File name:

Havij_1.12_Free.zip

Full analysis: https://app.any.run/tasks/025831ee-9ec2-4d51-9085-80144ed955fd
Verdict: Malicious activity
Analysis date: April 15, 2024, 17:05:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

16A722326BCB040582DCFDA8206CD919

SHA1:

30FDD7E2F3DFB410A39B7E23B87EEAEBE9454188

SHA256:

818BF148E1C85C6BF0CF45F83D751E77683C0533C8F7C4B366F732974D2D37DD

SSDEEP:

49152:D51xGcWvTkmoAzadCYe1nBKs5ySw+QE/N/tvWH4l65785SpZpUkAvo:Pxgv7oGad4VBKM/dtvWH4l/mYo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Havij 1.12 Free.exe (PID: 3140)
      • Havij 1.12 Free.exe (PID: 532)
      • Havij 1.12 Free.tmp (PID: 2416)
    • Creates a writable file in the system directory

      • Havij 1.12 Free.tmp (PID: 2416)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Havij 1.12 Free.tmp (PID: 2416)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Havij 1.12 Free.exe (PID: 3140)
      • Havij 1.12 Free.exe (PID: 532)
      • Havij 1.12 Free.tmp (PID: 2416)
    • Reads the Windows owner or organization settings

      • Havij 1.12 Free.tmp (PID: 2416)
    • Process drops legitimate windows executable

      • Havij 1.12 Free.tmp (PID: 2416)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3456)
      • regsvr32.exe (PID: 3988)
      • regsvr32.exe (PID: 2448)
      • regsvr32.exe (PID: 3744)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2308)
    • Checks supported languages

      • Havij 1.12 Free.exe (PID: 3140)
      • Havij 1.12 Free.tmp (PID: 3128)
      • Havij 1.12 Free.exe (PID: 532)
      • Havij 1.12 Free.tmp (PID: 2416)
      • Havij.exe (PID: 2740)
    • Create files in a temporary directory

      • Havij 1.12 Free.exe (PID: 3140)
      • Havij 1.12 Free.exe (PID: 532)
      • Havij 1.12 Free.tmp (PID: 2416)
      • Havij.exe (PID: 2740)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2308)
    • Manual execution by a user

      • Havij 1.12 Free.exe (PID: 3140)
    • Reads the computer name

      • Havij 1.12 Free.tmp (PID: 3128)
      • Havij 1.12 Free.tmp (PID: 2416)
      • Havij.exe (PID: 2740)
    • Creates files in the program directory

      • Havij 1.12 Free.tmp (PID: 2416)
    • Reads mouse settings

      • regsvr32.exe (PID: 3988)
      • Havij.exe (PID: 2740)
    • Reads Microsoft Office registry keys

      • Havij.exe (PID: 2740)
    • Creates a software uninstall entry

      • Havij 1.12 Free.tmp (PID: 2416)
    • Reads the machine GUID from the registry

      • Havij.exe (PID: 2740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2010:08:30 11:27:50
ZipCRC: 0xaca6fbad
ZipCompressedSize: 1903784
ZipUncompressedSize: 1929082
ZipFileName: Havij 1.12 Free.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe havij 1.12 free.exe havij 1.12 free.tmp no specs havij 1.12 free.exe havij 1.12 free.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs havij.exe

Process information

PID
CMD
Path
Indicators
Parent process
532"C:\Users\admin\Desktop\Havij 1.12 Free.exe" /SPAWNWND=$160180 /NOTIFYWND=$120162 C:\Users\admin\Desktop\Havij 1.12 Free.exe
Havij 1.12 Free.tmp
User:
admin
Company:
ITSecTeam
Integrity Level:
HIGH
Description:
Havij Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\havij 1.12 free.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2308"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Havij_1.12_Free.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2416"C:\Users\admin\AppData\Local\Temp\is-JQ1UU.tmp\Havij 1.12 Free.tmp" /SL5="$1A016A,1684492,54272,C:\Users\admin\Desktop\Havij 1.12 Free.exe" /SPAWNWND=$160180 /NOTIFYWND=$120162 C:\Users\admin\AppData\Local\Temp\is-JQ1UU.tmp\Havij 1.12 Free.tmp
Havij 1.12 Free.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-jq1uu.tmp\havij 1.12 free.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2448"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\Mswinsck.ocx"C:\Windows\System32\regsvr32.exeHavij 1.12 Free.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2740"C:\Program Files\Havij\Havij.exe"C:\Program Files\Havij\Havij.exe
Havij 1.12 Free.tmp
User:
admin
Company:
ITSecTeam
Integrity Level:
MEDIUM
Description:
Advanced SQL Injection Tool
Version:
1.12
Modules
Images
c:\program files\havij\havij.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3128"C:\Users\admin\AppData\Local\Temp\is-OOPG4.tmp\Havij 1.12 Free.tmp" /SL5="$120162,1684492,54272,C:\Users\admin\Desktop\Havij 1.12 Free.exe" C:\Users\admin\AppData\Local\Temp\is-OOPG4.tmp\Havij 1.12 Free.tmpHavij 1.12 Free.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-oopg4.tmp\havij 1.12 free.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3140"C:\Users\admin\Desktop\Havij 1.12 Free.exe" C:\Users\admin\Desktop\Havij 1.12 Free.exe
explorer.exe
User:
admin
Company:
ITSecTeam
Integrity Level:
MEDIUM
Description:
Havij Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\havij 1.12 free.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3456"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\RICHTX32.ocx"C:\Windows\System32\regsvr32.exeHavij 1.12 Free.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3744"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\comdlg32.ocx"C:\Windows\System32\regsvr32.exeHavij 1.12 Free.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3988"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\Mscomctl.ocx"C:\Windows\System32\regsvr32.exeHavij 1.12 Free.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
6 764
Read events
6 572
Write events
102
Delete events
90

Modification events

(PID) Process:(2308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2308) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Havij_1.12_Free.zip
(PID) Process:(2308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
15
Suspicious files
4
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
2308WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2308.5378\Havij 1.12 Free.exeexecutable
MD5:
SHA256:
3140Havij 1.12 Free.exeC:\Users\admin\AppData\Local\Temp\is-OOPG4.tmp\Havij 1.12 Free.tmpexecutable
MD5:
SHA256:
532Havij 1.12 Free.exeC:\Users\admin\AppData\Local\Temp\is-JQ1UU.tmp\Havij 1.12 Free.tmpexecutable
MD5:
SHA256:
2416Havij 1.12 Free.tmpC:\Users\admin\AppData\Local\Temp\is-H6DUA.tmp\_isetup\_RegDLL.tmpexecutable
MD5:
SHA256:
2416Havij 1.12 Free.tmpC:\Users\admin\AppData\Local\Temp\is-H6DUA.tmp\_isetup\_shfoldr.dllexecutable
MD5:
SHA256:
2416Havij 1.12 Free.tmpC:\Program Files\Havij\is-ITA2F.tmpexecutable
MD5:
SHA256:
2416Havij 1.12 Free.tmpC:\Program Files\Havij\unins000.exeexecutable
MD5:
SHA256:
2416Havij 1.12 Free.tmpC:\Windows\system32\is-FFCBI.tmpexecutable
MD5:
SHA256:
2416Havij 1.12 Free.tmpC:\Windows\System32\RICHTX32.ocxexecutable
MD5:
SHA256:
2416Havij 1.12 Free.tmpC:\Windows\system32\is-G4BU9.tmpexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
20
DNS requests
2
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=123
unknown
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=123%20and%201=1
unknown
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=-9.9
unknown
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=123%20and%201=0
unknown
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=123'%20and%20'x'='x
unknown
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=123'%20and%20'x'='y
unknown
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=123"%20and%20"x"="x
unknown
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=123"%20and%20"x"="y
unknown
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=123%20and%201=1
unknown
2740
Havij.exe
GET
301
151.101.2.187:80
http://www.target.com/index.asp?id=123'
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2740
Havij.exe
151.101.2.187:80
www.target.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
unknown
www.target.com
  • 151.101.2.187
  • 151.101.66.187
  • 151.101.130.187
  • 151.101.194.187
unknown

Threats

PID
Process
Class
Message
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
Web Application Attack
ET SCAN Havij SQL Injection Tool User-Agent Outbound
No debug info