File name:

GDI-Trojan.Win32.Lixo-by-ArTicZera-main.zip

Full analysis: https://app.any.run/tasks/73bc7807-9685-4c39-88d5-fd32f39179ae
Verdict: Malicious activity
Analysis date: October 20, 2023, 01:20:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

B41F41DFC34CC8BDC2525044760D6E2E

SHA1:

07DB32C6C2D6AA20A05C15F43CEC70FA1AC2EFD1

SHA256:

065CFAD474B90DD23E333B653D26CEBDE762D6B19CA051CCE0B4157D3924667B

SSDEEP:

6144:Nb7L6O9rw202W2TcUpVCEjfLya35qQB2bqC2yRlhvB+ILuZvuzB:NWwI2IUpVzj135qoQhvtuZvuN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Lixo.exe (PID: 2436)
      • Lixo.exe (PID: 3888)
      • Lixo.exe (PID: 2812)
      • Lixo.exe (PID: 3092)
      • Lixo.exe (PID: 1560)
    • Creates a writable file the system directory

      • Lixo.exe (PID: 3092)
    • Drops the executable file immediately after the start

      • Lixo.exe (PID: 3092)
  • SUSPICIOUS

    • Changes the title of the Internet Explorer window

      • Lixo.exe (PID: 3888)
      • Lixo.exe (PID: 1560)
      • Lixo.exe (PID: 3092)
    • Changes the Home page of Internet Explorer

      • Lixo.exe (PID: 3888)
      • Lixo.exe (PID: 3092)
      • Lixo.exe (PID: 1560)
  • INFO

    • Manual execution by a user

      • Lixo.exe (PID: 2436)
      • notepad.exe (PID: 328)
      • Lixo.exe (PID: 1560)
      • Lixo.exe (PID: 3888)
      • Lixo.exe (PID: 3092)
      • Lixo.exe (PID: 2812)
    • Checks supported languages

      • Lixo.exe (PID: 2436)
      • Lixo.exe (PID: 3888)
      • Lixo.exe (PID: 3092)
      • Lixo.exe (PID: 1560)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1240)
    • Reads the computer name

      • Lixo.exe (PID: 3888)
      • Lixo.exe (PID: 1560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: GDI-Trojan.Win32.Lixo-by-ArTicZera-main/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2023:04:02 09:48:20
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
7
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs lixo.exe lixo.exe notepad.exe no specs lixo.exe no specs lixo.exe lixo.exe

Process information

PID
CMD
Path
Indicators
Parent process
328"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\references.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\notepad.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1240"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1560"C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Lixo.exe" C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Lixo.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\gdi-trojan.win32.lixo-by-articzera-main\lixo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
2436"C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Lixo.exe" C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Lixo.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\users\admin\desktop\gdi-trojan.win32.lixo-by-articzera-main\lixo.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2812"C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Lixo.exe" C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Lixo.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\gdi-trojan.win32.lixo-by-articzera-main\lixo.exe
c:\windows\system32\ntdll.dll
3092"C:\Users\admin\Desktop\Lixo.exe" C:\Users\admin\Desktop\Lixo.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\lixo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
3888"C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Lixo.exe" C:\Users\admin\Desktop\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Lixo.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225477
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\gdi-trojan.win32.lixo-by-articzera-main\lixo.exe
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
Total events
1 043
Read events
1 021
Write events
22
Delete events
0

Modification events

(PID) Process:(1240) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(1240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
4
Suspicious files
1
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
1240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1240.36781\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\README.mdtext
MD5:00B056AB440229D74B56A645C224D92C
SHA256:0EE220EF7A553757A34D1068C6D95176806F8E9C0588386608BD082AF2FE9D0E
1240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1240.36781\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Source\Payloads.htext
MD5:84029441B2E6B03ABD071CD6AA34C981
SHA256:62A630137309A1DC00825959346113D87313BA9126CFC5BC519A62A62DC94168
1240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1240.36781\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Lixo.exeexecutable
MD5:7D538A430EB4E0BFD7671B921A8B76A1
SHA256:3A4EA5E72E50BCBA550EFA034818F35785076ADB37AF4C1CEE9374FE9E013EC1
1240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1240.36781\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Source\MBR\boot.imgbinary
MD5:4933409B08777DFC4625B8FEAA064756
SHA256:25DF4BE6DC6F4FD33395C0402C66DEAC2F5E73306F41CD8B933D2BAC761977F9
1240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1240.36781\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Source\TrashIcon.icoimage
MD5:BBF4ECA4D6280C4002B90B5579CA5A5C
SHA256:99A2F84625201EB7754B60A57BE24FB296CA7CB1112A1D2705C5411E07AF9157
1240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1240.36781\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Source\Colors.htext
MD5:0759108493562685003EF8F249E984FD
SHA256:CDF205F1E0B75DCC957B5915983DBAA7A93E351D7C4B218DC74CCD78F781E21C
1240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1240.36781\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Source\Lixo.htext
MD5:0E14049E3905BC8490A5E91121FB6D22
SHA256:3046DF1910BF0E72ECEA24E997E80A5F6EBD8D307D2E61013ED70ED24CAA5233
3092Lixo.exeC:\Windows\calc.exeexecutable
MD5:7D538A430EB4E0BFD7671B921A8B76A1
SHA256:3A4EA5E72E50BCBA550EFA034818F35785076ADB37AF4C1CEE9374FE9E013EC1
1240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1240.36781\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Source\System.htext
MD5:682B7341EDE5F26CB4129009163A6206
SHA256:DA969B18C27DE806128EEAED67440F6DFA2259D92E27EF6AFD0E6A7FBC118839
1240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1240.36781\GDI-Trojan.Win32.Lixo-by-ArTicZera-main\Source\main.cpptext
MD5:BFC078BFB6709F6A2F99D77CCF9F272F
SHA256:F203AE626CB2A7FBCD1332C794A6AA94D4D1F298F8FE349C64EDC1C46DF0122C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info