| File name: | #ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL.zip |
| Full analysis: | https://app.any.run/tasks/9f15d6db-b9a9-4356-8cf9-56bab8492a5a |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | October 11, 2024, 22:31:54 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5: | 68AF1FF3852E17BED27508637C7A69C3 |
| SHA1: | E961A5ECEE089E0A304B0E12AF514474B4CB653E |
| SHA256: | 66ACC7FF6E1B88EEBA7CE5762813BC05B9B38466BE964C48E57CED22B5159B47 |
| SSDEEP: | 98304:9Wc3gWonIKjHQFN5XJcvUlO20ZJXIMj9uw2w1LH8XQvrz1ROU7FemVgON0e5Cby7:TFBIatFsnAg |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | 0x0800 |
| ZipCompression: | None |
| ZipModifyDate: | 2024:10:09 00:28:28 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | #ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1196 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2928 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL.zip" "?\" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3532 | powershell -exec bypass -f "C:\Users\admin\AppData\Local\Temp\B6HX7K310HBH4D8BP.ps1" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | SearchIndexer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5592 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5920 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | more.com | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6300 | "C:\Users\admin\Desktop\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\Setup.exe" | C:\Users\admin\Desktop\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: HIGH Description: VirtualBox Interface Exit code: 1 Version: 4.2.18.88780 Modules
| |||||||||||||||
| 6396 | C:\WINDOWS\SysWOW64\SearchIndexer.exe | C:\Windows\SysWOW64\SearchIndexer.exe | more.com | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Windows Search Indexer Exit code: 0 Version: 7.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6572 | C:\ProgramData\uepl\IDUMCIVECOSHAYKNRLFME\StrCmp.exe | C:\ProgramData\uepl\IDUMCIVECOSHAYKNRLFME\StrCmp.exe | — | Setup.exe | |||||||||||
User: admin Company: aaa Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 6708 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\#ⱾS$et-U!ῥ-P͜aS$_2324__☆!_FU!!LL.zip | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 1 Version: 5.91.0 Modules
| |||||||||||||||
| 6712 | C:\WINDOWS\SysWOW64\more.com | C:\Windows\SysWOW64\more.com | Setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: More Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\General\Toolbar\Layout |
| Operation: | write | Name: | Band76_0 |
Value: 4C000000730100000402000000000000F0F0F00000000000000000000000000000000000000000004202040000000000000000003B000000B402000000000000000000000000000001000000 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\General\Toolbar\Layout |
| Operation: | write | Name: | Band76_1 |
Value: 4C000000730100000500000000000000F0F0F0000000000000000000000000000000000000000000E40204000000000000000000180000002A00000000000000000000000000000002000000 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\General\Toolbar\Layout |
| Operation: | write | Name: | Band76_2 |
Value: 4C000000730100000400000000000000F0F0F0000000000000000000000000000000000000000000F20207000000000000000000180000006400000000000000000000000000000003000000 | |||
| (PID) Process: | (2928) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | delete value | Name: | 15 |
Value: | |||
| (PID) Process: | (2928) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | delete value | Name: | 14 |
Value: | |||
| (PID) Process: | (2928) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | delete value | Name: | 13 |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6712 | more.com | C:\Users\admin\AppData\Local\Temp\wsffghncaqnum | — | |
MD5:— | SHA256:— | |||
| 2928 | WinRAR.exe | C:\Users\admin\Desktop\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\hidboy | binary | |
MD5:FDE218EEBED4F70105540A3B2B42AAC5 | SHA256:B60D53A6E2FFAB09CBBBDF2014458FF854B3852D667ED5B711DBBBB997B3C019 | |||
| 2928 | WinRAR.exe | C:\Users\admin\Desktop\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\msvcp100.dll | executable | |
MD5:D029339C0F59CF662094EDDF8C42B2B5 | SHA256:934D882EFD3C0F3F1EFBC238EF87708F3879F5BB456D30AF62F3368D58B6AA4C | |||
| 2928 | WinRAR.exe | C:\Users\admin\Desktop\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\Setup.exe | executable | |
MD5:C8A2DE7077F97D4BCE1A44317B49EF41 | SHA256:448402C129A721812FA1C5F279F5CA906B9C8BBCA652A91655D144D20CE5E6B4 | |||
| 2928 | WinRAR.exe | C:\Users\admin\Desktop\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\msvcr100.dll | executable | |
MD5:366FD6F3A451351B5DF2D7C4ECF4C73A | SHA256:AE3CB6C6AFBA9A4AA5C85F66023C35338CA579B30326DD02918F9D55259503D5 | |||
| 2928 | WinRAR.exe | C:\Users\admin\Desktop\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\#ⱾS$et-U!ῥ-P͜aS$$_2324__☆!_FU!!LL\fkii | binary | |
MD5:ED4F8F21A73EF78B8021F615A24DE244 | SHA256:D3F20044186292867E7502C915A4E2C26E97CEEB705082ED67C9888B89304DBD | |||
| 6300 | Setup.exe | C:\ProgramData\uepl\fkii | binary | |
MD5:ED4F8F21A73EF78B8021F615A24DE244 | SHA256:D3F20044186292867E7502C915A4E2C26E97CEEB705082ED67C9888B89304DBD | |||
| 6300 | Setup.exe | C:\ProgramData\uepl\VBoxDDU.dll | executable | |
MD5:496DF6AD1A158ED5037138E397713EF0 | SHA256:07C04290F53AAAAA7DF6B6EA3A53103B6E3EF8FF658D8097617A9C48DFC6E90A | |||
| 6300 | Setup.exe | C:\ProgramData\uepl\msvcr100.dll | executable | |
MD5:366FD6F3A451351B5DF2D7C4ECF4C73A | SHA256:AE3CB6C6AFBA9A4AA5C85F66023C35338CA579B30326DD02918F9D55259503D5 | |||
| 6300 | Setup.exe | C:\ProgramData\uepl\hidboy | binary | |
MD5:FDE218EEBED4F70105540A3B2B42AAC5 | SHA256:B60D53A6E2FFAB09CBBBDF2014458FF854B3852D667ED5B711DBBBB997B3C019 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6132 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7028 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5236 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5236 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6944 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1764 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4360 | SearchApp.exe | 104.126.37.147:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
5488 | MoUsoCoreWorker.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4360 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
5488 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4020 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2172 | svchost.exe | Misc activity | ET INFO Pastebin Service Domain in DNS Lookup (rentry .co) |
6396 | SearchIndexer.exe | Misc activity | ET INFO Observed Pastebin Service Domain (rentry .co in TLS SNI) |