File name:

MentalMentor.exe

Full analysis: https://app.any.run/tasks/c3e8fc25-d32a-4d06-8cbc-7ace5e4a4a93
Verdict: Malicious activity
Analysis date: March 06, 2024, 19:07:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A069EE7B342973E07C28045E30E674CF

SHA1:

0895E0E90BEEE9479839203E2475E6A08C725573

SHA256:

8445CC5AAC6A306220789B46C6A5D3C9E9296EDEF13DB36127007A7BBAF4BB5D

SSDEEP:

98304:4+cD4dnpanjHY8FYY3Yd6tIntZBrh5bMgW1m7lG1J3hXFJw+/iUc7srC+x3ILB1B:SNFvbG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MentalMentor.exe (PID: 3240)
      • MentalMentor.exe (PID: 2848)
      • MentalMentor.tmp (PID: 2840)
      • MentalMentor.exe (PID: 1236)
      • MentalMentor.tmp (PID: 2900)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MentalMentor.exe (PID: 3240)
      • MentalMentor.exe (PID: 2848)
      • MentalMentor.tmp (PID: 2840)
      • MentalMentor.exe (PID: 1236)
      • MentalMentor.tmp (PID: 2900)
    • Reads the Windows owner or organization settings

      • MentalMentor.tmp (PID: 2840)
      • MentalMentor.tmp (PID: 2900)
    • Reads the Internet Settings

      • wmplayer.exe (PID: 3428)
      • setup_wm.exe (PID: 3992)
    • Reads security settings of Internet Explorer

      • wmplayer.exe (PID: 3428)
      • setup_wm.exe (PID: 3992)
  • INFO

    • Checks supported languages

      • MentalMentor.tmp (PID: 3672)
      • MentalMentor.exe (PID: 3240)
      • MentalMentor.tmp (PID: 2840)
      • MentalMentor.exe (PID: 2848)
      • wmplayer.exe (PID: 3428)
      • setup_wm.exe (PID: 3992)
      • MentalMentor.exe (PID: 1236)
      • MentalMentor.tmp (PID: 2900)
    • Reads the computer name

      • MentalMentor.tmp (PID: 3672)
      • MentalMentor.tmp (PID: 2840)
      • wmplayer.exe (PID: 3428)
      • setup_wm.exe (PID: 3992)
      • MentalMentor.tmp (PID: 2900)
    • Create files in a temporary directory

      • MentalMentor.exe (PID: 2848)
      • MentalMentor.exe (PID: 3240)
      • MentalMentor.tmp (PID: 2840)
      • setup_wm.exe (PID: 3992)
      • MentalMentor.exe (PID: 1236)
      • MentalMentor.tmp (PID: 2900)
    • Reads the machine GUID from the registry

      • MentalMentor.tmp (PID: 2840)
      • setup_wm.exe (PID: 3992)
      • MentalMentor.tmp (PID: 2900)
    • Manual execution by a user

      • wmplayer.exe (PID: 3428)
      • explorer.exe (PID: 2292)
      • MentalMentor.exe (PID: 1236)
    • Reads Environment values

      • setup_wm.exe (PID: 3992)
    • Process checks computer location settings

      • setup_wm.exe (PID: 3992)
    • Checks proxy server information

      • setup_wm.exe (PID: 3992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 102400
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.0
ProductVersionNumber: 1.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mental Mentor
FileDescription: Mental Mentor Setup
FileVersion: 1.1.0
LegalCopyright: Copyright 2024 Agora International Agency
OriginalFileName: MentalMentor.exe
ProductName: Mental Mentor
ProductVersion: 1.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
9
Malicious processes
2
Suspicious processes
5

Behavior graph

Click at the process to see the details
start mentalmentor.exe mentalmentor.tmp no specs mentalmentor.exe mentalmentor.tmp wmplayer.exe no specs setup_wm.exe explorer.exe no specs mentalmentor.exe mentalmentor.tmp

Process information

PID
CMD
Path
Indicators
Parent process
1236"C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" C:\Users\admin\AppData\Local\Temp\MentalMentor.exe
explorer.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
HIGH
Description:
Mental Mentor Setup
Exit code:
0
Version:
1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\mentalmentor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2292"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2840"C:\Users\admin\AppData\Local\Temp\is-3EBIH.tmp\MentalMentor.tmp" /SL5="$100130,2483341,845312,C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-3EBIH.tmp\MentalMentor.tmp
MentalMentor.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-3ebih.tmp\mentalmentor.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2848"C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\MentalMentor.exe
MentalMentor.tmp
User:
admin
Company:
Mental Mentor
Integrity Level:
HIGH
Description:
Mental Mentor Setup
Exit code:
0
Version:
1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\mentalmentor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2900"C:\Users\admin\AppData\Local\Temp\is-A98R7.tmp\MentalMentor.tmp" /SL5="$901D4,2483341,845312,C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" C:\Users\admin\AppData\Local\Temp\is-A98R7.tmp\MentalMentor.tmp
MentalMentor.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-a98r7.tmp\mentalmentor.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3240"C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" C:\Users\admin\AppData\Local\Temp\MentalMentor.exe
explorer.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
MEDIUM
Description:
Mental Mentor Setup
Exit code:
0
Version:
1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\mentalmentor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3428"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1C:\Program Files\Windows Media Player\wmplayer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player
Exit code:
0
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3672"C:\Users\admin\AppData\Local\Temp\is-KBP8A.tmp\MentalMentor.tmp" /SL5="$E0170,2483341,845312,C:\Users\admin\AppData\Local\Temp\MentalMentor.exe" C:\Users\admin\AppData\Local\Temp\is-KBP8A.tmp\MentalMentor.tmpMentalMentor.exe
User:
admin
Company:
Mental Mentor
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-kbp8a.tmp\mentalmentor.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3992"C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1C:\Program Files\Windows Media Player\setup_wm.exe
wmplayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Configuration Utility
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\setup_wm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
5 498
Read events
5 428
Write events
57
Delete events
13

Modification events

(PID) Process:(2840) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
180B0000503E7D9AF96FDA01
(PID) Process:(2840) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
3AFF6718980B8B4BBF3FAE5F0128B04262A853013C4A9A64A8E6F090E403D132
(PID) Process:(2840) MentalMentor.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3428) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3428) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3428) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3428) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3992) setup_wm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:delete valueName:UsageTracking
Value:
(PID) Process:(3992) setup_wm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:delete valueName:ForceUsageTracking
Value:
(PID) Process:(3992) setup_wm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:delete valueName:SQMLaunchIndex
Value:
Executable files
7
Suspicious files
0
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
3240MentalMentor.exeC:\Users\admin\AppData\Local\Temp\is-KBP8A.tmp\MentalMentor.tmpexecutable
MD5:0D041F22D598F3A63BDF0E66C448BDAB
SHA256:E6B54015C403E3016B848B18FC488D4D281A752BC9AB2A3324BA4D8EFB642563
2848MentalMentor.exeC:\Users\admin\AppData\Local\Temp\is-3EBIH.tmp\MentalMentor.tmpexecutable
MD5:0D041F22D598F3A63BDF0E66C448BDAB
SHA256:E6B54015C403E3016B848B18FC488D4D281A752BC9AB2A3324BA4D8EFB642563
2840MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-D9A78.tmp\idp.dllexecutable
MD5:59FD376F6E67CF49BFB0AC6724140E72
SHA256:88D2DA3783C9EF9B2C9F20224A399FE3607581F338DAEA94F68606A760CC06D5
2900MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-BDUB1.tmp\idp.dllexecutable
MD5:59FD376F6E67CF49BFB0AC6724140E72
SHA256:88D2DA3783C9EF9B2C9F20224A399FE3607581F338DAEA94F68606A760CC06D5
2840MentalMentor.tmpC:\Users\admin\mentalmentor\settings\temp\install_configbinary
MD5:E86F3A2006876E7BF14A6B867A0B28DF
SHA256:5F20560387F97EE0DCDABD34F4AD4CCA793867791EF60612957D9972EEC05078
3992setup_wm.exeC:\Users\admin\AppData\Local\Temp\tmp93328.WMC\allservices.xmlxml
MD5:DF03E65B8E082F24DAB09C57BC9C6241
SHA256:155B9C588061C71832AF329FAFA5678835D9153B8FBB7592195AE953D0C455BA
3992setup_wm.exeC:\Users\admin\AppData\Local\Temp\tmp96421.WMC\serviceinfo.xmltext
MD5:D58DA90D6DC51F97CB84DFBFFE2B2300
SHA256:93ACDB79543D9248CA3FCA661F3AC287E6004E4B3DAFD79D4C4070794FFBF2AD
1236MentalMentor.exeC:\Users\admin\AppData\Local\Temp\is-A98R7.tmp\MentalMentor.tmpexecutable
MD5:0D041F22D598F3A63BDF0E66C448BDAB
SHA256:E6B54015C403E3016B848B18FC488D4D281A752BC9AB2A3324BA4D8EFB642563
2840MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-D9A78.tmp\mentor-inno-lib.dllexecutable
MD5:7D992DE7A01B53B3E243241D4A6DF978
SHA256:2F647A8DC42804459D6ACA834E532D407FD69F93A7FCD908E3BFDA5FAAFCD665
2900MentalMentor.tmpC:\Users\admin\AppData\Local\Temp\is-BDUB1.tmp\mentor-inno-lib.dllexecutable
MD5:7D992DE7A01B53B3E243241D4A6DF978
SHA256:2F647A8DC42804459D6ACA834E532D407FD69F93A7FCD908E3BFDA5FAAFCD665
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
14
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3992
setup_wm.exe
GET
302
104.124.11.201:80
http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86
unknown
unknown
3992
setup_wm.exe
GET
200
2.22.242.121:80
http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86
unknown
xml
546 b
unknown
3992
setup_wm.exe
GET
200
2.22.242.121:80
http://onlinestores.metaservices.microsoft.com/bing/bing.xml
unknown
text
523 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2840
MentalMentor.tmp
51.158.210.166:443
web.mymentalmentor.net
Online S.a.s.
FR
unknown
3992
setup_wm.exe
104.124.11.201:80
redir.metaservices.microsoft.com
Akamai International B.V.
DE
unknown
3992
setup_wm.exe
2.22.242.121:80
onlinestores.metaservices.microsoft.com
Akamai International B.V.
DE
unknown
2900
MentalMentor.tmp
51.158.210.166:443
web.mymentalmentor.net
Online S.a.s.
FR
unknown

DNS requests

Domain
IP
Reputation
web.mymentalmentor.net
  • 51.158.210.166
unknown
redir.metaservices.microsoft.com
  • 104.124.11.201
whitelisted
onlinestores.metaservices.microsoft.com
  • 2.22.242.121
whitelisted

Threats

No threats detected
No debug info