File name:

faf65b139e00fd784b93734d6a429369-sample.zip

Full analysis: https://app.any.run/tasks/6329de9f-12e9-4564-bdb7-db6dd99d68ad
Verdict: Malicious activity
Analysis date: June 29, 2023, 14:05:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3B823C05281545DC57FAE48ADAF2D9D4

SHA1:

687BF4735DEF7DB64BE52FE8C7DD6F2DD8133704

SHA256:

AC6B186D8971F71D8A2D9477D71526FC8A0E5F7D03772C9E134813BCE4FB2C89

SSDEEP:

49152:BS8xg93VuzgWtURCb3qZEWArs6tZ/w7Bo8bo2cdHxsVdHGuBiaVce:Cu5tUYbqZWs6tZ/8Y2cdHxKwMKe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MouseServer.exe (PID: 3956)
      • MouseServer.exe (PID: 3176)
      • net_updater32.exe (PID: 2228)
      • MouseServer.exe (PID: 624)
      • Mouse Server Luminati.exe (PID: 3328)
      • MouseServer.exe (PID: 3548)
      • test_wpf.exe (PID: 3476)
    • Loads dropped or rewritten executable

      • net_updater32.exe (PID: 2228)
      • MouseServer.exe (PID: 624)
      • MouseServer.exe (PID: 3548)
      • Mouse Server Luminati.exe (PID: 3328)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MouseServer.exe (PID: 3956)
      • MouseServer.tmp (PID: 2020)
      • Mouse Server Luminati.exe (PID: 3328)
    • Reads the Windows owner or organization settings

      • MouseServer.tmp (PID: 2020)
    • Connects to unusual port

      • Mouse Server Luminati.exe (PID: 3328)
    • Reads the Internet Settings

      • Mouse Server Luminati.exe (PID: 3328)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2772)
    • Checks supported languages

      • MouseServer.exe (PID: 3956)
      • MouseServer.tmp (PID: 2020)
      • net_updater32.exe (PID: 2228)
      • Mouse Server Luminati.exe (PID: 3328)
      • test_wpf.exe (PID: 3476)
      • MouseServer.exe (PID: 624)
      • MouseServer.exe (PID: 3548)
    • The process checks LSA protection

      • MouseServer.tmp (PID: 2020)
      • net_updater32.exe (PID: 2228)
      • test_wpf.exe (PID: 3476)
      • Mouse Server Luminati.exe (PID: 3328)
      • wisptis.exe (PID: 2904)
    • Reads the computer name

      • MouseServer.tmp (PID: 2020)
      • net_updater32.exe (PID: 2228)
      • MouseServer.exe (PID: 624)
      • test_wpf.exe (PID: 3476)
      • Mouse Server Luminati.exe (PID: 3328)
    • Create files in a temporary directory

      • MouseServer.exe (PID: 3956)
    • Creates files in the program directory

      • MouseServer.tmp (PID: 2020)
      • net_updater32.exe (PID: 2228)
      • Mouse Server Luminati.exe (PID: 3328)
    • Creates files or folders in the user directory

      • MouseServer.exe (PID: 624)
    • Reads the machine GUID from the registry

      • test_wpf.exe (PID: 3476)
      • Mouse Server Luminati.exe (PID: 3328)
    • Manual execution by a user

      • MouseServer.exe (PID: 624)
      • MouseServer.exe (PID: 3548)
    • Checks proxy server information

      • Mouse Server Luminati.exe (PID: 3328)
    • Reads Environment values

      • Mouse Server Luminati.exe (PID: 3328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: MouseServer.exe
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2023:06:29 14:05:24
ZipCompression: Deflated
ZipBitFlag: 0x0009
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
11
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start winrar.exe mouseserver.exe no specs mouseserver.exe mouseserver.tmp net_updater32.exe mouseserver.exe mouse server luminati.exe test_wpf.exe no specs wisptis.exe no specs wisptis.exe mouseserver.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
624"C:\Program Files\Mouse Server\MouseServer.exe" C:\Program Files\Mouse Server\MouseServer.exe
explorer.exe
User:
admin
Company:
wifimouse.necta.us
Integrity Level:
MEDIUM
Description:
MouseServer
Exit code:
0
Version:
1.7.7.7
Modules
Images
c:\program files\mouse server\mouseserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
2020"C:\Users\admin\AppData\Local\Temp\is-B3H20.tmp\MouseServer.tmp" /SL5="$F0172,2194459,113664,C:\Users\admin\AppData\Local\Temp\Rar$EXb2772.4937\MouseServer.exe" C:\Users\admin\AppData\Local\Temp\is-B3H20.tmp\MouseServer.tmp
MouseServer.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-b3h20.tmp\mouseserver.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2228"C:\Program Files\Mouse Server\net_updater32.exe" --install win_wifimouse.necta.usC:\Program Files\Mouse Server\net_updater32.exe
MouseServer.tmp
User:
admin
Company:
Luminati Networks Ltd.
Integrity Level:
HIGH
Description:
Luminati SDK Updater
Exit code:
0
Version:
1.148.748
Modules
Images
c:\program files\mouse server\net_updater32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mouse server\lum_sdk32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2772"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\faf65b139e00fd784b93734d6a429369-sample.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2904"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exe
Mouse Server Luminati.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3176"C:\Users\admin\AppData\Local\Temp\Rar$EXb2772.4937\MouseServer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2772.4937\MouseServer.exeWinRAR.exe
User:
admin
Company:
Necta Inc.
Integrity Level:
MEDIUM
Description:
Mouse Server Setup
Exit code:
3221226540
Version:
1.7.7.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2772.4937\mouseserver.exe
c:\windows\system32\ntdll.dll
3328"Mouse Server Luminati.exe"C:\Program Files\Mouse Server\Mouse Server Luminati.exe
MouseServer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3476C:\Program Files\Mouse Server\test_wpf.exeC:\Program Files\Mouse Server\test_wpf.exeMouse Server Luminati.exe
User:
admin
Company:
Luminati Networks Ltd.
Integrity Level:
MEDIUM
Description:
test_wpf
Exit code:
0
Version:
1.148.748
Modules
Images
c:\program files\mouse server\test_wpf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3548"C:\Program Files\Mouse Server\MouseServer.exe" C:\Program Files\Mouse Server\MouseServer.exeexplorer.exe
User:
admin
Company:
wifimouse.necta.us
Integrity Level:
MEDIUM
Description:
MouseServer
Exit code:
0
Version:
1.7.7.7
Modules
Images
c:\program files\mouse server\mouseserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\lpk.dll
3636"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exeMouse Server Luminati.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wisptis.exe
Total events
3 029
Read events
2 988
Write events
41
Delete events
0

Modification events

(PID) Process:(2772) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
17
Suspicious files
5
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2772.4937\MouseServer.exeexecutable
MD5:DBDF162EDC7121DFF5A1D88D55AD28A9
SHA256:BA83322499664B07901879FFF08062A793E650403EDA4A2031B54E66C79209DF
2020MouseServer.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mouse Server.lnkbinary
MD5:E91C798355CA42D0B647DAAB6121EB90
SHA256:03AA21F5C0E5A012C1735460F534A4344E12E65EAC805B05CB3391E1E3E0B9E0
2020MouseServer.tmpC:\Program Files\Mouse Server\is-MFGGM.tmpexecutable
MD5:B932ED62BAC4B5C958ED898F5028BEE3
SHA256:630CD0488C19585F3D228E0014F6B447587BC520C2FDD1E86512C6DA956200AB
3956MouseServer.exeC:\Users\admin\AppData\Local\Temp\is-B3H20.tmp\MouseServer.tmpexecutable
MD5:4EAB1095BBDE0191B7DF11D60B4A55EA
SHA256:F58EDCB4A19F2E6A37BEE98E5E23D48C0B214BBEAEC2AAEF4D9F85369BD2A2C6
2020MouseServer.tmpC:\Program Files\Mouse Server\unins000.exeexecutable
MD5:52C7C8CF5D10D306D0411B05C9E05C4C
SHA256:84402A052CD97B4A00DB2A4D90DCF2F6290E66C1A3938491795873A217B8CF9B
3328Mouse Server Luminati.exeC:\Program Files\Mouse Server\luminati\net_install.logbinary
MD5:EF37FE5754EB33639D2E1BA8D2CBE398
SHA256:D2C481D4DBD1256667F868F81D1CC5E3AFCEF4F58F5BEBFF8BC44D35B4681D9D
2020MouseServer.tmpC:\Program Files\Mouse Server\Mouse Server Luminati.exeexecutable
MD5:B932ED62BAC4B5C958ED898F5028BEE3
SHA256:630CD0488C19585F3D228E0014F6B447587BC520C2FDD1E86512C6DA956200AB
2020MouseServer.tmpC:\Users\Public\Desktop\Mouse Server.lnkbinary
MD5:9A91B46FCD1B9219E35D42C1CD9DE128
SHA256:CDC377F13E7CC2EE00BDAA6F4F2BA06B62A60F6051079E381CCA61C250350685
2020MouseServer.tmpC:\Program Files\Mouse Server\lum_sdk32.dllexecutable
MD5:84BB020A1D589FA54D8E569483D077D2
SHA256:37A4F87BD77CF78BBCCEA138C31353C0BB59E132EE12A7A3D4FD9B10AD0E6A33
2020MouseServer.tmpC:\Program Files\Mouse Server\is-0C94C.tmpexecutable
MD5:7B4F52810F2B4FCB91C5D888D524A963
SHA256:C1CB26F21D977F0929DC3D59AC17837AA68F62AD8689C84B263A9D0B06D62BDE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
22
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4004
svchost.exe
239.255.255.250:1900
whitelisted
624
MouseServer.exe
192.168.100.255:2008
whitelisted
2228
net_updater32.exe
206.189.231.23:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
suspicious
3328
Mouse Server Luminati.exe
206.189.231.23:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
suspicious
2228
net_updater32.exe
161.35.48.195:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
unknown
3328
Mouse Server Luminati.exe
162.144.62.9:80
www.necta.us
UNIFIEDLAYER-AS-1
US
unknown
3328
Mouse Server Luminati.exe
159.223.133.120:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
suspicious

DNS requests

Domain
IP
Reputation
perr.lum-sdk.io
  • 206.189.231.23
  • 161.35.48.195
  • 159.223.133.120
  • 192.81.214.145
suspicious
www.necta.us
  • 162.144.62.9
unknown
perr.luminatinet.com
  • 159.223.133.120
  • 206.189.231.23
  • 161.35.48.195
  • 192.81.214.145
suspicious

Threats

No threats detected
No debug info