| File name: | setup_patched.exe |
| Full analysis: | https://app.any.run/tasks/1c4d8449-1d3b-4542-8541-e71b5b2112b5 |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | February 02, 2025, 13:35:28 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | B1D0967E89F541867EFB959FBBD5414B |
| SHA1: | 98FB60C47346F8227DE2797FCC880E2CA3958A88 |
| SHA256: | 56289D2E99A99BED4E7F9CD723BB7F34AB69EE1EC7B2A5E939EE2B6DF8F59EDF |
| SSDEEP: | 98304:lXWUUIbs2WTNn5izRF6tD7oDiMKpPsZ4rXYCWTOglHMOE6q9Xh0jibLxNMJSgs7G:Mn/6UmF1urXjRk |
| .exe | | | Win32 Executable (generic) (3.6) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (1.6) |
| .exe | | | DOS Executable Generic (1.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:10:09 10:16:11+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 2074624 |
| InitializedDataSize: | 7549952 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1c3f15 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.2.0.1 |
| ProductVersionNumber: | 2.2.0.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (British) |
| CharacterSet: | Unicode |
| CompanyName: | Stardock Software |
| FileDescription: | Stardock Groupy 2 Configuration Utility |
| FileVersion: | 2.2.0.1 |
| InternalName: | GroupyConfig.exe |
| LegalCopyright: | Copyright (C) 2024 Stardock Software, Inc |
| OriginalFileName: | GroupyConfig.EXE |
| ProductName: | Stardock Groupy 2 |
| ProductVersion: | 2.2.0.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2084 | "C:\Users\admin\AppData\Local\Temp\287W3EORHA3YMK8TUQY6CAA\iTunesHelper.exe" | C:\Users\admin\AppData\Local\Temp\287W3EORHA3YMK8TUQY6CAA\iTunesHelper.exe | setup_patched.exe | ||||||||||||
User: admin Company: Apple Inc. Integrity Level: MEDIUM Description: iTunesHelper Exit code: 0 Version: 12.12.9.4 Modules
| |||||||||||||||
| 2164 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | more.com | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2192 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2436 | C:\WINDOWS\SysWOW64\more.com | C:\Windows\SysWOW64\more.com | iTunesHelper.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: More Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4520 | "C:\ProgramData\MsiSleuth\iTunesHelper.exe" | C:\ProgramData\MsiSleuth\iTunesHelper.exe | dllhost.exe | ||||||||||||
User: admin Company: Apple Inc. Integrity Level: HIGH Description: iTunesHelper Exit code: 1 Version: 12.12.9.4 Modules
| |||||||||||||||
| 4672 | C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7} | C:\Windows\SysWOW64\dllhost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4876 | C:\Users\admin\AppData\Local\Temp\updater.exe | C:\Users\admin\AppData\Local\Temp\updater.exe | more.com | ||||||||||||
User: admin Company: Caphyon Integrity Level: HIGH Description: updater 18.0 Version: 18.0 Modules
| |||||||||||||||
| 5208 | C:\ProgramData\MsiSleuth\iTunesHelper.exe | C:\ProgramData\MsiSleuth\iTunesHelper.exe | iTunesHelper.exe | ||||||||||||
User: admin Company: Apple Inc. Integrity Level: MEDIUM Description: iTunesHelper Exit code: 1 Version: 12.12.9.4 Modules
| |||||||||||||||
| 5752 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | more.com | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6092 | C:\WINDOWS\SysWOW64\more.com | C:\Windows\SysWOW64\more.com | — | iTunesHelper.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: More Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4672) dllhost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6376 | setup_patched.exe | C:\Users\admin\AppData\Local\Temp\287W3EORHA3YMK8TUQY6CAA\protozoa.m4a | — | |
MD5:— | SHA256:— | |||
| 6376 | setup_patched.exe | C:\Users\admin\AppData\Local\Temp\287W3EORHA3YMK8TUQY6CAA\CoreFoundation.dll | — | |
MD5:— | SHA256:— | |||
| 2084 | iTunesHelper.exe | C:\ProgramData\MsiSleuth\CoreFoundation.dll | — | |
MD5:— | SHA256:— | |||
| 6376 | setup_patched.exe | C:\Users\admin\AppData\Local\Temp\287W3EORHA3YMK8TUQY6CAA\signore.mkv | binary | |
MD5:904A594A59455B6F2D989FB74AAF50E1 | SHA256:B7D814A774BE4BACE56B4518C88360C87CBC73F807FC43BFB7474ABCD16CE4F0 | |||
| 6376 | setup_patched.exe | C:\Users\admin\AppData\Local\Temp\287W3EORHA3YMK8TUQY6CAA\msvcp140.dll | executable | |
MD5:1BA6D1CF0508775096F9E121A24E5863 | SHA256:74892D9B4028C05DEBAF0B9B5D9DC6D22F7956FA7D7EEE00C681318C26792823 | |||
| 6376 | setup_patched.exe | C:\Users\admin\AppData\Local\Temp\287W3EORHA3YMK8TUQY6CAA\libicuuc.dll | executable | |
MD5:1A55F550A35ABA7D2404D4BED761B370 | SHA256:B1B6301A654092E26A35B777D58ACF08F9CD6BEE554A0BBF3E94B6E1A2B2CBCB | |||
| 2084 | iTunesHelper.exe | C:\ProgramData\MsiSleuth\protozoa.m4a | — | |
MD5:— | SHA256:— | |||
| 5208 | iTunesHelper.exe | C:\Users\admin\AppData\Local\Temp\189c7c64 | — | |
MD5:— | SHA256:— | |||
| 4520 | iTunesHelper.exe | C:\Users\admin\AppData\Local\Temp\1deb912d | — | |
MD5:— | SHA256:— | |||
| 2436 | more.com | C:\Users\admin\AppData\Local\Temp\paiedicaxeqb | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
488 | svchost.exe | GET | 200 | 2.16.164.130:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.130:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
488 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
2380 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
7128 | SIHClient.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7128 | SIHClient.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5064 | SearchApp.exe | 2.21.65.153:443 | www.bing.com | Akamai International B.V. | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.16.164.130:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
488 | svchost.exe | 2.16.164.130:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
488 | svchost.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 20.106.86.13:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1176 | svchost.exe | 20.190.159.73:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1176 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
thingspouter.top |
| unknown |
clammypunero.com |
| malicious |
settings-win.data.microsoft.com |
| whitelisted |
cegu.shop |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2192 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
2192 | svchost.exe | Potentially Bad Traffic | SUSPICIOUS [ANY.RUN] Suspected Malicious domain by CrossDomain ( .servicelandingkaraoke .shop) |