File name:

sqli dumper v8.2 modified.rar

Full analysis: https://app.any.run/tasks/41d48dde-3d9a-46a0-bc03-02f272a70375
Verdict: Malicious activity
Analysis date: January 04, 2019, 01:41:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

CCA48EDE1A65C276251F4BDC1CC99AED

SHA1:

072F55EED4CCE1DB641051A97CB1428D4969D872

SHA256:

0A78E66D9293890F4106358A23859B9C11F163A6B43EF79453C67FC5E5DC0F5C

SSDEEP:

196608:F/XOUoJYHu//gSY/uVsSyHTtRFnK0EO9r+bNOcQ/PzmExVTHzZXLQK2tMwBRRlWt:1eDmO//S/uaSyztRFj3r8EcOqExVT1Xn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3488)
      • SQLi Dumper.exe (PID: 2284)
      • SQLi Dumper.exe (PID: 1940)
      • SQLi Dumper.exe (PID: 2780)
    • Application was dropped or rewritten from another process

      • SQLiDumperKeygen.exe (PID: 2296)
      • SQLi Dumper.exe (PID: 2284)
      • SQLi Dumper.exe (PID: 2780)
      • SQLi Dumper.exe (PID: 1940)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • SQLi Dumper.exe (PID: 1940)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3356)
    • Application launched itself

      • SQLi Dumper.exe (PID: 2780)
    • Reads internet explorer settings

      • SQLi Dumper.exe (PID: 1940)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe sqli dumper.exe no specs searchprotocolhost.exe no specs sqli dumper.exe no specs sqlidumperkeygen.exe no specs sqli dumper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1940"C:\Users\admin\Desktop\SQLi Dumper.exe" C:\Users\admin\Desktop\SQLi Dumper.exeSQLi Dumper.exe
User:
admin
Company:
c4rl0s@jabber.ru
Integrity Level:
MEDIUM
Description:
SQLi Dumper
Exit code:
0
Version:
8.2.0.0
Modules
Images
c:\users\admin\desktop\sqli dumper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2284"C:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\SQLi Dumper.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\SQLi Dumper.exeWinRAR.exe
User:
admin
Company:
c4rl0s@jabber.ru
Integrity Level:
MEDIUM
Description:
SQLi Dumper
Exit code:
3221225547
Version:
8.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3356.10686\sqli dumper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2296"C:\Users\admin\Desktop\SQLi.Dumper.v8.3.Keygen-RTN\SQLiDumperKeygen.exe" C:\Users\admin\Desktop\SQLi.Dumper.v8.3.Keygen-RTN\SQLiDumperKeygen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SQLiDumperKeygen
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\sqli.dumper.v8.3.keygen-rtn\sqlidumperkeygen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2780"C:\Users\admin\Desktop\SQLi Dumper.exe" C:\Users\admin\Desktop\SQLi Dumper.exeexplorer.exe
User:
admin
Company:
c4rl0s@jabber.ru
Integrity Level:
MEDIUM
Description:
SQLi Dumper
Exit code:
3221225547
Version:
8.2.0.0
Modules
Images
c:\users\admin\desktop\sqli dumper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3356"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\sqli dumper v8.2 modified.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3488"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 342
Read events
1 296
Write events
46
Delete events
0

Modification events

(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3356) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\sqli dumper v8.2 modified.rar
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
6
Suspicious files
2
Text files
17
Unknown types
2

Dropped files

PID
Process
Filename
Type
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\ErrLog.logtext
MD5:
SHA256:
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\Settings.xmlxml
MD5:
SHA256:
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\DIC\dic_file_dump.txttext
MD5:351CACFFC2884FCD4E69BB1FB04DDEB5
SHA256:C67BCC0B4ED5E5EF72AA1134C0838D9201A97C2BF462FDFF0AC9052A53B286A2
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\GeoIP.datbinary
MD5:CB9AD69965F9F4CFF8572983F60BE67C
SHA256:56C7079DC309168D9C41DD4A7A61033ACD264A120CA8D2E2182ABB5B9AE6B0A3
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\TXT\URL List.txttext
MD5:
SHA256:
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\TXT\URL Exploitables.xmlxml
MD5:
SHA256:
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\TXT\URL Injectables.xmlxml
MD5:
SHA256:
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3356.10686\TXT\URL Trash.txttext
MD5:
SHA256:
3356WinRAR.exeC:\Users\admin\Desktop\Engine.dllexecutable
MD5:
SHA256:
3356WinRAR.exeC:\Users\admin\Desktop\Settings.xmlxml
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info