File name:

Onlan SO-100 Gaming Mouse.exe

Full analysis: https://app.any.run/tasks/3e2ad962-4765-410b-901b-4629f3b59412
Verdict: Malicious activity
Analysis date: December 02, 2023, 22:32:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A090566FC87B7E5C1346220D6524E413

SHA1:

DFB1F746BAE337F0F74507F855CB496480DDE2B2

SHA256:

ED63D50E3B10273FC503B07923B6492A77AF666DC36577F693063DC16E2C93D9

SSDEEP:

98304:OiT8sTF9Ap6wMb44R6yBNxpA+dIyxu9Y7SHvy8FMcz95eBELnuLzCtDb3lpmj//i:vARKl6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Onlan SO-100 Gaming Mouse.exe (PID: 124)
      • Onlan SO-100 Gaming Mouse.tmp (PID: 2956)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Onlan SO-100 Gaming Mouse.tmp (PID: 2956)
    • Reads the Windows owner or organization settings

      • Onlan SO-100 Gaming Mouse.tmp (PID: 2956)
  • INFO

    • Checks supported languages

      • Onlan SO-100 Gaming Mouse.exe (PID: 124)
      • Onlan SO-100 Gaming Mouse.tmp (PID: 2956)
      • OemDrv.exe (PID: 2132)
    • Create files in a temporary directory

      • Onlan SO-100 Gaming Mouse.exe (PID: 124)
      • Onlan SO-100 Gaming Mouse.tmp (PID: 2956)
    • Reads the computer name

      • Onlan SO-100 Gaming Mouse.tmp (PID: 2956)
      • OemDrv.exe (PID: 2132)
    • Creates files in the program directory

      • Onlan SO-100 Gaming Mouse.tmp (PID: 2956)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:08:15 21:29:32+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 86016
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x163c4
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OnLan
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start onlan so-100 gaming mouse.exe onlan so-100 gaming mouse.tmp oemdrv.exe no specs onlan so-100 gaming mouse.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Users\admin\AppData\Local\Temp\Onlan SO-100 Gaming Mouse.exe" C:\Users\admin\AppData\Local\Temp\Onlan SO-100 Gaming Mouse.exe
explorer.exe
User:
admin
Company:
OnLan
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\onlan so-100 gaming mouse.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2132"C:\Program Files\OnLan SO-100 PRO\OemDrv.exe"C:\Program Files\OnLan SO-100 PRO\OemDrv.exeOnlan SO-100 Gaming Mouse.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
2
Version:
1, 0, 0, 7
Modules
Images
c:\program files\onlan so-100 pro\oemdrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
2644"C:\Users\admin\AppData\Local\Temp\Onlan SO-100 Gaming Mouse.exe" C:\Users\admin\AppData\Local\Temp\Onlan SO-100 Gaming Mouse.exeexplorer.exe
User:
admin
Company:
OnLan
Integrity Level:
MEDIUM
Description:
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\appdata\local\temp\onlan so-100 gaming mouse.exe
c:\windows\system32\ntdll.dll
2956"C:\Users\admin\AppData\Local\Temp\is-4TGFE.tmp\Onlan SO-100 Gaming Mouse.tmp" /SL5="$1201E2,2770747,140800,C:\Users\admin\AppData\Local\Temp\Onlan SO-100 Gaming Mouse.exe" C:\Users\admin\AppData\Local\Temp\is-4TGFE.tmp\Onlan SO-100 Gaming Mouse.tmp
Onlan SO-100 Gaming Mouse.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1048.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-4tgfe.tmp\onlan so-100 gaming mouse.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
780
Read events
780
Write events
0
Delete events
0

Modification events

No data
Executable files
15
Suspicious files
8
Text files
178
Unknown types
0

Dropped files

PID
Process
Filename
Type
124Onlan SO-100 Gaming Mouse.exeC:\Users\admin\AppData\Local\Temp\is-4TGFE.tmp\Onlan SO-100 Gaming Mouse.tmpexecutable
MD5:A4CB46C715D6E7B72755EAB92123A3EA
SHA256:686699D59606CD7D2253DFF2C92003380361F00B168305E959E66BAB9BC725C0
2956Onlan SO-100 Gaming Mouse.tmpC:\Users\admin\AppData\Local\Temp\is-24PCU.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2956Onlan SO-100 Gaming Mouse.tmpC:\Program Files\OnLan SO-100 PRO\skins\is-IVLVR.tmpimage
MD5:F88029AFE61E8724C21CC36B4F0C7F26
SHA256:E04ACDED41F34EC681B7C39B65D97E75E1147E6441C9FF0DED574DFAD3C4C041
2956Onlan SO-100 Gaming Mouse.tmpC:\Program Files\OnLan SO-100 PRO\unins000.exeexecutable
MD5:96FB1D44AEC9A47D1044A3F350FBC363
SHA256:0678DAB71AFC73B1EF7B303011B9CDEF17CDE1B00CE59F19881DB4C412412AB3
2956Onlan SO-100 Gaming Mouse.tmpC:\Program Files\OnLan SO-100 PRO\skins\is-4JO97.tmpimage
MD5:764250A3A48F9A0B8CD3A124463A5628
SHA256:E3D982CA585045D9407F6D7CDC0C454B42330B17A5198D3DD36722E74E608B7D
2956Onlan SO-100 Gaming Mouse.tmpC:\Program Files\OnLan SO-100 PRO\skins\add_ov.pngimage
MD5:23DF84EDB7C8166E54E9AE8E6D0A5FFE
SHA256:FA85C2637CAD1ECF8042B2D20302F27DBF70B744AE16435495E134A613FBC4A8
2956Onlan SO-100 Gaming Mouse.tmpC:\Users\admin\AppData\Local\Temp\is-24PCU.tmp\InitSetup.dllexecutable
MD5:3BB4A9FD05F14CC833291F7332565843
SHA256:72F5CFE575253EAFF31E27CE8F70B4CAAA079D2C42A4130515EECF7F0967115D
2956Onlan SO-100 Gaming Mouse.tmpC:\Program Files\OnLan SO-100 PRO\skins\is-CVDFI.tmpimage
MD5:784AA9F61FE065B25283D12D1483942E
SHA256:B07529B7EC8C61155523FC8D5155425004E1A30557A1E93FA750DBD163069684
2956Onlan SO-100 Gaming Mouse.tmpC:\Program Files\OnLan SO-100 PRO\skins\bar.pngimage
MD5:E19B89D130DF9328D378ECB0F693DDDD
SHA256:5D3A63CF4240616F92EC85A7CFA3470916DF6A458198E01E3A6B424B4E4A7731
2956Onlan SO-100 Gaming Mouse.tmpC:\Program Files\OnLan SO-100 PRO\skins\is-S0ODJ.tmpimage
MD5:DEC56C302B6747A75C0D5FA11EF7F382
SHA256:D0004EB1B5E169FBE9CA4BA2586E4A5B2DC1764FB216107B8BC61BCFDF1791BB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
868
svchost.exe
23.35.228.137:80
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
184.30.20.134:80
armmf.adobe.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 184.30.20.134
whitelisted

Threats

No threats detected
Process
Message
Onlan SO-100 Gaming Mouse.tmp
InitSetup: Remove Folder OK.