download:

Havij-v1.16-Pro-Portable-_ed.7z

Full analysis: https://app.any.run/tasks/83b2c8b5-7109-48a5-ad15-8d238053691e
Verdict: Malicious activity
Analysis date: November 08, 2018, 14:52:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.3
MD5:

8110374F1B2BB8208C364B09DA10F067

SHA1:

5CB04D950D222769AAF90139E284B45A8BD994B5

SHA256:

8B3BF9ADD68356B4B7141A75C5A314B5713E354D9E696BF344A4F59B1931A0AE

SSDEEP:

98304:rI58g3QgN5AmMA9OAE+tJ7qhmlz1APwIe1qsfSKSHKWO91W:858QQgN5nr9Ek+hmV1APw6sfSKu/EW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe (PID: 3700)
      • Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe (PID: 3712)
      • Havij.exe (PID: 1336)
    • Application was dropped or rewritten from another process

      • Havij_Load.exe (PID: 2796)
      • Havij.exe (PID: 1336)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe (PID: 3712)
      • Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe (PID: 3700)
    • Creates files in the Windows directory

      • Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe (PID: 3700)
    • Creates files in the user directory

      • Havij.exe (PID: 1336)
    • Low-level read access rights to disk partition

      • Havij.exe (PID: 1336)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (gen) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs havij v1.16 pro portable cracked by service manual [ aore team ].exe havij v1.16 pro portable cracked by service manual [ aore team ].exe havij_load.exe no specs havij.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
700"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Havij-v1.16-Pro-Portable-_ed.7z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
1336"C:\Windows\system32\HavijPro\Havij.exe" C:\Windows\system32\HavijPro\Havij.exeHavij_Load.exe
User:
admin
Company:
ITSecTeam
Integrity Level:
HIGH
Description:
Advanced SQL Injection Tool
Exit code:
0
Version:
1.16
Modules
Images
c:\windows\system32\havijpro\havij.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2796C:\Windows\system32\HavijPro\Havij_Load.exeC:\Windows\system32\HavijPro\Havij_Load.exeHavij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\havijpro\havij_load.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
3700"C:\Users\admin\Desktop\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe" C:\Users\admin\Desktop\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\havij v1.16 pro portable cracked by service manual [ aore team ]\havij v1.16 pro portable cracked by service manual [ aore team ].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3712"C:\Users\admin\Desktop\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe" C:\Users\admin\Desktop\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\havij v1.16 pro portable cracked by service manual [ aore team ]\havij v1.16 pro portable cracked by service manual [ aore team ].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
2 093
Read events
1 471
Write events
549
Delete events
73

Modification events

(PID) Process:(700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(700) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Havij-v1.16-Pro-Portable-_ed.7z
(PID) Process:(700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
9
Suspicious files
0
Text files
7
Unknown types
2

Dropped files

PID
Process
Filename
Type
700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa700.31675\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exe
MD5:
SHA256:
3712Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exeC:\users\admin\appdata\local\temp\REG-SM-AoRE.bmpimage
MD5:618EF93D12F1C201313F3E9DF0D34C2C
SHA256:0DE8FBD0686F6434F03DCB7EF2ED622980902D495E7483105F2ABB8318C8303C
3712Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exeC:\Users\admin\AppData\Local\Temp\IRANTK.INFOexecutable
MD5:0DAB1380431FF8A5BFE52797D4240DA8
SHA256:9E5453882DF10F54E8E9F8CFDFB99D919654479665D17F589DBC3D8622C0E256
3700Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exeC:\users\admin\appdata\local\temp\REG-SM-AoRE.bmpimage
MD5:618EF93D12F1C201313F3E9DF0D34C2C
SHA256:0DE8FBD0686F6434F03DCB7EF2ED622980902D495E7483105F2ABB8318C8303C
700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa700.31675\Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ]\www.hayzia.wordpress.com.nfotext
MD5:34EE3F8F8BB6E193E2C634B4A6DCC92C
SHA256:B3D90DF2C70E3F656477D8844F929DDCE1F85F45528D281DE810A0115D1909E7
3700Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exeC:\Windows\system32\MSINET.OCXexecutable
MD5:7BEC181A21753498B6BD001C42A42722
SHA256:73DA54B69911BDD08EA8BBBD508F815EF7CFA59C4684D75C1C602252EC88EE31
3700Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exeC:\Windows\system32\Mswinsck.ocxexecutable
MD5:E8A2190A9E8EE5E5D2E0B599BBF9DDA6
SHA256:80AB0B86DE58A657956B2A293BD9957F78E37E7383C86D6CD142208C153B6311
3700Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exeC:\Windows\system32\TABCTL32.OCXexecutable
MD5:79ED276AAE03D4F62551871D8094F09A
SHA256:341D97CB88C04C4B566C82EC36D4EE1F2BCA5E31BF04D240796277CE770B56C9
3700Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exeC:\Windows\system32\comdlg32.ocxexecutable
MD5:D76F0EAB36F83A31D411AEAF70DA7396
SHA256:46F4FDB12C30742FF4607876D2F36CF432CDC7EC3D2C99097011448FC57E997C
3700Havij v1.16 Pro Portable Cracked by Service Manual [ AoRE Team ].exeC:\Users\admin\AppData\Local\Temp\IRANTK.INFOexecutable
MD5:0DAB1380431FF8A5BFE52797D4240DA8
SHA256:9E5453882DF10F54E8E9F8CFDFB99D919654479665D17F589DBC3D8622C0E256
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info