ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| File name: | @!FulL_Ver_$etup_5566_pAs$W0rd.7z |
| Full analysis: | https://app.any.run/tasks/ed2a98df-70f8-4aae-a393-43f560439979 |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | April 07, 2024, 19:24:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 820E3E90C1158609FF259C8E4411BC90 |
| SHA1: | FD4002E63B305C33B788CB311570017A19DEA63C |
| SHA256: | A70576520A46CA740AAB3BA83AB919EBC94D1550EFD2FDB9A2DC9D5E12D9B62C |
| SSDEEP: | 98304:vUjaWTdCajOe3xw+hdB0a2HeqJr0DAlhhnb+sjs1UchJjk8vTs7ujEkKBFgJnM/M:g5PpftcR7vZmreqy+QOFIcuCWw |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1336 | "C:\Users\admin\Desktop\@!FulL_Ver_$etup_5566_pAs$W0rd\Setup.exe" | C:\Users\admin\Desktop\@!FulL_Ver_$etup_5566_pAs$W0rd\Setup.exe | explorer.exe | ||||||||||||
User: admin Company: MediaArea.net Integrity Level: HIGH Description: MediaInfo Version: 24.03.0.0 Modules
| |||||||||||||||
| 1836 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\@!FulL_Ver_$etup_5566_pAs$W0rd.7z" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1976 | "C:\Users\admin\Desktop\@!FulL_Ver_$etup_5566_pAs$W0rd\Setup.exe" | C:\Users\admin\Desktop\@!FulL_Ver_$etup_5566_pAs$W0rd\Setup.exe | explorer.exe | ||||||||||||
User: admin Company: MediaArea.net Integrity Level: MEDIUM Description: MediaInfo Exit code: 3221225502 Version: 24.03.0.0 Modules
| |||||||||||||||
| 3488 | "C:\Users\admin\Desktop\@!FulL_Ver_$etup_5566_pAs$W0rd\Setup.exe" | C:\Users\admin\Desktop\@!FulL_Ver_$etup_5566_pAs$W0rd\Setup.exe | explorer.exe | ||||||||||||
User: admin Company: MediaArea.net Integrity Level: MEDIUM Description: MediaInfo Exit code: 3221225502 Version: 24.03.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\@!FulL_Ver_$etup_5566_pAs$W0rd.7z | |||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1836) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\Pas$Word.png | image | |
MD5:— | SHA256:— | |||
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\shirk.m4a | binary | |
MD5:— | SHA256:— | |||
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\updater\GUP | executable | |
MD5:— | SHA256:— | |||
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\updater\gup.xml | xml | |
MD5:— | SHA256:— | |||
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\updater\LICENSE | text | |
MD5:— | SHA256:— | |||
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\updater\nativeLang.xml | xml | |
MD5:— | SHA256:— | |||
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\updater\README.md | text | |
MD5:— | SHA256:— | |||
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\utensil.psd | binary | |
MD5:— | SHA256:— | |||
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\Helper.dll | executable | |
MD5:— | SHA256:— | |||
| 1836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1836.36798\@!FulL_Ver_$etup_5566_pAs$W0rd\MediaInfo_i386.dll | executable | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |