| File name: | micro-with-editor.exe |
| Full analysis: | https://app.any.run/tasks/965e4ad1-d763-4c64-a38f-a238e8316001 |
| Verdict: | Malicious activity |
| Analysis date: | June 17, 2024, 01:25:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F244D3D390171485D2D4DB91BCE83685 |
| SHA1: | 0BBAC7A006E514FC0AB4269D42DCC27230F648BC |
| SHA256: | D4B8E6E32325BAA8739808A4E47E75F6C8E51DE0BD74B38F004ED8AF3463B3D0 |
| SSDEEP: | 98304:2jc0wgAOv+KLoISIK+UKgmtfjoUVViAtmSisoHosMpedKdWx8CVDi/C6dZf4eJCZ:pmC+G |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 41472 |
| InitializedDataSize: | 17920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xaa98 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.3.1.0 |
| ProductVersionNumber: | 5.3.1.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | AutomaticSolution Software |
| FileDescription: | ReMouse |
| FileVersion: | ReMouse Micro V5.3.1 |
| LegalCopyright: | AutomaticSolution Software |
| ProductName: | ReMouse Micro |
| ProductVersion: | Micro V5.3.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\societyseason.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3968 | "C:\Users\admin\AppData\Local\Temp\micro-with-editor.exe" | C:\Users\admin\AppData\Local\Temp\micro-with-editor.exe | explorer.exe | ||||||||||||
User: admin Company: AutomaticSolution Software Integrity Level: MEDIUM Description: ReMouse Exit code: 0 Version: ReMouse Micro V5.3.1 Modules
| |||||||||||||||
| 3984 | "C:\Users\admin\AppData\Local\Temp\is-IHAI4.tmp\micro-with-editor.tmp" /SL5="$20138,1983860,57856,C:\Users\admin\AppData\Local\Temp\micro-with-editor.exe" | C:\Users\admin\AppData\Local\Temp\is-IHAI4.tmp\micro-with-editor.tmp | micro-with-editor.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 4040 | "C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\ReMouse.exe" | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\ReMouse.exe | — | micro-with-editor.tmp | |||||||||||
User: admin Integrity Level: MEDIUM Description: ReMouse Micro Version: 5.3.1 Modules
| |||||||||||||||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 900F000092FA733055C0DA01 | |||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 33090FB0D886DA158A1068EE8D76BB97A4F96692F51AC6876D68D3B89B093A90 | |||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\ReMouse.exe | |||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: E34F146A2E967FAA4ED6F00BEFE373D0FF28090BD250BD36226DB910327B6D89 | |||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ReMouse Micro_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.9 (a) | |||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ReMouse Micro_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro | |||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ReMouse Micro_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\ | |||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ReMouse Micro_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: ReMouse Micro | |||
| (PID) Process: | (3984) micro-with-editor.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\ReMouse Micro_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3984 | micro-with-editor.tmp | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\is-99R2U.tmp | executable | |
MD5:6FC61A2907F2E39A1E450D7801ECAE43 | SHA256:4E31D3155A3408805C91D1714BB45DE7847E77780BF3D91F3405FEB3EF9AC15B | |||
| 3984 | micro-with-editor.tmp | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\is-7QI1D.tmp | executable | |
MD5:FF79277DF5151CF5A8914A0E85866984 | SHA256:D4F17CF96337223071AE65E05D09DBDBABFFD98937DB353B16F62968BB16863D | |||
| 3968 | micro-with-editor.exe | C:\Users\admin\AppData\Local\Temp\is-IHAI4.tmp\micro-with-editor.tmp | executable | |
MD5:832DAB307E54AA08F4B6CDD9B9720361 | SHA256:CC783A04CCBCA4EDD06564F8EC88FE5A15F1E3BB26CEC7DE5E090313520D98F3 | |||
| 3984 | micro-with-editor.tmp | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\unins000.exe | executable | |
MD5:FF79277DF5151CF5A8914A0E85866984 | SHA256:D4F17CF96337223071AE65E05D09DBDBABFFD98937DB353B16F62968BB16863D | |||
| 3984 | micro-with-editor.tmp | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\conf\rms_conf.ini | ini | |
MD5:826B36CD9EBE733894E65B65774FEC91 | SHA256:2BF2D12963AD4C61DFFEF9449B624C06F0E340D51C427417585AC889F3A56792 | |||
| 3984 | micro-with-editor.tmp | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\ReMouseMode.exe | executable | |
MD5:6FC61A2907F2E39A1E450D7801ECAE43 | SHA256:4E31D3155A3408805C91D1714BB45DE7847E77780BF3D91F3405FEB3EF9AC15B | |||
| 3984 | micro-with-editor.tmp | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\is-H8AC4.tmp | executable | |
MD5:4C4C885168375B0DE7F92561976DB66B | SHA256:653DE0891EC62F39C0C6492FBF6F8F3466D7A1172937B0ABC189FDB0DD5CD97C | |||
| 3984 | micro-with-editor.tmp | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\conf\is-TAMO8.tmp | ini | |
MD5:826B36CD9EBE733894E65B65774FEC91 | SHA256:2BF2D12963AD4C61DFFEF9449B624C06F0E340D51C427417585AC889F3A56792 | |||
| 3984 | micro-with-editor.tmp | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\ReMouseEditor.exe | executable | |
MD5:4C4C885168375B0DE7F92561976DB66B | SHA256:653DE0891EC62F39C0C6492FBF6F8F3466D7A1172937B0ABC189FDB0DD5CD97C | |||
| 3984 | micro-with-editor.tmp | C:\Users\admin\AppData\Roaming\AutomaticSolution Software\ReMouse Micro\ReMouse.exe | executable | |
MD5:AA004CC64E97C12913CEBA65D79CA523 | SHA256:9CB7A66939EB517A3196A9E1921DB1215D6D5299BF39B0E1A0BD68C1B81F3E78 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |