File name:

MouseWithoutBordersSetup.msi

Full analysis: https://app.any.run/tasks/aa221922-b4ef-4b50-a294-eec76d6d49b1
Verdict: Malicious activity
Analysis date: September 18, 2023, 20:01:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Microsoft Garage Mouse without Borders, Author: Microsoft Garage, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft Garage Mouse without Borders., Template: Intel;1033, Revision Number: {20A8A91A-80F2-4860-8FDD-6F5ACDFC731D}, Create Time/Date: Tue Mar 23 03:11:56 2021, Last Saved Time/Date: Tue Mar 23 03:11:56 2021, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
MD5:

2DAA9BAEDE028A537514CA882DF818FB

SHA1:

0609FD238849A9BC2AAC3ED5AC0AF68E8EB4BE17

SHA256:

52EE7F6DDCD934AC50C937DB06820E7EA6CB1A3908C6431B8B0BCB1E641712CB

SSDEEP:

12288:/GqjbLnwl82DtIanlboksKEwcAHiYnq0jnzh85P+8jOZy2KsGU6a4Ks:hjbUtIWoJwcACYnN65PhOE2Z34K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MouseWithoutBorders.exe (PID: 2784)
      • MouseWithoutBorders.exe (PID: 620)
      • MouseWithoutBordersSvc.exe (PID: 3356)
      • MouseWithoutBorders.exe (PID: 3084)
      • MouseWithoutBordersHelper.exe (PID: 3404)
      • MouseWithoutBordersHelper.exe (PID: 616)
      • MouseWithoutBorders.exe (PID: 1200)
      • MouseWithoutBordersHelper.exe (PID: 664)
      • MouseWithoutBorders.exe (PID: 3408)
      • MouseWithoutBorders.exe (PID: 688)
      • MouseWithoutBordersHelper.exe (PID: 2012)
    • Loads dropped or rewritten executable

      • MouseWithoutBorders.exe (PID: 2784)
      • MouseWithoutBorders.exe (PID: 3084)
      • MouseWithoutBorders.exe (PID: 1200)
      • MouseWithoutBorders.exe (PID: 3408)
      • msiexec.exe (PID: 3636)
      • msiexec.exe (PID: 3116)
    • Creates a writable file the system directory

      • MouseWithoutBorders.exe (PID: 3084)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • msiexec.exe (PID: 2388)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2992)
      • MouseWithoutBordersSvc.exe (PID: 3356)
    • Reads the Internet Settings

      • MouseWithoutBordersHelper.exe (PID: 2012)
  • INFO

    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 2388)
      • msiexec.exe (PID: 3116)
      • MouseWithoutBorders.exe (PID: 2784)
      • MouseWithoutBordersSvc.exe (PID: 3356)
      • MouseWithoutBordersHelper.exe (PID: 616)
      • MouseWithoutBorders.exe (PID: 3084)
      • MouseWithoutBordersHelper.exe (PID: 3404)
      • MouseWithoutBorders.exe (PID: 1200)
      • MouseWithoutBordersHelper.exe (PID: 664)
      • MouseWithoutBorders.exe (PID: 3408)
      • msiexec.exe (PID: 3636)
      • MouseWithoutBordersHelper.exe (PID: 2012)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 3488)
    • Reads the computer name

      • MouseWithoutBordersHelper.exe (PID: 2012)
      • msiexec.exe (PID: 2388)
      • msiexec.exe (PID: 3636)
      • msiexec.exe (PID: 3116)
      • MouseWithoutBorders.exe (PID: 2784)
      • MouseWithoutBordersSvc.exe (PID: 3356)
      • MouseWithoutBordersHelper.exe (PID: 616)
      • MouseWithoutBorders.exe (PID: 3084)
      • MouseWithoutBordersHelper.exe (PID: 3404)
      • MouseWithoutBorders.exe (PID: 1200)
      • MouseWithoutBordersHelper.exe (PID: 664)
      • MouseWithoutBorders.exe (PID: 3408)
    • Checks supported languages

      • msiexec.exe (PID: 2388)
      • msiexec.exe (PID: 3116)
      • msiexec.exe (PID: 3636)
      • MouseWithoutBorders.exe (PID: 2784)
      • MouseWithoutBordersSvc.exe (PID: 3356)
      • MouseWithoutBordersHelper.exe (PID: 616)
      • MouseWithoutBorders.exe (PID: 3084)
      • MouseWithoutBordersHelper.exe (PID: 3404)
      • MouseWithoutBorders.exe (PID: 1200)
      • MouseWithoutBordersHelper.exe (PID: 664)
      • MouseWithoutBorders.exe (PID: 3408)
      • MouseWithoutBordersHelper.exe (PID: 2012)
    • Create files in a temporary directory

      • msiexec.exe (PID: 2388)
    • Application launched itself

      • msiexec.exe (PID: 2388)
    • Manual execution by a user

      • MouseWithoutBorders.exe (PID: 688)
      • MouseWithoutBorders.exe (PID: 3408)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: Read-only recommended
Software: Windows Installer XML Toolset (3.11.2.4516)
Words: 2
Pages: 200
ModifyDate: 2021:03:23 03:11:56
CreateDate: 2021:03:23 03:11:56
RevisionNumber: {20A8A91A-80F2-4860-8FDD-6F5ACDFC731D}
Template: Intel;1033
Comments: This installer database contains the logic and data required to install Microsoft Garage Mouse without Borders.
Keywords: Installer
Author: Microsoft Garage
Subject: Microsoft Garage Mouse without Borders
Title: Installation Database
CodePage: Windows Latin 1 (Western European)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
16
Malicious processes
12
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs mousewithoutbordershelper.exe no specs mousewithoutborders.exe no specs mousewithoutborders.exe mousewithoutborderssvc.exe no specs mousewithoutbordershelper.exe no specs mousewithoutborders.exe no specs mousewithoutbordershelper.exe no specs mousewithoutborders.exe no specs mousewithoutbordershelper.exe no specs mousewithoutborders.exe no specs mousewithoutborders.exe

Process information

PID
CMD
Path
Indicators
Parent process
616"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe" "SvcExec" "winlogon"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exeMouseWithoutBordersSvc.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
Mouse Without Borders Helper
Exit code:
0
Version:
2.2.1.0327
Modules
Images
c:\program files\microsoft garage\mouse without borders\mousewithoutbordershelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
620"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exeMouseWithoutBordersHelper.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Mouse without Borders
Exit code:
3221226540
Version:
2.2.1.0327
Modules
Images
c:\program files\microsoft garage\mouse without borders\mousewithoutborders.exe
c:\windows\system32\ntdll.dll
664"C:\Program Files\Microsoft Garage\Mouse without Borders\MousewithoutBordersHelper.exe" C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exeMouseWithoutBorders.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Mouse Without Borders Helper
Exit code:
0
Version:
2.2.1.0327
Modules
Images
c:\program files\microsoft garage\mouse without borders\mousewithoutbordershelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
688"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exeexplorer.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Mouse without Borders
Exit code:
3221226540
Version:
2.2.1.0327
Modules
Images
c:\program files\microsoft garage\mouse without borders\mousewithoutborders.exe
c:\windows\system32\ntdll.dll
1200"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" "default"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exeMouseWithoutBordersHelper.exe
User:
SYSTEM
Company:
Microsoft
Integrity Level:
SYSTEM
Description:
Mouse without Borders
Exit code:
0
Version:
2.2.1.0327
Modules
Images
c:\program files\microsoft garage\mouse without borders\mousewithoutborders.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2012"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe" install completedC:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exemsiexec.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Mouse Without Borders Helper
Exit code:
0
Version:
2.2.1.0327
Modules
Images
c:\program files\microsoft garage\mouse without borders\mousewithoutbordershelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2388C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2784"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe
MouseWithoutBordersHelper.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Mouse without Borders
Exit code:
0
Version:
2.2.1.0327
Modules
Images
c:\program files\microsoft garage\mouse without borders\mousewithoutborders.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
2992C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3084"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" "winlogon"C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exeMouseWithoutBordersHelper.exe
User:
SYSTEM
Company:
Microsoft
Integrity Level:
SYSTEM
Description:
Mouse without Borders
Exit code:
0
Version:
2.2.1.0327
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft garage\mouse without borders\mousewithoutborders.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
Total events
10 660
Read events
10 558
Write events
92
Delete events
10

Modification events

(PID) Process:(3488) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
72
(PID) Process:(2388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008C62D6BA16B0D901C80700002C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
400000000000000064514ABC16B0D901C80700002C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
400000000000000064514ABC16B0D901C80700002C0A0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Leave)
Value:
400000000000000034645DBC16B0D901C80700002C0A0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
4000000000000000781D5ABD16B0D901C80700002C0A0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2388) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Leave)
Value:
4000000000000000781D5ABD16B0D901C80700002C0A0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
Executable files
10
Suspicious files
11
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
2388msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2388msiexec.exeC:\Windows\Installer\fb78f.msiexecutable
MD5:2DAA9BAEDE028A537514CA882DF818FB
SHA256:52EE7F6DDCD934AC50C937DB06820E7EA6CB1A3908C6431B8B0BCB1E641712CB
2388msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:24F8BB4660E6AAFACFA1F80FBFEB6847
SHA256:6D3DF5813C5CE8EE34047E46A97DA6AE0E8637E48FF013B450EE582839C9DF7E
2388msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF9FFAF1A9A6FCEF31.TMPbinary
MD5:EA3EC5A572DF6630F7DE39F877ACF35E
SHA256:ED9139DCA1074BFD94F92881FFAEBA544BE7047725672C6CD26EFEEEC44EF11E
2388msiexec.exeC:\Windows\Installer\fb790.ipibinary
MD5:FD40EB6F784B0F0BBD0F81054E077644
SHA256:D53F8D2C07A12B8785C4185967D5C68FF70532029FEB7EB716B28F8E6B355755
2388msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{d6bbfd07-d841-4299-b123-45285b720b80}_OnDiskSnapshotPropbinary
MD5:24F8BB4660E6AAFACFA1F80FBFEB6847
SHA256:6D3DF5813C5CE8EE34047E46A97DA6AE0E8637E48FF013B450EE582839C9DF7E
2388msiexec.exeC:\Program Files\Microsoft Garage\Mouse without Borders\Microsoft.ApplicationInsights.dllexecutable
MD5:4C4DFB5B8E6298B68254D4CC3166E71A
SHA256:7A02A236FCF1A21FC43E26AB6179AEA593074D70CBF1E11B46731106A4956107
2388msiexec.exeC:\Windows\Installer\MSIBB0B.tmpexecutable
MD5:93394D2866590FB66759F5F0263453F2
SHA256:5C29B8255ACE0CD94C066C528C8AD04F0F45EBA12FCF94DA7B9CA1B64AD4288B
2388msiexec.exeC:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe.configxml
MD5:B17A85C57FC2733A410E8F2C0BC3FD01
SHA256:48D7EF9BC8949F337F958B54145130C4A666E8CCC261B2E27D156F09AEA2E893
2388msiexec.exeC:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe.manifestxml
MD5:9E1EDE53B9AE340709E352F676878EDA
SHA256:BD38A43C7BC9A5943F72197F6C6AD5601E0F7FB3545F9DE2AB57F3867E1D4291
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info