File name:

SQLi Dumper 8.3.rar

Full analysis: https://app.any.run/tasks/e52c73f2-17ce-4961-9464-66512e1eb771
Verdict: Malicious activity
Analysis date: March 06, 2024, 19:47:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

CC96828D159EAF9218E09693CEB39755

SHA1:

FAE99B704EA2E895FC42BE084D0B34EC72D36670

SHA256:

88B0031BC611EE20B27C96A9FD1910D610987D08962A2D1EC51EF599FA5E1633

SSDEEP:

98304:j1ztOm5JFNG8MbqtqjrHajwSaVTpEu4Khslcr0GV17T3TlMg4VqkfubOUWsiYzxb:Oal62A31VNh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3668)
  • SUSPICIOUS

    • Reads Internet Explorer settings

      • SQLi Dumper.exe (PID: 1776)
    • Reads Microsoft Outlook installation path

      • SQLi Dumper.exe (PID: 1776)
    • Reads security settings of Internet Explorer

      • SQLi Dumper.exe (PID: 1776)
    • Reads the Internet Settings

      • SQLi Dumper.exe (PID: 1776)
  • INFO

    • Manual execution by a user

      • SQLi Dumper.exe (PID: 1776)
    • Reads the machine GUID from the registry

      • SQLi Dumper.exe (PID: 1776)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3668)
    • Reads the computer name

      • SQLi Dumper.exe (PID: 1776)
    • Checks proxy server information

      • SQLi Dumper.exe (PID: 1776)
    • Reads Environment values

      • SQLi Dumper.exe (PID: 1776)
    • Checks supported languages

      • SQLi Dumper.exe (PID: 1776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sqli dumper.exe

Process information

PID
CMD
Path
Indicators
Parent process
1776"C:\Users\admin\Desktop\SQLi Dumper 8.3\SQLi Dumper.exe" C:\Users\admin\Desktop\SQLi Dumper 8.3\SQLi Dumper.exe
explorer.exe
User:
admin
Company:
c4rl0s@jabber.ru
Integrity Level:
MEDIUM
Description:
SQLi Dumper
Exit code:
0
Version:
8.3.0.0
Modules
Images
c:\users\admin\desktop\sqli dumper 8.3\sqli dumper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3668"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SQLi Dumper 8.3.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 532
Read events
5 497
Write events
33
Delete events
2

Modification events

(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SQLi Dumper 8.3.rar
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
3
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3668.44274\SQLi Dumper 8.3\ChilkatDotNet2.dllexecutable
MD5:6990F5076EB51EE135492BA5BA619B72
SHA256:6733F1B7DAF40076FFE88DC8A88E23181D1BA449D6E5BB36A5325B4353849460
1776SQLi Dumper.exeC:\Users\admin\Desktop\SQLi Dumper 8.3\DIC\dic_file_dump.txttext
MD5:351CACFFC2884FCD4E69BB1FB04DDEB5
SHA256:C67BCC0B4ED5E5EF72AA1134C0838D9201A97C2BF462FDFF0AC9052A53B286A2
1776SQLi Dumper.exeC:\Users\admin\Desktop\SQLi Dumper 8.3\DIC\dic_admin.txttext
MD5:A0E54634DDD435DF5B82E20EA20C7EFE
SHA256:963E3A1E46D5F4C35B85464DB61B7C346C5C44669E64A5C016192DDE078F997A
1776SQLi Dumper.exeC:\Users\admin\Desktop\SQLi Dumper 8.3\Settings.xmlxml
MD5:F9C95DFCC4A4C0B2B9051F2BF2CB87F7
SHA256:907F1A27D85665ACF85A9756C3B8A2FF253069A3A7EBD672148D539173CA08FC
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3668.44274\SQLi Dumper 8.3\ControlsGui.dllexecutable
MD5:F6660AE3A390595E834D1DAEBB14136B
SHA256:276FCEECF4199B6352D073D8DA7C143D47BB9CD03B6A9546154D99832F0C47F5
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3668.44274\SQLi Dumper 8.3\SQLi Dumper.exeexecutable
MD5:E5D3F124126A4B1FAA148FC8ECEDF433
SHA256:3F3ED131FE2A88B0085F5F2E1C5BCDDA32D7C76BCF3F28F82065048966887706
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3668.44274\SQLi Dumper 8.3\GeoIP.datbinary
MD5:CB9AD69965F9F4CFF8572983F60BE67C
SHA256:56C7079DC309168D9C41DD4A7A61033ACD264A120CA8D2E2182ABB5B9AE6B0A3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
82
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
301
151.101.2.114:80
http://www.ask.com/web?q=%3fitem_id%3d
unknown
unknown
1776
SQLi Dumper.exe
GET
200
2.20.142.180:80
http://www.bing.com/search?q=%3fitem_id%3d&count=50
unknown
html
28.0 Kb
unknown
GET
301
212.82.100.137:80
http://search.aol.com/aol/search?s_it=sb-top&v_t=na&q=%3fitem_id%3d
unknown
text
25 b
unknown
GET
301
212.82.100.137:80
http://search.yahoo.com/search?n=100&p=%3fitem_id%3d
unknown
text
25 b
unknown
1776
SQLi Dumper.exe
GET
200
2.20.142.180:80
http://www.bing.com/search?q=article+%3fid%3d&count=50
unknown
html
28.0 Kb
unknown
1776
SQLi Dumper.exe
GET
301
212.82.100.137:80
http://www.wow.com/search?s_it=topsearchbox.search&v_t=na&q=%3fitem_id%3d
unknown
text
25 b
unknown
1776
SQLi Dumper.exe
GET
301
212.82.100.137:80
http://search.yahoo.com/search?n=100&p=%3fitem_id%3d
unknown
text
25 b
unknown
1776
SQLi Dumper.exe
GET
301
212.82.100.137:80
http://search.aol.com/aol/search?s_it=sb-top&v_t=na&q=%3fitem_id%3d
unknown
text
25 b
unknown
1776
SQLi Dumper.exe
GET
200
2.20.142.180:80
http://www.bing.com/search?q=detail+%3fid%3d&count=50
unknown
html
28.2 Kb
unknown
1776
SQLi Dumper.exe
GET
301
151.101.2.114:80
http://www.ask.com/web?q=%3fitem_id%3d
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1776
SQLi Dumper.exe
142.250.186.164:443
www.google.com
GOOGLE
US
whitelisted
1776
SQLi Dumper.exe
212.82.100.137:80
search.aol.com
Yahoo! UK Services Limited
IE
shared
1776
SQLi Dumper.exe
2.20.142.180:80
www.bing.com
Akamai International B.V.
DE
unknown
1776
SQLi Dumper.exe
151.101.2.114:80
www.ask.com
FASTLY
US
unknown
1776
SQLi Dumper.exe
151.101.2.114:443
www.ask.com
FASTLY
US
unknown
1776
SQLi Dumper.exe
212.82.100.137:443
search.aol.com
Yahoo! UK Services Limited
IE
shared

DNS requests

Domain
IP
Reputation
search.aol.com
  • 212.82.100.137
whitelisted
www.ask.com
  • 151.101.2.114
  • 151.101.130.114
  • 151.101.66.114
  • 151.101.194.114
whitelisted
www.wow.com
  • 212.82.100.137
whitelisted
www.bing.com
  • 2.20.142.180
  • 2.20.142.3
  • 2.20.142.178
  • 2.20.142.136
  • 2.20.142.138
  • 2.20.142.155
  • 2.20.142.162
  • 92.122.215.99
  • 92.122.215.98
whitelisted
search.yahoo.com
  • 212.82.100.137
whitelisted
www.google.com
  • 142.250.186.164
whitelisted

Threats

No threats detected
Process
Message
SQLi Dumper.exe
Scanner_Progress, Host: Google, Percentage 0 %
SQLi Dumper.exe
Scanner_Progress, Host: Bing, Percentage 0 %
SQLi Dumper.exe
Scanner_Progress, Host: Yahoo, Percentage 0 %
SQLi Dumper.exe
Scanner_Progress, Host: Ask, Percentage 0 %
SQLi Dumper.exe
Scanner_Progress, Host: AOL, Percentage 0 %
SQLi Dumper.exe
Scanner_Progress, Host: WOW, Percentage 0 %
SQLi Dumper.exe
bckWorkerSearch_DoWork, Loop Error: Object reference not set to an instance of an object.
SQLi Dumper.exe
bckWorkerSearch_DoWork, Loop Error: Object reference not set to an instance of an object.
SQLi Dumper.exe
bckWorkerSearch_DoWork, Loop Error: Object reference not set to an instance of an object.
SQLi Dumper.exe
bckWorkerSearch_DoWork, Loop Error: Object reference not set to an instance of an object.