File name: | DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time.rar |
Full analysis: | https://app.any.run/tasks/30784735-48a4-4f1a-8763-fbff5e6234ca |
Verdict: | Malicious activity |
Analysis date: | November 18, 2023, 15:04:19 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | 42AAAF661635C1C0AD2D3D64E4001A2B |
SHA1: | 325F1310980F89D94EA00CC071A7B7CAEDE3DEB9 |
SHA256: | 67D7577B5E250119D839764B307537461CB8DC41BF4661E4B53D24B507930B6D |
SSDEEP: | 98304:VrkumF5gNXZett/nb7OxAUnPyUCEw3TmJybiOTYD2OKoMfIcMeAk1asPFlZGqibD:+yaFuHKG5lvIkquQwEL+bFDn |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
316 | "C:\Program Files\DU Meter\DUMeterSvc.exe" /startedbyscm:E1F6D4BE-40E33354-DUMeterService | C:\Program Files\DU Meter\DUMeterSvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Hagel Technologies Ltd. Integrity Level: SYSTEM Description: DU Meter Service Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
600 | "C:\Program Files\DU Meter\DUMeterSvc.exe" /reinstall | C:\Program Files\DU Meter\DUMeterSvc.exe | — | DUMeter-Install 7.30.tmp | |||||||||||
User: admin Company: Hagel Technologies Ltd. Integrity Level: HIGH Description: DU Meter Service Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
752 | "C:\Program Files\DU Meter\DUMeter.exe" /regserver | C:\Program Files\DU Meter\DUMeter.exe | — | DUMeter-Install 7.30.tmp | |||||||||||
User: admin Company: Hagel Technologies Ltd. Integrity Level: HIGH Description: DU Meter Monitor Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
908 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\DU Meter\DuMonitor32.dll" | C:\Windows\System32\regsvr32.exe | — | DUMeter-Install 7.30.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1788 | "C:\Windows\system32\taskmgr.exe" | C:\Windows\System32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2908 | C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3212 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
3436 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3508 | "regedit.exe" "C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Your Files Is Here\Registration.reg" | C:\Windows\regedit.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3532 | "C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmp" /SL5="$50214,6035441,119296,C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\DUMeter-Install 7.30.exe" | C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmp | — | DUMeter-Install 7.30.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
|
(PID) Process: | (3436) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7C16E6-6828-4EF0-AF7B-C2A324CC6E41}\{6798FEA9-3E25-4B20-86D3-2399CB14B3FC} |
Operation: | delete key | Name: | (default) |
Value: | |||
(PID) Process: | (3436) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7C16E6-6828-4EF0-AF7B-C2A324CC6E41} |
Operation: | delete key | Name: | (default) |
Value: | |||
(PID) Process: | (3436) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{60B040B4-8ACA-4273-85DB-6095E6E5845C} |
Operation: | delete key | Name: | (default) |
Value: | |||
(PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3212 | WinRAR.exe | C:\Users\admin\Desktop\DU Meter 7.30 Build 4769 (Latest full version crack with patch) Life Time\Instructions !!!.txt | text | |
MD5:B618BC8787FD39C459B819C46C6E11EE | SHA256:207CB9020581379F8BE1A684C68F13FD6A57A6C3897CCFBAD19447B7FB9AA0B5 | |||
3600 | DUMeter-Install 7.30.tmp | C:\Program Files\DU Meter\DUMeter.exe | executable | |
MD5:3D9597E978CF0D57335EA82C1EADB20B | SHA256:BFC298B3E7A59368B32EF99D00AB6C1EBF36F1EAFA32AE19FC07A5DC5F515A3E | |||
3600 | DUMeter-Install 7.30.tmp | C:\Users\admin\AppData\Local\Temp\is-HVSRN.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
4036 | DUMeter-Install 7.30.exe | C:\Users\admin\AppData\Local\Temp\is-HFCQS.tmp\DUMeter-Install 7.30.tmp | executable | |
MD5:B3B2BFF0E1928612F6B97D90898570A8 | SHA256:2056F24FC37E52987885EA78DABCAE4575C0CE52A54CCC036CCACAE5768DFD89 | |||
3600 | DUMeter-Install 7.30.tmp | C:\Program Files\DU Meter\is-IHRJN.tmp | executable | |
MD5:B3B2BFF0E1928612F6B97D90898570A8 | SHA256:2056F24FC37E52987885EA78DABCAE4575C0CE52A54CCC036CCACAE5768DFD89 | |||
3600 | DUMeter-Install 7.30.tmp | C:\Program Files\DU Meter\Locale\de\LC_MESSAGES\is-J89C7.tmp | binary | |
MD5:072649605ABDDA08E15CE87DCC930B64 | SHA256:D05AD9CF95F3F5ED799AFE087EF5A3D8C90B49060C231A37FE0BA617F84B079A | |||
3600 | DUMeter-Install 7.30.tmp | C:\Program Files\DU Meter\is-16EP0.tmp | executable | |
MD5:3D9597E978CF0D57335EA82C1EADB20B | SHA256:BFC298B3E7A59368B32EF99D00AB6C1EBF36F1EAFA32AE19FC07A5DC5F515A3E | |||
3600 | DUMeter-Install 7.30.tmp | C:\Program Files\DU Meter\Locale\de\LC_MESSAGES\is-M63G0.tmp | binary | |
MD5:C3E12CF09D029480A500FDD1EF2C3824 | SHA256:09AF6550539C9F6D15AB259529DFDB2F2F44A6ED5A57DC293735A167BE26D6F5 | |||
3600 | DUMeter-Install 7.30.tmp | C:\Program Files\DU Meter\Locale\de\LC_MESSAGES\default.mo | binary | |
MD5:C3E12CF09D029480A500FDD1EF2C3824 | SHA256:09AF6550539C9F6D15AB259529DFDB2F2F44A6ED5A57DC293735A167BE26D6F5 | |||
3600 | DUMeter-Install 7.30.tmp | C:\Program Files\DU Meter\DUMeterSvc.exe | executable | |
MD5:AE93DE206C77D92C8C712C4DDA9999CD | SHA256:7FA117D1DAAB4EE559BC82503CD41AD6566D3DB5A1A5566056F609577775B89F |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3804 | DUMeter.exe | GET | 200 | 184.24.77.46:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgPx5c9pBw%2BtSpTQPIQq9CiFnQ%3D%3D | unknown | binary | 503 b | — |
3804 | DUMeter.exe | GET | 200 | 23.212.210.158:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | — |
3804 | DUMeter.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?215ed28ca5795ac5 | unknown | compressed | 4.66 Kb | — |
3804 | DUMeter.exe | POST | 200 | 140.238.137.239:80 | http://www.hageltech.com/service/software_version_check?protocol_version=1&product=du&ver=7.304769&lang=en&iid=045e8febb49e4132921fc8ebfbfda21f&edl=30 | unknown | text | 237 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
3804 | DUMeter.exe | 140.238.137.239:80 | www.hageltech.com | ORACLE-BMC-31898 | CA | unknown |
3804 | DUMeter.exe | 140.238.137.239:443 | www.hageltech.com | ORACLE-BMC-31898 | CA | unknown |
3804 | DUMeter.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | unknown |
3804 | DUMeter.exe | 23.212.210.158:80 | x1.c.lencr.org | AKAMAI-AS | AU | unknown |
3804 | DUMeter.exe | 184.24.77.46:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
---|---|---|
www.hageltech.com |
| unknown |
ctldl.windowsupdate.com |
| unknown |
x1.c.lencr.org |
| unknown |
r3.o.lencr.org |
| unknown |