| URL: | https://www.heidisql.com |
| Full analysis: | https://app.any.run/tasks/8516cbcd-09c5-4b0a-b919-5edc3c41f97e |
| Verdict: | Malicious activity |
| Analysis date: | March 11, 2024, 00:20:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 17B713AFA71C447E44AE4463F98AE20F |
| SHA1: | 0CEABDE7F2F1CD7B5091CBFB6E52294C7676D218 |
| SHA256: | FCAAF8816095D0A5B49E5577CCF28A4665DE73A93D43406804AD94140DA18D2C |
| SSDEEP: | 3:N8DSLCWZT:2OLVZT |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 240 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\HeidiSQL_12.6.0.6765_Setup.exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\HeidiSQL_12.6.0.6765_Setup.exe | iexplore.exe | ||||||||||||
User: admin Company: Ansgar Becker Integrity Level: MEDIUM Description: HeidiSQL Setup Exit code: 0 Version: 12.6.0.6765 Modules
| |||||||||||||||
| 1860 | "C:\Users\admin\AppData\Local\Temp\is-36K9E.tmp\HeidiSQL_12.6.0.6765_Setup.tmp" /SL5="$160138,41713096,893952,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\HeidiSQL_12.6.0.6765_Setup.exe" | C:\Users\admin\AppData\Local\Temp\is-36K9E.tmp\HeidiSQL_12.6.0.6765_Setup.tmp | HeidiSQL_12.6.0.6765_Setup.exe | ||||||||||||
User: admin Company: Ansgar Becker Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2060 | "C:\Users\admin\AppData\Local\Programs\HeidiSQL\VC_redist.x86.exe" /q /norestart /q:a /c:"VC_RED~1.EXE /q:a /c:""msiexec /i vcredist.msi /qn"" " | C:\Users\admin\AppData\Local\Programs\HeidiSQL\VC_redist.x86.exe | HeidiSQL_12.6.0.6765_Setup.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29914 Exit code: 1638 Version: 14.28.29914.0 Modules
| |||||||||||||||
| 2100 | "C:\Users\admin\AppData\Local\Temp\{C8561273-6980-4AD5-9BE8-79EF7F30CAA5}\.cr\VC_redist.x86.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Programs\HeidiSQL\VC_redist.x86.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 /q /norestart /q:a /c:"VC_RED~1.EXE /q:a /c:""msiexec /i vcredist.msi /qn"" " | C:\Users\admin\AppData\Local\Temp\{C8561273-6980-4AD5-9BE8-79EF7F30CAA5}\.cr\VC_redist.x86.exe | VC_redist.x86.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29914 Exit code: 1638 Version: 14.28.29914.0 Modules
| |||||||||||||||
| 2920 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3700 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2968 | "C:\Users\admin\AppData\Local\Programs\HeidiSQL\heidisql.exe" | C:\Users\admin\AppData\Local\Programs\HeidiSQL\heidisql.exe | HeidiSQL_12.6.0.6765_Setup.tmp | ||||||||||||
User: admin Integrity Level: MEDIUM Description: HeidiSQL 12.6.0.6765 32 Bit Exit code: 0 Modules
| |||||||||||||||
| 3700 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://www.heidisql.com" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: 24864912 | |||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31093578 | |||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 325028662 | |||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31093578 | |||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3700) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2920 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:B743B3CAFF59ED593602C1CD1BBC79B3 | SHA256:793047C8A0AC8B52E347FE69790C2C76A623642B6CE6C298693BD462DE094C1B | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\84AFE219AEC53B0C9251F5E19EF019BD_2C9D5E6D83DF507CBE6C15521D5D3562 | binary | |
MD5:0888EFAC98996FC4BECE3A142FDF77B7 | SHA256:3EA4561E588D1E49F000899458CC3C14BF7DE37F6A9CE05B81110931F75CFB23 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\84AFE219AEC53B0C9251F5E19EF019BD_2C9D5E6D83DF507CBE6C15521D5D3562 | der | |
MD5:EDA45DFE3932BF8661CFB3E41B5BB789 | SHA256:AAF6A74785C2CA4B49BEDD454B8950F8C02FEDC185D6C8BFC3C155EA56E44027 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E41285A173160E7DDF7CF1AD9E6968C2_848781681684DA374D15312DACB4A3F1 | binary | |
MD5:602797227D192DEF56D1D52761AC15E7 | SHA256:85826CA128A17E464402C9E5482E22244E8E9536BE1CDBC59E37675B272B07D6 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\7JONOM7H.htm | html | |
MD5:CA53CB6C57F63BE76A0101590FDDE077 | SHA256:6A1FD98176299B0269320F2E45C65D1D00DA776C052C3D9ABF634CABA86D485E | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\instagram-icon[1].png | image | |
MD5:52F8A980DDF262F8A5A64E2E2C7F51A5 | SHA256:E44F07283830D60A2FFF2B541998C002AC0427B2106B2127D4E2CC86E234398E | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\facebook-icon[1].png | image | |
MD5:AB52461DF9FBAF75FAC2F3DBEB427E5D | SHA256:C2F95EB22E656D3451B76FF63CAF80D4889D5F6A76F30876667C09243421F66A | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\create_db[1].png | image | |
MD5:CD1BCFF80D340698B5A10D685ABBDB41 | SHA256:232B3F1C681B426D4B757589537EAC2D0BED1A75AF59BC204D7EFE11F9744853 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\embarcadero-rad-studio[1].png | image | |
MD5:4ED8DF16D76FE04EA1D39D72B9568B7B | SHA256:3C7A85DEC3DB3D9B8660FC18DD79CEEF744FC7671919EAF75DB96124EEF2F30F | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\server-mariadb[1].png | image | |
MD5:0E43377168F7005C48DEA8EE79516470 | SHA256:FAEB7E795C1C94943127C0D97425E8B5335E51FE016EB1A66B9CD302A491259A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2920 | iexplore.exe | GET | 304 | 92.123.48.145:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?545e1839169dd0e6 | unknown | — | — | unknown |
2920 | iexplore.exe | GET | 304 | 92.122.225.235:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f78d505714a595e3 | unknown | — | — | unknown |
2920 | iexplore.exe | GET | 200 | 192.124.249.23:80 | http://ocsp.starfieldtech.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQUwPiEZQ6%2FsVZNPaFToNfxx8ZwqAQUfAwyH6fZMH%2FEfWijYqihzqsHWycCAQc%3D | unknown | binary | 2.05 Kb | unknown |
2920 | iexplore.exe | GET | 200 | 192.124.249.23:80 | http://ocsp.starfieldtech.com//MEkwRzBFMEMwQTAJBgUrDgMCGgUABBT1ZqtwV0O1KcYi0gdzcFkHM%2BuArAQUJUWBaFAmOD07LSy%2BzWrZtj2zZmMCCF7FjMX8rTw9 | unknown | binary | 2.10 Kb | unknown |
2920 | iexplore.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D | unknown | binary | 1.42 Kb | unknown |
2920 | iexplore.exe | GET | 200 | 142.250.186.99:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | unknown |
2920 | iexplore.exe | GET | 200 | 142.250.186.99:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | binary | 724 b | unknown |
2920 | iexplore.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd | unknown | binary | 978 b | unknown |
2920 | iexplore.exe | GET | 200 | 142.250.186.99:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQC%2BP0iGO7o7nQoIudW3BwdU | unknown | binary | 472 b | unknown |
2920 | iexplore.exe | GET | 200 | 142.250.186.99:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDbVdzMVsELUBBnL7Zp8PpU | unknown | binary | 472 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2920 | iexplore.exe | 5.175.26.196:443 | www.heidisql.com | Host Europe GmbH | FR | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2920 | iexplore.exe | 92.122.225.235:80 | ctldl.windowsupdate.com | TELECOM ITALIA SPARKLE S.p.A. | IT | unknown |
2920 | iexplore.exe | 92.123.48.145:80 | ctldl.windowsupdate.com | TELECOM ITALIA SPARKLE S.p.A. | IT | unknown |
2920 | iexplore.exe | 192.124.249.23:80 | ocsp.starfieldtech.com | SUCURI-SEC | US | unknown |
2920 | iexplore.exe | 142.250.185.68:443 | www.google.com | GOOGLE | US | whitelisted |
2920 | iexplore.exe | 192.0.73.2:443 | www.gravatar.com | AUTOMATTIC | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.heidisql.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.starfieldtech.com |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
www.google.com |
| whitelisted |
www.gravatar.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
www.gstatic.com |
| whitelisted |