| File name: | crowdstrike-hotfix.zip |
| Full analysis: | https://app.any.run/tasks/541d5d3d-28fc-4a15-b102-ac1fc82e64e6 |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | July 22, 2024, 11:19:32 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 1E84736EFCE206DC973ACBC16540D3E5 |
| SHA1: | FEF212EC979F2FE2F48641160AADEB86B83F7B35 |
| SHA256: | C44506FE6E1EDE5A104008755ABF5B6ACE51F1A84AD656A2DCCC7F2C39C0ECA2 |
| SSDEEP: | 98304:tqYE8lPCNYpYpkNU7Tfb5WK0ZLcCb9C52ycVfRRX2/o+czw94RF+XfUpyO7crJg1:bNDJ5+uzMWJ3 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:07:19 07:46:20 |
| ZipCRC: | 0x42981c68 |
| ZipCompressedSize: | 779055 |
| ZipUncompressedSize: | 2012160 |
| ZipFileName: | vcl120.bpl |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1020 | C:\WINDOWS\SysWOW64\cmd.exe | C:\Windows\SysWOW64\cmd.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1032 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\crowdstrike-hotfix.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1144 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1960 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2104 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2728 | C:\WINDOWS\system32\OpenWith.exe -Embedding | C:\Windows\System32\OpenWith.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Pick an app Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3624 | Setup.exe | C:\Users\admin\Desktop\crowdstrike-hotfix\Setup.exe | — | cmd.exe | |||||||||||
User: admin Company: iTop Inc. Integrity Level: MEDIUM Description: iTop Data Recovery Backup Exit code: 1 Version: 1.0.0.418 Modules
| |||||||||||||||
| 4156 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5156 | "C:\Users\admin\Desktop\crowdstrike-hotfix\Setup.exe" | C:\Users\admin\Desktop\crowdstrike-hotfix\Setup.exe | — | explorer.exe | |||||||||||
User: admin Company: iTop Inc. Integrity Level: MEDIUM Description: iTop Data Recovery Backup Exit code: 1 Version: 1.0.0.418 Modules
| |||||||||||||||
| 5492 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\Setup.exe | WinRAR.exe | ||||||||||||
User: admin Company: iTop Inc. Integrity Level: MEDIUM Description: iTop Data Recovery Backup Exit code: 1 Version: 1.0.0.418 Modules
| |||||||||||||||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\crowdstrike-hotfix.zip | |||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1032) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1032 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\vcl120.bpl | binary | |
MD5:849070EBD34CBAEDC525599D6C3F8914 | SHA256:B6F321A48812DC922B26953020C9A60949EC429A921033CFAF1E9F7D088EE628 | |||
| 1032 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\battuta.flv | binary | |
MD5:8274785D42B79444767FB0261746FE91 | SHA256:BE074196291CCF74B3C4C8BD292F92DA99EC37A25DC8AF651BD0BA3F0D020349 | |||
| 1032 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\datastate.dll | executable | |
MD5:28F0CCF746F952F94FF434CA989B7814 | SHA256:6010E2147A0F51A7BFA2F942A5A9EAAD9A294F463F717963B486ED3F53D305C2 | |||
| 1032 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\maddisAsm_.bpl | executable | |
MD5:84BC072F8EA30746F0982AFBDA3C638F | SHA256:52019F47F96CA868FA4E747C3B99CBA1B7AA57317BF8EBF9FCBF09AA576FE006 | |||
| 1032 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\instrucciones.txt | text | |
MD5:11D67598BAFFEE39CB3827251F2A255E | SHA256:4F450ABAA4DAF72D974A830B16F91DEED77BA62412804DCA41A6D42A7D8B6FD0 | |||
| 1032 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\madbasic_.bpl | executable | |
MD5:DA03EBD2A8448F53D1BD9E16FC903168 | SHA256:D6D5FF8E9DC6D2B195A6715280C2F1BA471048A7CE68D256040672B801FDA0EA | |||
| 1032 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\madexcept_.bpl | executable | |
MD5:21068DFD733435C866312D35B9432733 | SHA256:835F1141ECE59C36B18E76927572D229136AEB12EFF44CB4BA98D7808257C299 | |||
| 1032 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1032.49701\maidenhair.cfg | binary | |
MD5:451049D3AC526F1ABDD704C3B1FED580 | SHA256:931308CFE733376E19D6CD2401E27F8B2945CEC0B9C696AEBE7029EA76D45BF6 | |||
| 5492 | Setup.exe | C:\Users\admin\AppData\Local\controlfm\madbasic_.bpl | executable | |
MD5:DA03EBD2A8448F53D1BD9E16FC903168 | SHA256:D6D5FF8E9DC6D2B195A6715280C2F1BA471048A7CE68D256040672B801FDA0EA | |||
| 5936 | cmd.exe | C:\Users\admin\AppData\Local\Temp\mxgfdcohhdeuwr | — | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4716 | svchost.exe | 40.126.32.74:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
7856 | svchost.exe | 4.209.32.67:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
5620 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2760 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7972 | slui.exe | 20.83.72.98:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7856 | svchost.exe | 4.208.221.206:443 | licensing.mp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4716 | svchost.exe | 40.126.32.72:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
licensing.mp.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
www.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
8004 | explorer.exe | A Network Trojan was detected | REMOTE [ANY.RUN] REMCOS TLS Connection JA3 Hash |
8004 | explorer.exe | Malware Command and Control Activity Detected | ET JA3 Hash - Remcos 3.x/4.x TLS Connection |