download:

/irwir/eMule/releases/download/eMule_v0.70b-community/eMule0.70b.zip

Full analysis: https://app.any.run/tasks/1c84d132-199a-4aaa-9e29-43a6603ef8aa
Verdict: Malicious activity
Analysis date: January 23, 2025, 13:32:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

7E5F6B24C8A1AC9CA1B47B960A45C2C9

SHA1:

AAEAA2F0DF0DEA150F617A123D7D6FDF58BB2AE9

SHA256:

CD35DC3F41E5ADD864EF535EC382B969D05BB6CEE19731DECA355978A6832279

SSDEEP:

98304:L+psD7IKSsDD+1ORVmG4gSUFLEmll2fu98OwF8MM6xMkFCdymKIOvZGfMbIf/xMF:SkYSeW6R

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • emule.exe (PID: 2128)
    • Reads security settings of Internet Explorer

      • emule.exe (PID: 2128)
    • Reads the Internet Settings

      • emule.exe (PID: 2128)
    • Reads settings of System Certificates

      • emule.exe (PID: 2128)
    • Potential Corporate Privacy Violation

      • emule.exe (PID: 2128)
    • Checks Windows Trust Settings

      • emule.exe (PID: 2128)
    • Connects to unusual port

      • emule.exe (PID: 2128)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 2896)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2896)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1832)
      • WinRAR.exe (PID: 2896)
      • emule.exe (PID: 2128)
      • wmpnscfg.exe (PID: 2652)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1832)
      • emule.exe (PID: 2128)
      • wmpnscfg.exe (PID: 2652)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1832)
      • emule.exe (PID: 2128)
      • wmpnscfg.exe (PID: 2652)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 2896)
    • Reads the machine GUID from the registry

      • emule.exe (PID: 2128)
    • Creates files in the program directory

      • emule.exe (PID: 2128)
    • Creates files or folders in the user directory

      • emule.exe (PID: 2128)
    • Checks proxy server information

      • emule.exe (PID: 2128)
    • Reads the software policy settings

      • emule.exe (PID: 2128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2010:04:07 15:03:04
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: eMule0.70b/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs wmpnscfg.exe no specs winrar.exe emule.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1832"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1932"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\eMule0.70b.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2128"C:\Users\admin\Desktop\eMule0.70b\emule.exe" C:\Users\admin\Desktop\eMule0.70b\emule.exe
explorer.exe
User:
admin
Company:
https://www.emule-project.net
Integrity Level:
MEDIUM
Description:
eMule
Version:
0.70.1 Unicode
Modules
Images
c:\users\admin\desktop\emule0.70b\emule.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
2652"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2896"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\eMule0.70b.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
6 520
Read events
6 449
Write events
63
Delete events
8

Modification events

(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1932) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\eMule0.70b.zip
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
5
Suspicious files
33
Text files
206
Unknown types
0

Dropped files

PID
Process
Filename
Type
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\lang\de_DE.dllexecutable
MD5:E20877FA86EE00A4D0031D8D6305DFB4
SHA256:E0C3F2E35650D494F1B004FAF2C52F861AFB9287FE11326D207B5382671E2C9B
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\config\server.metbinary
MD5:BE3EA98B2E865BA4320F6F81527BCAA5
SHA256:D0046472C8BB5A105DC3144177B6D0F0AAF29F2FD67B3105CC9BC7235A7757E2
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\config\staticservers.dattext
MD5:248858A6725CE0629276E7814C9B9981
SHA256:A6520B0CE2711F7D71E9B12DCF15D7EA5BC6489125057B654FD183DE38F4CBF3
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\config\eMule.tmplhtml
MD5:4B938565D309FEBC8BB50543AC4BAB5E
SHA256:09E4C42F069F06EE77C0A2185A84265DCF08A00A5805CDD197741C2DE742C08E
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\config\webservices.dattext
MD5:A5D35DA7A41EB088CEB711D27B65030F
SHA256:58419AF85C271E73750DBF806EB4D947017159DEB9520E9C6522FA9C3291A01B
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\lang\es_ES_T.dllexecutable
MD5:96ED96E972B0C2F12A10D7B4CC534FD0
SHA256:882A3DB328C1BD19EF3D79F4E01A15A25064B3E4E5C0CE0827229A5C70107A82
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\license-DK.txtbinary
MD5:205DAB03D3B474910425E80039A982F3
SHA256:9286BA87C1E9790E9CAD4CDA8CEB0E0B1F6EA2544004721EB9D5196867CCA106
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\license-FR.txtbinary
MD5:E496F812E0E38049711CDA99A63FC60D
SHA256:1C6CA57A3D9397B50AA7C2034317EA1A7BDE6EDC74CEE1A4DC73D057CD653DC1
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\config\nodes.datbinary
MD5:E032E0029A39DBB252E3C9618294394F
SHA256:F7D9ED39DDA7D95AF3324EAB56923DDC00940EDC1D689D9974B99BE3E4A84D5E
2896WinRAR.exeC:\Users\admin\Desktop\eMule0.70b\license-GR.txtbinary
MD5:A6218071FEB8F77BB1AB8E95129BE0DB
SHA256:98CC6CFEC182EE47E463CA5705DB977DABCA2FCB4032AF696422E4F1C2C7A3B9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
44
DNS requests
4
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2128
emule.exe
GET
200
142.250.185.131:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
2128
emule.exe
GET
200
23.50.131.216:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5c0c0c1c253ba2ff
unknown
whitelisted
2128
emule.exe
GET
200
142.250.185.131:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
2128
emule.exe
104.21.3.116:443
upd.emule-security.org
CLOUDFLARENET
unknown
2128
emule.exe
23.50.131.216:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted
2128
emule.exe
142.250.185.131:80
c.pki.goog
GOOGLE
US
whitelisted
2128
emule.exe
66.81.169.135:36515
unknown
2128
emule.exe
79.50.81.164:4672
unknown
2128
emule.exe
2.245.45.219:8883
unknown
2128
emule.exe
79.116.26.99:4672
unknown

DNS requests

Domain
IP
Reputation
cvvcdns2.emule-project.org
  • 16.1.60.1
unknown
upd.emule-security.org
  • 104.21.3.116
  • 172.67.130.169
unknown
ctldl.windowsupdate.com
  • 23.50.131.216
  • 23.50.131.200
whitelisted
c.pki.goog
  • 142.250.185.131
whitelisted

Threats

PID
Process
Class
Message
2128
emule.exe
Potential Corporate Privacy Violation
ET P2P eMule KAD Network Connection Request
2128
emule.exe
Potential Corporate Privacy Violation
ET P2P eDonkey Server Status Request
No debug info