| File name: | MouseWithoutBordersSetup.msi |
| Full analysis: | https://app.any.run/tasks/aa221922-b4ef-4b50-a294-eec76d6d49b1 |
| Verdict: | Malicious activity |
| Analysis date: | September 18, 2023, 20:01:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Microsoft Garage Mouse without Borders, Author: Microsoft Garage, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft Garage Mouse without Borders., Template: Intel;1033, Revision Number: {20A8A91A-80F2-4860-8FDD-6F5ACDFC731D}, Create Time/Date: Tue Mar 23 03:11:56 2021, Last Saved Time/Date: Tue Mar 23 03:11:56 2021, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2 |
| MD5: | 2DAA9BAEDE028A537514CA882DF818FB |
| SHA1: | 0609FD238849A9BC2AAC3ED5AC0AF68E8EB4BE17 |
| SHA256: | 52EE7F6DDCD934AC50C937DB06820E7EA6CB1A3908C6431B8B0BCB1E641712CB |
| SSDEEP: | 12288:/GqjbLnwl82DtIanlboksKEwcAHiYnq0jnzh85P+8jOZy2KsGU6a4Ks:hjbUtIWoJwcACYnN65PhOE2Z34K |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| Security: | Read-only recommended |
|---|---|
| Software: | Windows Installer XML Toolset (3.11.2.4516) |
| Words: | 2 |
| Pages: | 200 |
| ModifyDate: | 2021:03:23 03:11:56 |
| CreateDate: | 2021:03:23 03:11:56 |
| RevisionNumber: | {20A8A91A-80F2-4860-8FDD-6F5ACDFC731D} |
| Template: | Intel;1033 |
| Comments: | This installer database contains the logic and data required to install Microsoft Garage Mouse without Borders. |
| Keywords: | Installer |
| Author: | Microsoft Garage |
| Subject: | Microsoft Garage Mouse without Borders |
| Title: | Installation Database |
| CodePage: | Windows Latin 1 (Western European) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 616 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe" "SvcExec" "winlogon" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe | — | MouseWithoutBordersSvc.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: Mouse Without Borders Helper Exit code: 0 Version: 2.2.1.0327 Modules
| |||||||||||||||
| 620 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe | — | MouseWithoutBordersHelper.exe | |||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Mouse without Borders Exit code: 3221226540 Version: 2.2.1.0327 Modules
| |||||||||||||||
| 664 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MousewithoutBordersHelper.exe" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe | — | MouseWithoutBorders.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Mouse Without Borders Helper Exit code: 0 Version: 2.2.1.0327 Modules
| |||||||||||||||
| 688 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Mouse without Borders Exit code: 3221226540 Version: 2.2.1.0327 Modules
| |||||||||||||||
| 1200 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" "default" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe | — | MouseWithoutBordersHelper.exe | |||||||||||
User: SYSTEM Company: Microsoft Integrity Level: SYSTEM Description: Mouse without Borders Exit code: 0 Version: 2.2.1.0327 Modules
| |||||||||||||||
| 2012 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe" install completed | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe | — | msiexec.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Mouse Without Borders Helper Exit code: 0 Version: 2.2.1.0327 Modules
| |||||||||||||||
| 2388 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2784 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe | MouseWithoutBordersHelper.exe | ||||||||||||
User: admin Company: Microsoft Integrity Level: HIGH Description: Mouse without Borders Exit code: 0 Version: 2.2.1.0327 Modules
| |||||||||||||||
| 2992 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3084 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" "winlogon" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe | — | MouseWithoutBordersHelper.exe | |||||||||||
User: SYSTEM Company: Microsoft Integrity Level: SYSTEM Description: Mouse without Borders Exit code: 0 Version: 2.2.1.0327 Modules
| |||||||||||||||
| (PID) Process: | (3488) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2388) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2388) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2388) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 72 | |||
| (PID) Process: | (2388) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000008C62D6BA16B0D901C80700002C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2388) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Leave) |
Value: 400000000000000064514ABC16B0D901C80700002C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2388) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Enter) |
Value: 400000000000000064514ABC16B0D901C80700002C0A0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2388) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Leave) |
Value: 400000000000000034645DBC16B0D901C80700002C0A0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2388) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Leave) |
Value: 4000000000000000781D5ABD16B0D901C80700002C0A0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2388) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Leave) |
Value: 4000000000000000781D5ABD16B0D901C80700002C0A0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2388 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2388 | msiexec.exe | C:\Windows\Installer\fb78f.msi | executable | |
MD5:2DAA9BAEDE028A537514CA882DF818FB | SHA256:52EE7F6DDCD934AC50C937DB06820E7EA6CB1A3908C6431B8B0BCB1E641712CB | |||
| 2388 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:24F8BB4660E6AAFACFA1F80FBFEB6847 | SHA256:6D3DF5813C5CE8EE34047E46A97DA6AE0E8637E48FF013B450EE582839C9DF7E | |||
| 2388 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF9FFAF1A9A6FCEF31.TMP | binary | |
MD5:EA3EC5A572DF6630F7DE39F877ACF35E | SHA256:ED9139DCA1074BFD94F92881FFAEBA544BE7047725672C6CD26EFEEEC44EF11E | |||
| 2388 | msiexec.exe | C:\Windows\Installer\fb790.ipi | binary | |
MD5:FD40EB6F784B0F0BBD0F81054E077644 | SHA256:D53F8D2C07A12B8785C4185967D5C68FF70532029FEB7EB716B28F8E6B355755 | |||
| 2388 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{d6bbfd07-d841-4299-b123-45285b720b80}_OnDiskSnapshotProp | binary | |
MD5:24F8BB4660E6AAFACFA1F80FBFEB6847 | SHA256:6D3DF5813C5CE8EE34047E46A97DA6AE0E8637E48FF013B450EE582839C9DF7E | |||
| 2388 | msiexec.exe | C:\Program Files\Microsoft Garage\Mouse without Borders\Microsoft.ApplicationInsights.dll | executable | |
MD5:4C4DFB5B8E6298B68254D4CC3166E71A | SHA256:7A02A236FCF1A21FC43E26AB6179AEA593074D70CBF1E11B46731106A4956107 | |||
| 2388 | msiexec.exe | C:\Windows\Installer\MSIBB0B.tmp | executable | |
MD5:93394D2866590FB66759F5F0263453F2 | SHA256:5C29B8255ACE0CD94C066C528C8AD04F0F45EBA12FCF94DA7B9CA1B64AD4288B | |||
| 2388 | msiexec.exe | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe.config | xml | |
MD5:B17A85C57FC2733A410E8F2C0BC3FD01 | SHA256:48D7EF9BC8949F337F958B54145130C4A666E8CCC261B2E27D156F09AEA2E893 | |||
| 2388 | msiexec.exe | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe.manifest | xml | |
MD5:9E1EDE53B9AE340709E352F676878EDA | SHA256:BD38A43C7BC9A5943F72197F6C6AD5601E0F7FB3545F9DE2AB57F3867E1D4291 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |