File name:

SQLi 8.5.rar

Full analysis: https://app.any.run/tasks/4cbb46c9-c786-4d6a-ad5d-e2fa3b660a23
Verdict: Malicious activity
Analysis date: December 25, 2023, 13:00:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

DCB6B1A15E3B625168B765CFBAEDE249

SHA1:

C1AF37F0221B2A9841FBD9BBBA28CC346CD79056

SHA256:

893AE827C338159B625B83E4E4B46050C4BB5AC9E9606F2E27046863B12415B4

SSDEEP:

98304:vrEQ9hwn0Cd1UPnlmTwg8gd6pkYCmgoPajrnOSihz9rhJt4pfl7Ko17IavJhUZw6:k4LhSy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • SQLi_v_8_5.exe (PID: 2020)
      • ~SQLi_v_8_5.exe (PID: 316)
      • Network.exe (PID: 1796)
    • Requests information from PasteBin

      • ~SQLi_v_8_5.exe (PID: 316)
    • Reads settings of System Certificates

      • ~SQLi_v_8_5.exe (PID: 316)
    • Reads Microsoft Outlook installation path

      • ~SQLi_v_8_5.exe (PID: 316)
    • Reads Internet Explorer settings

      • ~SQLi_v_8_5.exe (PID: 316)
  • INFO

    • Checks supported languages

      • SQLi_v_8_5.exe (PID: 2020)
      • ~SQLi_v_8_5.exe (PID: 316)
      • Network.exe (PID: 1796)
    • Reads the computer name

      • SQLi_v_8_5.exe (PID: 2020)
      • ~SQLi_v_8_5.exe (PID: 316)
      • Network.exe (PID: 1796)
    • Reads the machine GUID from the registry

      • SQLi_v_8_5.exe (PID: 2020)
      • ~SQLi_v_8_5.exe (PID: 316)
      • Network.exe (PID: 1796)
    • Creates files or folders in the user directory

      • SQLi_v_8_5.exe (PID: 2020)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2184)
      • SQLi_v_8_5.exe (PID: 2020)
    • Reads Environment values

      • ~SQLi_v_8_5.exe (PID: 316)
      • Network.exe (PID: 1796)
    • Manual execution by a user

      • SQLi_v_8_5.exe (PID: 2020)
    • Checks proxy server information

      • ~SQLi_v_8_5.exe (PID: 316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs sqli_v_8_5.exe no specs ~sqli_v_8_5.exe network.exe no specs network.exe

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Users\admin\Desktop\SQLi 8.5\~SQLi_v_8_5.exe" C:\Users\admin\Desktop\SQLi 8.5\~SQLi_v_8_5.exe
SQLi_v_8_5.exe
User:
admin
Company:
SQLi Trush Corp
Integrity Level:
MEDIUM
Description:
SQLi Dumper v8.0
Exit code:
0
Version:
8.0.0.0
Modules
Images
c:\users\admin\desktop\sqli 8.5\~sqli_v_8_5.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1344"C:\Users\admin\AppData\Roaming\SQLi_v_8_5\SQLi_v_8_5\8.1.1.7800\Network.exe" C:\Users\admin\AppData\Roaming\SQLi_v_8_5\SQLi_v_8_5\8.1.1.7800\Network.exeSQLi_v_8_5.exe
User:
admin
Integrity Level:
MEDIUM
Description:
dowloader
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\sqli_v_8_5\sqli_v_8_5\8.1.1.7800\network.exe
c:\windows\system32\ntdll.dll
1796"C:\Users\admin\AppData\Roaming\SQLi_v_8_5\SQLi_v_8_5\8.1.1.7800\Network.exe" C:\Users\admin\AppData\Roaming\SQLi_v_8_5\SQLi_v_8_5\8.1.1.7800\Network.exe
SQLi_v_8_5.exe
User:
admin
Integrity Level:
HIGH
Description:
dowloader
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\sqli_v_8_5\sqli_v_8_5\8.1.1.7800\network.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2020"C:\Users\admin\Desktop\SQLi 8.5\SQLi_v_8_5.exe" C:\Users\admin\Desktop\SQLi 8.5\SQLi_v_8_5.exeexplorer.exe
User:
admin
Company:
SQLi_v_8_5
Integrity Level:
MEDIUM
Description:
SQLi_v_8_5
Exit code:
0
Version:
8.1.1.7800
Modules
Images
c:\users\admin\desktop\sqli 8.5\sqli_v_8_5.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2184"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SQLi 8.5.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
6 009
Read events
5 957
Write events
52
Delete events
0

Modification events

(PID) Process:(2184) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
3
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.25155\SQLi 8.5\Settingsxml
MD5:6CADCD28429156CBC1D77447BBDDDF42
SHA256:88AD0488FE62D131F1CA29A7DE9470038E436F33F76CE1A83D6B41BDF3DC6C7C
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.25155\SQLi 8.5\GeoIP.datbinary
MD5:CB9AD69965F9F4CFF8572983F60BE67C
SHA256:56C7079DC309168D9C41DD4A7A61033ACD264A120CA8D2E2182ABB5B9AE6B0A3
2020SQLi_v_8_5.exeC:\Users\admin\AppData\Roaming\SQLi_v_8_5\SQLi_v_8_5\8.1.1.7800\Network.exeexecutable
MD5:6FBA8AD3CE4847E8FF14627BFFEC9E2A
SHA256:7E069179F9A8436709D043AF2A392611E8E714A32E0541F1DBBDB28D4A04F863
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.25155\SQLi 8.5\DIC\dic_admin.txttext
MD5:F4675FA366AAE47396F8CFB2F3EB1B9A
SHA256:826FBBAA5DE45C1238FC7B9F4436C1B87444F8103F4F65180F8547E3F271A413
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.25155\SQLi 8.5\DIC\dic_file_dump.txttext
MD5:351CACFFC2884FCD4E69BB1FB04DDEB5
SHA256:C67BCC0B4ED5E5EF72AA1134C0838D9201A97C2BF462FDFF0AC9052A53B286A2
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.25155\SQLi 8.5\Settings.xmlxml
MD5:424A63DC1B977A3B667DF1E4969B529E
SHA256:11BEF668BF015FECB556008B6F6738229A174A97AAB805F0B5B4D913DE5CC8E4
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.25155\SQLi 8.5\SQLi_v_8_5.exeexecutable
MD5:1128182ECBE5145686C4EF270B7CA8F7
SHA256:928CA59BDFB9B09FD6871DCAEBE9CEDDD8A667DED2417190320643650579B63E
2020SQLi_v_8_5.exeC:\Users\admin\AppData\Roaming\SQLi_v_8_5\SQLi_v_8_5\8.1.1.7800\Network.zipcompressed
MD5:C975DFD9DF4CD2BBCD57D891317946FB
SHA256:6D17494079B4E2011A14C2DAC538DBE5618865FA90A5882084BEB4E454CEFC9D
2020SQLi_v_8_5.exeC:\Users\admin\Desktop\SQLi 8.5\~SQLi_v_8_5.exeexecutable
MD5:F558500B09118C2D5482C0097D41B986
SHA256:4081A78BA280D28C56551983E515486A1DACF9BA26A3E76A71060982CC9E5ED7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
2
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
316
~SQLi_v_8_5.exe
GET
301
104.20.68.143:80
http://pastebin.com/raw/3vsJLpWu
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
316
~SQLi_v_8_5.exe
104.20.68.143:80
pastebin.com
CLOUDFLARENET
unknown
316
~SQLi_v_8_5.exe
104.20.68.143:443
pastebin.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
pastebin.com
  • 104.20.68.143
  • 104.20.67.143
  • 172.67.34.170
shared
ciputrapro.org
unknown

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info