File name:

mouse-jiggler-1-8-35.zip

Full analysis: https://app.any.run/tasks/b20429a1-5a55-4fa2-a3ac-c41eb744822f
Verdict: No threats detected
Analysis date: June 02, 2020, 00:54:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

2F717AD23DD76D5FEEC0D4ACABE355F7

SHA1:

D620964F451A7927795E2E27EEAFCFC680956F55

SHA256:

3265C9646E2A59D86679FDA8120348C1F667A3180F0925928DA927B707CDAD74

SSDEEP:

768:rt+NkXNZXlREId3eJG53Gl3my86iCgkJvBH7:Sk/Xj3eJG53Gl3mxdvsb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MouseJiggle.exe (PID: 1904)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3100)
    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 3100)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:05:17 04:48:21
ZipCRC: 0x5c21589e
ZipCompressedSize: 38406
ZipUncompressedSize: 54784
ZipFileName: MouseJiggle.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe mousejiggle.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1904"C:\Users\admin\AppData\Local\Temp\Rar$EXa3100.14172\MouseJiggle.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3100.14172\MouseJiggle.exeWinRAR.exe
User:
admin
Company:
Arkane Systems
Integrity Level:
MEDIUM
Description:
MouseJiggle
Exit code:
0
Version:
1.8.35
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3100.14172\mousejiggle.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3100"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\mouse-jiggler-1-8-35.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4084"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa3100.17093\MouseJiggle.exe.configC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
448
Read events
435
Write events
13
Delete events
0

Modification events

(PID) Process:(3100) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3100) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3100) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3100) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3100) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\mouse-jiggler-1-8-35.zip
(PID) Process:(3100) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3100) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3100) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3100) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3100) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
1
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3100WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3100.14172\MouseJiggle.exeexecutable
MD5:132B4BAA418D4CD557E7792A9E3671CE
SHA256:4D787F358EC40B587939E69FF7A3A1D5E95F2646EF680F4B8C0E390E0BB2EE76
3100WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3100.17093\MouseJiggle.exe.configxml
MD5:0C02012F18E2755CE1BFAA8C81ABE14E
SHA256:93B3433679EE8D782F69E37136E207BD5E125F1EF79542BF9D7E84C1C84FEEA5
3100WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3100.14172\MouseJiggle.exe.configxml
MD5:0C02012F18E2755CE1BFAA8C81ABE14E
SHA256:93B3433679EE8D782F69E37136E207BD5E125F1EF79542BF9D7E84C1C84FEEA5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info