File name:

mousecc (1).zip

Full analysis: https://app.any.run/tasks/93e70618-8e66-4751-b7d1-6868d8d1ea4a
Verdict: Malicious activity
Analysis date: September 03, 2025, 16:18:58
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
qrcode
anti-evasion
phishing
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

35DFACACE04E06137EACE1F816757D59

SHA1:

A489225F33B8F4F889781215473E587F48937846

SHA256:

AACA778558E1A4901085375D9FCD0A7EABB866ECF9A6940498F2E5D69C6A57E3

SSDEEP:

98304:VD6Sn47YiMtXAEOzXhp845fftYLaZ4rbwhhRg2UxXoOtbHlKkihNPc1JPymb/anu:uz4qxMH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2972)
    • Changes the autorun value in the registry

      • dxwebsetup.exe (PID: 1668)
      • VC_redist.x64.exe (PID: 8072)
    • Executing a file with an untrusted certificate

      • infinst.exe (PID: 5876)
      • infinst.exe (PID: 8028)
      • infinst.exe (PID: 8156)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 7512)
      • infinst.exe (PID: 4044)
      • infinst.exe (PID: 4768)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 2112)
      • infinst.exe (PID: 7216)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 4724)
      • infinst.exe (PID: 7368)
      • infinst.exe (PID: 7960)
      • infinst.exe (PID: 1356)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 8016)
      • infinst.exe (PID: 7332)
      • infinst.exe (PID: 7556)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 6868)
      • infinst.exe (PID: 4048)
      • infinst.exe (PID: 1132)
      • infinst.exe (PID: 7624)
      • infinst.exe (PID: 7592)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 7712)
      • infinst.exe (PID: 440)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 1880)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 4476)
      • infinst.exe (PID: 6400)
      • infinst.exe (PID: 3112)
      • infinst.exe (PID: 4888)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 6344)
      • infinst.exe (PID: 7204)
      • infinst.exe (PID: 4164)
      • infinst.exe (PID: 4528)
      • infinst.exe (PID: 1636)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 1440)
      • infinst.exe (PID: 8012)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 6724)
      • infinst.exe (PID: 5140)
      • infinst.exe (PID: 3644)
      • infinst.exe (PID: 5576)
      • infinst.exe (PID: 6832)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 7252)
      • infinst.exe (PID: 6648)
      • infinst.exe (PID: 7532)
      • infinst.exe (PID: 7928)
      • infinst.exe (PID: 4780)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 4560)
      • infinst.exe (PID: 5268)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 2188)
      • infinst.exe (PID: 4844)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 2320)
      • infinst.exe (PID: 4808)
      • infinst.exe (PID: 7808)
      • infinst.exe (PID: 8156)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 6900)
      • infinst.exe (PID: 6320)
    • Registers / Runs the DLL via REGSVR32.EXE

      • dxwsetup.exe (PID: 7264)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • msedge.exe (PID: 4760)
      • msedge.exe (PID: 6524)
      • dxwebsetup.exe (PID: 1668)
      • dxwsetup.exe (PID: 7264)
      • VC_redist.x64.exe (PID: 8004)
      • VC_redist.x64.exe (PID: 7028)
      • VC_redist.x64.exe (PID: 8072)
      • msiexec.exe (PID: 5708)
      • VC_redist.x64.exe (PID: 7304)
      • infinst.exe (PID: 5876)
      • infinst.exe (PID: 8028)
      • infinst.exe (PID: 8156)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 7512)
      • infinst.exe (PID: 4044)
      • infinst.exe (PID: 4768)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 2112)
      • infinst.exe (PID: 7216)
      • infinst.exe (PID: 7368)
      • infinst.exe (PID: 4724)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 7960)
      • infinst.exe (PID: 1356)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 8016)
      • infinst.exe (PID: 7332)
      • infinst.exe (PID: 7556)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 6868)
      • infinst.exe (PID: 4048)
      • infinst.exe (PID: 1132)
      • infinst.exe (PID: 7624)
      • infinst.exe (PID: 7592)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 7712)
      • infinst.exe (PID: 440)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 1880)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 4476)
      • infinst.exe (PID: 6400)
      • infinst.exe (PID: 3112)
      • infinst.exe (PID: 4888)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 6344)
      • infinst.exe (PID: 7204)
      • infinst.exe (PID: 4164)
      • infinst.exe (PID: 4528)
      • infinst.exe (PID: 1636)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 1440)
      • infinst.exe (PID: 8012)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 6724)
      • infinst.exe (PID: 5140)
      • infinst.exe (PID: 3644)
      • infinst.exe (PID: 5576)
      • infinst.exe (PID: 6832)
      • infinst.exe (PID: 7252)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 7532)
      • infinst.exe (PID: 6648)
      • infinst.exe (PID: 7928)
      • infinst.exe (PID: 4780)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 5268)
      • infinst.exe (PID: 4560)
      • infinst.exe (PID: 2188)
      • infinst.exe (PID: 4844)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 7808)
      • infinst.exe (PID: 2320)
      • infinst.exe (PID: 4808)
      • infinst.exe (PID: 8156)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 6900)
      • infinst.exe (PID: 6320)
    • Executable content was dropped or overwritten

      • dxwebsetup.exe (PID: 1668)
      • dxwsetup.exe (PID: 7264)
      • VC_redist.x64.exe (PID: 8004)
      • VC_redist.x64.exe (PID: 7028)
      • VC_redist.x64.exe (PID: 8072)
      • VC_redist.x64.exe (PID: 2032)
      • VC_redist.x64.exe (PID: 7304)
      • infinst.exe (PID: 5876)
      • infinst.exe (PID: 8028)
      • infinst.exe (PID: 8156)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 7512)
      • infinst.exe (PID: 4044)
      • infinst.exe (PID: 4768)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 2112)
      • infinst.exe (PID: 7216)
      • infinst.exe (PID: 4724)
      • infinst.exe (PID: 7368)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 7960)
      • infinst.exe (PID: 1356)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 8016)
      • infinst.exe (PID: 7332)
      • infinst.exe (PID: 7556)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 6868)
      • infinst.exe (PID: 4048)
      • infinst.exe (PID: 1132)
      • infinst.exe (PID: 7624)
      • infinst.exe (PID: 7592)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 7712)
      • infinst.exe (PID: 440)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 1880)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 4476)
      • infinst.exe (PID: 6400)
      • infinst.exe (PID: 3112)
      • infinst.exe (PID: 4888)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 6344)
      • infinst.exe (PID: 4164)
      • infinst.exe (PID: 4528)
      • infinst.exe (PID: 7204)
      • infinst.exe (PID: 1636)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 1440)
      • infinst.exe (PID: 8012)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 6724)
      • infinst.exe (PID: 5140)
      • infinst.exe (PID: 3644)
      • infinst.exe (PID: 5576)
      • infinst.exe (PID: 6832)
      • infinst.exe (PID: 7252)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 6648)
      • infinst.exe (PID: 7532)
      • infinst.exe (PID: 7928)
      • infinst.exe (PID: 4780)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 4560)
      • infinst.exe (PID: 5268)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 2188)
      • infinst.exe (PID: 4844)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 2320)
      • infinst.exe (PID: 4808)
      • infinst.exe (PID: 7808)
      • infinst.exe (PID: 8156)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 6900)
      • infinst.exe (PID: 6320)
    • Starts a Microsoft application from unusual location

      • dxwsetup.exe (PID: 7264)
      • VC_redist.x64.exe (PID: 7028)
      • VC_redist.x64.exe (PID: 8072)
    • Reads security settings of Internet Explorer

      • dxwsetup.exe (PID: 7264)
      • VC_redist.x64.exe (PID: 7028)
      • VC_redist.x64.exe (PID: 2032)
    • Searches for installed software

      • VC_redist.x64.exe (PID: 7028)
      • dllhost.exe (PID: 7244)
      • VC_redist.x64.exe (PID: 2032)
      • VC_redist.x64.exe (PID: 7304)
    • Starts itself from another location

      • VC_redist.x64.exe (PID: 7028)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6368)
    • Creates a software uninstall entry

      • VC_redist.x64.exe (PID: 8072)
    • The process checks if it is being run in the virtual environment

      • msiexec.exe (PID: 5708)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5708)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 5708)
    • Application launched itself

      • VC_redist.x64.exe (PID: 7412)
      • VC_redist.x64.exe (PID: 2032)
    • Write to the desktop.ini file (may be used to cloak folders)

      • dxwsetup.exe (PID: 7264)
    • Creates/Modifies COM task schedule object

      • dxwsetup.exe (PID: 7264)
      • regsvr32.exe (PID: 4012)
      • regsvr32.exe (PID: 7768)
      • regsvr32.exe (PID: 7432)
      • regsvr32.exe (PID: 7756)
      • regsvr32.exe (PID: 7300)
      • regsvr32.exe (PID: 7596)
      • regsvr32.exe (PID: 5468)
      • regsvr32.exe (PID: 3572)
      • regsvr32.exe (PID: 7464)
      • regsvr32.exe (PID: 640)
      • regsvr32.exe (PID: 8136)
      • regsvr32.exe (PID: 3720)
      • regsvr32.exe (PID: 6320)
      • regsvr32.exe (PID: 6764)
      • regsvr32.exe (PID: 2396)
      • regsvr32.exe (PID: 6236)
      • regsvr32.exe (PID: 420)
      • regsvr32.exe (PID: 7420)
      • regsvr32.exe (PID: 7952)
      • regsvr32.exe (PID: 4112)
      • regsvr32.exe (PID: 6812)
      • regsvr32.exe (PID: 7904)
      • regsvr32.exe (PID: 3876)
      • regsvr32.exe (PID: 640)
      • regsvr32.exe (PID: 4476)
      • regsvr32.exe (PID: 3768)
      • regsvr32.exe (PID: 5532)
    • Starts CMD.EXE for commands execution

      • mousecc.exe (PID: 8144)
  • INFO

    • Manual execution by a user

      • mousecc.exe (PID: 4744)
      • mousecc.exe (PID: 4060)
      • msedge.exe (PID: 6524)
      • mousecc.exe (PID: 3872)
      • mousecc.exe (PID: 2804)
      • msedge.exe (PID: 8108)
      • mousecc.exe (PID: 3288)
      • mousecc.exe (PID: 8088)
      • mousecc.exe (PID: 7472)
      • mousecc.exe (PID: 4232)
      • mousecc.exe (PID: 4012)
      • mousecc.exe (PID: 8144)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2972)
      • msedge.exe (PID: 4760)
      • msedge.exe (PID: 6524)
      • msedge.exe (PID: 7272)
      • msiexec.exe (PID: 5708)
    • Checks supported languages

      • identity_helper.exe (PID: 7760)
      • dxwebsetup.exe (PID: 1668)
      • dxwsetup.exe (PID: 7264)
      • identity_helper.exe (PID: 7592)
      • VC_redist.x64.exe (PID: 7028)
      • VC_redist.x64.exe (PID: 8004)
      • identity_helper.exe (PID: 4724)
      • VC_redist.x64.exe (PID: 8072)
      • msiexec.exe (PID: 5708)
      • VC_redist.x64.exe (PID: 7412)
      • VC_redist.x64.exe (PID: 2032)
      • VC_redist.x64.exe (PID: 7304)
      • infinst.exe (PID: 5876)
      • infinst.exe (PID: 8028)
      • infinst.exe (PID: 8156)
      • infinst.exe (PID: 7512)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 4044)
      • infinst.exe (PID: 4768)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 2112)
      • infinst.exe (PID: 7216)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 7368)
      • infinst.exe (PID: 4724)
      • infinst.exe (PID: 7960)
      • infinst.exe (PID: 1356)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 8016)
      • infinst.exe (PID: 7332)
      • infinst.exe (PID: 7556)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 6868)
      • infinst.exe (PID: 1132)
      • infinst.exe (PID: 4048)
      • infinst.exe (PID: 7624)
      • infinst.exe (PID: 7592)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 7712)
      • infinst.exe (PID: 440)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 1880)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 4476)
      • infinst.exe (PID: 6400)
      • infinst.exe (PID: 3112)
      • infinst.exe (PID: 4888)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 6344)
      • infinst.exe (PID: 7204)
      • infinst.exe (PID: 4528)
      • infinst.exe (PID: 1636)
      • infinst.exe (PID: 4164)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 1440)
      • infinst.exe (PID: 8012)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 6724)
      • infinst.exe (PID: 5140)
      • infinst.exe (PID: 3644)
      • infinst.exe (PID: 5576)
      • infinst.exe (PID: 6832)
      • infinst.exe (PID: 7252)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 6648)
      • infinst.exe (PID: 7532)
      • infinst.exe (PID: 7928)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 4780)
      • infinst.exe (PID: 4560)
      • infinst.exe (PID: 5268)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 2188)
      • infinst.exe (PID: 4844)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 2320)
      • infinst.exe (PID: 4808)
      • infinst.exe (PID: 7808)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 6900)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 6320)
      • infinst.exe (PID: 8156)
      • mousecc.exe (PID: 8144)
    • Reads Environment values

      • identity_helper.exe (PID: 7760)
      • identity_helper.exe (PID: 7592)
      • identity_helper.exe (PID: 4724)
    • Application launched itself

      • msedge.exe (PID: 6524)
      • msedge.exe (PID: 7272)
      • msedge.exe (PID: 4644)
    • Reads the computer name

      • identity_helper.exe (PID: 7760)
      • dxwsetup.exe (PID: 7264)
      • VC_redist.x64.exe (PID: 7028)
      • identity_helper.exe (PID: 7592)
      • VC_redist.x64.exe (PID: 8072)
      • identity_helper.exe (PID: 4724)
      • msiexec.exe (PID: 5708)
      • VC_redist.x64.exe (PID: 2032)
      • VC_redist.x64.exe (PID: 7304)
      • mousecc.exe (PID: 8144)
    • The sample compiled with english language support

      • msedge.exe (PID: 4760)
      • msedge.exe (PID: 6524)
      • dxwebsetup.exe (PID: 1668)
      • dxwsetup.exe (PID: 7264)
      • VC_redist.x64.exe (PID: 8004)
      • VC_redist.x64.exe (PID: 7028)
      • VC_redist.x64.exe (PID: 8072)
      • msiexec.exe (PID: 5708)
      • VC_redist.x64.exe (PID: 2032)
      • VC_redist.x64.exe (PID: 7304)
      • infinst.exe (PID: 5876)
      • infinst.exe (PID: 8028)
      • infinst.exe (PID: 8156)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 7512)
      • infinst.exe (PID: 4044)
      • infinst.exe (PID: 4768)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 2112)
      • infinst.exe (PID: 7216)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 4724)
      • infinst.exe (PID: 7368)
      • infinst.exe (PID: 1356)
      • infinst.exe (PID: 7960)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 8016)
      • infinst.exe (PID: 7332)
      • infinst.exe (PID: 7556)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 6868)
      • infinst.exe (PID: 4048)
      • infinst.exe (PID: 1132)
      • infinst.exe (PID: 7624)
      • infinst.exe (PID: 7592)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 7712)
      • infinst.exe (PID: 440)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 1880)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 4476)
      • infinst.exe (PID: 6400)
      • infinst.exe (PID: 4888)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 3112)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 6344)
      • infinst.exe (PID: 4164)
      • infinst.exe (PID: 4528)
      • infinst.exe (PID: 1636)
      • infinst.exe (PID: 7204)
      • infinst.exe (PID: 7588)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 1440)
      • infinst.exe (PID: 8012)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 2528)
      • infinst.exe (PID: 6724)
      • infinst.exe (PID: 5140)
      • infinst.exe (PID: 3644)
      • infinst.exe (PID: 5576)
      • infinst.exe (PID: 6832)
      • infinst.exe (PID: 7252)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 6648)
      • infinst.exe (PID: 7532)
      • infinst.exe (PID: 7928)
      • infinst.exe (PID: 4780)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 5268)
      • infinst.exe (PID: 544)
      • infinst.exe (PID: 4560)
      • infinst.exe (PID: 2188)
      • infinst.exe (PID: 4844)
      • infinst.exe (PID: 4160)
      • infinst.exe (PID: 1324)
      • infinst.exe (PID: 2320)
      • infinst.exe (PID: 4808)
      • infinst.exe (PID: 7808)
      • infinst.exe (PID: 8156)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 6900)
      • infinst.exe (PID: 6320)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 6524)
      • msedge.exe (PID: 7272)
    • Create files in a temporary directory

      • dxwebsetup.exe (PID: 1668)
      • dxwsetup.exe (PID: 7264)
      • VC_redist.x64.exe (PID: 8004)
      • VC_redist.x64.exe (PID: 7028)
      • VC_redist.x64.exe (PID: 8072)
      • VC_redist.x64.exe (PID: 2032)
    • Launching a file from a Registry key

      • dxwebsetup.exe (PID: 1668)
      • VC_redist.x64.exe (PID: 8072)
    • Reads the software policy settings

      • dxwsetup.exe (PID: 7264)
      • slui.exe (PID: 7956)
      • msiexec.exe (PID: 5708)
      • mousecc.exe (PID: 8144)
    • Checks proxy server information

      • dxwsetup.exe (PID: 7264)
      • slui.exe (PID: 7956)
    • Reads the machine GUID from the registry

      • dxwsetup.exe (PID: 7264)
      • VC_redist.x64.exe (PID: 8072)
      • msiexec.exe (PID: 5708)
    • Creates files or folders in the user directory

      • dxwsetup.exe (PID: 7264)
    • Process checks computer location settings

      • VC_redist.x64.exe (PID: 7028)
      • VC_redist.x64.exe (PID: 2032)
    • Manages system restore points

      • SrTasks.exe (PID: 7808)
      • SrTasks.exe (PID: 8144)
    • Creates files in the program directory

      • VC_redist.x64.exe (PID: 8072)
      • mousecc.exe (PID: 8144)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 5708)
    • Gets the hash of the file via CERTUTIL.EXE

      • certutil.exe (PID: 504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:08:13 18:06:22
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: assets/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
381
Monitored processes
225
Malicious processes
81
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
320"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --instant-process --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3632,i,12997952910017583448,4701202338967505899,262144 --variations-seed-version --mojo-platform-channel-handle=3644 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
420C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\XAudio2_2.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
440C:\Users\admin\AppData\Local\Temp\DX436F.tmp\infinst.exe d3dx10_35_x64.infC:\Users\admin\AppData\Local\Temp\DX436F.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dx436f.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
504certutil -hashfile "C:\Users\admin\Desktop\mousecc.exe" MD5 C:\Windows\System32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CertUtil.exe
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\certutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
544C:\Users\admin\AppData\Local\Temp\DX436F.tmp\infinst.exe XACT2_8_x64.infC:\Users\admin\AppData\Local\Temp\DX436F.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dx436f.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
544C:\Users\admin\AppData\Local\Temp\DX436F.tmp\infinst.exe XACT3_5_x64.infC:\Users\admin\AppData\Local\Temp\DX436F.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dx436f.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
640C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\xactengine2_9.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
640C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\xactengine3_6.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
684"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3368,i,9174205280265117640,9845305880010426628,262144 --variations-seed-version --mojo-platform-channel-handle=3972 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1096\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exemousecc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
46 652
Read events
45 247
Write events
1 009
Delete events
396

Modification events

(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\mousecc (1).zip
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
783
Suspicious files
2 066
Text files
304
Unknown types
1

Dropped files

PID
Process
Filename
Type
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1937b0.TMP
MD5:
SHA256:
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1937bf.TMP
MD5:
SHA256:
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1937bf.TMP
MD5:
SHA256:
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1937fe.TMP
MD5:
SHA256:
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1937bf.TMP
MD5:
SHA256:
6524msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
192
TCP/UDP connections
283
DNS requests
312
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4760
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:YsXDIapS9QizrkrCSJJmmcpktGj1uvJvuNS1M7x-vMo&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
99 b
whitelisted
3876
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
2460
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
1268
svchost.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
3876
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
7264
dxwsetup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
7264
dxwsetup.exe
GET
200
2.16.164.112:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
7264
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxupdate.cab
SE
whitelisted
7264
dxwsetup.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
DE
binary
1.05 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2040
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2460
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2460
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.142
whitelisted
login.live.com
  • 20.190.160.22
  • 20.190.160.17
  • 20.190.160.2
  • 40.126.32.72
  • 40.126.32.140
  • 20.190.160.66
  • 40.126.32.76
  • 40.126.32.134
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.0
  • 20.190.159.68
  • 40.126.31.71
  • 40.126.31.0
  • 40.126.31.129
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.24
  • 2.16.164.113
  • 2.16.164.75
  • 2.16.164.96
  • 2.16.164.131
  • 2.16.164.34
  • 2.16.164.112
  • 2.16.164.120
  • 2.16.164.25
  • 2.16.164.104
  • 2.16.164.98
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 74.178.76.128
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain in DNS Lookup (keyauth .win)
8144
mousecc.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain (keyauth .win) in TLS SNI
8144
mousecc.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain (keyauth .win) in TLS SNI
2200
svchost.exe
Misc activity
ET INFO Observed DNS Query to Cloudflare workers.dev Domain
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] DNS Query to Cloudflare Worker App
8144
mousecc.exe
Misc activity
ET INFO Observed Cloudflare workers.dev Domain in TLS SNI
8144
mousecc.exe
Misc activity
ET INFO Observed Cloudflare workers.dev Domain in TLS SNI
Process
Message
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_ATTACH
msiexec.exe
Failed to release Service
dxwsetup.exe
DLL_PROCESS_DETACH