File name:

MentalMentor.exe

Full analysis: https://app.any.run/tasks/afbc866d-7420-4c97-af12-d4e0d2c3af33
Verdict: Malicious activity
Analysis date: April 08, 2024, 00:43:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6AE9A89CC08FCF9DF0B6277A4158FD13

SHA1:

A89E8DDC035F2C5837F2DF1F67D195ED81F62ACA

SHA256:

4219AD1ABA06E67DC8F4978DC32CDF1DA817A360798256F907B813BE201580EC

SSDEEP:

98304:i+cD4dnCanjHY8FYY3Yd6tIntZBrh5bMgW1m7lG1J3hXFJw+/iUc7srC+x3ILB10:xNF2bK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MentalMentor.exe (PID: 3956)
      • MentalMentor.exe (PID: 2792)
      • 7z.exe (PID: 1560)
      • 7z.exe (PID: 1572)
      • MentalMentor.tmp (PID: 1824)
      • luminati.exe (PID: 2020)
      • 7z.exe (PID: 1768)
    • Changes the autorun value in the registry

      • mentalmentor.exe (PID: 2972)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • MentalMentor.tmp (PID: 1824)
    • The process drops C-runtime libraries

      • 7z.exe (PID: 1560)
      • luminati.exe (PID: 2020)
    • Drops 7-zip archiver for unpacking

      • MentalMentor.tmp (PID: 1824)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • MentalMentor.tmp (PID: 1824)
    • Non-standard symbols in registry

      • MentalMentor.tmp (PID: 1824)
    • Searches for installed software

      • MentalMentor.tmp (PID: 1824)
    • Reads the Internet Settings

      • mentalmentor.exe (PID: 2972)
      • luminati.exe (PID: 2020)
    • Process drops legitimate windows executable

      • 7z.exe (PID: 1560)
      • luminati.exe (PID: 2020)
    • Detected use of alternative data streams (AltDS)

      • luminati.exe (PID: 2020)
    • Adds/modifies Windows certificates

      • luminati.exe (PID: 2020)
    • Reads security settings of Internet Explorer

      • luminati.exe (PID: 2020)
      • mentalmentor.exe (PID: 2972)
    • Reads settings of System Certificates

      • luminati.exe (PID: 2020)
      • mentalmentor.exe (PID: 2972)
    • Reads the date of Windows installation

      • mentalmentor.exe (PID: 2972)
  • INFO

    • Checks supported languages

      • MentalMentor.tmp (PID: 1692)
      • 7z.exe (PID: 1560)
      • 7z.exe (PID: 1768)
      • mentalmentor.exe (PID: 2972)
      • mentalmentor_crashpad_handler.exe (PID: 3616)
      • MentalMentor.exe (PID: 2792)
      • luminati.exe (PID: 2020)
      • MentalMentor.tmp (PID: 1824)
      • 7z.exe (PID: 1572)
      • MentalMentor.exe (PID: 3956)
      • test_wpf.exe (PID: 1584)
      • mentalmentor.exe (PID: 2620)
      • 7z.exe (PID: 1308)
    • Create files in a temporary directory

      • MentalMentor.exe (PID: 3956)
      • MentalMentor.exe (PID: 2792)
      • MentalMentor.tmp (PID: 1824)
    • Reads the machine GUID from the registry

      • mentalmentor.exe (PID: 2972)
      • MentalMentor.tmp (PID: 1824)
      • luminati.exe (PID: 2020)
      • test_wpf.exe (PID: 1584)
    • Reads the computer name

      • mentalmentor.exe (PID: 2972)
      • test_wpf.exe (PID: 1584)
      • MentalMentor.tmp (PID: 1692)
      • MentalMentor.tmp (PID: 1824)
      • luminati.exe (PID: 2020)
    • Creates a software uninstall entry

      • MentalMentor.tmp (PID: 1824)
    • Manual execution by a user

      • mentalmentor.exe (PID: 2620)
    • Reads Environment values

      • luminati.exe (PID: 2020)
    • Creates files in the program directory

      • luminati.exe (PID: 2020)
    • Reads the software policy settings

      • luminati.exe (PID: 2020)
    • Process checks computer location settings

      • luminati.exe (PID: 2020)
    • Checks proxy server information

      • luminati.exe (PID: 2020)
    • Creates files or folders in the user directory

      • luminati.exe (PID: 2020)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 102400
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.0
ProductVersionNumber: 1.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mental Mentor
FileDescription: Mental Mentor Setup
FileVersion: 1.1.0
LegalCopyright: Copyright 2024 Agora International Agency
OriginalFileName: MentalMentor.exe
ProductName: Mental Mentor
ProductVersion: 1.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
15
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start mentalmentor.exe no specs mentalmentor.tmp no specs mentalmentor.exe mentalmentor.tmp 7z.exe no specs 7z.exe no specs 7z.exe no specs 7z.exe no specs netsh.exe no specs netsh.exe no specs mentalmentor.exe mentalmentor_crashpad_handler.exe no specs mentalmentor.exe no specs luminati.exe test_wpf.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1308"C:\Users\admin\AppData\Local\Temp\is-353R0.tmp\7z.exe" x "C:\Users\admin\AppData\Local\Temp\is-353R0.tmp\zip_html.7z" -o"C:\Users\admin\mentalmentor\settings\temp\inst_gui\" * -r -aoaC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\7z.exeMentalMentor.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\is-353r0.tmp\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1560"C:\Users\admin\AppData\Local\Temp\is-353R0.tmp\7z.exe" x "C:\Users\admin\AppData\Local\Temp\is-353R0.tmp\zip_libs.7z" -o"C:\Users\admin\mentalmentor\" * -r -aoaC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\7z.exeMentalMentor.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\is-353r0.tmp\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1572"C:\Users\admin\AppData\Local\Temp\is-353R0.tmp\7z.exe" x "C:\Users\admin\AppData\Local\Temp\is-353R0.tmp\zip_bin.7z" -o"C:\Users\admin\mentalmentor\" * -r -aoaC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\7z.exeMentalMentor.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\is-353r0.tmp\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1584C:\ProgramData\BrightData\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exeC:\ProgramData\BrightData\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exeluminati.exe
User:
admin
Company:
BrightData Ltd.
Integrity Level:
HIGH
Description:
test_wpf
Exit code:
0
Version:
1.429.308
Modules
Images
c:\programdata\brightdata\1c38ac4e31598c50e45dd311c7d362929c5fedd9\test_wpf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1692"C:\Users\admin\AppData\Local\Temp\is-1VHH8.tmp\MentalMentor.tmp" /SL5="$E0170,2483841,845312,C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" C:\Users\admin\AppData\Local\Temp\is-1VHH8.tmp\MentalMentor.tmpMentalMentor.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-1vhh8.tmp\mentalmentor.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1768"C:\Users\admin\AppData\Local\Temp\is-353R0.tmp\7z.exe" x "C:\Users\admin\AppData\Local\Temp\is-353R0.tmp\zip_lum.7z" -o"C:\Users\admin\mentalmentor\luminati\" * -r -aoaC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\7z.exeMentalMentor.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\is-353r0.tmp\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1824"C:\Users\admin\AppData\Local\Temp\is-8T4HH.tmp\MentalMentor.tmp" /SL5="$100130,2483841,845312,C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-8T4HH.tmp\MentalMentor.tmp
MentalMentor.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-8t4hh.tmp\mentalmentor.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2020"C:\Users\admin\mentalmentor\luminati\luminati.exe" switch_onC:\Users\admin\mentalmentor\luminati\luminati.exe
mentalmentor.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\mentalmentor\luminati\luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\mentalmentor\luminati\lum_sdk32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
2240"netsh" advfirewall firewall add rule name="Mental Mentor" dir=in action=allow program="C:\Users\admin\mentalmentor\mentalmentor.exe" enable=yesC:\Windows\System32\netsh.exeMentalMentor.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2620"C:\Users\admin\mentalmentor\mentalmentor.exe" C:\Users\admin\mentalmentor\mentalmentor.exeexplorer.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
MEDIUM
Description:
Mental Mentor
Exit code:
1
Version:
1.3.3
Modules
Images
c:\users\admin\mentalmentor\mentalmentor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\mentalmentor\sentry.dll
Total events
19 433
Read events
19 158
Write events
258
Delete events
17

Modification events

(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
2007000022FCE9C64D89DA01
(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
E941EF1419953735B5B3481CF2A0A4FC9AD45E4B4D15A76AE799EBBAA53158BA
(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\mentalmentor
Operation:writeName:autostart
Value:
true
(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\mentalmentor
Operation:writeName:reinstall
Value:
false
(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\mentalmentor
Operation:writeName:installer
Value:
true
(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:InstallLocation
Value:
C:\Users\admin\mentalmentor
(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:DisplayName
Value:
Mental Mentor
(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\mentalmentor\mentalmentor.exe
(PID) Process:(1824) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mental Mentor
Operation:writeName:UninstallString
Value:
C:\Users\admin\mentalmentor\uninstall.exe
Executable files
95
Suspicious files
86
Text files
18
Unknown types
11

Dropped files

PID
Process
Filename
Type
3956MentalMentor.exeC:\Users\admin\AppData\Local\Temp\is-1VHH8.tmp\MentalMentor.tmpexecutable
MD5:
SHA256:
2792MentalMentor.exeC:\Users\admin\AppData\Local\Temp\is-8T4HH.tmp\MentalMentor.tmpexecutable
MD5:
SHA256:
1824MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\idp.dllexecutable
MD5:
SHA256:
1824MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\mentor-inno-lib.dllexecutable
MD5:
SHA256:
1824MentalMentor.tmpC:\Users\admin\mentalmentor\settings\temp\install_configbinary
MD5:
SHA256:
1824MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\zip_bin.7zcompressed
MD5:
SHA256:
1824MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\zip_libs.7z
MD5:
SHA256:
1824MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\zip_lum.7zcompressed
MD5:
SHA256:
1824MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\zip_html.7zcompressed
MD5:
SHA256:
1824MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-353R0.tmp\7z.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
37
DNS requests
4
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1824
MentalMentor.tmp
51.158.210.166:443
web.mymentalmentor.net
Online S.a.s.
FR
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2972
mentalmentor.exe
51.158.210.166:443
web.mymentalmentor.net
Online S.a.s.
FR
unknown
2972
mentalmentor.exe
216.239.32.178:443
www.google-analytics.com
GOOGLE
US
unknown
2020
luminati.exe
161.35.48.195:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
unknown
2020
luminati.exe
3.228.177.90:443
AMAZON-AES
US
unknown
2020
luminati.exe
206.189.231.23:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
unknown

DNS requests

Domain
IP
Reputation
web.mymentalmentor.net
  • 51.158.210.166
unknown
www.google-analytics.com
  • 216.239.32.178
  • 216.239.36.178
  • 216.239.34.178
  • 216.239.38.178
whitelisted
perr.lum-sdk.io
  • 161.35.48.195
  • 206.189.231.23
  • 159.223.133.120
  • 192.81.214.145
unknown
perr.l-err.biz
  • 206.189.231.23
  • 159.223.133.120
  • 161.35.48.195
  • 192.81.214.145
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
Process
Message
mentalmentor.exe
QWindowsEGLStaticContext::create: Could not initialize EGL display: error 0x3001
mentalmentor.exe
QWindowsEGLStaticContext::create: When using ANGLE, check if d3dcompiler_4x.dll is available