| File name: | 01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC.zip |
| Full analysis: | https://app.any.run/tasks/a5f0a384-b112-416e-b61a-ab5a4588e331 |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | April 18, 2024, 13:58:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 93BA103F662E8DDBDA25EBC316887F76 |
| SHA1: | F0F5850E3ADF4FE9A73FCD16AFD2132CC71A5AE0 |
| SHA256: | 943AFB9406571059DD842DD828D1CAA1EA28C8B91447460CED61B0E90008B2B6 |
| SSDEEP: | 98304:+6Au4g1NgkwlYZZskpOvFdGZwkqQWfwbxNt6u/ckSNZhACi+heVD+GHojLXCL7sO:4T0 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:04:16 12:54:20 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | CITACION DEMANDA JUZGADO CIVIL DEL CIRC/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 1924 | "C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\01 CITACION DEMANDA.exe" | C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\01 CITACION DEMANDA.exe | explorer.exe | ||||||||||||
User: admin Company: IObit Integrity Level: HIGH Description: IObit RttHlp Version: 11.0.0.0 Modules
| |||||||||||||||
| 2160 | "C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE" "C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\blimp.pptx" | C:\Program Files\microsoft office\Office14\POWERPNT.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft PowerPoint Exit code: 0 Version: 14.0.6009.1000 Modules
| |||||||||||||||
| 3072 | "C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE" "C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\blimp.pptx" | C:\Program Files\microsoft office\Office14\POWERPNT.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft PowerPoint Exit code: 0 Version: 14.0.6009.1000 Modules
| |||||||||||||||
| 3852 | "C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\01 CITACION DEMANDA.exe" | C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\01 CITACION DEMANDA.exe | explorer.exe | ||||||||||||
User: admin Company: IObit Integrity Level: MEDIUM Description: IObit RttHlp Exit code: 3221225477 Version: 11.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC.zip | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2160 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Temp\CVRDAF1.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3072 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Temp\CVRDC49.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 324 | WinRAR.exe | C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\blimp.pptx | binary | |
MD5:9B0A3C4AC5FBBC54414DE7BDDB6E4DD7 | SHA256:9563FF30632D17CDD810D4F51C24A22DABC960C3A1DB2EE5F229DCF57CDB9EA9 | |||
| 324 | WinRAR.exe | C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\01 CITACION DEMANDA.exe | executable | |
MD5:A2D70FBAB5181A509369D96B682FC641 | SHA256:8AED681AD8D660257C10D2F0E85AE673184055A341901643F27AFC38E5EF8473 | |||
| 2160 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso1201.tmp | compressed | |
MD5:112324B6F1275FCB20E76E1EC01FE2CF | SHA256:2252A704DD81E1F839894A44E9EC5594AD5A22B926AEEFA251FB2F3FF76D385D | |||
| 2160 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso416.tmp | compressed | |
MD5:112324B6F1275FCB20E76E1EC01FE2CF | SHA256:2252A704DD81E1F839894A44E9EC5594AD5A22B926AEEFA251FB2F3FF76D385D | |||
| 324 | WinRAR.exe | C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\vcl120.bpl | binary | |
MD5:C594D746FF6C99D140B5E8DA97F12FD4 | SHA256:572EDB7D630E9B03F93BD15135D2CA360176C1232051293663EC5B75C2428AEC | |||
| 324 | WinRAR.exe | C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\trial.sql | binary | |
MD5:86EF8137A63B54454D12721ED0BDC8F8 | SHA256:CE02C1401FB1C7BD28694CC899CD3E00336A30B55BE2448FFCB32243CD5B80EE | |||
| 2160 | POWERPNT.EXE | C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\~$blimp.pptx | binary | |
MD5:4733361B45F08621FE3F6F1362BCBE79 | SHA256:F85558284CBAB47C2EB6170E0B9AE5D27B5231637A4C1675474F7135AD08BF4E | |||
| 324 | WinRAR.exe | C:\Users\admin\Desktop\01-CITACION DEMANDA JUZGADO CIVIL DEL CIRC\CITACION DEMANDA JUZGADO CIVIL DEL CIRC\rtl120.bpl | executable | |
MD5:ADF82ED333FB5567F8097C7235B0E17F | SHA256:D6DD7A4F46F2CFDE9C4EB9463B79D5FF90FC690DA14672BA1DA39708EE1B9B50 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |