download:

/yeongpin/cursor-free-vip/main/scripts/install.ps1

Full analysis: https://app.any.run/tasks/4b8fd14e-f058-4b79-ad97-2b3bea58eb24
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: April 13, 2025, 14:10:09
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
python
stealer
Indicators:
MIME: text/plain
File info: Unicode text, UTF-8 text
MD5:

C383FE46E2FAA3D7E59FA1D15026624A

SHA1:

33C9667E4A9BF755C934368AEEA7CED4DB8C7C4D

SHA256:

4314D773937FA789BD0659870CB499DFDFED1571B8EA1F88E71C0EBF82118D0C

SSDEEP:

192:xDZZffZeiAzziikvdeOe4FKRc1tP24E9mRMIxwNBC1M8xlhPDAw5nONCZzSllf/g:xcc9bvLvwqUCT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 4776)
    • Script downloads file (POWERSHELL)

      • powershell.exe (PID: 4776)
    • Actions looks like stealing of personal data

      • CursorFreeVIP_1.9.02_windows.exe (PID: 8052)
  • SUSPICIOUS

    • Gets path to any of the special folders (POWERSHELL)

      • powershell.exe (PID: 4776)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 4776)
    • Creates new GUID (POWERSHELL)

      • powershell.exe (PID: 4776)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 4776)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7956)
    • Process drops python dynamic module

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7956)
    • The process drops C-runtime libraries

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7956)
    • Process drops legitimate windows executable

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7956)
    • Application launched itself

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7760)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7956)
    • Loads Python modules

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7760)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 8052)
    • Reads security settings of Internet Explorer

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7760)
    • Reads the date of Windows installation

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7760)
  • INFO

    • Checks proxy server information

      • powershell.exe (PID: 4776)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 8052)
    • Disables trace logs

      • powershell.exe (PID: 4776)
    • Checks supported languages

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7760)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7956)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 8052)
    • The executable file from the user directory is run by the Powershell process

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
    • Reads the computer name

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7956)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 8052)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7760)
    • The sample compiled with english language support

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7956)
    • Create files in a temporary directory

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7676)
      • CursorFreeVIP_1.9.02_windows.exe (PID: 7956)
    • Process checks computer location settings

      • CursorFreeVIP_1.9.02_windows.exe (PID: 7760)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • CursorFreeVIP_1.9.02_windows.exe (PID: 8052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
10
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start powershell.exe conhost.exe no specs sppextcomobj.exe no specs slui.exe no specs cursorfreevip_1.9.02_windows.exe conhost.exe no specs cursorfreevip_1.9.02_windows.exe no specs cursorfreevip_1.9.02_windows.exe conhost.exe no specs cursorfreevip_1.9.02_windows.exe

Process information

PID
CMD
Path
Indicators
Parent process
4776"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ep bypass C:\Users\admin\AppData\Local\Temp\install.ps1C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5972\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7244C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7276"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7676"C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exe" C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exe
powershell.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\downloads\cursorfreevip_1.9.02_windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7684\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeCursorFreeVIP_1.9.02_windows.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7760"C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exe" C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exeCursorFreeVIP_1.9.02_windows.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\downloads\cursorfreevip_1.9.02_windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7956"C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exe" "C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exe"C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exe
CursorFreeVIP_1.9.02_windows.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\downloads\cursorfreevip_1.9.02_windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7968\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeCursorFreeVIP_1.9.02_windows.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8052"C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exe" "C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exe"C:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exe
CursorFreeVIP_1.9.02_windows.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\downloads\cursorfreevip_1.9.02_windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
7 848
Read events
7 848
Write events
0
Delete events
0

Modification events

No data
Executable files
166
Suspicious files
47
Text files
82
Unknown types
0

Dropped files

PID
Process
Filename
Type
4776powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_hxlnubhv.3jq.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4776powershell.exeC:\Users\admin\Downloads\CursorFreeVIP_1.9.02_windows.exeexecutable
MD5:B57C38A5424E8514D29AD5FB3BE1AA95
SHA256:AEB1640F4444153B9EBF749D7D3C4D8A1F210D46E5B2F5386D1F2052A2FC1D23
4776powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\I70S40RHXFXBDMREIJW9.tempbinary
MD5:80A19AE45ADAB6A5E814F3D248D90262
SHA256:E04FD672DCA7A7725E3ACDF1D293CCFD92FC9AD128929A123D724AD740F5D6AE
7676CursorFreeVIP_1.9.02_windows.exeC:\Users\admin\AppData\Local\Temp\_MEI76762\.envtext
MD5:FF0836B4B4AE4306C8876E21CD23B139
SHA256:EEC838829EA4B89370F0C4FBDFD72B9B474563143503AF5A56BBD673F165C654
4776powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF10b74c.TMPbinary
MD5:D040F64E9E7A2BB91ABCA5613424598E
SHA256:D04E0A6940609BD6F3B561B0F6027F5CA4E8C5CF0FB0D0874B380A0374A8D670
4776powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_qnant5n3.tp0.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4776powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:80A19AE45ADAB6A5E814F3D248D90262
SHA256:E04FD672DCA7A7725E3ACDF1D293CCFD92FC9AD128929A123D724AD740F5D6AE
7676CursorFreeVIP_1.9.02_windows.exeC:\Users\admin\AppData\Local\Temp\_MEI76762\VCRUNTIME140.dllexecutable
MD5:862F820C3251E4CA6FC0AC00E4092239
SHA256:36585912E5EAF83BA9FEA0631534F690CCDC2D7BA91537166FE53E56C221E153
7676CursorFreeVIP_1.9.02_windows.exeC:\Users\admin\AppData\Local\Temp\_MEI76762\PBlock\enabled16.pngimage
MD5:9DAC5BD26CC87432E558A3654D1D2D9D
SHA256:6A657292D79D7F98410658C222FB418C2B732CD941BE16AEB893EF021B8A848F
7676CursorFreeVIP_1.9.02_windows.exeC:\Users\admin\AppData\Local\Temp\_MEI76762\PBlock\rules.jsonbinary
MD5:114C7B0A84F39904DA39789284C91EDC
SHA256:BB98AB23D1E2FA799CF4AA490C1C6AD074AA07888F3E7971321BB0C759BA7C1E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
23
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8160
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8160
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6544
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4776
powershell.exe
140.82.121.5:443
api.github.com
GITHUB
US
whitelisted
4776
powershell.exe
140.82.121.4:443
github.com
GITHUB
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.72
  • 2.16.164.34
  • 2.16.164.113
  • 2.16.164.106
  • 2.16.164.25
  • 2.16.164.98
  • 2.16.164.112
  • 2.16.164.99
whitelisted
login.live.com
  • 20.190.159.71
  • 40.126.31.129
  • 20.190.159.2
  • 20.190.159.130
  • 40.126.31.73
  • 40.126.31.130
  • 40.126.31.71
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
api.github.com
  • 140.82.121.5
whitelisted
github.com
  • 140.82.121.4
whitelisted
objects.githubusercontent.com
  • 185.199.110.133
  • 185.199.109.133
  • 185.199.111.133
  • 185.199.108.133
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
No debug info