File name: | RemoteMouse.exe |
Full analysis: | https://app.any.run/tasks/76c785c0-285c-4bfd-800b-97cb51ce4480 |
Verdict: | Malicious activity |
Analysis date: | November 25, 2023, 10:54:17 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 82BDBD98358B28B05A65F8BE37979FF2 |
SHA1: | 8C9E1B71C3A72CF6EB006C41E90F8990E920CE09 |
SHA256: | 705536708E71583D67BA1EB75011FB8DCA771900CDB8036A1BE24D023C70AC9B |
SSDEEP: | 49152:Nqe3f6e5qU/798Jnkw+DidXvh6dS/04OOR5QvuE:cSie5T/7E+DidXvh6d204OOR5quE |
.exe | | | Inno Setup installer (51.8) |
---|---|---|
.exe | | | InstallShield setup (20.3) |
.exe | | | Win32 EXE PECompact compressed (generic) (19.6) |
.dll | | | Win32 Dynamic Link Library (generic) (3.1) |
.exe | | | Win32 Executable (generic) (2.1) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2020:11:15 10:48:30+01:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 741376 |
InitializedDataSize: | 38400 |
UninitializedDataSize: | - |
EntryPoint: | 0xb5eec |
OSVersion: | 6.1 |
ImageVersion: | 6 |
SubsystemVersion: | 6.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 0.0.0.0 |
ProductVersionNumber: | 0.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | This installation was built with Inno Setup. |
CompanyName: | Remote Mouse |
FileDescription: | Remote Mouse Setup |
FileVersion: | |
LegalCopyright: | |
OriginalFileName: | |
ProductName: | Remote Mouse |
ProductVersion: | 4.601 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
120 | "C:\Windows\System32\sc.exe" stop RemoteMouseService | C:\Windows\System32\sc.exe | — | RemoteMouse.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
296 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=3 --ie-frame-hwnd=801be | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | ie_to_edge_stub.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Edge Exit code: 1002 Version: 109.0.1518.115 Modules
| |||||||||||||||
664 | "C:\Program Files\Internet Explorer\iexplore.exe" https://www.remotemouse.net/faq.php | C:\Program Files\Internet Explorer\iexplore.exe | RemoteMouse.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
880 | "C:\Windows\system32\netsh.exe" firewall add allowedprogram "C:\Program Files\Remote Mouse\RemoteMouse.exe" "Remote Mouse" ENABLE ALL | C:\Windows\System32\netsh.exe | — | RemoteMouse.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
900 | "C:\Windows\system32\sc.exe" create RemoteMouseService binPath= "C:\Program Files\Remote Mouse\RemoteMouseService.exe" start= auto | C:\Windows\System32\sc.exe | — | RemoteMouse.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
948 | "C:\Users\admin\AppData\Local\Temp\RemoteMouse.exe" | C:\Users\admin\AppData\Local\Temp\RemoteMouse.exe | — | explorer.exe | |||||||||||
User: admin Company: Remote Mouse Integrity Level: MEDIUM Description: Remote Mouse Setup Exit code: 0 Version: Modules
| |||||||||||||||
1212 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:664 CREDAT:275457 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
1820 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3268 CREDAT:275457 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
1988 | "C:\Users\admin\AppData\Local\Temp\is-IS8C7.tmp\RemoteMouse.tmp" /SL5="$90158,1425428,780800,C:\Users\admin\AppData\Local\Temp\RemoteMouse.exe" /SPAWNWND=$D0182 /NOTIFYWND=$7019C | C:\Users\admin\AppData\Local\Temp\is-IS8C7.tmp\RemoteMouse.tmp | RemoteMouse.exe | ||||||||||||
User: admin Company: Remote Mouse Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
1992 | C:\Windows\system32\rundll32.exe C:\Windows\system32\inetcpl.cpl,ClearMyTracksByProcess Flags:65800 WinX:0 WinY:0 IEFrame:00000000 | C:\Windows\System32\rundll32.exe | — | iexplore.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (1988) RemoteMouse.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (1988) RemoteMouse.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1988) RemoteMouse.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (1988) RemoteMouse.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (1988) RemoteMouse.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (1988) RemoteMouse.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (1988) RemoteMouse.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (1988) RemoteMouse.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (1988) RemoteMouse.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3144) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{1105971C-7ABE-448B-B3DE-25911D49485E}\{8CA35885-36FF-474B-9336-17482B594C96} |
Operation: | delete key | Name: | (default) |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
1988 | RemoteMouse.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464 | binary | |
MD5:4FACCFF6EF8CB075081E76648A993FDE | SHA256:F686EEDDB5733E8A64E25380EB6B79DA0F85F241F5719144B01A8F4F7E32DDCC | |||
948 | RemoteMouse.exe | C:\Users\admin\AppData\Local\Temp\is-3TKD9.tmp\RemoteMouse.tmp | executable | |
MD5:81EB391252535D290C3D4AC7954C6FDE | SHA256:0D9DCF6F1186D719BE00D14D1A17D147A7EFEA2D5DD3A9569ED29D8E0BF525B2 | |||
1988 | RemoteMouse.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:8BDC863AF1C1B013AFFC62F84F80230C | SHA256:041EE8A96BE4D0418E7843FB9E66F320A0E56B86CC17A67D358A0C28F01B248B | |||
1988 | RemoteMouse.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464 | binary | |
MD5:8202A1CD02E7D69597995CABBE881A12 | SHA256:58F381C3A0A0ACE6321DA22E40BD44A597BD98B9C9390AB9258426B5CF75A7A5 | |||
3836 | NetFrameworkInstaller.exe | C:\a9cda75f5139450cfc03\DisplayIcon.ico | image | |
MD5:F9657D290048E169FFABBBB9C7412BE0 | SHA256:B74AD253B9B8F9FCADE725336509143828EE739CC2B24782BE3ECFF26F229160 | |||
3836 | NetFrameworkInstaller.exe | C:\a9cda75f5139450cfc03\header.bmp | image | |
MD5:41C22EFA84CA74F0CE7076EB9A482E38 | SHA256:255025A0D79EF2DAC04BD610363F966EF58328400BF31E1F8915E676478CD750 | |||
1988 | RemoteMouse.tmp | C:\Users\admin\AppData\Local\Temp\is-VG6NA.tmp\NetFrameworkInstaller.exe | executable | |
MD5:4D1BB86D0EEE168E1DA91A36350C1C21 | SHA256:E10C2A36C5013EE83815FCC38963AE3E5C4AFD7FFE770E817322FE366BDEF6E1 | |||
3836 | NetFrameworkInstaller.exe | C:\a9cda75f5139450cfc03\Graphics\Rotate10.ico | image | |
MD5:0CCA04A3468575FDCEFEE9957E32F904 | SHA256:B94E68C711B3B06D9A63C80AD013C7C7BBDB5F8E82CBC866B246FF22D99B03FE | |||
3836 | NetFrameworkInstaller.exe | C:\a9cda75f5139450cfc03\Graphics\Print.ico | image | |
MD5:D39BAD9DDA7B91613CB29B6BD55F0901 | SHA256:D80FFEB020927F047C11FC4D9F34F985E0C7E5DFEA9FB23F2BC134874070E4E6 | |||
3836 | NetFrameworkInstaller.exe | C:\a9cda75f5139450cfc03\watermark.bmp | image | |
MD5:B0075CEE80173D764C0237E840BA5879 | SHA256:AB18374B3AAB10E5979E080D0410579F9771DB888BA1B80A5D81BA8896E2D33A |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1988 | RemoteMouse.tmp | GET | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | — |
1988 | RemoteMouse.tmp | GET | 200 | 67.27.233.126:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?93fae79f393bea3b | unknown | compressed | 4.66 Kb | — |
1988 | RemoteMouse.tmp | GET | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D | unknown | binary | 724 b | — |
1080 | svchost.exe | GET | 304 | 67.27.233.126:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?60b2f43ad8cf70d9 | unknown | — | — | — |
2868 | Setup.exe | GET | 200 | 2.22.242.121:80 | http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | unknown | binary | 767 b | — |
2868 | Setup.exe | GET | 200 | 2.22.242.121:80 | http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl | unknown | binary | 519 b | — |
3268 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | binary | 471 b | — |
1820 | iexplore.exe | GET | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D | unknown | binary | 724 b | — |
1820 | iexplore.exe | GET | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | — |
1820 | iexplore.exe | GET | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | binary | 724 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1988 | RemoteMouse.tmp | 188.114.97.3:443 | www.remotemouse.net | CLOUDFLARENET | NL | unknown |
1988 | RemoteMouse.tmp | 67.27.233.126:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
1988 | RemoteMouse.tmp | 142.250.185.99:80 | ocsp.pki.goog | GOOGLE | US | unknown |
1080 | svchost.exe | 67.27.233.126:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
2868 | Setup.exe | 2.22.242.121:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
3752 | RemoteMouse.exe | 192.168.100.255:2008 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
www.remotemouse.net |
| unknown |
ctldl.windowsupdate.com |
| unknown |
ocsp.pki.goog |
| unknown |
crl.microsoft.com |
| unknown |
go.microsoft.com |
| unknown |
ocsp.digicert.com |
| unknown |
fonts.googleapis.com |
| unknown |
static.cloudflareinsights.com |
| unknown |
query.prod.cms.rt.microsoft.com |
| unknown |
fonts.gstatic.com |
| unknown |
Process | Message |
---|---|
Setup.exe | The operation completed successfully.
|