File name:

Havij 1.152 Pro (www.pasuruanteam.blogspot.com).zip

Full analysis: https://app.any.run/tasks/8a547f00-92ed-45f1-a378-8e795000b1af
Verdict: Malicious activity
Analysis date: January 28, 2022, 21:16:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

BC6652F69A9ACFE2D608674A6F6A2340

SHA1:

FA5418D1ECCDCC04834FC6052AB68085D07AB13C

SHA256:

BEE0C95E5F8D6DB65E9665F1DFA3E658921D51C8FA408558524B5D45CE830D86

SSDEEP:

24576:xcXDgz3DjN34A3QoryCGTwSV+GhIbvtk+EEODqhGRGBS04YMjb:aXAJ9/rtGTwSfibvtfEEODqhcGB7no

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Havij.exe (PID: 2988)
      • Havij.exe (PID: 4000)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2180)
      • Havij.exe (PID: 4000)
      • Havij.exe (PID: 2988)
    • Reads mouse settings

      • Havij.exe (PID: 4000)
      • Havij.exe (PID: 2988)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2180)
    • Reads the computer name

      • WinRAR.exe (PID: 2180)
  • INFO

    • Reads Microsoft Office registry keys

      • Havij.exe (PID: 4000)
      • Havij.exe (PID: 2988)
    • Manual execution by user

      • Havij.exe (PID: 4000)
      • Havij.exe (PID: 2988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Havij 1.52 Pro (www.pasuruanteam.blogspot.com)/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2016:05:15 22:03:08
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe havij.exe no specs havij.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2180"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Havij 1.152 Pro (www.pasuruanteam.blogspot.com).zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2988"C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exe" C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exeExplorer.EXE
User:
admin
Company:
ITSecTeam
Integrity Level:
MEDIUM
Description:
Advanced SQL Injection Tool
Exit code:
0
Version:
1.152
Modules
Images
c:\users\admin\desktop\havij 1.52 pro (www.pasuruanteam.blogspot.com)\havij.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
4000"C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exe" C:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exeExplorer.EXE
User:
admin
Company:
ITSecTeam
Integrity Level:
MEDIUM
Description:
Advanced SQL Injection Tool
Exit code:
0
Version:
1.152
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\havij 1.52 pro (www.pasuruanteam.blogspot.com)\havij.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
3 306
Read events
3 276
Write events
30
Delete events
0

Modification events

(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2180) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Havij 1.152 Pro (www.pasuruanteam.blogspot.com).zip
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
4
Text files
5
Unknown types
1

Dropped files

PID
Process
Filename
Type
2180WinRAR.exeC:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\regfile.hrfbinary
MD5:
SHA256:
4000Havij.exeC:\Users\admin\AppData\Local\Temp\~DF67B40744DB84C4E4.TMPbinary
MD5:
SHA256:
2988Havij.exeC:\Users\admin\AppData\Local\Temp\~DFE02A758D8B3B997F.TMPbinary
MD5:
SHA256:
2180WinRAR.exeC:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Crack\HavijKey.licbinary
MD5:
SHA256:
2180WinRAR.exeC:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Read Me.txttext
MD5:E3D7D042587587A5DCEEFE7C6D091942
SHA256:AABEA67EBB74C80F4C7AF674E664FE28B02B8C6826FDAE13AB21D0CFDBFDB828
2180WinRAR.exeC:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\columns.txttext
MD5:F20FC2C47EB9477DC709206D0E0991ED
SHA256:EF24C1C1329C176D24A65B702F161494F5B0CC2789D0993981EBFEC9CEEE3235
2180WinRAR.exeC:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exeexecutable
MD5:
SHA256:
2180WinRAR.exeC:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Havij.exe.manifestxml
MD5:39A58DAF51A64EF74605F02E725EB62F
SHA256:38020B5EC4FCAF9402B207F53B192D2822B623930228C21188BE39B5DA40D044
2180WinRAR.exeC:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\tables.txttext
MD5:C100748489C99F000D7C9D7940C76146
SHA256:5A4B46FF5AB8018B7560F6D6D79C910F2A97F48178E5995C401C06A5E81E46A2
2180WinRAR.exeC:\Users\admin\Desktop\Havij 1.52 Pro (www.pasuruanteam.blogspot.com)\Help.chmchm
MD5:0738DE0E76BC6A1143E74CE37B1DE1C2
SHA256:11714E86D77E36F170C99F2856E3C924AC6BA962191B459844CCD0CC51B605B3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info