| File name: | DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time.rar |
| Full analysis: | https://app.any.run/tasks/30784735-48a4-4f1a-8763-fbff5e6234ca |
| Verdict: | Malicious activity |
| Analysis date: | November 18, 2023, 15:04:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 42AAAF661635C1C0AD2D3D64E4001A2B |
| SHA1: | 325F1310980F89D94EA00CC071A7B7CAEDE3DEB9 |
| SHA256: | 67D7577B5E250119D839764B307537461CB8DC41BF4661E4B53D24B507930B6D |
| SSDEEP: | 98304:VrkumF5gNXZett/nb7OxAUnPyUCEw3TmJybiOTYD2OKoMfIcMeAk1asPFlZGqibD:+yaFuHKG5lvIkquQwEL+bFDn |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | "C:\Program Files\DU Meter\DUMeterSvc.exe" /startedbyscm:E1F6D4BE-40E33354-DUMeterService | C:\Program Files\DU Meter\DUMeterSvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Hagel Technologies Ltd. Integrity Level: SYSTEM Description: DU Meter Service Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
| 600 | "C:\Program Files\DU Meter\DUMeterSvc.exe" /reinstall | C:\Program Files\DU Meter\DUMeterSvc.exe | — | DUMeter-Install 7.30.tmp | |||||||||||
User: admin Company: Hagel Technologies Ltd. Integrity Level: HIGH Description: DU Meter Service Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
| 752 | "C:\Program Files\DU Meter\DUMeter.exe" /regserver | C:\Program Files\DU Meter\DUMeter.exe | — | DUMeter-Install 7.30.tmp | |||||||||||
User: admin Company: Hagel Technologies Ltd. Integrity Level: HIGH Description: DU Meter Monitor Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
| 908 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\DU Meter\DuMonitor32.dll" | C:\Windows\System32\regsvr32.exe | — | DUMeter-Install 7.30.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1788 | "C:\Windows\system32\taskmgr.exe" | C:\Windows\System32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2908 | C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3212 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3436 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3508 | "regedit.exe" "C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Registration.reg" | C:\Windows\regedit.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3532 | "C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmp" /SL5="$50214,6035441,119296,C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\DUMeter-Install 7.30.exe" | C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmp | — | DUMeter-Install 7.30.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3436) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7C16E6-6828-4EF0-AF7B-C2A324CC6E41}\{6798FEA9-3E25-4B20-86D3-2399CB14B3FC} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3436) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7C16E6-6828-4EF0-AF7B-C2A324CC6E41} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3436) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{60B040B4-8ACA-4273-85DB-6095E6E5845C} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3600 | DUMeter-Install 7.30.tmp | C:\Program Files\DU Meter\Locale\de\LC_MESSAGES\is-J89C7.tmp | binary | |
MD5:072649605ABDDA08E15CE87DCC930B64 | SHA256:D05AD9CF95F3F5ED799AFE087EF5A3D8C90B49060C231A37FE0BA617F84B079A | |||
| 3212 | WinRAR.exe | C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\DUMeter-Install 7.30.exe | executable | |
MD5:C43C019BA3B6C183B7997A389D709F95 | SHA256:2C707CE4625FCA8CC8CCA81EEDB7ABBEF1EDF13D0230F1EE5CBD81D3C6746F1B | |||
| 3212 | WinRAR.exe | C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Instructions !!!.txt | text | |
MD5:B618BC8787FD39C459B819C46C6E11EE | SHA256:207CB9020581379F8BE1A684C68F13FD6A57A6C3897CCFBAD19447B7FB9AA0B5 | |||
| 4036 | DUMeter-Install 7.30.exe | C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmp | executable | |
MD5:B3B2BFF0E1928612F6B97D90898570A8 | SHA256:2056F24FC37E52987885EA78DABCAE4575C0CE52A54CCC036CCACAE5768DFD89 | |||
| 3212 | WinRAR.exe | C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Crack File\DUMeterSvc.exe | executable | |
MD5:F992F127DE9572E84AA3FAC6AFCEB90D | SHA256:59FE2F967F9F53BC8423C584DB384AE9BF2219D457D72FD768334490918026B6 | |||
| 3212 | WinRAR.exe | C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Registration.reg | text | |
MD5:4EB6D81B585741F121FAAB5C3FF64E6B | SHA256:11A672EA284DE067F7DCE23DE84BECC4FD8946BAD79DD33849F85ABF60256FE3 | |||
| 3212 | WinRAR.exe | C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Crack file Past Here.lnk | binary | |
MD5:BBE0B3AD5EBE4124A3ED9659A69EDBE3 | SHA256:9785F88A9DD9A38946D29653E6E2F9298EEE0EEC6EE639F88788A215D4A61776 | |||
| 3600 | DUMeter-Install 7.30.tmp | C:\Users\admin\AppData\Local\Temp\is-HVSRN.tmp\DuHelper.dll | executable | |
MD5:226CA1ACE882E5C3DDB63A5CAAE9F5C0 | SHA256:B0CA2CC6EC8D6C3E81CA9B4D1D4673ED7E14FAE9E738984F8F3FEFD68F81173B | |||
| 3616 | DUMeter-Install 7.30.exe | C:\Users\admin\AppData\Local\Temp\is-Q33FM.tmp\DUMeter-Install 7.30.tmp | executable | |
MD5:B3B2BFF0E1928612F6B97D90898570A8 | SHA256:2056F24FC37E52987885EA78DABCAE4575C0CE52A54CCC036CCACAE5768DFD89 | |||
| 3600 | DUMeter-Install 7.30.tmp | C:\Program Files\DU Meter\DUMeter.exe | executable | |
MD5:3D9597E978CF0D57335EA82C1EADB20B | SHA256:BFC298B3E7A59368B32EF99D00AB6C1EBF36F1EAFA32AE19FC07A5DC5F515A3E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3804 | DUMeter.exe | GET | 200 | 184.24.77.46:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgPx5c9pBw%2BtSpTQPIQq9CiFnQ%3D%3D | unknown | binary | 503 b | unknown |
3804 | DUMeter.exe | GET | 200 | 23.212.210.158:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
3804 | DUMeter.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?215ed28ca5795ac5 | unknown | compressed | 4.66 Kb | unknown |
3804 | DUMeter.exe | POST | 200 | 140.238.137.239:80 | http://www.hageltech.com/service/software_version_check?protocol_version=1&product=du&ver=7.304769&lang=en&iid=045e8febb49e4132921fc8ebfbfda21f&edl=30 | unknown | text | 237 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3804 | DUMeter.exe | 140.238.137.239:80 | www.hageltech.com | ORACLE-BMC-31898 | CA | unknown |
3804 | DUMeter.exe | 140.238.137.239:443 | www.hageltech.com | ORACLE-BMC-31898 | CA | unknown |
3804 | DUMeter.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
3804 | DUMeter.exe | 23.212.210.158:80 | x1.c.lencr.org | AKAMAI-AS | AU | unknown |
3804 | DUMeter.exe | 184.24.77.46:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.hageltech.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |