| File name: | DU.Meter.7.30.Build.4769 (1).rar |
| Full analysis: | https://app.any.run/tasks/c23c6d5b-d1e9-4839-9432-23e3565d4347 |
| Verdict: | Malicious activity |
| Analysis date: | July 01, 2024, 06:07:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32, flags: RecoveryRecordPresent |
| MD5: | F19939A261FE1943368DA8F6E5BB7B6F |
| SHA1: | E155777DDA038211F2DB20DD60D6FC4E49DC1DAE |
| SHA256: | AC30E0C3C69B0BA2D75957280E856F5504B685B2887D2491DE1F33289E3BA937 |
| SSDEEP: | 98304:xNOCPjB9Px8f70c3S3Fzxt909VYeRWkoIk/LQfJoMcN2wzYp7dcoswbezNWISSzV:6dTvt2bqVDW47p6 |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 6434142 |
|---|---|
| UncompressedSize: | 6498288 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2018:02:11 12:35:16 |
| PackingMethod: | Good Compression |
| ArchivedFileName: | DU.Meter.7.30.Build.4769\DU.Meter.7.30.Build.4769_Soft98.iR.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 540 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769 (1).rar" C:\Users\admin\Desktop\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 832 | "C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\taskkill.exe" /F /IM DUMeter.exe | C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\taskkill.exe | — | du.meter.7.x-patch.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Kill Process Exit code: 128 Version: 5.1.2600.5512 (xpsp.080413-2105) Modules
| |||||||||||||||
| 936 | "C:\Users\admin\AppData\Local\Temp\is-N0OH6.tmp\DU.Meter.7.30.Build.4769_Soft98.iR.tmp" /SL5="$501C8,6035441,119296,C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\DU.Meter.7.30.Build.4769_Soft98.iR.exe" /SPAWNWND=$401C6 /NOTIFYWND=$20220 | C:\Users\admin\AppData\Local\Temp\is-N0OH6.tmp\DU.Meter.7.30.Build.4769_Soft98.iR.tmp | DU.Meter.7.30.Build.4769_Soft98.iR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1144 | "C:\Program Files\DU Meter\DUMeter.exe" /regserver | C:\Program Files\DU Meter\DUMeter.exe | DU.Meter.7.30.Build.4769_Soft98.iR.tmp | ||||||||||||
User: admin Company: Hagel Technologies Ltd. Integrity Level: HIGH Description: DU Meter Monitor Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
| 1428 | "C:\Program Files\DU Meter\DUMeterSvc.exe" /reinstall | C:\Program Files\DU Meter\DUMeterSvc.exe | — | DU.Meter.7.30.Build.4769_Soft98.iR.tmp | |||||||||||
User: admin Company: Hagel Technologies Ltd. Integrity Level: HIGH Description: DU Meter Service Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
| 1808 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\Patch 7.x.rar" C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2036 | "C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\DU.Meter.7.30.Build.4769_Soft98.iR.exe" /SPAWNWND=$401C6 /NOTIFYWND=$20220 | C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\DU.Meter.7.30.Build.4769_Soft98.iR.exe | DU.Meter.7.30.Build.4769_Soft98.iR.tmp | ||||||||||||
User: admin Company: Hagel Technologies Ltd. Integrity Level: HIGH Description: Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
| 2060 | "C:\Windows\regedit.exe" /s "C:\Users\admin\AppData\Local\Temp\\regpatch.reg" | C:\Windows\regedit.exe | — | du.meter.7.x-patch.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2200 | "C:\Program Files\DU Meter\DUMeter.exe" | C:\Program Files\DU Meter\DUMeter.exe | — | explorer.exe | |||||||||||
User: admin Company: Hagel Technologies Ltd. Integrity Level: MEDIUM Description: DU Meter Monitor Exit code: 0 Version: 7.30 Modules
| |||||||||||||||
| 2304 | "C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\du.meter.7.x-patch.exe" | C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\du.meter.7.x-patch.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769 (1).rar | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3224 | WinRAR.exe | C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\DU.Meter.7.30.Build.4769_Soft98.iR.exe | — | |
MD5:— | SHA256:— | |||
| 936 | DU.Meter.7.30.Build.4769_Soft98.iR.tmp | C:\Users\admin\AppData\Local\Temp\is-VDR4S.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 540 | WinRAR.exe | C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\DU.Meter.7.30.Build.4769_Soft98.iR.exe | executable | |
MD5:C43C019BA3B6C183B7997A389D709F95 | SHA256:2C707CE4625FCA8CC8CCA81EEDB7ABBEF1EDF13D0230F1EE5CBD81D3C6746F1B | |||
| 540 | WinRAR.exe | C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\Soft98.iR.url | text | |
MD5:3DDF222B0633A83ECD9F4DD34F1D3FD3 | SHA256:CD49C8C8A991A045E07E301C17735760A6C0C4EF533882C48A7F1D9AF6FC8582 | |||
| 3224 | WinRAR.exe | C:\Users\admin\Desktop\DU.Meter.7.30.Build.4769\Soft98.iR.url | binary | |
MD5:2D8E0A1E616A048DAA3541CFD4A2D295 | SHA256:DADC4639D965AC742D69CA4E7DFBF0C8056E2A11EC06D57864506478DDB2ACAA | |||
| 936 | DU.Meter.7.30.Build.4769_Soft98.iR.tmp | C:\Users\admin\AppData\Local\Temp\is-VDR4S.tmp\DuHelper.dll | executable | |
MD5:226CA1ACE882E5C3DDB63A5CAAE9F5C0 | SHA256:B0CA2CC6EC8D6C3E81CA9B4D1D4673ED7E14FAE9E738984F8F3FEFD68F81173B | |||
| 936 | DU.Meter.7.30.Build.4769_Soft98.iR.tmp | C:\Program Files\DU Meter\is-DJMP2.tmp | executable | |
MD5:AE93DE206C77D92C8C712C4DDA9999CD | SHA256:7FA117D1DAAB4EE559BC82503CD41AD6566D3DB5A1A5566056F609577775B89F | |||
| 936 | DU.Meter.7.30.Build.4769_Soft98.iR.tmp | C:\Program Files\DU Meter\DUMeter.exe | executable | |
MD5:3D9597E978CF0D57335EA82C1EADB20B | SHA256:BFC298B3E7A59368B32EF99D00AB6C1EBF36F1EAFA32AE19FC07A5DC5F515A3E | |||
| 936 | DU.Meter.7.30.Build.4769_Soft98.iR.tmp | C:\Program Files\DU Meter\Locale\de\LC_MESSAGES\default.mo | gmo | |
MD5:C3E12CF09D029480A500FDD1EF2C3824 | SHA256:09AF6550539C9F6D15AB259529DFDB2F2F44A6ED5A57DC293735A167BE26D6F5 | |||
| 936 | DU.Meter.7.30.Build.4769_Soft98.iR.tmp | C:\Program Files\DU Meter\DUMeterSvc.exe | executable | |
MD5:AE93DE206C77D92C8C712C4DDA9999CD | SHA256:7FA117D1DAAB4EE559BC82503CD41AD6566D3DB5A1A5566056F609577775B89F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1372 | svchost.exe | GET | — | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33 | unknown | — | — | unknown |
1060 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a9f83325acc8ca75 | unknown | — | — | unknown |
1372 | svchost.exe | GET | 200 | 2.16.164.72:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
1372 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
3648 | DUMeter.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d55a953f429eeaed | unknown | — | — | unknown |
3648 | DUMeter.exe | GET | 200 | 95.101.54.195:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgSu%2FQIst%2FNFToesbiQzLynaPw%3D%3D | unknown | — | — | unknown |
3648 | DUMeter.exe | GET | 200 | 2.23.197.184:80 | http://x1.c.lencr.org/ | unknown | — | — | unknown |
3648 | DUMeter.exe | POST | 200 | 192.18.158.175:80 | http://www.hageltech.com/service/software_version_check?protocol_version=1&product=du&ver=7.304769&lang=en&iid=51108968399443b893a2b2aeb004d735&edl=30 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1372 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1372 | svchost.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
1372 | svchost.exe | 2.16.164.72:80 | crl.microsoft.com | Akamai International B.V. | NL | unknown |
1372 | svchost.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
1060 | svchost.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
3648 | DUMeter.exe | 192.18.158.175:80 | www.hageltech.com | ORACLE-BMC-31898 | CA | unknown |
3648 | DUMeter.exe | 192.18.158.175:443 | www.hageltech.com | ORACLE-BMC-31898 | CA | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.hageltech.com |
| unknown |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |