File name:

DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time.rar

Full analysis: https://app.any.run/tasks/30784735-48a4-4f1a-8763-fbff5e6234ca
Verdict: Malicious activity
Analysis date: November 18, 2023, 15:04:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

42AAAF661635C1C0AD2D3D64E4001A2B

SHA1:

325F1310980F89D94EA00CC071A7B7CAEDE3DEB9

SHA256:

67D7577B5E250119D839764B307537461CB8DC41BF4661E4B53D24B507930B6D

SSDEEP:

98304:VrkumF5gNXZett/nb7OxAUnPyUCEw3TmJybiOTYD2OKoMfIcMeAk1asPFlZGqibD:+yaFuHKG5lvIkquQwEL+bFDn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DUMeter-Install 7.30.exe (PID: 4036)
      • DUMeter-Install 7.30.exe (PID: 3616)
      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Registers / Runs the DLL via REGSVR32.EXE

      • DUMeter-Install 7.30.tmp (PID: 3600)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Process drops legitimate windows executable

      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Process drops SQLite DLL files

      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Drops a system driver (possible attempt to evade defenses)

      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Executes as Windows Service

      • DUMeterSvc.exe (PID: 316)
    • Reads the Internet Settings

      • DUMeter.exe (PID: 3804)
    • Reads Microsoft Outlook installation path

      • DUMeter.exe (PID: 3804)
    • Reads settings of System Certificates

      • DUMeter.exe (PID: 3804)
    • Reads Internet Explorer settings

      • DUMeter.exe (PID: 3804)
    • Checks Windows Trust Settings

      • DUMeter.exe (PID: 3804)
    • Reads security settings of Internet Explorer

      • DUMeter.exe (PID: 3804)
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 3436)
      • DUMeter-Install 7.30.tmp (PID: 3532)
      • DUMeter-Install 7.30.tmp (PID: 3600)
      • DUMeter.exe (PID: 3804)
      • DUMeterSvc.exe (PID: 600)
      • DUMeterSvc.exe (PID: 316)
      • DUMeter.exe (PID: 752)
      • DUMeter.exe (PID: 4012)
      • DUMeter.exe (PID: 3748)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3436)
      • DUMeter-Install 7.30.exe (PID: 4036)
      • DUMeter-Install 7.30.tmp (PID: 3532)
      • DUMeter-Install 7.30.exe (PID: 3616)
      • DUMeter-Install 7.30.tmp (PID: 3600)
      • DUMeter.exe (PID: 752)
      • DUMeterSvc.exe (PID: 600)
      • DUMeterSvc.exe (PID: 316)
      • DUMeter.exe (PID: 3804)
      • DUMeter.exe (PID: 4012)
      • DUMeter.exe (PID: 3748)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3436)
      • DUMeter-Install 7.30.tmp (PID: 3600)
      • DUMeterSvc.exe (PID: 600)
      • DUMeterSvc.exe (PID: 316)
      • DUMeter.exe (PID: 752)
      • DUMeter.exe (PID: 3804)
      • DUMeter.exe (PID: 4012)
      • DUMeter.exe (PID: 3748)
    • Manual execution by a user

      • DUMeter-Install 7.30.exe (PID: 4036)
      • DUMeter.exe (PID: 4012)
      • taskmgr.exe (PID: 1788)
      • regedit.exe (PID: 3508)
      • regedit.exe (PID: 3828)
    • Create files in a temporary directory

      • DUMeter-Install 7.30.exe (PID: 4036)
      • DUMeter-Install 7.30.exe (PID: 3616)
      • DUMeter-Install 7.30.tmp (PID: 3600)
      • DUMeterSvc.exe (PID: 600)
      • DUMeter.exe (PID: 752)
      • DUMeter.exe (PID: 4012)
      • DUMeter.exe (PID: 3804)
      • DUMeter.exe (PID: 3748)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3212)
    • Creates files in the program directory

      • DUMeterSvc.exe (PID: 600)
      • DUMeterSvc.exe (PID: 316)
      • DUMeter-Install 7.30.tmp (PID: 3600)
    • Creates files or folders in the user directory

      • DUMeter.exe (PID: 3804)
    • Process checks computer location settings

      • DUMeter.exe (PID: 3804)
      • DUMeter.exe (PID: 752)
      • DUMeter.exe (PID: 4012)
      • DUMeter.exe (PID: 3748)
    • Checks proxy server information

      • DUMeter.exe (PID: 3804)
    • Reads the time zone

      • DUMeterSvc.exe (PID: 316)
    • Reads CPU info

      • DUMeterSvc.exe (PID: 316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
17
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs dumeter-install 7.30.exe no specs dumeter-install 7.30.tmp no specs dumeter-install 7.30.exe dumeter-install 7.30.tmp no specs regsvr32.exe no specs dumetersvc.exe no specs dumetersvc.exe no specs dumeter.exe no specs dumeter.exe Copy/Move/Rename/Delete/Link Object no specs taskmgr.exe no specs regedit.exe no specs regedit.exe dumeter.exe no specs dumeter.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Program Files\DU Meter\DUMeterSvc.exe" /startedbyscm:E1F6D4BE-40E33354-DUMeterServiceC:\Program Files\DU Meter\DUMeterSvc.exeservices.exe
User:
SYSTEM
Company:
Hagel Technologies Ltd.
Integrity Level:
SYSTEM
Description:
DU Meter Service
Exit code:
0
Version:
7.30
Modules
Images
c:\program files\du meter\dumetersvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
600"C:\Program Files\DU Meter\DUMeterSvc.exe" /reinstallC:\Program Files\DU Meter\DUMeterSvc.exeDUMeter-Install 7.30.tmp
User:
admin
Company:
Hagel Technologies Ltd.
Integrity Level:
HIGH
Description:
DU Meter Service
Exit code:
0
Version:
7.30
Modules
Images
c:\program files\du meter\dumetersvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
752"C:\Program Files\DU Meter\DUMeter.exe" /regserverC:\Program Files\DU Meter\DUMeter.exeDUMeter-Install 7.30.tmp
User:
admin
Company:
Hagel Technologies Ltd.
Integrity Level:
HIGH
Description:
DU Meter Monitor
Exit code:
0
Version:
7.30
Modules
Images
c:\program files\du meter\dumeter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
908"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\DU Meter\DuMonitor32.dll"C:\Windows\System32\regsvr32.exeDUMeter-Install 7.30.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1788"C:\Windows\system32\taskmgr.exe" C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2908C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3212"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3436"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3508"regedit.exe" "C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Registration.reg"C:\Windows\regedit.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
3532"C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmp" /SL5="$50214,6035441,119296,C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\DUMeter-Install 7.30.exe" C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmpDUMeter-Install 7.30.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hfcqs.tmp\dumeter-install 7.30.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
8 843
Read events
8 728
Write events
100
Delete events
15

Modification events

(PID) Process:(3436) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7C16E6-6828-4EF0-AF7B-C2A324CC6E41}\{6798FEA9-3E25-4B20-86D3-2399CB14B3FC}
Operation:delete keyName:(default)
Value:
(PID) Process:(3436) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7C16E6-6828-4EF0-AF7B-C2A324CC6E41}
Operation:delete keyName:(default)
Value:
(PID) Process:(3436) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{60B040B4-8ACA-4273-85DB-6095E6E5845C}
Operation:delete keyName:(default)
Value:
(PID) Process:(3212) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3212) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
25
Suspicious files
125
Text files
86
Unknown types
0

Dropped files

PID
Process
Filename
Type
3212WinRAR.exeC:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\DUMeter-Install 7.30.exeexecutable
MD5:C43C019BA3B6C183B7997A389D709F95
SHA256:2C707CE4625FCA8CC8CCA81EEDB7ABBEF1EDF13D0230F1EE5CBD81D3C6746F1B
3212WinRAR.exeC:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Crack file Past Here.lnkbinary
MD5:BBE0B3AD5EBE4124A3ED9659A69EDBE3
SHA256:9785F88A9DD9A38946D29653E6E2F9298EEE0EEC6EE639F88788A215D4A61776
3212WinRAR.exeC:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Instructions !!!.txttext
MD5:B618BC8787FD39C459B819C46C6E11EE
SHA256:207CB9020581379F8BE1A684C68F13FD6A57A6C3897CCFBAD19447B7FB9AA0B5
3212WinRAR.exeC:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Crack File\DUMeter.exeexecutable
MD5:A93E966F8550E593B0C5AE5DA7356476
SHA256:3B5309A3E0F930FBCD67AF73CC351070CDC0BDC3163D39FF3F63FD27DABF1309
3212WinRAR.exeC:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Registration.regtext
MD5:4EB6D81B585741F121FAAB5C3FF64E6B
SHA256:11A672EA284DE067F7DCE23DE84BECC4FD8946BAD79DD33849F85ABF60256FE3
4036DUMeter-Install 7.30.exeC:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmpexecutable
MD5:B3B2BFF0E1928612F6B97D90898570A8
SHA256:2056F24FC37E52987885EA78DABCAE4575C0CE52A54CCC036CCACAE5768DFD89
3600DUMeter-Install 7.30.tmpC:\Users\admin\AppData\Local\Temp\is-HVSRN.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3616DUMeter-Install 7.30.exeC:\Users\admin\AppData\Local\Temp\is-Q33FM.tmp\DUMeter-Install 7.30.tmpexecutable
MD5:B3B2BFF0E1928612F6B97D90898570A8
SHA256:2056F24FC37E52987885EA78DABCAE4575C0CE52A54CCC036CCACAE5768DFD89
3212WinRAR.exeC:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Crack File\DUMeterSvc.exeexecutable
MD5:F992F127DE9572E84AA3FAC6AFCEB90D
SHA256:59FE2F967F9F53BC8423C584DB384AE9BF2219D457D72FD768334490918026B6
3600DUMeter-Install 7.30.tmpC:\Program Files\DU Meter\Locale\de\LC_MESSAGES\is-M63G0.tmpbinary
MD5:C3E12CF09D029480A500FDD1EF2C3824
SHA256:09AF6550539C9F6D15AB259529DFDB2F2F44A6ED5A57DC293735A167BE26D6F5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
7
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3804
DUMeter.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?215ed28ca5795ac5
unknown
compressed
4.66 Kb
unknown
3804
DUMeter.exe
GET
200
23.212.210.158:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
3804
DUMeter.exe
GET
200
184.24.77.46:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgPx5c9pBw%2BtSpTQPIQq9CiFnQ%3D%3D
unknown
binary
503 b
unknown
3804
DUMeter.exe
POST
200
140.238.137.239:80
http://www.hageltech.com/service/software_version_check?protocol_version=1&product=du&ver=7.304769&lang=en&iid=045e8febb49e4132921fc8ebfbfda21f&edl=30
unknown
text
237 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3804
DUMeter.exe
140.238.137.239:80
www.hageltech.com
ORACLE-BMC-31898
CA
unknown
3804
DUMeter.exe
140.238.137.239:443
www.hageltech.com
ORACLE-BMC-31898
CA
unknown
3804
DUMeter.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3804
DUMeter.exe
23.212.210.158:80
x1.c.lencr.org
AKAMAI-AS
AU
unknown
3804
DUMeter.exe
184.24.77.46:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.hageltech.com
  • 140.238.137.239
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
x1.c.lencr.org
  • 23.212.210.158
whitelisted
r3.o.lencr.org
  • 184.24.77.46
  • 184.24.77.54
  • 184.24.77.56
  • 184.24.77.79
shared

Threats

No threats detected
No debug info