download:

/irwir/eMule/releases/download/eMule_v0.70b-community/eMule0.70b.zip

Full analysis: https://app.any.run/tasks/1c84d132-199a-4aaa-9e29-43a6603ef8aa
Verdict: Malicious activity
Analysis date: January 23, 2025, 13:32:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

7E5F6B24C8A1AC9CA1B47B960A45C2C9

SHA1:

AAEAA2F0DF0DEA150F617A123D7D6FDF58BB2AE9

SHA256:

CD35DC3F41E5ADD864EF535EC382B969D05BB6CEE19731DECA355978A6832279

SSDEEP:

98304:L+psD7IKSsDD+1ORVmG4gSUFLEmll2fu98OwF8MM6xMkFCdymKIOvZGfMbIf/xMF:SkYSeW6R

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • emule.exe (PID: 2128)
    • There is functionality for taking screenshot (YARA)

      • emule.exe (PID: 2128)
    • Reads the Internet Settings

      • emule.exe (PID: 2128)
    • Reads settings of System Certificates

      • emule.exe (PID: 2128)
    • Checks Windows Trust Settings

      • emule.exe (PID: 2128)
    • Potential Corporate Privacy Violation

      • emule.exe (PID: 2128)
    • Connects to unusual port

      • emule.exe (PID: 2128)
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 1832)
      • emule.exe (PID: 2128)
      • WinRAR.exe (PID: 2896)
      • wmpnscfg.exe (PID: 2652)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1832)
      • emule.exe (PID: 2128)
      • wmpnscfg.exe (PID: 2652)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2896)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1832)
      • emule.exe (PID: 2128)
      • wmpnscfg.exe (PID: 2652)
    • Reads the machine GUID from the registry

      • emule.exe (PID: 2128)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 2896)
    • Creates files in the program directory

      • emule.exe (PID: 2128)
    • Creates files or folders in the user directory

      • emule.exe (PID: 2128)
    • Checks proxy server information

      • emule.exe (PID: 2128)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2896)
    • Reads the software policy settings

      • emule.exe (PID: 2128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2010:04:07 15:03:04
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: eMule0.70b/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs wmpnscfg.exe no specs winrar.exe emule.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1832"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1932"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\eMule0.70b.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2128"C:\Users\admin\Desktop\eMule0.70b\emule.exe" C:\Users\admin\Desktop\eMule0.70b\emule.exe
explorer.exe
User:
admin
Company:
https://www.emule-project.net
Integrity Level:
MEDIUM
Description:
eMule
Version:
0.70.1 Unicode
Modules
Images
c:\users\admin\desktop\emule0.70b\emule.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
2652"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2896"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\eMule0.70b.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
6 520
Read events
6 449
Write events
63
Delete events
8

Modification events

(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1932) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\eMule0.70b.zip
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
5
Suspicious files
33
Text files
206
Unknown types
0

Dropped files

PID
Process
Filename
Type
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\config\eMule.tmplhtml
MD5:4B938565D309FEBC8BB50543AC4BAB5E
SHA256:09E4C42F069F06EE77C0A2185A84265DCF08A00A5805CDD197741C2DE742C08E
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\config\staticservers.dattext
MD5:248858A6725CE0629276E7814C9B9981
SHA256:A6520B0CE2711F7D71E9B12DCF15D7EA5BC6489125057B654FD183DE38F4CBF3
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\changelog.txttext
MD5:983A98025729011C31CC0F82DE1000F8
SHA256:34DE40489253416680D776FC457D549B3A521A0FE89B4597C838CB49287C2C2C
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\config\nodes.datbinary
MD5:E032E0029A39DBB252E3C9618294394F
SHA256:F7D9ED39DDA7D95AF3324EAB56923DDC00940EDC1D689D9974B99BE3E4A84D5E
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\license-HE.txtbinary
MD5:0E8DDF32D7C0D31E522D4EBD1FB898EE
SHA256:8BA50362BC3AC0E044E38DF0D0A9D092146CDF84C9F397D67E7E011480124778
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\config\webservices.dattext
MD5:A5D35DA7A41EB088CEB711D27B65030F
SHA256:58419AF85C271E73750DBF806EB4D947017159DEB9520E9C6522FA9C3291A01B
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\lang\fr_FR.dllexecutable
MD5:ABB8B5A5E5072A1E227819500E77D1B5
SHA256:174A2038FF6CF211A9E59056BD8DD8570E9A4BAC24FC55126AD1A2586803C910
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\lang\de_DE.dllexecutable
MD5:E20877FA86EE00A4D0031D8D6305DFB4
SHA256:E0C3F2E35650D494F1B004FAF2C52F861AFB9287FE11326D207B5382671E2C9B
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\license-DK.txtbinary
MD5:205DAB03D3B474910425E80039A982F3
SHA256:9286BA87C1E9790E9CAD4CDA8CEB0E0B1F6EA2544004721EB9D5196867CCA106
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\license-GER.txtbinary
MD5:80309D8BDD7C936851D1AA726D480B31
SHA256:9CFD9E3AA5D6F86DE704056E12A1221CC836111FF8E1F82993B45097106593FD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
44
DNS requests
4
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2128
emule.exe
GET
200
23.50.131.216:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5c0c0c1c253ba2ff
unknown
whitelisted
2128
emule.exe
GET
200
142.250.185.131:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
2128
emule.exe
GET
200
142.250.185.131:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
2128
emule.exe
104.21.3.116:443
upd.emule-security.org
CLOUDFLARENET
unknown
2128
emule.exe
23.50.131.216:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted
2128
emule.exe
142.250.185.131:80
c.pki.goog
GOOGLE
US
whitelisted
2128
emule.exe
66.81.169.135:36515
unknown
2128
emule.exe
79.50.81.164:4672
unknown
2128
emule.exe
2.245.45.219:8883
unknown
2128
emule.exe
79.116.26.99:4672
unknown

DNS requests

Domain
IP
Reputation
cvvcdns2.emule-project.org
  • 16.1.60.1
unknown
upd.emule-security.org
  • 104.21.3.116
  • 172.67.130.169
unknown
ctldl.windowsupdate.com
  • 23.50.131.216
  • 23.50.131.200
whitelisted
c.pki.goog
  • 142.250.185.131
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET P2P eMule KAD Network Connection Request
Potential Corporate Privacy Violation
ET P2P eDonkey Server Status Request
No debug info