| File name: | ram-encrypthub.exe |
| Full analysis: | https://app.any.run/tasks/ab7d7b27-ac7c-4869-9184-b4558973078f |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | February 14, 2025, 11:26:41 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | CF0514B56F6498161A3AF8737D6A5CBB |
| SHA1: | 42146E9DD1BDC415B1D9B4E036812D2ECC41E70E |
| SHA256: | 06628B0447C94DD270ECAF798BD052891CDA386D504A20D439EB994004FF483C |
| SSDEEP: | 98304:rP/h/5E1SZVY4MGfjN2OaXoHITbDwCw/FerHz6HalDfs8HLqLPTpVzDrXvFaZsAQ:4REa6fZ |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:11:18 22:00:38+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit, Removable run from swap, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 14.11 |
| CodeSize: | 301568 |
| InitializedDataSize: | 160768 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2e2a6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.8.6.0 |
| ProductVersionNumber: | 3.8.6.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Caddy |
| FileDescription: | Stethoscope |
| FileVersion: | 3.8.6.0 |
| InternalName: | setup |
| LegalCopyright: | Copyright (c) Caddy. All rights reserved. |
| OriginalFileName: | autumn.exe |
| ProductName: | Stethoscope |
| ProductVersion: | 3.8.6.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 440 | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\AppCheckS.exe | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\AppCheckS.exe | ram-encrypthub.exe | ||||||||||||
User: admin Company: CheckMAL Inc. Integrity Level: MEDIUM Description: AppCheck Anti-Ransomware Service Exit code: 0 Version: 3.1.39.3 Modules
| |||||||||||||||
| 1344 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | UCPDMgr.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3364 | "C:\Users\admin\AppData\Local\Temp\ram-encrypthub.exe" | C:\Users\admin\AppData\Local\Temp\ram-encrypthub.exe | explorer.exe | ||||||||||||
User: admin Company: Caddy Integrity Level: MEDIUM Description: Stethoscope Exit code: 0 Version: 3.8.6.0 Modules
| |||||||||||||||
| 3564 | "C:\Windows\System32\svchost.exe" | C:\Windows\SysWOW64\svchost.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3816 | C:\WINDOWS\SysWOW64\explorer.exe | C:\Windows\SysWOW64\explorer.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3952 | C:\Users\admin\AppData\Roaming\MakeExploreso\AppCheckS.exe | C:\Users\admin\AppData\Roaming\MakeExploreso\AppCheckS.exe | AppCheckS.exe | ||||||||||||
User: admin Company: CheckMAL Inc. Integrity Level: MEDIUM Description: AppCheck Anti-Ransomware Service Exit code: 1 Version: 3.1.39.3 Modules
| |||||||||||||||
| 4548 | C:\WINDOWS\SysWOW64\cmd.exe | C:\Windows\SysWOW64\cmd.exe | — | AppCheckS.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5028 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5208 | "C:\Users\admin\AppData\Local\Temp\{3EE21BA6-1C3B-46A4-9C52-7D1C665E67FB}\.cr\ram-encrypthub.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\ram-encrypthub.exe" -burn.filehandle.attached=584 -burn.filehandle.self=596 | C:\Users\admin\AppData\Local\Temp\{3EE21BA6-1C3B-46A4-9C52-7D1C665E67FB}\.cr\ram-encrypthub.exe | ram-encrypthub.exe | ||||||||||||
User: admin Company: Caddy Integrity Level: MEDIUM Description: Stethoscope Exit code: 0 Version: 3.8.6.0 Modules
| |||||||||||||||
| 6088 | "C:\WINDOWS\system32\UCPDMgr.exe" | C:\Windows\System32\UCPDMgr.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: User Choice Protection Manager Exit code: 0 Version: 1.0.0.414301 Modules
| |||||||||||||||
| (PID) Process: | (3816) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\SibCode |
| Operation: | write | Name: | sn3 |
Value: 188F67EFB3FFC5659CC3338B05E0F1E7A04E9113A0E2BA8B4D81B65E560926F5A024CF6E4B16AC8DA79246E855844B09FEE5FBE321C6253BD01F53C4BDB1E44E | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4548 | cmd.exe | C:\Users\admin\AppData\Local\Temp\wdowkxwxvh | — | |
MD5:— | SHA256:— | |||
| 5208 | ram-encrypthub.exe | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\femur.mpeg | binary | |
MD5:9725902A98AABA0BFFAF37B84CD38DF5 | SHA256:3A31907E1AF868ECEF7A1491FD415A73C5306C47282F3F762621C472CD752EFF | |||
| 5208 | ram-encrypthub.exe | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\BootstrapperApplicationData.xml | xml | |
MD5:A3B870562E75ED056FB90CA879445E14 | SHA256:9648F240A31BAF83F7877F4A80899E66222EF1B7A86573D536CB8985A3DE648D | |||
| 5208 | ram-encrypthub.exe | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\invenit.dmg | binary | |
MD5:25F3EA697C8D3D0182D51970F2114E1F | SHA256:09F3F70B33ECCABD0BF6F909856198A28C9C56B2C474AF9229ADBEDAEA6348D2 | |||
| 5208 | ram-encrypthub.exe | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\mfc140u.dll | executable | |
MD5:52F8286BE04B82608C1591DC618F9DC9 | SHA256:A158913485D0FBC0C6F5A61623D6B54AADD5E50F8F084E39CB5EC472BD35EBCC | |||
| 5208 | ram-encrypthub.exe | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\msvcp140.dll | executable | |
MD5:9FF712C25312821B8AEC84C4F8782A34 | SHA256:517CD3AAC2177A357CCA6032F07AD7360EE8CA212A02DD6E1301BF6CFADE2094 | |||
| 5208 | ram-encrypthub.exe | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\vcruntime140.dll | executable | |
MD5:EDF9D5C18111D82CF10EC99F6AFA6B47 | SHA256:D89C7B863FC1AC3A179D45D5FE1B9FD35FB6FBD45171CA68D0D68AB1C1AD04FB | |||
| 3364 | ram-encrypthub.exe | C:\Users\admin\AppData\Local\Temp\{3EE21BA6-1C3B-46A4-9C52-7D1C665E67FB}\.cr\ram-encrypthub.exe | executable | |
MD5:AD8A21FCA3E5EBE3BA6A8B643B23D69E | SHA256:62D6F804FDA5ABF1D2FFABE039FF6B541CA5DBE0A4E4123DF8A2D6985FFC1DBE | |||
| 5208 | ram-encrypthub.exe | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\AppCheckS.exe | executable | |
MD5:18247442E0F9378E739F650FD51ACB4E | SHA256:A5BF40C29313EB9F0E711BEE0D63B411EF35E80BA0FBDCC5964D0539DB59290E | |||
| 5208 | ram-encrypthub.exe | C:\Users\admin\AppData\Local\Temp\{2D702A4C-D5BD-4970-87E2-A07680990056}\.ba\Homologue.dll | executable | |
MD5:406654D989DD8A573C739A8A8837BA41 | SHA256:EB833E493CE14A305B033D55EE6994B01DCFD4C3280632C227C0F1BA25545844 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5128 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5300 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5300 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6092 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5064 | SearchApp.exe | 184.86.251.9:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5064 | SearchApp.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1176 | svchost.exe | 20.190.160.67:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1076 | svchost.exe | 23.35.238.131:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
5128 | backgroundTaskHost.exe | 20.103.156.88:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |