download: | /irwir/eMule/releases/download/eMule_v0.70b-community/eMule0.70b.zip |
Full analysis: | https://app.any.run/tasks/1c84d132-199a-4aaa-9e29-43a6603ef8aa |
Verdict: | Malicious activity |
Analysis date: | January 23, 2025, 13:32:36 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v1.0 to extract, compression method=store |
MD5: | 7E5F6B24C8A1AC9CA1B47B960A45C2C9 |
SHA1: | AAEAA2F0DF0DEA150F617A123D7D6FDF58BB2AE9 |
SHA256: | CD35DC3F41E5ADD864EF535EC382B969D05BB6CEE19731DECA355978A6832279 |
SSDEEP: | 98304:L+psD7IKSsDD+1ORVmG4gSUFLEmll2fu98OwF8MM6xMkFCdymKIOvZGfMbIf/xMF:SkYSeW6R |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 10 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2010:04:07 15:03:04 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | - |
ZipUncompressedSize: | - |
ZipFileName: | eMule0.70b/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1832 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1932 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\eMule0.70b.zip | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
2128 | "C:\Users\admin\Desktop\eMule0.70b\emule.exe" | C:\Users\admin\Desktop\eMule0.70b\emule.exe | explorer.exe | ||||||||||||
User: admin Company: https://www.emule-project.net Integrity Level: MEDIUM Description: eMule Version: 0.70.1 Unicode Modules
| |||||||||||||||
2652 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2896 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\eMule0.70b.zip" C:\Users\admin\Desktop\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
|
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\eMule0.70b.zip | |||
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (1932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\config\eMule.tmpl | html | |
MD5:4B938565D309FEBC8BB50543AC4BAB5E | SHA256:09E4C42F069F06EE77C0A2185A84265DCF08A00A5805CDD197741C2DE742C08E | |||
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\config\staticservers.dat | text | |
MD5:248858A6725CE0629276E7814C9B9981 | SHA256:A6520B0CE2711F7D71E9B12DCF15D7EA5BC6489125057B654FD183DE38F4CBF3 | |||
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\changelog.txt | text | |
MD5:983A98025729011C31CC0F82DE1000F8 | SHA256:34DE40489253416680D776FC457D549B3A521A0FE89B4597C838CB49287C2C2C | |||
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\config\nodes.dat | binary | |
MD5:E032E0029A39DBB252E3C9618294394F | SHA256:F7D9ED39DDA7D95AF3324EAB56923DDC00940EDC1D689D9974B99BE3E4A84D5E | |||
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\license-HE.txt | binary | |
MD5:0E8DDF32D7C0D31E522D4EBD1FB898EE | SHA256:8BA50362BC3AC0E044E38DF0D0A9D092146CDF84C9F397D67E7E011480124778 | |||
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\config\webservices.dat | text | |
MD5:A5D35DA7A41EB088CEB711D27B65030F | SHA256:58419AF85C271E73750DBF806EB4D947017159DEB9520E9C6522FA9C3291A01B | |||
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\lang\fr_FR.dll | executable | |
MD5:ABB8B5A5E5072A1E227819500E77D1B5 | SHA256:174A2038FF6CF211A9E59056BD8DD8570E9A4BAC24FC55126AD1A2586803C910 | |||
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\lang\de_DE.dll | executable | |
MD5:E20877FA86EE00A4D0031D8D6305DFB4 | SHA256:E0C3F2E35650D494F1B004FAF2C52F861AFB9287FE11326D207B5382671E2C9B | |||
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\license-DK.txt | binary | |
MD5:205DAB03D3B474910425E80039A982F3 | SHA256:9286BA87C1E9790E9CAD4CDA8CEB0E0B1F6EA2544004721EB9D5196867CCA106 | |||
2896 | WinRAR.exe | C:\Users\admin\Desktop\eMule0.70b\license-GER.txt | binary | |
MD5:80309D8BDD7C936851D1AA726D480B31 | SHA256:9CFD9E3AA5D6F86DE704056E12A1221CC836111FF8E1F82993B45097106593FD |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2128 | emule.exe | GET | 200 | 23.50.131.216:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5c0c0c1c253ba2ff | unknown | — | — | whitelisted |
2128 | emule.exe | GET | 200 | 142.250.185.131:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
2128 | emule.exe | GET | 200 | 142.250.185.131:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1108 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2128 | emule.exe | 104.21.3.116:443 | upd.emule-security.org | CLOUDFLARENET | — | unknown |
2128 | emule.exe | 23.50.131.216:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | whitelisted |
2128 | emule.exe | 142.250.185.131:80 | c.pki.goog | GOOGLE | US | whitelisted |
2128 | emule.exe | 66.81.169.135:36515 | — | — | — | unknown |
2128 | emule.exe | 79.50.81.164:4672 | — | — | — | unknown |
2128 | emule.exe | 2.245.45.219:8883 | — | — | — | unknown |
2128 | emule.exe | 79.116.26.99:4672 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
cvvcdns2.emule-project.org |
| unknown |
upd.emule-security.org |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
c.pki.goog |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET P2P eMule KAD Network Connection Request |
— | — | Potential Corporate Privacy Violation | ET P2P eDonkey Server Status Request |