| File name: | setup.exe |
| Full analysis: | https://app.any.run/tasks/cb949432-46e2-4250-a818-024f0ab7452b |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | February 02, 2025, 12:59:26 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 992F7D23DF1C73FC1F8237CCC76356F6 |
| SHA1: | F72A6DDC291966EB92FA63005EA9CD743DE02717 |
| SHA256: | 746EF1A45EA2ED7A5B871E7F59CCB4EE545E31A60BA00A076D6CE555B5DEACBF |
| SSDEEP: | 98304:/XWUUIbs2WTNn5izRF6tDiogiMKpPsZ4rXYCWTOglHMOE6q9Xh0jibLxNMJSgs7z:Kn/6UmF1urXjW |
| .exe | | | Win32 Executable (generic) (3.6) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (1.6) |
| .exe | | | DOS Executable Generic (1.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:10:09 10:16:11+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 2074624 |
| InitializedDataSize: | 7549952 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1c3f15 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.2.0.1 |
| ProductVersionNumber: | 2.2.0.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (British) |
| CharacterSet: | Unicode |
| CompanyName: | Stardock Software |
| FileDescription: | Stardock Groupy 2 Configuration Utility |
| FileVersion: | 2.2.0.1 |
| InternalName: | GroupyConfig.exe |
| LegalCopyright: | Copyright (C) 2024 Stardock Software, Inc |
| OriginalFileName: | GroupyConfig.EXE |
| ProductName: | Stardock Groupy 2 |
| ProductVersion: | 2.2.0.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1684 | C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7} | C:\Windows\SysWOW64\dllhost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2192 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2928 | C:\Users\admin\AppData\Local\Temp\updater.exe | C:\Users\admin\AppData\Local\Temp\updater.exe | more.com | ||||||||||||
User: admin Company: Caphyon Integrity Level: HIGH Description: updater 18.0 Version: 18.0 Modules
| |||||||||||||||
| 3220 | "C:\Users\admin\AppData\Local\Temp\ZWB1F75QCOAJMMRT9G7KU\iTunesHelper.exe" | C:\Users\admin\AppData\Local\Temp\ZWB1F75QCOAJMMRT9G7KU\iTunesHelper.exe | setup.exe | ||||||||||||
User: admin Company: Apple Inc. Integrity Level: MEDIUM Description: iTunesHelper Exit code: 0 Version: 12.12.9.4 Modules
| |||||||||||||||
| 3508 | "C:\ProgramData\MsiSleuth\iTunesHelper.exe" | C:\ProgramData\MsiSleuth\iTunesHelper.exe | dllhost.exe | ||||||||||||
User: admin Company: Apple Inc. Integrity Level: HIGH Description: iTunesHelper Exit code: 1 Version: 12.12.9.4 Modules
| |||||||||||||||
| 4672 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | more.com | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5472 | C:\ProgramData\MsiSleuth\iTunesHelper.exe | C:\ProgramData\MsiSleuth\iTunesHelper.exe | iTunesHelper.exe | ||||||||||||
User: admin Company: Apple Inc. Integrity Level: MEDIUM Description: iTunesHelper Exit code: 1 Version: 12.12.9.4 Modules
| |||||||||||||||
| 5872 | C:\WINDOWS\SysWOW64\more.com | C:\Windows\SysWOW64\more.com | — | iTunesHelper.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: More Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6148 | C:\WINDOWS\SysWOW64\more.com | C:\Windows\SysWOW64\more.com | iTunesHelper.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: More Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6156 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | more.com | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6728 | setup.exe | C:\Users\admin\AppData\Local\Temp\ZWB1F75QCOAJMMRT9G7KU\protozoa.m4a | — | |
MD5:— | SHA256:— | |||
| 6728 | setup.exe | C:\Users\admin\AppData\Local\Temp\ZWB1F75QCOAJMMRT9G7KU\CoreFoundation.dll | — | |
MD5:— | SHA256:— | |||
| 3220 | iTunesHelper.exe | C:\ProgramData\MsiSleuth\CoreFoundation.dll | — | |
MD5:— | SHA256:— | |||
| 6728 | setup.exe | C:\Users\admin\AppData\Local\Temp\ZWB1F75QCOAJMMRT9G7KU\vcruntime140.dll | executable | |
MD5:49C96CECDA5C6C660A107D378FDFC3D4 | SHA256:69320F278D90EFAAEB67E2A1B55E5B0543883125834C812C8D9C39676E0494FC | |||
| 6728 | setup.exe | C:\Users\admin\AppData\Local\Temp\ZWB1F75QCOAJMMRT9G7KU\msvcp140.dll | executable | |
MD5:1BA6D1CF0508775096F9E121A24E5863 | SHA256:74892D9B4028C05DEBAF0B9B5D9DC6D22F7956FA7D7EEE00C681318C26792823 | |||
| 6728 | setup.exe | C:\Users\admin\AppData\Local\Temp\ZWB1F75QCOAJMMRT9G7KU\libicuin.dll | executable | |
MD5:87E2273BF7E052EC5B8ED96DFCA5D5EA | SHA256:09D99E34E29B86E46633EF6E9E6EB6915EB2CCC92F6DD34B39CF459DFF77040F | |||
| 3220 | iTunesHelper.exe | C:\ProgramData\MsiSleuth\protozoa.m4a | — | |
MD5:— | SHA256:— | |||
| 5472 | iTunesHelper.exe | C:\Users\admin\AppData\Local\Temp\1970cde2 | — | |
MD5:— | SHA256:— | |||
| 3508 | iTunesHelper.exe | C:\Users\admin\AppData\Local\Temp\1ea6c1a2 | — | |
MD5:— | SHA256:— | |||
| 6148 | more.com | C:\Users\admin\AppData\Local\Temp\oardpoawo | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6640 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6640 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6324 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1176 | svchost.exe | 20.190.160.128:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
— | — | 23.35.238.131:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
6728 | setup.exe | 104.21.32.1:443 | clammypunero.com | CLOUDFLARENET | — | malicious |
4536 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1916 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6728 | setup.exe | 188.114.96.3:443 | u2.servicelandingkaraoke.shop | CLOUDFLARENET | NL | malicious |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
thingspouter.top |
| unknown |
clammypunero.com |
| malicious |
cegu.shop |
| unknown |
u2.servicelandingkaraoke.shop |
| malicious |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2192 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
2192 | svchost.exe | Potentially Bad Traffic | SUSPICIOUS [ANY.RUN] Suspected Malicious domain by CrossDomain ( .servicelandingkaraoke .shop) |