File name:

faf65b139e00fd784b93734d6a429369-sample.zip

Full analysis: https://app.any.run/tasks/6329de9f-12e9-4564-bdb7-db6dd99d68ad
Verdict: Malicious activity
Analysis date: June 29, 2023, 14:05:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3B823C05281545DC57FAE48ADAF2D9D4

SHA1:

687BF4735DEF7DB64BE52FE8C7DD6F2DD8133704

SHA256:

AC6B186D8971F71D8A2D9477D71526FC8A0E5F7D03772C9E134813BCE4FB2C89

SSDEEP:

49152:BS8xg93VuzgWtURCb3qZEWArs6tZ/w7Bo8bo2cdHxsVdHGuBiaVce:Cu5tUYbqZWs6tZ/8Y2cdHxKwMKe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • net_updater32.exe (PID: 2228)
      • MouseServer.exe (PID: 3176)
      • MouseServer.exe (PID: 3956)
      • MouseServer.exe (PID: 624)
      • Mouse Server Luminati.exe (PID: 3328)
      • test_wpf.exe (PID: 3476)
      • MouseServer.exe (PID: 3548)
    • Loads dropped or rewritten executable

      • MouseServer.exe (PID: 624)
      • net_updater32.exe (PID: 2228)
      • Mouse Server Luminati.exe (PID: 3328)
      • MouseServer.exe (PID: 3548)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MouseServer.exe (PID: 3956)
      • MouseServer.tmp (PID: 2020)
      • Mouse Server Luminati.exe (PID: 3328)
    • Reads the Windows owner or organization settings

      • MouseServer.tmp (PID: 2020)
    • Reads the Internet Settings

      • Mouse Server Luminati.exe (PID: 3328)
    • Connects to unusual port

      • Mouse Server Luminati.exe (PID: 3328)
  • INFO

    • Reads the computer name

      • MouseServer.tmp (PID: 2020)
      • net_updater32.exe (PID: 2228)
      • MouseServer.exe (PID: 624)
      • Mouse Server Luminati.exe (PID: 3328)
      • test_wpf.exe (PID: 3476)
    • Checks supported languages

      • net_updater32.exe (PID: 2228)
      • MouseServer.exe (PID: 3956)
      • MouseServer.exe (PID: 624)
      • Mouse Server Luminati.exe (PID: 3328)
      • test_wpf.exe (PID: 3476)
      • MouseServer.exe (PID: 3548)
      • MouseServer.tmp (PID: 2020)
    • Creates files in the program directory

      • net_updater32.exe (PID: 2228)
      • MouseServer.tmp (PID: 2020)
      • Mouse Server Luminati.exe (PID: 3328)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2772)
    • Create files in a temporary directory

      • MouseServer.exe (PID: 3956)
    • The process checks LSA protection

      • net_updater32.exe (PID: 2228)
      • MouseServer.tmp (PID: 2020)
      • Mouse Server Luminati.exe (PID: 3328)
      • test_wpf.exe (PID: 3476)
      • wisptis.exe (PID: 2904)
    • Manual execution by a user

      • MouseServer.exe (PID: 624)
      • MouseServer.exe (PID: 3548)
    • Creates files or folders in the user directory

      • MouseServer.exe (PID: 624)
    • Reads Environment values

      • Mouse Server Luminati.exe (PID: 3328)
    • Reads the machine GUID from the registry

      • test_wpf.exe (PID: 3476)
      • Mouse Server Luminati.exe (PID: 3328)
    • Checks proxy server information

      • Mouse Server Luminati.exe (PID: 3328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: MouseServer.exe
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2023:06:29 14:05:24
ZipCompression: Deflated
ZipBitFlag: 0x0009
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
11
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start winrar.exe mouseserver.exe no specs mouseserver.exe mouseserver.tmp net_updater32.exe mouseserver.exe mouse server luminati.exe test_wpf.exe no specs wisptis.exe no specs wisptis.exe mouseserver.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
624"C:\Program Files\Mouse Server\MouseServer.exe" C:\Program Files\Mouse Server\MouseServer.exe
explorer.exe
User:
admin
Company:
wifimouse.necta.us
Integrity Level:
MEDIUM
Description:
MouseServer
Exit code:
0
Version:
1.7.7.7
Modules
Images
c:\program files\mouse server\mouseserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
2020"C:\Users\admin\AppData\Local\Temp\is-B3H20.tmp\MouseServer.tmp" /SL5="$F0172,2194459,113664,C:\Users\admin\AppData\Local\Temp\Rar$EXb2772.4937\MouseServer.exe" C:\Users\admin\AppData\Local\Temp\is-B3H20.tmp\MouseServer.tmp
MouseServer.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-b3h20.tmp\mouseserver.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2228"C:\Program Files\Mouse Server\net_updater32.exe" --install win_wifimouse.necta.usC:\Program Files\Mouse Server\net_updater32.exe
MouseServer.tmp
User:
admin
Company:
Luminati Networks Ltd.
Integrity Level:
HIGH
Description:
Luminati SDK Updater
Exit code:
0
Version:
1.148.748
Modules
Images
c:\program files\mouse server\net_updater32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mouse server\lum_sdk32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2772"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\faf65b139e00fd784b93734d6a429369-sample.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2904"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exe
Mouse Server Luminati.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3176"C:\Users\admin\AppData\Local\Temp\Rar$EXb2772.4937\MouseServer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2772.4937\MouseServer.exeWinRAR.exe
User:
admin
Company:
Necta Inc.
Integrity Level:
MEDIUM
Description:
Mouse Server Setup
Exit code:
3221226540
Version:
1.7.7.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2772.4937\mouseserver.exe
c:\windows\system32\ntdll.dll
3328"Mouse Server Luminati.exe"C:\Program Files\Mouse Server\Mouse Server Luminati.exe
MouseServer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3476C:\Program Files\Mouse Server\test_wpf.exeC:\Program Files\Mouse Server\test_wpf.exeMouse Server Luminati.exe
User:
admin
Company:
Luminati Networks Ltd.
Integrity Level:
MEDIUM
Description:
test_wpf
Exit code:
0
Version:
1.148.748
Modules
Images
c:\program files\mouse server\test_wpf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3548"C:\Program Files\Mouse Server\MouseServer.exe" C:\Program Files\Mouse Server\MouseServer.exeexplorer.exe
User:
admin
Company:
wifimouse.necta.us
Integrity Level:
MEDIUM
Description:
MouseServer
Exit code:
0
Version:
1.7.7.7
Modules
Images
c:\program files\mouse server\mouseserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\lpk.dll
3636"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exeMouse Server Luminati.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wisptis.exe
Total events
3 029
Read events
2 988
Write events
41
Delete events
0

Modification events

(PID) Process:(2772) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
17
Suspicious files
5
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2020MouseServer.tmpC:\Program Files\Mouse Server\BluetoothAdapter.dllexecutable
MD5:0CEBCC8B4EBD15C11CD2D789A0576215
SHA256:921F88A4DDE208B0625EA0D37E076E110F7A8AC6866D6BC0CFBB0567E609814F
2020MouseServer.tmpC:\Program Files\Mouse Server\net_updater32.exeexecutable
MD5:7B4F52810F2B4FCB91C5D888D524A963
SHA256:C1CB26F21D977F0929DC3D59AC17837AA68F62AD8689C84B263A9D0B06D62BDE
3956MouseServer.exeC:\Users\admin\AppData\Local\Temp\is-B3H20.tmp\MouseServer.tmpexecutable
MD5:4EAB1095BBDE0191B7DF11D60B4A55EA
SHA256:F58EDCB4A19F2E6A37BEE98E5E23D48C0B214BBEAEC2AAEF4D9F85369BD2A2C6
2020MouseServer.tmpC:\Program Files\Mouse Server\lum_sdk32.dllexecutable
MD5:84BB020A1D589FA54D8E569483D077D2
SHA256:37A4F87BD77CF78BBCCEA138C31353C0BB59E132EE12A7A3D4FD9B10AD0E6A33
2020MouseServer.tmpC:\Program Files\Mouse Server\MouseServer.exeexecutable
MD5:3D5C98F32EDCCFB01882ED4588BC736C
SHA256:5EA4B51C9EA6FA3EBEF4056559D26DCEBCDBEBBC4EF0F6396AA363AF07E0D3CE
2020MouseServer.tmpC:\Program Files\Mouse Server\Mouse Server Luminati.exeexecutable
MD5:B932ED62BAC4B5C958ED898F5028BEE3
SHA256:630CD0488C19585F3D228E0014F6B447587BC520C2FDD1E86512C6DA956200AB
2772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2772.4937\MouseServer.exeexecutable
MD5:DBDF162EDC7121DFF5A1D88D55AD28A9
SHA256:BA83322499664B07901879FFF08062A793E650403EDA4A2031B54E66C79209DF
2020MouseServer.tmpC:\Program Files\Mouse Server\is-8JNHN.tmpexecutable
MD5:3D5C98F32EDCCFB01882ED4588BC736C
SHA256:5EA4B51C9EA6FA3EBEF4056559D26DCEBCDBEBBC4EF0F6396AA363AF07E0D3CE
2020MouseServer.tmpC:\Program Files\Mouse Server\is-I2C1I.tmpexecutable
MD5:52C7C8CF5D10D306D0411B05C9E05C4C
SHA256:84402A052CD97B4A00DB2A4D90DCF2F6290E66C1A3938491795873A217B8CF9B
2020MouseServer.tmpC:\Program Files\Mouse Server\unins000.exeexecutable
MD5:52C7C8CF5D10D306D0411B05C9E05C4C
SHA256:84402A052CD97B4A00DB2A4D90DCF2F6290E66C1A3938491795873A217B8CF9B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
22
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4004
svchost.exe
239.255.255.250:1900
whitelisted
624
MouseServer.exe
192.168.100.255:2008
whitelisted
2228
net_updater32.exe
206.189.231.23:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
suspicious
3328
Mouse Server Luminati.exe
206.189.231.23:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
suspicious
3328
Mouse Server Luminati.exe
162.144.62.9:80
www.necta.us
UNIFIEDLAYER-AS-1
US
unknown
2228
net_updater32.exe
159.223.133.120:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
suspicious
3328
Mouse Server Luminati.exe
192.81.222.239:22222
DIGITALOCEAN-ASN
NL
unknown

DNS requests

Domain
IP
Reputation
perr.lum-sdk.io
  • 206.189.231.23
  • 161.35.48.195
  • 159.223.133.120
  • 192.81.214.145
suspicious
www.necta.us
  • 162.144.62.9
unknown
perr.luminatinet.com
  • 159.223.133.120
  • 206.189.231.23
  • 161.35.48.195
  • 192.81.214.145
suspicious

Threats

No threats detected
No debug info