| File name: | DVREMU2 Manager.rar |
| Full analysis: | https://app.any.run/tasks/60cfb18c-fea3-4eb1-8c4e-7d7ac5990a95 |
| Verdict: | Malicious activity |
| Analysis date: | January 29, 2025, 13:57:41 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | CB53452DD84EBE8C9C38AAE6D262B7FC |
| SHA1: | D63804290959D02281AA8EFBCD0BD94873AFE9BA |
| SHA256: | F44B73BF202F0827D6812337D56271AD7EF486F03A755BF86BF66B0B890A26CE |
| SSDEEP: | 98304:+8V9N/pC/XAD2OtdmS3D8zQtlJlwIpAmiUxW5PqQHzAX497hraK9SD4cUg6HxQDp:+3HU |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|---|
| CompressedSize: | 22 |
| UncompressedSize: | 22 |
| OperatingSystem: | Win32 |
| ArchivedFileName: | DVREMU2 Manager/commands/DVREMU2 - Install Emulator.cmd |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 556 | "C:\Users\admin\Desktop\DVREMU2 Manager\DVREMU2MAN.exe" killruntime | C:\Users\admin\Desktop\DVREMU2 Manager\DVREMU2MAN.exe | cmd.exe | ||||||||||||
User: admin Company: TEAM R2R Integrity Level: HIGH Description: DVREMU2 Manager Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 904 | "C:\Users\admin\Desktop\DVREMU2 Manager\DVREMU2MAN.exe" test | C:\Users\admin\Desktop\DVREMU2 Manager\DVREMU2MAN.exe | — | cmd.exe | |||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: DVREMU2 Manager Exit code: 3221226540 Version: 1.0.0.1 Modules
| |||||||||||||||
| 1228 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1476 | C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\DVREMU2 Manager\commands\DVREMU2 - Install Emulator.cmd" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1668 | ..\\DVREMU2MAN killruntime | C:\Users\admin\Desktop\DVREMU2 Manager\DVREMU2MAN.exe | — | cmd.exe | |||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: DVREMU2 Manager Exit code: 3221226540 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2212 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2796 | "C:\Windows\explorer.exe" C:\Users\admin\Desktop\DVREMU2 Manager\commands\ | C:\Windows\explorer.exe | — | DVREMU2MAN.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4160 | C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4500 | "C:\Users\admin\Desktop\DVREMU2 Manager\DVREMU2MAN.exe" renew | C:\Users\admin\Desktop\DVREMU2 Manager\DVREMU2MAN.exe | — | cmd.exe | |||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: DVREMU2 Manager Exit code: 3221226540 Version: 1.0.0.1 Modules
| |||||||||||||||
| 4504 | "C:\Users\admin\Desktop\DVREMU2 Manager\DVREMU2MAN.exe" | C:\Users\admin\Desktop\DVREMU2 Manager\DVREMU2MAN.exe | — | explorer.exe | |||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: DVREMU2 Manager Exit code: 3221226540 Version: 1.0.0.1 Modules
| |||||||||||||||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\DVREMU2 Manager.rar | |||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000 | |||
| (PID) Process: | (6488) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 256 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\commands\DVREMU2 - Install Emulator.cmd | text | |
MD5:74D85C83CDBE109E9972B8DB37E30492 | SHA256:9C5465254C6ECC96177657BC039F33EEF1B8F99F6349187566E6E4D1F5CD0C89 | |||
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\libcrypto-3-x64.dll | executable | |
MD5:E7463D58D7AFF43C7D71A3847BA8201E | SHA256:2249476A14DEA73AE271D661483BDC6C15E45B931F8DBFD0BD1B84193CF420EA | |||
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\Readme.txt | text | |
MD5:0DE76EA95B6ECF3866D834FA1B078018 | SHA256:632E2772F9536A30DDA7E1F61F267CCEC1AAC7DD5F568260377C0573570A32A8 | |||
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\DVREMU2MAN.exe | executable | |
MD5:2A052D9B7BDD115E24B7BC4B8475EDCE | SHA256:2083BEB78B4CEBA4A8FE819ED2307B4C0A22622F32CAEA60FCEA7DE0BCBD76B8 | |||
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\libbz2.dll | executable | |
MD5:B6C39AB833A3BC29183D0633BB9421AB | SHA256:57D9CB6E10BA90A3B8E9C2B2EAB2B80937B088123ADB482EAB71EF550CCE7794 | |||
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\unins000.dat | dat | |
MD5:93DA1CC725B51A2579598510681F5141 | SHA256:9AAD9819D33A6390770BD69051B18D1CC978B17B1906B36857713FCE68F6C5EC | |||
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\unins000.exe | executable | |
MD5:908F64B344BCE85C344E88DB0C4C334F | SHA256:6BDC1C8F0A1BD5951E94F575E6B693D0150D25F3B62BC7314567B2C4C3A8F009 | |||
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\commands\DVREMU2 - Test License and Emulator.cmd | text | |
MD5:509354EDE1A8E4DC9387F8F1D2CB874F | SHA256:4514AA7E9B6114DA0A3B0B985A9107F5184DE99F9F822FF13D2204263C373B0E | |||
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\commands\DVREMU2 - Use Shared VCRuntime.cmd | text | |
MD5:AD5D2C4DD94AF587A27FE87FDAEE24CF | SHA256:4CAC1BFB65A43E2FA9C95D7431DC20A4E204F3D407200BE04929684BA9D8F0C0 | |||
| 6488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6488.38528\DVREMU2 Manager\commands\DVREMU2 - Renew Emulator License.cmd | text | |
MD5:CD55DB859B9C6F1811D72AC4DD793356 | SHA256:D941AAF2E03BE3EAB4670F34E0DE05BCDFBE622674779A093A91CA500E98CE71 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.241.12:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7112 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7112 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
3988 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | unknown |
— | — | 2.16.241.12:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
— | — | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
1176 | svchost.exe | 20.190.159.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | unknown |
1076 | svchost.exe | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | unknown |
4712 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| unknown |
google.com |
| unknown |
ocsp.digicert.com |
| unknown |
crl.microsoft.com |
| unknown |
www.microsoft.com |
| unknown |
login.live.com |
| unknown |
go.microsoft.com |
| unknown |
www.bing.com |
| unknown |
slscr.update.microsoft.com |
| unknown |
fe3cr.delivery.mp.microsoft.com |
| unknown |