File name:

fxcloud.exe

Full analysis: https://app.any.run/tasks/6d5bc364-fb77-4ac1-8d6d-ad2432f6595e
Verdict: Malicious activity
Threats:

HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses.

Analysis date: June 13, 2024, 17:31:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
hijackloader
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DAAFF76B0BAF0A1F9CEC253560C5DB20

SHA1:

0311CF0EEB4BEDDD2C69C6E97462595313A41E78

SHA256:

5706C6F5421A6A34FDCB67E9C9E71283C8FC1C33499904519CBDC6A21E6B071C

SSDEEP:

98304:AuM/GMqG9owyahi7VNgMcr50y4IRNmV/S3jqA4xIdR37DkMhRb39H+KtA:A9p7+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fxcloud.exe (PID: 3968)
    • HIJACKLOADER has been detected (YARA)

      • fxcloud.exe (PID: 3968)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • fxcloud.exe (PID: 3968)
    • Reads the computer name

      • fxcloud.exe (PID: 3968)
    • Create files in a temporary directory

      • fxcloud.exe (PID: 3968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:25 05:40:53+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 987648
InitializedDataSize: 1371136
UninitializedDataSize: -
EntryPoint: 0xd6308
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #HIJACKLOADER fxcloud.exe

Process information

PID
CMD
Path
Indicators
Parent process
3968"C:\Users\admin\AppData\Local\Temp\fxcloud.exe" C:\Users\admin\AppData\Local\Temp\fxcloud.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\fxcloud.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
22
Read events
22
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3968fxcloud.exeC:\Users\admin\AppData\Local\Temp\e250dcf9image
MD5:C62F812E250409FBD3C78141984270F2
SHA256:D8617477C800CC10F9B52E90B885117A27266831FB5033647B6B6BD6025380A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info