| File name: | Havij 1.152 Pro (www.pasuruanteam.blogspot.com).zip |
| Full analysis: | https://app.any.run/tasks/8a547f00-92ed-45f1-a378-8e795000b1af |
| Verdict: | Malicious activity |
| Analysis date: | January 28, 2022, 21:16:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | BC6652F69A9ACFE2D608674A6F6A2340 |
| SHA1: | FA5418D1ECCDCC04834FC6052AB68085D07AB13C |
| SHA256: | BEE0C95E5F8D6DB65E9665F1DFA3E658921D51C8FA408558524B5D45CE830D86 |
| SSDEEP: | 24576:xcXDgz3DjN34A3QoryCGTwSV+GhIbvtk+EEODqhGRGBS04YMjb:aXAJ9/rtGTwSfibvtfEEODqhcGB7no |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Havij 1.52 Pro (www.pasuruanteam.blogspot.com)/ |
|---|---|
| ZipUncompressedSize: | - |
| ZipCompressedSize: | - |
| ZipCRC: | 0x00000000 |
| ZipModifyDate: | 2016:05:15 22:03:08 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2180 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Havij 1.152 Pro (www.pasuruanteam.blogspot.com).zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2988 | "C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exe" | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exe | — | Explorer.EXE | |||||||||||
User: admin Company: ITSecTeam Integrity Level: MEDIUM Description: Advanced SQL Injection Tool Exit code: 0 Version: 1.152 Modules
| |||||||||||||||
| 4000 | "C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exe" | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exe | — | Explorer.EXE | |||||||||||
User: admin Company: ITSecTeam Integrity Level: MEDIUM Description: Advanced SQL Injection Tool Exit code: 0 Version: 1.152 Modules
| |||||||||||||||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Havij 1.152 Pro (www.pasuruanteam.blogspot.com).zip | |||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2180) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2180 | WinRAR.exe | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\regfile.hrf | binary | |
MD5:— | SHA256:— | |||
| 4000 | Havij.exe | C:\Users\admin\AppData\Local\Temp\~DF67B40744DB84C4E4.TMP | binary | |
MD5:— | SHA256:— | |||
| 2988 | Havij.exe | C:\Users\admin\AppData\Local\Temp\~DFE02A758D8B3B997F.TMP | binary | |
MD5:— | SHA256:— | |||
| 2180 | WinRAR.exe | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Crack\HavijKey.lic | binary | |
MD5:— | SHA256:— | |||
| 2180 | WinRAR.exe | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Read Me.txt | text | |
MD5:E3D7D042587587A5DCEEFE7C6D091942 | SHA256:AABEA67EBB74C80F4C7AF674E664FE28B02B8C6826FDAE13AB21D0CFDBFDB828 | |||
| 2180 | WinRAR.exe | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\columns.txt | text | |
MD5:F20FC2C47EB9477DC709206D0E0991ED | SHA256:EF24C1C1329C176D24A65B702F161494F5B0CC2789D0993981EBFEC9CEEE3235 | |||
| 2180 | WinRAR.exe | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exe | executable | |
MD5:— | SHA256:— | |||
| 2180 | WinRAR.exe | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exe.manifest | xml | |
MD5:39A58DAF51A64EF74605F02E725EB62F | SHA256:38020B5EC4FCAF9402B207F53B192D2822B623930228C21188BE39B5DA40D044 | |||
| 2180 | WinRAR.exe | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\tables.txt | text | |
MD5:C100748489C99F000D7C9D7940C76146 | SHA256:5A4B46FF5AB8018B7560F6D6D79C910F2A97F48178E5995C401C06A5E81E46A2 | |||
| 2180 | WinRAR.exe | C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Help.chm | chm | |
MD5:0738DE0E76BC6A1143E74CE37B1DE1C2 | SHA256:11714E86D77E36F170C99F2856E3C924AC6BA962191B459844CCD0CC51B605B3 | |||