File name:

SQLi Dumper v10.3.zip

Full analysis: https://app.any.run/tasks/5b068f3b-9d48-44e7-857d-7b8dd88ab401
Verdict: Malicious activity
Analysis date: February 24, 2024, 16:46:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

253C3BA262A7B7AA1422D8D24A24990C

SHA1:

06DDAEA151186535EA6C6B3AF690900A0CF9C4B4

SHA256:

8F780D91890051F43BB7826EEC18A029EEB9F0D59D37E1B135AAB104FCA767B1

SSDEEP:

98304:SWV+s8ccCta2fXNdTJvNY7q8DvAQMzbsGXOrNZ7fCjv9O//pRmQJf+tP82QEABHR:iOwv2x2z/3ANdbxsMk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 4052)
      • SQLi Dumper 10.3 Cracked.exe (PID: 2852)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • SQLi Dumper 10.3 Cracked.exe (PID: 2852)
      • SQLi Dumper 10.3 Cracked.exe (PID: 3940)
    • Executable content was dropped or overwritten

      • SQLi Dumper 10.3 Cracked.exe (PID: 2852)
    • Reads the Internet Settings

      • SQLi Dumper 10.3 Cracked.exe (PID: 2852)
      • SQLi Dumper 10.3 Cracked.exe (PID: 3940)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4052)
    • Reads the computer name

      • SQLi Dumper 10.3 Cracked.exe (PID: 2852)
      • dw20.exe (PID: 3848)
      • SQLi Dumper 10.3 Cracked.exe (PID: 3940)
      • dw20.exe (PID: 2420)
    • Manual execution by a user

      • SQLi Dumper 10.3 Cracked.exe (PID: 2852)
      • SQLi Dumper 10.3 Cracked.exe (PID: 2340)
      • SQLi Dumper 10.3 Cracked.exe (PID: 3940)
    • Create files in a temporary directory

      • SQLi Dumper 10.3 Cracked.exe (PID: 3940)
      • SQLi Dumper 10.3 Cracked.exe (PID: 2852)
    • Checks supported languages

      • SQLi Dumper 10.3 Cracked.exe (PID: 3940)
      • SQLi Dumper 10.3 Cracked.exe (PID: 2852)
      • dw20.exe (PID: 3848)
      • dw20.exe (PID: 2420)
    • Reads the machine GUID from the registry

      • dw20.exe (PID: 3848)
      • dw20.exe (PID: 2420)
    • Creates files or folders in the user directory

      • dw20.exe (PID: 3848)
    • Creates files in the program directory

      • dw20.exe (PID: 2420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2022:07:22 14:47:26
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: SQLi Dumper v10.3/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe sqli dumper 10.3 cracked.exe dw20.exe no specs sqli dumper 10.3 cracked.exe no specs sqli dumper 10.3 cracked.exe dw20.exe

Process information

PID
CMD
Path
Indicators
Parent process
2340"C:\Users\admin\Desktop\SQLi Dumper v10.3\SQLi Dumper 10.3 Cracked.exe" C:\Users\admin\Desktop\SQLi Dumper v10.3\SQLi Dumper 10.3 Cracked.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\sqli dumper v10.3\sqli dumper 10.3 cracked.exe
c:\windows\system32\ntdll.dll
2420dw20.exe -x -s 828C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe
SQLi Dumper 10.3 Cracked.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Error Reporting Shim
Exit code:
0
Version:
2.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2852"C:\Users\admin\Desktop\SQLi Dumper v10.3\SQLi Dumper 10.3 Cracked.exe" C:\Users\admin\Desktop\SQLi Dumper v10.3\SQLi Dumper 10.3 Cracked.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
3762507597
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\sqli dumper v10.3\sqli dumper 10.3 cracked.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3848dw20.exe -x -s 740C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exeSQLi Dumper 10.3 Cracked.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Error Reporting Shim
Exit code:
0
Version:
2.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
3940"C:\Users\admin\Desktop\SQLi Dumper v10.3\SQLi Dumper 10.3 Cracked.exe" C:\Users\admin\Desktop\SQLi Dumper v10.3\SQLi Dumper 10.3 Cracked.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Exit code:
3762507597
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\sqli dumper v10.3\sqli dumper 10.3 cracked.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
4052"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SQLi Dumper v10.3.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
10 007
Read events
9 965
Write events
42
Delete events
0

Modification events

(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4052) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SQLi Dumper v10.3.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
5
Suspicious files
0
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
3848dw20.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_sqli dumper 10.3_2c623545e7a3487168374ef469b5382c52679cfd_0f10313c\Report.wer
MD5:
SHA256:
2420dw20.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_sqli dumper 10.3_2c623545e7a3487168374ef469b5382c52679cfd_096c5b79\Report.wer
MD5:
SHA256:
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4052.19879\SQLi Dumper v10.3\LNG\Persian.xmlxml
MD5:6BDC041287825A04B67895BB9111806C
SHA256:B947F3E9558296EEAEE767FFBF1CE4270DEFF8DBA8BC57EF648E1E86A1D55FB3
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4052.19879\SQLi Dumper v10.3\LNG\German.xmlxml
MD5:4A25B19B26DEF334C719E8D543F23486
SHA256:97BB355062589C2C89E139E8174B71A15FBE89F10E2C72DE1489AD3B9B035B91
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4052.19879\SQLi Dumper v10.3\SkinSoft.VisualStyler.dllexecutable
MD5:D93366374B57B5A0FE3A1A8A1CA95F78
SHA256:14F231441DAD16EF046AB97415C33195056A61B0240D7D890971E5F626068925
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4052.19879\SQLi Dumper v10.3\LNG\Russian.xmlxml
MD5:4C3341A7BFC47F68E779A50F9E669900
SHA256:72515A8F2B7A29FC06E3A8FFD28D3D0DEA9E98D00CD9EB7B941703F7A3AFAB3E
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4052.19879\SQLi Dumper v10.3\LNG\French.xmlxml
MD5:A46FDB87ECF4E654CAC6348C542A6D2C
SHA256:A4A5086AB9BFC8755F199B0F1C80F70EBF660768D031727BF71A624FBF99D2D9
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4052.19879\SQLi Dumper v10.3\LNG\Portuguese.xmlxml
MD5:E1B7540D846CA89F57DE64305B94DBC9
SHA256:F6CDC1E33C9F9637B56FDAAB6AD47C8E72E9F384A9CFC9C2B356825C62531DCB
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4052.19879\SQLi Dumper v10.3\ChilkatDotNet46.dllexecutable
MD5:C347B978DB64C5B0922FDB620A30A757
SHA256:FA3A167968BE8ADFD68B88BF303EFC8F71E895366BF9297679988549534A8895
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4052.19879\SQLi Dumper v10.3\Settings.xmlxml
MD5:75A5096A8D55E17102DF4580D915D6EE
SHA256:84EF09FA32AA6C8E1171ED02EF98B2F3FCB64BDA620E74BCBC9B4B4969038457
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

No threats detected
Process
Message
SQLi Dumper 10.3 Cracked.exe
FTH: (3940): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
dw20.exe
FTH: (2420): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***