File name:

DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time.rar

Full analysis: https://app.any.run/tasks/30784735-48a4-4f1a-8763-fbff5e6234ca
Verdict: Malicious activity
Analysis date: November 18, 2023, 15:04:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

42AAAF661635C1C0AD2D3D64E4001A2B

SHA1:

325F1310980F89D94EA00CC071A7B7CAEDE3DEB9

SHA256:

67D7577B5E250119D839764B307537461CB8DC41BF4661E4B53D24B507930B6D

SSDEEP:

98304:VrkumF5gNXZett/nb7OxAUnPyUCEw3TmJybiOTYD2OKoMfIcMeAk1asPFlZGqibD:+yaFuHKG5lvIkquQwEL+bFDn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DUMeter-Install 7.30.exe (PID: 4036)
      • DUMeter-Install 7.30.exe (PID: 3616)
      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Registers / Runs the DLL via REGSVR32.EXE

      • DUMeter-Install 7.30.tmp (PID: 3600)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Process drops legitimate windows executable

      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Process drops SQLite DLL files

      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Drops a system driver (possible attempt to evade defenses)

      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Executes as Windows Service

      • DUMeterSvc.exe (PID: 316)
    • Reads settings of System Certificates

      • DUMeter.exe (PID: 3804)
    • Reads security settings of Internet Explorer

      • DUMeter.exe (PID: 3804)
    • Reads the Internet Settings

      • DUMeter.exe (PID: 3804)
    • Reads Microsoft Outlook installation path

      • DUMeter.exe (PID: 3804)
    • Reads Internet Explorer settings

      • DUMeter.exe (PID: 3804)
    • Checks Windows Trust Settings

      • DUMeter.exe (PID: 3804)
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 3436)
      • DUMeter-Install 7.30.tmp (PID: 3532)
      • DUMeter-Install 7.30.tmp (PID: 3600)
      • DUMeterSvc.exe (PID: 600)
      • DUMeterSvc.exe (PID: 316)
      • DUMeter.exe (PID: 752)
      • DUMeter.exe (PID: 3804)
      • DUMeter.exe (PID: 4012)
      • DUMeter.exe (PID: 3748)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3436)
      • DUMeter-Install 7.30.tmp (PID: 3600)
      • DUMeterSvc.exe (PID: 600)
      • DUMeterSvc.exe (PID: 316)
      • DUMeter.exe (PID: 752)
      • DUMeter.exe (PID: 3804)
      • DUMeter.exe (PID: 4012)
      • DUMeter.exe (PID: 3748)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3436)
      • DUMeter-Install 7.30.exe (PID: 4036)
      • DUMeter-Install 7.30.tmp (PID: 3532)
      • DUMeter-Install 7.30.exe (PID: 3616)
      • DUMeter-Install 7.30.tmp (PID: 3600)
      • DUMeterSvc.exe (PID: 600)
      • DUMeterSvc.exe (PID: 316)
      • DUMeter.exe (PID: 752)
      • DUMeter.exe (PID: 3804)
      • DUMeter.exe (PID: 4012)
      • DUMeter.exe (PID: 3748)
    • Manual execution by a user

      • DUMeter-Install 7.30.exe (PID: 4036)
      • DUMeter.exe (PID: 4012)
      • taskmgr.exe (PID: 1788)
      • regedit.exe (PID: 3508)
      • regedit.exe (PID: 3828)
    • Create files in a temporary directory

      • DUMeter-Install 7.30.exe (PID: 4036)
      • DUMeter-Install 7.30.exe (PID: 3616)
      • DUMeter-Install 7.30.tmp (PID: 3600)
      • DUMeterSvc.exe (PID: 600)
      • DUMeter.exe (PID: 752)
      • DUMeter.exe (PID: 3804)
      • DUMeter.exe (PID: 4012)
      • DUMeter.exe (PID: 3748)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3212)
    • Creates files in the program directory

      • DUMeterSvc.exe (PID: 316)
      • DUMeterSvc.exe (PID: 600)
      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Process checks computer location settings

      • DUMeter.exe (PID: 752)
      • DUMeter.exe (PID: 3804)
      • DUMeter.exe (PID: 3748)
      • DUMeter.exe (PID: 4012)
    • Checks proxy server information

      • DUMeter.exe (PID: 3804)
    • Creates files or folders in the user directory

      • DUMeter.exe (PID: 3804)
    • Reads CPU info

      • DUMeterSvc.exe (PID: 316)
    • Reads the time zone

      • DUMeterSvc.exe (PID: 316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
17
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs dumeter-install 7.30.exe no specs dumeter-install 7.30.tmp no specs dumeter-install 7.30.exe dumeter-install 7.30.tmp no specs regsvr32.exe no specs dumetersvc.exe no specs dumetersvc.exe no specs dumeter.exe no specs dumeter.exe Copy/Move/Rename/Delete/Link Object no specs taskmgr.exe no specs regedit.exe no specs regedit.exe dumeter.exe no specs dumeter.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Program Files\DU Meter\DUMeterSvc.exe" /startedbyscm:E1F6D4BE-40E33354-DUMeterServiceC:\Program Files\DU Meter\DUMeterSvc.exeservices.exe
User:
SYSTEM
Company:
Hagel Technologies Ltd.
Integrity Level:
SYSTEM
Description:
DU Meter Service
Exit code:
0
Version:
7.30
Modules
Images
c:\program files\du meter\dumetersvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
600"C:\Program Files\DU Meter\DUMeterSvc.exe" /reinstallC:\Program Files\DU Meter\DUMeterSvc.exeDUMeter-Install 7.30.tmp
User:
admin
Company:
Hagel Technologies Ltd.
Integrity Level:
HIGH
Description:
DU Meter Service
Exit code:
0
Version:
7.30
Modules
Images
c:\program files\du meter\dumetersvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
752"C:\Program Files\DU Meter\DUMeter.exe" /regserverC:\Program Files\DU Meter\DUMeter.exeDUMeter-Install 7.30.tmp
User:
admin
Company:
Hagel Technologies Ltd.
Integrity Level:
HIGH
Description:
DU Meter Monitor
Exit code:
0
Version:
7.30
Modules
Images
c:\program files\du meter\dumeter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
908"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\DU Meter\DuMonitor32.dll"C:\Windows\System32\regsvr32.exeDUMeter-Install 7.30.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1788"C:\Windows\system32\taskmgr.exe" C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2908C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3212"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3436"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3508"regedit.exe" "C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Registration.reg"C:\Windows\regedit.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
3532"C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmp" /SL5="$50214,6035441,119296,C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\DUMeter-Install 7.30.exe" C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmpDUMeter-Install 7.30.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hfcqs.tmp\dumeter-install 7.30.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
8 843
Read events
8 728
Write events
100
Delete events
15

Modification events

(PID) Process:(3436) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7C16E6-6828-4EF0-AF7B-C2A324CC6E41}\{6798FEA9-3E25-4B20-86D3-2399CB14B3FC}
Operation:delete keyName:(default)
Value:
(PID) Process:(3436) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7C16E6-6828-4EF0-AF7B-C2A324CC6E41}
Operation:delete keyName:(default)
Value:
(PID) Process:(3436) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{60B040B4-8ACA-4273-85DB-6095E6E5845C}
Operation:delete keyName:(default)
Value:
(PID) Process:(3212) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
25
Suspicious files
125
Text files
86
Unknown types
0

Dropped files

PID
Process
Filename
Type
3212WinRAR.exeC:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Instructions !!!.txttext
MD5:B618BC8787FD39C459B819C46C6E11EE
SHA256:207CB9020581379F8BE1A684C68F13FD6A57A6C3897CCFBAD19447B7FB9AA0B5
3600DUMeter-Install 7.30.tmpC:\Program Files\DU Meter\DUMeter.exeexecutable
MD5:3D9597E978CF0D57335EA82C1EADB20B
SHA256:BFC298B3E7A59368B32EF99D00AB6C1EBF36F1EAFA32AE19FC07A5DC5F515A3E
3600DUMeter-Install 7.30.tmpC:\Users\admin\AppData\Local\Temp\is-HVSRN.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
4036DUMeter-Install 7.30.exeC:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmpexecutable
MD5:B3B2BFF0E1928612F6B97D90898570A8
SHA256:2056F24FC37E52987885EA78DABCAE4575C0CE52A54CCC036CCACAE5768DFD89
3600DUMeter-Install 7.30.tmpC:\Program Files\DU Meter\is-IHRJN.tmpexecutable
MD5:B3B2BFF0E1928612F6B97D90898570A8
SHA256:2056F24FC37E52987885EA78DABCAE4575C0CE52A54CCC036CCACAE5768DFD89
3600DUMeter-Install 7.30.tmpC:\Program Files\DU Meter\Locale\de\LC_MESSAGES\is-J89C7.tmpbinary
MD5:072649605ABDDA08E15CE87DCC930B64
SHA256:D05AD9CF95F3F5ED799AFE087EF5A3D8C90B49060C231A37FE0BA617F84B079A
3600DUMeter-Install 7.30.tmpC:\Program Files\DU Meter\is-16EP0.tmpexecutable
MD5:3D9597E978CF0D57335EA82C1EADB20B
SHA256:BFC298B3E7A59368B32EF99D00AB6C1EBF36F1EAFA32AE19FC07A5DC5F515A3E
3600DUMeter-Install 7.30.tmpC:\Program Files\DU Meter\Locale\de\LC_MESSAGES\is-M63G0.tmpbinary
MD5:C3E12CF09D029480A500FDD1EF2C3824
SHA256:09AF6550539C9F6D15AB259529DFDB2F2F44A6ED5A57DC293735A167BE26D6F5
3600DUMeter-Install 7.30.tmpC:\Program Files\DU Meter\Locale\de\LC_MESSAGES\default.mobinary
MD5:C3E12CF09D029480A500FDD1EF2C3824
SHA256:09AF6550539C9F6D15AB259529DFDB2F2F44A6ED5A57DC293735A167BE26D6F5
3600DUMeter-Install 7.30.tmpC:\Program Files\DU Meter\DUMeterSvc.exeexecutable
MD5:AE93DE206C77D92C8C712C4DDA9999CD
SHA256:7FA117D1DAAB4EE559BC82503CD41AD6566D3DB5A1A5566056F609577775B89F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
7
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3804
DUMeter.exe
GET
200
184.24.77.46:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgPx5c9pBw%2BtSpTQPIQq9CiFnQ%3D%3D
unknown
binary
503 b
3804
DUMeter.exe
GET
200
23.212.210.158:80
http://x1.c.lencr.org/
unknown
binary
717 b
3804
DUMeter.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?215ed28ca5795ac5
unknown
compressed
4.66 Kb
3804
DUMeter.exe
POST
200
140.238.137.239:80
http://www.hageltech.com/service/software_version_check?protocol_version=1&product=du&ver=7.304769&lang=en&iid=045e8febb49e4132921fc8ebfbfda21f&edl=30
unknown
text
237 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
3804
DUMeter.exe
140.238.137.239:80
www.hageltech.com
ORACLE-BMC-31898
CA
unknown
3804
DUMeter.exe
140.238.137.239:443
www.hageltech.com
ORACLE-BMC-31898
CA
unknown
3804
DUMeter.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
unknown
3804
DUMeter.exe
23.212.210.158:80
x1.c.lencr.org
AKAMAI-AS
AU
unknown
3804
DUMeter.exe
184.24.77.46:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.hageltech.com
  • 140.238.137.239
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
unknown
x1.c.lencr.org
  • 23.212.210.158
unknown
r3.o.lencr.org
  • 184.24.77.46
  • 184.24.77.54
  • 184.24.77.56
  • 184.24.77.79
unknown

Threats

No threats detected
No debug info