File name:

RemoteMouse_windows.zip

Full analysis: https://app.any.run/tasks/1ae1b9b0-6703-428d-8360-902ec372c29a
Verdict: Malicious activity
Analysis date: January 04, 2024, 03:59:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

8A43184C1A91AA6F5654D1EECA7C3A6B

SHA1:

3046BD359C750E9F895F74F2C60A2322801343CF

SHA256:

2E7343C915CDC313778BB75C48924FB4382EEB68CEF4769A2D66640521AFB26B

SSDEEP:

98304:EPnHpiLLju+xy2L1bGD+iPmRSN1UOySCvi8qPOTX0D7XCFlzCkzqBqDnjx7fd1c9:pavqF4Q3K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • RemoteMouseCore.exe (PID: 984)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • msiexec.exe (PID: 2020)
    • Reads the Internet Settings

      • RemoteMouse.exe (PID: 2476)
    • Reads settings of System Certificates

      • RemoteMouse.exe (PID: 2476)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2040)
      • msiexec.exe (PID: 2080)
      • msiexec.exe (PID: 2020)
    • Checks supported languages

      • msiexec.exe (PID: 2020)
      • msiexec.exe (PID: 480)
      • msiexec.exe (PID: 376)
      • RemoteMouseService.exe (PID: 664)
      • RemoteMouseCore.exe (PID: 984)
      • RemoteMouse.exe (PID: 2476)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2080)
    • Application launched itself

      • msiexec.exe (PID: 2020)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 2020)
      • msiexec.exe (PID: 480)
      • msiexec.exe (PID: 376)
      • RemoteMouseCore.exe (PID: 984)
      • RemoteMouse.exe (PID: 2476)
    • Reads the computer name

      • msiexec.exe (PID: 480)
      • msiexec.exe (PID: 2020)
      • msiexec.exe (PID: 376)
      • RemoteMouseService.exe (PID: 664)
      • RemoteMouseCore.exe (PID: 984)
      • RemoteMouse.exe (PID: 2476)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1972)
      • RemoteMouseService.exe (PID: 664)
    • Create files in a temporary directory

      • msiexec.exe (PID: 2020)
    • Manual execution by a user

      • RemoteMouse.exe (PID: 2596)
      • RemoteMouse.exe (PID: 2476)
    • Reads Environment values

      • RemoteMouse.exe (PID: 2476)
    • Reads product name

      • RemoteMouse.exe (PID: 2476)
    • Creates files in the program directory

      • RemoteMouse.exe (PID: 2476)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:12:12 12:42:56
ZipCRC: 0x9e73ece9
ZipCompressedSize: 4163771
ZipUncompressedSize: 6150656
ZipFileName: RemoteMouse.msi
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs remotemouseservice.exe no specs remotemousecore.exe no specs remotemouse.exe no specs remotemouse.exe

Process information

PID
CMD
Path
Indicators
Parent process
376C:\Windows\system32\MsiExec.exe -Embedding 7151A15F8E521586A90F3CDFB6175CF1C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
480C:\Windows\system32\MsiExec.exe -Embedding 43E97459FCC4A317F5ADE9A86324DCD7 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
664"C:\Program Files\Remote Mouse\RemoteMouseService.exe"C:\Program Files\Remote Mouse\RemoteMouseService.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
Remote Mouse Service
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\program files\remote mouse\remotemouseservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
984"C:\Program Files\Remote Mouse\RemoteMouseCore.exe"C:\Program Files\Remote Mouse\RemoteMouseCore.exeRemoteMouseService.exe
User:
SYSTEM
Company:
RemoteMouse.net
Integrity Level:
SYSTEM
Description:
Remote Mouse
Exit code:
0
Version:
2.8.0.4
Modules
Images
c:\program files\remote mouse\remotemousecore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1972C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2020C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2040"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\RemoteMouse_windows.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2080"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa2040.26927\RemoteMouse.msi" C:\Windows\System32\msiexec.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2476"C:\Program Files\Remote Mouse\RemoteMouse.exe" C:\Program Files\Remote Mouse\RemoteMouse.exe
explorer.exe
User:
admin
Company:
remotemouse.net
Integrity Level:
HIGH
Description:
Remote Mouse
Exit code:
0
Version:
4.6.0.1
Modules
Images
c:\program files\remote mouse\remotemouse.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2596"C:\Program Files\Remote Mouse\RemoteMouse.exe" C:\Program Files\Remote Mouse\RemoteMouse.exeexplorer.exe
User:
admin
Company:
remotemouse.net
Integrity Level:
MEDIUM
Description:
Remote Mouse
Exit code:
3221226540
Version:
4.6.0.1
Modules
Images
c:\program files\remote mouse\remotemouse.exe
c:\windows\system32\ntdll.dll
Total events
13 628
Read events
13 527
Write events
91
Delete events
10

Modification events

(PID) Process:(2040) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
22
Suspicious files
10
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2040.26927\RemoteMouse.msi
MD5:
SHA256:
2020msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2020msiexec.exeC:\Windows\Installer\e3bbc.msi
MD5:
SHA256:
2080msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIC11.tmpexecutable
MD5:5A1F2196056C0A06B79A77AE981C7761
SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E
2080msiexec.exeC:\Users\admin\AppData\Local\Temp\MSID30.tmpexecutable
MD5:5A1F2196056C0A06B79A77AE981C7761
SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E
2080msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIC81.tmpexecutable
MD5:5A1F2196056C0A06B79A77AE981C7761
SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E
2020msiexec.exeC:\Program Files\Remote Mouse\WindowsInput.dllexecutable
MD5:D711DAF0138D35BDB878E397E0ABB7C0
SHA256:81110D44256397F0F3C572A20CA94BB4C669E5DE89F9348ABAD263FBD81C54B9
2020msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{0076567d-9e60-4e2a-b59c-0dae10c0e761}_OnDiskSnapshotPropbinary
MD5:308665C1BA5FB4693260B4F00CBFDC5E
SHA256:6710807C5F6217A45BB7E1B03E311C46D43ABEB369C589B2D54834E61004F012
2020msiexec.exeC:\Windows\Installer\MSI40ED.tmpexecutable
MD5:5A1F2196056C0A06B79A77AE981C7761
SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E
2020msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:308665C1BA5FB4693260B4F00CBFDC5E
SHA256:6710807C5F6217A45BB7E1B03E311C46D43ABEB369C589B2D54834E61004F012
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2476
RemoteMouse.exe
192.168.100.255:2008
whitelisted
2476
RemoteMouse.exe
188.114.96.0:443
www.remotemouse.net
CLOUDFLARENET
NL
unknown

DNS requests

Domain
IP
Reputation
www.remotemouse.net
  • 188.114.96.0
whitelisted

Threats

No threats detected
No debug info