6912)
    • Create files in a temporary directory

      • MentalMentor.exe (PID: 5284)
      • MentalMentor.exe (PID: 7052)
      • MentalMentor.tmp (PID: 2180)
    • Process checks computer location settings

      • MentalMentor.tmp (PID: 3036)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • QtWebEngineProcess.exe (PID: 7072)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Reads the computer name

      • MentalMentor.tmp (PID: 3036)
      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • test_wpf.exe (PID: 2904)
      • idle_report.exe (PID: 5376)
      • brightdata.exe (PID: 2876)
      • mentalmentor.exe (PID: 3964)
      • QtWebEngineProcess.exe (PID: 7072)
      • luminati.exe (PID: 1084)
      • test_wpf.exe (PID: 32)
      • test_wpf.exe (PID: 3448)
      • test_wpf.exe (PID: 6912)
      • luminati.exe (PID: 2108)
      • test_wpf.exe (PID: 6204)
      • luminati.exe (PID: 1064)
      • idle_report.exe (PID: 3376)
      • QtWebEngineProcess.exe (PID: 1440)
    • Reads the software policy settings

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • QtWebEngineProcess.exe (PID: 1440)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Checks proxy server information

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • mentalmentor.exe (PID: 3964)
      • QtWebEngineProcess.exe (PID: 1440)
    • Reads the machine GUID from the registry

      • MentalMentor.tmp (PID: 2180)
      • test_wpf.exe (PID: 2904)
      • idle_report.exe (PID: 5376)
      • net_updater32.exe (PID: 2400)
      • brightdata.exe (PID: 2876)
      • mentalmentor.exe (PID: 3964)
      • luminati.exe (PID: 1084)
      • test_wpf.exe (PID: 3448)
      • luminati.exe (PID: 3984)
      • QtWebEngineProcess.exe (PID: 1440)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
      • test_wpf.exe (PID: 6204)
      • idle_report.exe (PID: 3376)
      • test_wpf.exe (PID: 6912)
      • test_wpf.exe (PID: 32)
    • Creates files or folders in the user directory

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • QtWebEngineProcess.exe (PID: 1440)
    • Creates a software uninstall entry

      • MentalMentor.tmp (PID: 2180)
    • Creates files in the program directory

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • brightdata.exe (PID: 2876)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 1064)
      • luminati.exe (PID: 2108)
    • Disables trace logs

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
    • The process uses the downloaded file

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
    • Reads the time zone

      • net_updater32.exe (PID: 2400)
    • Reads CPU info

      • net_updater32.exe (PID: 2400)
    • Sends debugging messages

      • QtWebEngineProcess.exe (PID: 7072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 102400
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.0
ProductVersionNumber: 1.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mental Mentor
FileDescription: Mental Mentor Setup
FileVersion: 1.1.0
LegalCopyright: Copyright 2024 Agora International Agency
OriginalFileName: MentalMentor.exe
ProductName: Mental Mentor
ProductVersion: 1.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
171
Monitored processes
39
Malicious processes
10
Suspicious processes
1

Behavior graph

Click at the process to see the details
start mentalmentor.exe mentalmentor.tmp no specs mentalmentor.exe mentalmentor.tmp 7z.exe conhost.exe no specs 7z.exe conhost.exe no specs 7z.exe conhost.exe no specs 7z.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs luminati.exe test_wpf.exe no specs net_updater32.exe conhost.exe no specs net_updater32.exe test_wpf.exe no specs idle_report.exe no specs conhost.exe no specs brightdata.exe no specs conhost.exe no specs wmiapsrv.exe no specs mentalmentor.exe mentalmentor_crashpad_handler.exe no specs luminati.exe qtwebengineprocess.exe qtwebengineprocess.exe no specs test_wpf.exe no specs luminati.exe test_wpf.exe no specs luminati.exe test_wpf.exe no specs idle_report.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32C:\ProgramData\BrightData\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exeC:\ProgramData\BrightData\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exeluminati.exe
User:
admin
Company:
BrightData Ltd.
Integrity Level:
HIGH
Description:
test_wpf
Exit code:
0
Version:
1.429.308
Modules
Images
c:\programdata\brightdata\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1064C:\Users\admin\mentalmentor\luminati\luminati.exe is_switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
101
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1084C:\Users\admin\mentalmentor\luminati\luminati.exe is_switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
101
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1440"C:\Users\admin\mentalmentor\QtWebEngineProcess.exe" --type=utility --enable-features=AllowContentInitiatedDataUrlNavigations,TracingServiceInProcess --disable-features=BackgroundFetch,ConsolidatedMovementXY,DnsOverHttpsUpgrade,FormControlsRefresh,MojoVideoCapture,PictureInPicture,SmsReceiver,UseSkiaRenderer,WebPayments,WebUSB --lang=en-US --service-sandbox-type=network --use-gl=angle --application-name=mentalmentor --webengine-schemes=qrc:sLV --mojo-platform-channel-handle=3180 /prefetch:8C:\Users\admin\mentalmentor\QtWebEngineProcess.exe
mentalmentor.exe
User:
admin
Company:
The Qt Company Ltd.
Integrity Level:
HIGH
Description:
C++ Application Development Framework
Version:
5.15.2.0
Modules
Images
c:\users\admin\mentalmentor\qtwebengineprocess.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2008\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exebrightdata.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2108C:\Users\admin\mentalmentor\luminati\luminati.exe is_switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
101
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2144\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeidle_report.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2180"C:\Users\admin\AppData\Local\Temp\is-K3QV4.tmp\MentalMentor.tmp" /SL5="$B028C,2487297,845312,C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" /SPAWNWND=$803A4 /NOTIFYWND=$60202 C:\Users\admin\AppData\Local\Temp\is-K3QV4.tmp\MentalMentor.tmp
MentalMentor.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-k3qv4.tmp\mentalmentor.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2400"C:/Users/admin/mentalmentor/luminati/net_updater32.exe" --updater win_global_microtrading.mental_mentorC:\Users\admin\mentalmentor\luminati\net_updater32.exe
services.exe
User:
SYSTEM
Company:
BrightData Ltd.
Integrity Level:
SYSTEM
Description:
BrightData service allows free use of certain features in an app you installed
Version:
1.429.308
Modules
Images
c:\users\admin\mentalmentor\luminati\net_updater32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\wintrust.dll
c:\windows\syswow64\msvcrt.dll
2588"C:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\7z.exe" x "C:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\zip_libs.7z" -o"C:\Users\admin\mentalmentor\" * -r -aoaC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\7z.exe
MentalMentor.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\is-hf6e9.tmp\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
25 648
Read events
25 527
Write events
117
Delete events
4

Modification events

(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\mentalmentor
Operation:writeName:autostart
Value:
true
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\mentalmentor
Operation:writeName:reinstall
Value:
false
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\mentalmentor
Operation:writeName:installer
Value:
true
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:InstallLocation
Value:
C:\Users\admin\mentalmentor
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:DisplayName
Value:
Mental Mentor
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\mentalmentor\mentalmentor.exe
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:UninstallString
Value:
C:\Users\admin\mentalmentor\uninstall.exe
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:Publisher
Value:
Mental Mentor
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:URLInfoAbout
Value:
https://mmentorapp.com
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:HelpLink
Value:
https://mmentorapp.com
Executable files
56
Suspicious files
158
Text files
35
Unknown types
3

Dropped files

PID
Process
Filename
Type
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\zip_libs.7z
MD5:
SHA256:
25887z.exeC:\Users\admin\mentalmentor\resources\icudtl.dat
MD5:
SHA256:
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\zip_html.7zcompressed
MD5:891FE79896A40F7037D19B655EBB8619
SHA256:1A6E88E9E8D02F79C4E7E5F02D6BF359BDAB01D2736E8ACAFF98197D1DF2985F
25887z.exeC:\Users\admin\mentalmentor\readme.txttext
MD5:C66D6A9682C03627F7339786462AB519
SHA256:1E7F87F9D1B8C54B63B49C2EF05F91310B03699B14B2C8ACCCE96FD541D211A0
25887z.exeC:\Users\admin\mentalmentor\resources\qtwebengine_resources.pakbinary
MD5:14F2F9BD381FB1E1E903304AF053137D
SHA256:5F96BB8B73792CCAB961DC06B1190FF2D7AA65E24BBCCD806FFFCA24140CBE9C
25887z.exeC:\Users\admin\mentalmentor\resources\qtwebengine_devtools_resources.pakpgc
MD5:4C7BE74B56DB30E1643A1E4E279133DE
SHA256:AF9BE65C63D4A6B6C6A204E8AB8A74CD7D1B892D22677F8FD43DAB0C17CC47EC
25887z.exeC:\Users\admin\mentalmentor\resources\qtwebengine_resources_200p.pakbinary
MD5:083950E31E62FD878A63F30D52C8602B
SHA256:DEEBBA302ACEBFA268B317A57F56BA631325EDBF053FF32A8D7832347D1ED44D
2180MentalMentor.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0EA6E8CAD956874A74056FFF9B4B0D39binary
MD5:5E537D7FE4EE27D0BB82122292119431
SHA256:231B6DD51A090DFCA95B9853396C4C2D02785723CD3090F2BD4F1385F39A70BC
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\idp.dllexecutable
MD5:347530853FD2439CE98BD9A4FAF643A0
SHA256:6280E78986521F8662E1408D7CFE3BAB343AA043E4FA15C8FE9B424306B194D9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
96
DNS requests
44
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2180
MentalMentor.tmp
GET
200
195.138.255.18:80
http://r10.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRpD%2BQVZ%2B1vf7U0RGQGBm8JZwdxcgQUdKR2KRcYVIUxN75n5gZYwLzFBXICEgSoSeYxtNXJ0yqn6tuYArPQNw%3D%3D
unknown
whitelisted
1436
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4316
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
644
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
644
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2400
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4SYN8HbX1atPqRDi932Tc%3D
unknown
whitelisted
2400
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
2400
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
2400
net_updater32.exe
GET
200
54.221.247.193:80
http://http-test1.brdtnet.com/connection/http-test1.html
unknown
unknown
1440
QtWebEngineProcess.exe
GET
200
142.250.186.99:80
http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQDD%2FDl2Cgjx%2FQrl3YkOdh7a
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4316
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6244
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2180
MentalMentor.tmp
51.158.210.166:443
web.mymentalmentor.net
Online S.a.s.
FR
unknown
4316
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2180
MentalMentor.tmp
195.138.255.18:80
r10.o.lencr.org
AS33891 Netzbetrieb GmbH
DE
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1436
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
web.mymentalmentor.net
  • 51.158.210.166
unknown
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.104.136.2
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
r10.o.lencr.org
  • 195.138.255.18
  • 195.138.255.24
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.133
  • 20.190.160.17
  • 20.190.160.22
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.140
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

PID
Process
Class
Message
2400
net_updater32.exe
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
No debug info