File name:

uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.zip

Full analysis: https://app.any.run/tasks/1365531c-fef2-4a08-9ca7-987e226fc24c
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: October 08, 2020, 22:44:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F11C6AA35C88D16850A5DE0B492158AC

SHA1:

673A25759437D6455D912B5D982733BFD143B47D

SHA256:

E4E6977D8E30A5E4172C143E7D6B2E3873B7DEC75D7BA68BF4828652EAD394D1

SSDEEP:

393216:845CHvhTLcyW3DjiQzHVOwRsrqJE7hB7oO8kt9U8jZF:845CPh3c53DuQxsmJE7Ym9Nv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • XMouseButtonControlSetup.2.18.8.exe (PID: 548)
      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
      • XMouseButtonControl.exe (PID: 3104)
      • XMouseButtonControl.exe (PID: 348)
      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe (PID: 2484)
      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe (PID: 2688)
      • vdsuite.exe (PID: 3744)
    • Loads dropped or rewritten executable

      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
      • XMouseButtonControl.exe (PID: 348)
    • Changes the autorun value in the registry

      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
  • SUSPICIOUS

    • Starts application with an unusual extension

      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
    • Executable content was dropped or overwritten

      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe (PID: 2484)
      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe (PID: 2688)
      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp (PID: 3012)
    • Creates files in the program directory

      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
    • Creates files in the Windows directory

      • certutil.exe (PID: 1360)
    • Removes files from Windows directory

      • certutil.exe (PID: 1360)
    • Creates files in the user directory

      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
      • XMouseButtonControl.exe (PID: 348)
    • Modifies the open verb of a shell class

      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
    • Creates a software uninstall entry

      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
  • INFO

    • Manual execution by user

      • XMouseButtonControlSetup.2.18.8.exe (PID: 3164)
      • XMouseButtonControlSetup.2.18.8.exe (PID: 548)
      • XMouseButtonControl.exe (PID: 3104)
      • iexplore.exe (PID: 2944)
      • XMouseButtonControl.exe (PID: 348)
      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe (PID: 2484)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2944)
      • iexplore.exe (PID: 2796)
    • Application launched itself

      • iexplore.exe (PID: 2944)
    • Changes internet zones settings

      • iexplore.exe (PID: 2944)
    • Application was dropped or rewritten from another process

      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp (PID: 3012)
      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp (PID: 3100)
    • Creates files in the program directory

      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp (PID: 3012)
    • Creates a software uninstall entry

      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp (PID: 3012)
    • Loads dropped or rewritten executable

      • uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp (PID: 3012)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:12:23 14:58:22
ZipCRC: 0xa1e81e9c
ZipCompressedSize: 2567785
ZipUncompressedSize: 2589936
ZipFileName: XMouseButtonControlSetup.2.18.8.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
14
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe no specs xmousebuttoncontrolsetup.2.18.8.exe no specs xmousebuttoncontrolsetup.2.18.8.exe ns2b17.tmp no specs certutil.exe no specs iexplore.exe xmousebuttoncontrol.exe no specs iexplore.exe xmousebuttoncontrol.exe uspsetup-among-us-mod-menu_qtivop2uvwlt5.exe uspsetup-among-us-mod-menu_qtivop2uvwlt5.tmp no specs uspsetup-among-us-mod-menu_qtivop2uvwlt5.exe uspsetup-among-us-mod-menu_qtivop2uvwlt5.tmp vdsuite.exe

Process information

PID
CMD
Path
Indicators
Parent process
348"C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe" /Installed /notportableC:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
explorer.exe
User:
admin
Company:
Highresolution Enterprises
Integrity Level:
HIGH
Description:
X-Mouse Button Control
Exit code:
0
Version:
2.18.8
Modules
Images
c:\program files\highresolution enterprises\x-mouse button control\xmousebuttoncontrol.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
548"C:\Users\admin\Desktop\XMouseButtonControlSetup.2.18.8.exe" C:\Users\admin\Desktop\XMouseButtonControlSetup.2.18.8.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\xmousebuttoncontrolsetup.2.18.8.exe
c:\systemroot\system32\ntdll.dll
1360certutil -delstore root "82 53 30 f1 fa 00 53 f0 03 5a 19 83 63 cd f3 78 22 1d d7 7f"C:\Windows\system32\certutil.exens2B17.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CertUtil.exe
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\certutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\certcli.dll
c:\windows\system32\atl.dll
2484"C:\Users\admin\Desktop\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe" C:\Users\admin\Desktop\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe
explorer.exe
User:
admin
Company:
eodownloader.org
Integrity Level:
MEDIUM
Description:
Rella Setup
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\uspsetup-among-us-mod-menu_qtivop2uvwlt5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2688"C:\Users\admin\Desktop\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe" /SPAWNWND=$201EC /NOTIFYWND=$20194 C:\Users\admin\Desktop\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe
uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp
User:
admin
Company:
eodownloader.org
Integrity Level:
HIGH
Description:
Rella Setup
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\uspsetup-among-us-mod-menu_qtivop2uvwlt5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2796"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2944 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2944"C:\Program Files\Internet Explorer\iexplore.exe" http://www.highrez.co.uk/scripts/postinstall.asp?package=XMouse&major=2&minor=18&build=8&revision=0&platform=x86C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3012"C:\Users\admin\AppData\Local\Temp\is-74DGU.tmp\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp" /SL5="$301EA,11326023,59392,C:\Users\admin\Desktop\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe" /SPAWNWND=$201EC /NOTIFYWND=$20194 C:\Users\admin\AppData\Local\Temp\is-74DGU.tmp\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp
uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-74dgu.tmp\uspsetup-among-us-mod-menu_qtivop2uvwlt5.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3100"C:\Users\admin\AppData\Local\Temp\is-4B084.tmp\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmp" /SL5="$20194,11326023,59392,C:\Users\admin\Desktop\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe" C:\Users\admin\AppData\Local\Temp\is-4B084.tmp\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.tmpuspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-4b084.tmp\uspsetup-among-us-mod-menu_qtivop2uvwlt5.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3104"C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe" /Installed /notportableC:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exeexplorer.exe
User:
admin
Company:
Highresolution Enterprises
Integrity Level:
MEDIUM
Description:
X-Mouse Button Control
Exit code:
3221226540
Version:
2.18.8
Modules
Images
c:\program files\highresolution enterprises\x-mouse button control\xmousebuttoncontrol.exe
c:\systemroot\system32\ntdll.dll
Total events
1 050
Read events
926
Write events
124
Delete events
0

Modification events

(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3908) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.zip
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF67FFFFFF7D0100002703000072030000
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
23
Suspicious files
1
Text files
61
Unknown types
6

Dropped files

PID
Process
Filename
Type
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3908.43437\XMouseButtonControlSetup.2.18.8.exe
MD5:
SHA256:
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3908.43437\uspsetup-among-us-mod-menu_QTiVoP2uVWlT5.exe
MD5:
SHA256:
3164XMouseButtonControlSetup.2.18.8.exeC:\Users\admin\AppData\Local\Temp\nso10B8.tmp\ns2B17.tmp
MD5:
SHA256:
3164XMouseButtonControlSetup.2.18.8.exeC:\Program Files\Highresolution Enterprises\X-Mouse Button Control\uninstaller.exeexecutable
MD5:
SHA256:
3164XMouseButtonControlSetup.2.18.8.exeC:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonHook.dllexecutable
MD5:
SHA256:
3164XMouseButtonControlSetup.2.18.8.exeC:\Program Files\Highresolution Enterprises\X-Mouse Button Control\X-Mouse Button Control User Guide.pdfpdf
MD5:
SHA256:
3164XMouseButtonControlSetup.2.18.8.exeC:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exeexecutable
MD5:
SHA256:
3164XMouseButtonControlSetup.2.18.8.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Highresolution Enterprises\X-Mouse Button Control\X-Mouse Button Control User Guide.lnklnk
MD5:
SHA256:
3164XMouseButtonControlSetup.2.18.8.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Highresolution Enterprises\X-Mouse Button Control\X-Mouse Button Control.lnklnk
MD5:
SHA256:
3164XMouseButtonControlSetup.2.18.8.exeC:\Program Files\Highresolution Enterprises\X-Mouse Button Control\ChangeLog.txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
6
DNS requests
6
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2796
iexplore.exe
GET
212.105.165.194:80
http://www.highrez.co.uk/scripts/postinstall.asp?package=XMouse&major=2&minor=18&build=8&revision=0&platform=x86
GB
whitelisted
1988
WerFault.exe
GET
52.158.209.219:80
http://watson.microsoft.com/StageOne/vdsuite_exe/9_1_2_17/5f7f92d5/ntdll_dll/6_1_7601_18247/521ea91c/c0000005/000533b1.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.48.17514&SM=DELL&SPN=DELL&BV=DELL&MID=3ADE2C42-4AB9-49B7-B142-BE9AEEA69063
US
whitelisted
3744
vdsuite.exe
POST
104.27.182.150:80
http://opengolad.com/v2/events
US
malicious
2944
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
1988
WerFault.exe
52.158.209.219:80
watson.microsoft.com
Microsoft Corporation
US
suspicious
2796
iexplore.exe
212.105.165.194:80
www.highrez.co.uk
Daisy Communications Ltd
GB
unknown
3744
vdsuite.exe
104.27.182.150:80
opengolad.com
Cloudflare Inc
US
malicious

DNS requests

Domain
IP
Reputation
www.highrez.co.uk
  • 212.105.165.194
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
opengolad.com
  • 104.27.182.150
  • 172.67.188.36
  • 104.27.183.150
unknown
watson.microsoft.com
  • 52.158.209.219
whitelisted

Threats

PID
Process
Class
Message
3744
vdsuite.exe
A Network Trojan was detected
ET MALWARE DownloadAssistant Activity
3744
vdsuite.exe
Misc activity
ADWARE [PTsecurity] Possible DownloadAssistant
3744
vdsuite.exe
Misc activity
ADWARE [PTsecurity] DownloadAssistant
Process
Message
XMouseButtonControlSetup.2.18.8.exe
ExecShellAsUser: DLL_PROCESS_ATTACH
XMouseButtonControlSetup.2.18.8.exe
ExecShellAsUser: elevated process detected
XMouseButtonControlSetup.2.18.8.exe
ExecShellAsUser: got desktop
XMouseButtonControlSetup.2.18.8.exe
ExecShellAsUser: NSPIM_UNLOAD wait...
XMouseButtonControlSetup.2.18.8.exe
ExecShellAsUser: DLL_PROCESS_DETACH
XMouseButtonControlSetup.2.18.8.exe
ExecShellAsUser: NSPIM_UNLOAD
XMouseButtonControlSetup.2.18.8.exe
ExecShellAsUser: thread finished
XMouseButtonControl.exe
08-10-2020 23:45:30.930> CXButtonControllApp: Constructing Main Application Class
XMouseButtonControl.exe
08-10-2020 23:45:30.930> InitInstance: XMBC is starting
XMouseButtonControl.exe
08-10-2020 23:45:30.961> X-Mouse Button Control v2.18.8 (x86) Startup. Commandline '/installed /notportable'