File name:

MentalMentor.exe

Full analysis: https://app.any.run/tasks/8908f50f-5e35-417b-98d8-2da807f94c12
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: September 16, 2024, 21:29:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AEE4DD798DA9F13AC44FCD2EB5B6B296

SHA1:

7079918F2AE966E78F7F234C088CE1FEB7DB00B9

SHA256:

2952264B226A7F252A4195087E104E326CB2D70AE0FFB526C5051006059B0166

SSDEEP:

98304:z+cD4dndIQYaQCn0zYIShe3YC09z13z0WoJezEsvHG512Dcd2D+gsrC+x3ILB1UQ:kOIbt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • MentalMentor.tmp (PID: 2180)
    • Changes the autorun value in the registry

      • mentalmentor.exe (PID: 3964)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • MentalMentor.tmp (PID: 3036)
      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
    • Executable content was dropped or overwritten

      • MentalMentor.exe (PID: 7052)
      • MentalMentor.exe (PID: 5284)
      • MentalMentor.tmp (PID: 2180)
      • 7z.exe (PID: 2588)
      • 7z.exe (PID: 6484)
      • 7z.exe (PID: 2640)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Reads the Windows owner or organization settings

      • MentalMentor.tmp (PID: 2180)
    • Searches for installed software

      • MentalMentor.tmp (PID: 2180)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • MentalMentor.tmp (PID: 2180)
    • Checks Windows Trust Settings

      • MentalMentor.tmp (PID: 2180)
      • net_updater32.exe (PID: 2400)
    • Detected use of alternative data streams (AltDS)

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 1064)
      • luminati.exe (PID: 2108)
    • Executes as Windows Service

      • net_updater32.exe (PID: 2400)
      • WmiApSrv.exe (PID: 6188)
    • Potential Corporate Privacy Violation

      • net_updater32.exe (PID: 2400)
    • The process checks if it is being run in the virtual environment

      • net_updater32.exe (PID: 2400)
    • Adds/modifies Windows certificates

      • QtWebEngineProcess.exe (PID: 1440)
  • INFO

    • Create files in a temporary directory

      • MentalMentor.exe (PID: 5284)
      • MentalMentor.exe (PID: 7052)
      • MentalMentor.tmp (PID: 2180)
    • Checks supported languages

      • MentalMentor.exe (PID: 5284)
      • MentalMentor.tmp (PID: 3036)
      • MentalMentor.exe (PID: 7052)
      • MentalMentor.tmp (PID: 2180)
      • 7z.exe (PID: 2588)
      • 7z.exe (PID: 2640)
      • 7z.exe (PID: 6484)
      • 7z.exe (PID: 6152)
      • luminati.exe (PID: 3984)
      • test_wpf.exe (PID: 32)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • idle_report.exe (PID: 5376)
      • brightdata.exe (PID: 2876)
      • test_wpf.exe (PID: 2904)
      • mentalmentor.exe (PID: 3964)
      • mentalmentor_crashpad_handler.exe (PID: 4644)
      • luminati.exe (PID: 1084)
      • test_wpf.exe (PID: 3448)
      • QtWebEngineProcess.exe (PID: 1440)
      • QtWebEngineProcess.exe (PID: 7072)
      • luminati.exe (PID: 2108)
      • test_wpf.exe (PID: 6912)
      • test_wpf.exe (PID: 6204)
      • idle_report.exe (PID: 3376)
      • luminati.exe (PID: 1064)
    • Process checks computer location settings

      • MentalMentor.tmp (PID: 3036)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • QtWebEngineProcess.exe (PID: 7072)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Reads the computer name

      • MentalMentor.tmp (PID: 3036)
      • MentalMentor.tmp (PID: 2180)
      • test_wpf.exe (PID: 32)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
      • net_updater32.exe (PID: 3332)
      • test_wpf.exe (PID: 2904)
      • idle_report.exe (PID: 5376)
      • test_wpf.exe (PID: 3448)
      • brightdata.exe (PID: 2876)
      • mentalmentor.exe (PID: 3964)
      • luminati.exe (PID: 1084)
      • QtWebEngineProcess.exe (PID: 1440)
      • QtWebEngineProcess.exe (PID: 7072)
      • test_wpf.exe (PID: 6912)
      • luminati.exe (PID: 2108)
      • test_wpf.exe (PID: 6204)
      • luminati.exe (PID: 1064)
      • idle_report.exe (PID: 3376)
    • Reads the machine GUID from the registry

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • test_wpf.exe (PID: 32)
      • test_wpf.exe (PID: 2904)
      • idle_report.exe (PID: 5376)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • test_wpf.exe (PID: 3448)
      • brightdata.exe (PID: 2876)
      • mentalmentor.exe (PID: 3964)
      • QtWebEngineProcess.exe (PID: 1440)
      • luminati.exe (PID: 2108)
      • test_wpf.exe (PID: 6912)
      • test_wpf.exe (PID: 6204)
      • idle_report.exe (PID: 3376)
      • luminati.exe (PID: 1064)
    • Reads the software policy settings

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • luminati.exe (PID: 1084)
      • QtWebEngineProcess.exe (PID: 1440)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Checks proxy server information

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • mentalmentor.exe (PID: 3964)
      • QtWebEngineProcess.exe (PID: 1440)
    • Creates a software uninstall entry

      • MentalMentor.tmp (PID: 2180)
    • Creates files in the program directory

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
      • brightdata.exe (PID: 2876)
      • luminati.exe (PID: 1084)
      • luminati.exe (PID: 2108)
      • luminati.exe (PID: 1064)
    • Creates files or folders in the user directory

      • MentalMentor.tmp (PID: 2180)
      • luminati.exe (PID: 3984)
      • QtWebEngineProcess.exe (PID: 1440)
    • Disables trace logs

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 2400)
    • The process uses the downloaded file

      • luminati.exe (PID: 3984)
      • net_updater32.exe (PID: 3332)
      • net_updater32.exe (PID: 2400)
    • Reads the time zone

      • net_updater32.exe (PID: 2400)
    • Reads CPU info

      • net_updater32.exe (PID: 2400)
    • Sends debugging messages

      • QtWebEngineProcess.exe (PID: 7072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 102400
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.0
ProductVersionNumber: 1.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mental Mentor
FileDescription: Mental Mentor Setup
FileVersion: 1.1.0
LegalCopyright: Copyright 2024 Agora International Agency
OriginalFileName: MentalMentor.exe
ProductName: Mental Mentor
ProductVersion: 1.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
171
Monitored processes
39
Malicious processes
10
Suspicious processes
1

Behavior graph

Click at the process to see the details
start mentalmentor.exe mentalmentor.tmp no specs mentalmentor.exe mentalmentor.tmp 7z.exe conhost.exe no specs 7z.exe conhost.exe no specs 7z.exe conhost.exe no specs 7z.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs luminati.exe test_wpf.exe no specs net_updater32.exe conhost.exe no specs net_updater32.exe test_wpf.exe no specs idle_report.exe no specs conhost.exe no specs brightdata.exe no specs conhost.exe no specs wmiapsrv.exe no specs mentalmentor.exe mentalmentor_crashpad_handler.exe no specs luminati.exe qtwebengineprocess.exe qtwebengineprocess.exe no specs test_wpf.exe no specs luminati.exe test_wpf.exe no specs luminati.exe test_wpf.exe no specs idle_report.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32C:\ProgramData\BrightData\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exeC:\ProgramData\BrightData\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exeluminati.exe
User:
admin
Company:
BrightData Ltd.
Integrity Level:
HIGH
Description:
test_wpf
Exit code:
0
Version:
1.429.308
Modules
Images
c:\programdata\brightdata\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1064C:\Users\admin\mentalmentor\luminati\luminati.exe is_switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
101
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1084C:\Users\admin\mentalmentor\luminati\luminati.exe is_switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
101
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1440"C:\Users\admin\mentalmentor\QtWebEngineProcess.exe" --type=utility --enable-features=AllowContentInitiatedDataUrlNavigations,TracingServiceInProcess --disable-features=BackgroundFetch,ConsolidatedMovementXY,DnsOverHttpsUpgrade,FormControlsRefresh,MojoVideoCapture,PictureInPicture,SmsReceiver,UseSkiaRenderer,WebPayments,WebUSB --lang=en-US --service-sandbox-type=network --use-gl=angle --application-name=mentalmentor --webengine-schemes=qrc:sLV --mojo-platform-channel-handle=3180 /prefetch:8C:\Users\admin\mentalmentor\QtWebEngineProcess.exe
mentalmentor.exe
User:
admin
Company:
The Qt Company Ltd.
Integrity Level:
HIGH
Description:
C++ Application Development Framework
Version:
5.15.2.0
Modules
Images
c:\users\admin\mentalmentor\qtwebengineprocess.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2008\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exebrightdata.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2108C:\Users\admin\mentalmentor\luminati\luminati.exe is_switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
101
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2144\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeidle_report.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2180"C:\Users\admin\AppData\Local\Temp\is-K3QV4.tmp\MentalMentor.tmp" /SL5="$B028C,2487297,845312,C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" /SPAWNWND=$803A4 /NOTIFYWND=$60202 C:\Users\admin\AppData\Local\Temp\is-K3QV4.tmp\MentalMentor.tmp
MentalMentor.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-k3qv4.tmp\mentalmentor.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2400"C:/Users/admin/mentalmentor/luminati/net_updater32.exe" --updater win_global_microtrading.mental_mentorC:\Users\admin\mentalmentor\luminati\net_updater32.exe
services.exe
User:
SYSTEM
Company:
BrightData Ltd.
Integrity Level:
SYSTEM
Description:
BrightData service allows free use of certain features in an app you installed
Version:
1.429.308
Modules
Images
c:\users\admin\mentalmentor\luminati\net_updater32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\wintrust.dll
c:\windows\syswow64\msvcrt.dll
2588"C:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\7z.exe" x "C:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\zip_libs.7z" -o"C:\Users\admin\mentalmentor\" * -r -aoaC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\7z.exe
MentalMentor.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\is-hf6e9.tmp\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
25 648
Read events
25 527
Write events
117
Delete events
4

Modification events

(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\mentalmentor
Operation:writeName:autostart
Value:
true
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\mentalmentor
Operation:writeName:reinstall
Value:
false
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\mentalmentor
Operation:writeName:installer
Value:
true
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:InstallLocation
Value:
C:\Users\admin\mentalmentor
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:DisplayName
Value:
Mental Mentor
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\mentalmentor\mentalmentor.exe
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:UninstallString
Value:
C:\Users\admin\mentalmentor\uninstall.exe
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:Publisher
Value:
Mental Mentor
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:URLInfoAbout
Value:
https://mmentorapp.com
(PID) Process:(2180) MentalMentor.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:HelpLink
Value:
https://mmentorapp.com
Executable files
56
Suspicious files
158
Text files
35
Unknown types
3

Dropped files

PID
Process
Filename
Type
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\zip_libs.7z
MD5:
SHA256:
25887z.exeC:\Users\admin\mentalmentor\resources\icudtl.dat
MD5:
SHA256:
2180MentalMentor.tmpC:\Users\admin\mentalmentor\settings\temp\install_configbinary
MD5:18E95DFA863592DBF829D49BA5FB124F
SHA256:FCDF47E2C55487DC993DF954A991409DA886B1CA5E87D9957931A1CD16C62601
2180MentalMentor.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0EA6E8CAD956874A74056FFF9B4B0D39binary
MD5:D59F56F91DC8742CD289C93682B6A63F
SHA256:4DC79005B597F455C2DDA0F02628004B473D2A4F99A633775CD82285D975A8DA
2180MentalMentor.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:3DFCA46E00FFA4795C72A41375F159D3
SHA256:DCBA1A505396539BAC40A7253C9F5DCCF06CBB79957E21D56305E1FC3AF5F40E
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\mentor-inno-lib.dllexecutable
MD5:B53E08B82850626C046A5CEBD295E41C
SHA256:5120508B7CBDEE3D9C89C8ECE6E95C9BEE018C4E09F13D5E0E2F7CF99828D0C6
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\zip_bin.7zcompressed
MD5:88C257EB5DEA882C3CE007C0C2D3AC0F
SHA256:EC3AE2B251F6C2FCCEFE07A364B6D906B2DC309FF184C4A9E0EE63AB68B519B5
2180MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-HF6E9.tmp\7z.dllexecutable
MD5:04AD4B80880B32C94BE8D0886482C774
SHA256:A1E1D1F0FFF4FCCCFBDFA313F3BDFEA4D3DFE2C2D9174A615BBC39A0A6929338
2180MentalMentor.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0EA6E8CAD956874A74056FFF9B4B0D39binary
MD5:5E537D7FE4EE27D0BB82122292119431
SHA256:231B6DD51A090DFCA95B9853396C4C2D02785723CD3090F2BD4F1385F39A70BC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
96
DNS requests
44
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2180
MentalMentor.tmp
GET
200
195.138.255.18:80
http://r10.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRpD%2BQVZ%2B1vf7U0RGQGBm8JZwdxcgQUdKR2KRcYVIUxN75n5gZYwLzFBXICEgSoSeYxtNXJ0yqn6tuYArPQNw%3D%3D
unknown
whitelisted
4316
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1436
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
644
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
644
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2400
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
2400
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
2400
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4SYN8HbX1atPqRDi932Tc%3D
unknown
whitelisted
2400
net_updater32.exe
GET
200
54.221.247.193:80
http://http-test1.brdtnet.com/connection/http-test1.html
unknown
unknown
1440
QtWebEngineProcess.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4316
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6244
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2180
MentalMentor.tmp
51.158.210.166:443
web.mymentalmentor.net
Online S.a.s.
FR
unknown
4316
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2180
MentalMentor.tmp
195.138.255.18:80
r10.o.lencr.org
AS33891 Netzbetrieb GmbH
DE
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1436
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
web.mymentalmentor.net
  • 51.158.210.166
unknown
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.104.136.2
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
r10.o.lencr.org
  • 195.138.255.18
  • 195.138.255.24
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.133
  • 20.190.160.17
  • 20.190.160.22
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.140
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

PID
Process
Class
Message
2400
net_updater32.exe
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
No debug info