| File name: | CITACION DEMANDA JUDICIAL (1).zip |
| Full analysis: | https://app.any.run/tasks/7eee754a-9794-4b2f-9bb1-0756da583f7a |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | April 26, 2024, 14:58:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 108ADDBED9D017E1665DBAFA3654B837 |
| SHA1: | C1E77A5E22A4C1CAE9EC2E3AECF4B831D04701DC |
| SHA256: | 06D966537F2236E4ECC8F4BA62070398980CF42D74971B47D0018DD8089C3A15 |
| SSDEEP: | 98304:DUlYv0PHyFqg57anKGzBoIY02RCMzK5v4Fcq+OGw6SA8hDjnn1Udl6F3ZKcymmTV:3K/x |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:04:22 11:06:36 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | CITACION DEMANDA JUDICIAL/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3976 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CITACION DEMANDA JUDICIAL (1).zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 4064 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\01 CITACION DEMANDA.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\01 CITACION DEMANDA.exe | WinRAR.exe | ||||||||||||
User: admin Company: VMware, Inc. Integrity Level: MEDIUM Description: VMware Tools Core Service Exit code: 3221225477 Version: 10.0.12.325 Modules
| |||||||||||||||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\CITACION DEMANDA JUDICIAL (1).zip | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\iconv.dll | executable | |
MD5:862DFC9BF209A46D6F4874614A6631CC | SHA256:84538F1AACEBF9DAAD9FDB856611AB3D98A6D71C9EC79A8250EEE694D2652A8B | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\gthread-2.0.dll | executable | |
MD5:78CF6611F6928A64B03A57FE218C3CD4 | SHA256:DBAAD965702B89C371462E735DD925C694EDA8D8557B280F7264BBA992C0E698 | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\glib-2.0.dll | executable | |
MD5:3E7CD1D2B1BDEE2E417E928DABBA5098 | SHA256:723EE58A96214EF72018467196F168C021E3B20D08A2299D1994AA4912E4012A | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\gobject-2.0.dll | executable | |
MD5:24A7A712160ABC3F23F7410B18DE85B8 | SHA256:78DD76027E10C17824978DB821777FCAA58D7CD5D5EB9D80D6EE817E26B18AB8 | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\vmtools.dll | executable | |
MD5:65C3C2A741838474A592679CDA346753 | SHA256:4E5F2C54D9ECFE48999EDFCCE0DE038948F8B20FF68E299C55D9A2D6F65713E8 | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\gmodule-2.0.dll | executable | |
MD5:B0A421B1534F3194132EC091780472D8 | SHA256:2D6BC34B38BC0ABF0C5E2F40E2513B4DF47AF57848534E011A76D4E974AD958B | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\01 CITACION DEMANDA.exe | executable | |
MD5:AE224C5E196FF381836C9E95DEEBB7D5 | SHA256:BF933CCF86C55FC328E343B55DBF2E8EBD528E8A0A54F8F659CD0D4B4F261F26 | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\intl.dll | executable | |
MD5:D1A21E38593FDDBA8E51ED6BF7ACF404 | SHA256:6A64C9CB0904ED48CE0D5CDA137FCFD6DD463D84681436CA647B195AA2038A7E | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3976.35616\CITACION DEMANDA JUDICIAL\peso.html | binary | |
MD5:4CDCB5684BF00CD2CF2ADDDF97E3E982 | SHA256:B9D6261970BFDE1E5E8830C0C6F03286B064732F4C0C9FA9E2BDE8EFAA79ACB4 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |