| URL: | https://sunmd5.com/dksds/check |
| Full analysis: | https://app.any.run/tasks/a3c58e4c-f63b-42b5-bfcf-4d3c193a56d0 |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | October 23, 2023, 20:07:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| SHA1: | 104749872830AA5F48C884737B5E32740D80E33B |
| SHA256: | 60175D2B287BE5BB398DA0F0063F217004ADC96CED935A713E7585F92EA9C183 |
| SSDEEP: | 3:N8d8WBOGNG1O:2GZ8GE |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1000 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2856.20798\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2856.20798\Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Company: VideoLAN Integrity Level: MEDIUM Description: VLC media player Exit code: 1 Version: 3.0.18 Modules
| |||||||||||||||
| 1392 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://sunmd5.com/dksds/check" | C:\Program Files\Mozilla Firefox\firefox.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1456 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.2.54736961\116177513" -childID 1 -isForBrowser -prefsHandle 2056 -prefMapHandle 2052 -prefsLen 25524 -prefMapSize 244187 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {3c446ef6-9a93-42f3-9658-5ed7f9a48a5f} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 2068 1914dd58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2328 | C:\Windows\SysWOW64\explorer.exe | C:\Windows\SysWOW64\explorer.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2688 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.6.2007932336\507696340" -childID 5 -isForBrowser -prefsHandle 3964 -prefMapHandle 3712 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7681647c-c771-4a34-b742-1749ab255d72} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 4152 214fcc58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2732 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.5.261683734\651501905" -childID 4 -isForBrowser -prefsHandle 3888 -prefMapHandle 3892 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {9390bf87-e1ac-4d58-a2b7-47da292df5bc} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 3876 2057ce58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2800 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.7.1913500321\1595709808" -childID 6 -isForBrowser -prefsHandle 4140 -prefMapHandle 4136 -prefsLen 35561 -prefMapSize 244187 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {bdaf3cbf-46f7-4322-9752-ec3c16d2794e} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 4172 230eb958 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2856 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Setup_Pswd_2023.rar" | C:\program files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2884 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.0.593388630\339231777" -parentBuildID 20230710165010 -prefsHandle 1112 -prefMapHandle 1104 -prefsLen 29780 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0c19ea6f-2768-40f5-ae60-526592c00da4} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 1184 fad2858 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2932 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.3.1616431944\186695732" -childID 2 -isForBrowser -prefsHandle 2840 -prefMapHandle 2836 -prefsLen 35402 -prefMapSize 244187 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {935effd1-fd38-4b05-b3a5-8b240f9fbda6} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 2852 1e8ac058 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0000000000000000 | |||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 0 | |||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: F8B731ACA1C5D901 | |||
| (PID) Process: | (1392) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 1392 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.bin | binary | |
MD5:4DF9B77C7650AF87B264E535779AE2A4 | SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58 | |||
| 1392 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\ED9826654AE8BD972BDE17A9E0A449D3F881E430 | binary | |
MD5:0CD2A9798F89AE1FFD6C7E7CA4FEEE23 | SHA256:15F5B91D1A184E814F7725E3DCF0105FE667034E3DCA1CF5E6D17982C94E803E | |||
| 1392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs.js | text | |
MD5:D393BC732B5E6F401BD928B4A2F00ACD | SHA256:F19569443E387FDC12D0921788486307E35D503ACBEA3C611AD042B2B24F519D | |||
| 1392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:7D9485106994338D6060A64FC872140B | SHA256:254AAF41F963991F0F561FC4F708BA77E5DBAB62E0698CE43117432A473FA860 | |||
| 1392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs-1.js | text | |
MD5:D393BC732B5E6F401BD928B4A2F00ACD | SHA256:F19569443E387FDC12D0921788486307E35D503ACBEA3C611AD042B2B24F519D | |||
| 1392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cert9.db-journal | binary | |
MD5:09A7A8C15248E26AF0D9FA2D72774E30 | SHA256:442F95F37D768471BF1DCFD473C516E151D925D9CDA8A3E5285972072F0BC133 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1392 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
1392 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
1392 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
1392 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
1392 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
1392 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
1392 | firefox.exe | POST | 200 | 18.66.183.220:80 | http://ocsp.r2m02.amazontrust.com/ | unknown | binary | 471 b | unknown |
1392 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 471 b | unknown |
1392 | firefox.exe | POST | 200 | 142.250.186.67:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
1392 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1392 | firefox.exe | 172.67.73.163:443 | sunmd5.com | CLOUDFLARENET | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1392 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
1392 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1392 | firefox.exe | 34.192.30.2:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
1392 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | unknown |
1392 | firefox.exe | 184.24.77.56:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
1392 | firefox.exe | 142.250.185.234:443 | safebrowsing.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
sunmd5.com |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
r3.o.lencr.org |
| shared |
content-signature-2.cdn.mozilla.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
324 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discordapp .com) |
324 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discordapp .com) |
324 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discordapp .com) |
1392 | firefox.exe | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
2328 | explorer.exe | Malware Command and Control Activity Detected | ET MALWARE [ANY.RUN] Win32/Lumma Stealer Check-In |
2328 | explorer.exe | Malware Command and Control Activity Detected | STEALER [ANY.RUN] Win32/Lumma Stealer Check-In |
2328 | explorer.exe | Malware Command and Control Activity Detected | ET MALWARE [ANY.RUN] Win32/Lumma Stealer Exfiltration |
2328 | explorer.exe | Malware Command and Control Activity Detected | STEALER [ANY.RUN] Win32/Lumma Stealer Exfiltration |
2328 | explorer.exe | Malware Command and Control Activity Detected | ET MALWARE [ANY.RUN] Win32/Lumma Stealer Exfiltration |
2328 | explorer.exe | Malware Command and Control Activity Detected | STEALER [ANY.RUN] Win32/Lumma Stealer Exfiltration |