| download: | Havij-v1.16-Pro-Portable-_ed.7z |
| Full analysis: | https://app.any.run/tasks/83b2c8b5-7109-48a5-ad15-8d238053691e |
| Verdict: | Malicious activity |
| Analysis date: | November 08, 2018, 14:52:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.3 |
| MD5: | 8110374F1B2BB8208C364B09DA10F067 |
| SHA1: | 5CB04D950D222769AAF90139E284B45A8BD994B5 |
| SHA256: | 8B3BF9ADD68356B4B7141A75C5A314B5713E354D9E696BF344A4F59B1931A0AE |
| SSDEEP: | 98304:rI58g3QgN5AmMA9OAE+tJ7qhmlz1APwIe1qsfSKSHKWO91W:858QQgN5nr9Ek+hmV1APw6sfSKu/EW |
| .7z | | | 7-Zip compressed archive (gen) (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 700 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Havij-v1.16-Pro-Portable-_ed.7z" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 1336 | "C:\Windows\system32\HavijPro\Havij.exe" | C:\Windows\system32\HavijPro\Havij.exe | — | Havij_Load.exe | |||||||||||
User: admin Company: ITSecTeam Integrity Level: HIGH Description: Advanced SQL Injection Tool Exit code: 0 Version: 1.16 Modules
| |||||||||||||||
| 2796 | C:\Windows\system32\HavijPro\Havij_Load.exe | C:\Windows\system32\HavijPro\Havij_Load.exe | — | Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3700 | "C:\Users\admin\Desktop\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe" | C:\Users\admin\Desktop\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3712 | "C:\Users\admin\Desktop\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe" | C:\Users\admin\Desktop\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Havij-v1.16-Pro-Portable-_ed.7z | |||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (700) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 700 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa700.31675\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | — | |
MD5:— | SHA256:— | |||
| 3712 | Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | C:\users\admin\appdata\local\temp\REG-SM-AoRE.bmp | image | |
MD5:618EF93D12F1C201313F3E9DF0D34C2C | SHA256:0DE8FBD0686F6434F03DCB7EF2ED622980902D495E7483105F2ABB8318C8303C | |||
| 3712 | Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | C:\Users\admin\AppData\Local\Temp\IRANTK.INFO | executable | |
MD5:0DAB1380431FF8A5BFE52797D4240DA8 | SHA256:9E5453882DF10F54E8E9F8CFDFB99D919654479665D17F589DBC3D8622C0E256 | |||
| 3700 | Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | C:\users\admin\appdata\local\temp\REG-SM-AoRE.bmp | image | |
MD5:618EF93D12F1C201313F3E9DF0D34C2C | SHA256:0DE8FBD0686F6434F03DCB7EF2ED622980902D495E7483105F2ABB8318C8303C | |||
| 700 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa700.31675\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\www.hayzia.wordpress.com.nfo | text | |
MD5:34EE3F8F8BB6E193E2C634B4A6DCC92C | SHA256:B3D90DF2C70E3F656477D8844F929DDCE1F85F45528D281DE810A0115D1909E7 | |||
| 3700 | Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | C:\Windows\system32\MSINET.OCX | executable | |
MD5:7BEC181A21753498B6BD001C42A42722 | SHA256:73DA54B69911BDD08EA8BBBD508F815EF7CFA59C4684D75C1C602252EC88EE31 | |||
| 3700 | Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | C:\Windows\system32\Mswinsck.ocx | executable | |
MD5:E8A2190A9E8EE5E5D2E0B599BBF9DDA6 | SHA256:80AB0B86DE58A657956B2A293BD9957F78E37E7383C86D6CD142208C153B6311 | |||
| 3700 | Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | C:\Windows\system32\TABCTL32.OCX | executable | |
MD5:79ED276AAE03D4F62551871D8094F09A | SHA256:341D97CB88C04C4B566C82EC36D4EE1F2BCA5E31BF04D240796277CE770B56C9 | |||
| 3700 | Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | C:\Windows\system32\comdlg32.ocx | executable | |
MD5:D76F0EAB36F83A31D411AEAF70DA7396 | SHA256:46F4FDB12C30742FF4607876D2F36CF432CDC7EC3D2C99097011448FC57E997C | |||
| 3700 | Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe | C:\Users\admin\AppData\Local\Temp\IRANTK.INFO | executable | |
MD5:0DAB1380431FF8A5BFE52797D4240DA8 | SHA256:9E5453882DF10F54E8E9F8CFDFB99D919654479665D17F589DBC3D8622C0E256 | |||