File name:

Havij 1.15 Pro portable.rar

Full analysis: https://app.any.run/tasks/00290183-1892-42f0-9b9a-54cf13f6e62b
Verdict: Malicious activity
Analysis date: April 06, 2021, 23:16:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

3A25F369C01BAF1B45864F5AAA0BB4CA

SHA1:

5CE3FBA699D503E1C99C54B608EE54A983020FB7

SHA256:

A4D4DE23BF4DD3502F7C74143E3E8517FF8C8D44F6EFF008BD837FE516D99911

SSDEEP:

49152:i/daSJ4CzgoCCycWAKmbS2tIYKRoeGVwPernBJP4Tk6wl+o0vF2EvvfoXe6CH6:Sda6gyWArbzqbmjL4jb9noX8H6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Havij.exe (PID: 3220)
      • Havij.exe (PID: 1296)
    • Loads dropped or rewritten executable

      • Havij.exe (PID: 3220)
      • Havij.exe (PID: 1296)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2448)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2448)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2448)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 1287
UncompressedSize: 4378
OperatingSystem: Win32
ModifyDate: 2010:11:28 15:26:02
PackingMethod: Normal
ArchivedFileName: Havij 1.15 Pro portable\admins.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe havij.exe no specs havij.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1296"C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.35016\Havij 1.15 Pro portable\Havij.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.35016\Havij 1.15 Pro portable\Havij.exeWinRAR.exe
User:
admin
Company:
ITSecTeam
Integrity Level:
MEDIUM
Description:
Advanced SQL Injection Tool
Exit code:
0
Version:
1.15
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2448.35016\havij 1.15 pro portable\havij.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa2448.35016\havij 1.15 pro portable\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
2448"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Havij 1.15 Pro portable.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3220"C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\Havij.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\Havij.exeWinRAR.exe
User:
admin
Company:
ITSecTeam
Integrity Level:
MEDIUM
Description:
Advanced SQL Injection Tool
Exit code:
0
Version:
1.15
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2448.34107\havij 1.15 pro portable\havij.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa2448.34107\havij 1.15 pro portable\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
1 355
Read events
1 334
Write events
21
Delete events
0

Modification events

(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2448) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2448) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13C\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Havij 1.15 Pro portable.rar
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2448) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13C\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
26
Suspicious files
4
Text files
14
Unknown types
2

Dropped files

PID
Process
Filename
Type
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\Instructions.txttext
MD5:
SHA256:
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\Help.chmchm
MD5:0738DE0E76BC6A1143E74CE37B1DE1C2
SHA256:11714E86D77E36F170C99F2856E3C924AC6BA962191B459844CCD0CC51B605B3
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\HavijKey.licbinary
MD5:7149E60A4205E1D01B89EABBDC305E6D
SHA256:188F8BCF84EFE1D4A36FB7F2667079DD9B1D43D84449B95C7E1050D113EF127E
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\Mscomctl.ocxexecutable
MD5:ECC7D7F0D3446DE36045D1D9E964FAFE
SHA256:BC58D624CEEA02AB086F1CCE809C992BF5A7105E88931853317A2F5AA5AFD6E4
3220Havij.exeC:\Users\admin\AppData\Local\Temp\~DF6D85BEEF4308B607.TMP
MD5:
SHA256:
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\Havij.exe.manifestxml
MD5:39A58DAF51A64EF74605F02E725EB62F
SHA256:38020B5EC4FCAF9402B207F53B192D2822B623930228C21188BE39B5DA40D044
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\olepro32.dllexecutable
MD5:CE0155405EA902797E88B92A78443AEB
SHA256:789C3C45EDA1749BD939F4A96616E1E9EF1B7DCC62A2889F65088954C64D0938
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\MSInet.ocxexecutable
MD5:7BEC181A21753498B6BD001C42A42722
SHA256:73DA54B69911BDD08EA8BBBD508F815EF7CFA59C4684D75C1C602252EC88EE31
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\asycfilt.dllexecutable
MD5:C89E401800DE62E5702E085D898EED20
SHA256:DE83C9D9203050B40C098E4143EF8F577AA90016C7A64D4F2931B57A4C43E566
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.34107\Havij 1.15 Pro portable\regfile.hrfbinary
MD5:7149E60A4205E1D01B89EABBDC305E6D
SHA256:188F8BCF84EFE1D4A36FB7F2667079DD9B1D43D84449B95C7E1050D113EF127E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info