| File name: | SQLi Dumper v.8.3 Free.rar |
| Full analysis: | https://app.any.run/tasks/ca1a90e5-d472-417d-8bfb-129cb73da77a |
| Verdict: | Malicious activity |
| Analysis date: | June 14, 2018, 00:00:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 7338FC023546DB93D2B57220FEABC6F2 |
| SHA1: | 3D14DB3AC17CF763B2A3A7DDC35C90A6F9491248 |
| SHA256: | 3A54689AFA9C61AF8B2092E68B3C496AEFA238210CB6FB5D78613E72A527056B |
| SSDEEP: | 98304:7FDUqIhhYd11J6Cyc1MAjRDWNKuSdqrko3hdAqlLXLqP+vH8jjzeFPhqTjIQ6IDN:RDUqIAbyONyGUH6P5jjzeFpqTLTWHus8 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2832 | "C:\Users\admin\Desktop\SQLi Dumper v.8.3 Free\SQLi Dumper.exe" | C:\Users\admin\Desktop\SQLi Dumper v.8.3 Free\SQLi Dumper.exe | — | explorer.exe | |||||||||||
User: admin Company: c4rl0s@jabber.ru Integrity Level: MEDIUM Description: SQLi Dumper Exit code: 0 Version: 8.3.0.0 Modules
| |||||||||||||||
| 3664 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\SQLi Dumper v.8.3 Free.rar" | C:\Program Files\7-Zip\7zFM.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Exit code: 0 Version: 16.04 Modules
| |||||||||||||||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | FolderShortcuts |
Value: | |||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | FolderHistory |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C00530051004C0069002000440075006D00700065007200200076002E0038002E003300200046007200650065002E007200610072005C000000 | |||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | PanelPath0 |
Value: C:\Users\admin\AppData\Local\Temp\ | |||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | FlatViewArc0 |
Value: 0 | |||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | PanelPath1 |
Value: | |||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | FlatViewArc1 |
Value: 0 | |||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | ListMode |
Value: 771 | |||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | Position |
Value: 1600000016000000D60300000B02000000000000 | |||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | Panels |
Value: 0100000000000000DA010000 | |||
| (PID) Process: | (3664) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM\Columns |
| Operation: | write | Name: | 7-Zip.Rar5 |
Value: 0100000004000000010000000400000001000000A00000000700000001000000640000000800000001000000640000000C00000001000000640000000A00000001000000640000000B00000001000000640000000900000001000000640000003F00000001000000640000000F00000001000000640000000D00000001000000640000001000000001000000640000001100000001000000640000001300000001000000640000001700000001000000640000001600000001000000640000003600000001000000640000005A00000001000000640000005F00000001000000640000001F00000001000000640000002000000001000000640000002E00000001000000640000003E0000000100000064000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3664 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zE05EE6434\SQLi Dumper v.8.3 Free\SQLi Dumper.exe | — | |
MD5:— | SHA256:— | |||
| 3664 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zE05EE6434\SQLi Dumper v.8.3 Free\SQLi Dumper.pdb | — | |
MD5:— | SHA256:— | |||
| 3664 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zE05EE6434\SQLi Dumper v.8.3 Free\Settings.xml | xml | |
MD5:— | SHA256:— | |||
| 2832 | SQLi Dumper.exe | C:\Users\admin\Desktop\SQLi Dumper v.8.3 Free\Settings.xml | xml | |
MD5:— | SHA256:— | |||
| 3664 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zE05EE6434\SQLi Dumper v.8.3 Free\DIC\dic_admin.txt | text | |
MD5:A0E54634DDD435DF5B82E20EA20C7EFE | SHA256:963E3A1E46D5F4C35B85464DB61B7C346C5C44669E64A5C016192DDE078F997A | |||
| 3664 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zE05EE6434\SQLi Dumper v.8.3 Free\DIC\dic_file_dump.txt | text | |
MD5:351CACFFC2884FCD4E69BB1FB04DDEB5 | SHA256:C67BCC0B4ED5E5EF72AA1134C0838D9201A97C2BF462FDFF0AC9052A53B286A2 | |||
| 3664 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zE05EE6434\SQLi Dumper v.8.3 Free\GeoIP.dat | binary | |
MD5:CB9AD69965F9F4CFF8572983F60BE67C | SHA256:56C7079DC309168D9C41DD4A7A61033ACD264A120CA8D2E2182ABB5B9AE6B0A3 | |||