| File name: | mal4.7z |
| Full analysis: | https://app.any.run/tasks/c2766196-f7cd-40ad-aba1-277f1545357c |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | December 05, 2024, 14:46:32 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 88387FAB6193E342974A48E3D5D2EC82 |
| SHA1: | BD8334C94412568C4A8040E063D59B053D3CC7C7 |
| SHA256: | CB0C82F8E8DA2785D1E338C3EE9226483FEF6F4460F788FEE05C3278400AC5DB |
| SSDEEP: | 196608:UdFJFY/QgmJsq3cGnKHHi9MFNozDiDr6Zw:CJFYT+sqsGgi922DuW2 |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
| FileVersion: | 7z v0.04 |
|---|---|
| ModifyDate: | 2024:12:05 13:49:29+00:00 |
| ArchivedFileName: | mal4 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1140 | C:\Users\admin\AppData\Roaming\tamd64\ADAGWPURBMFJFYPHSWSYOBBX\Caller.exe | C:\Users\admin\AppData\Roaming\tamd64\ADAGWPURBMFJFYPHSWSYOBBX\Caller.exe | — | Setup.exe | |||||||||||
User: admin Company: Custom Solutions of Maryland Integrity Level: MEDIUM Exit code: 1 Version: 4.2.0.0 Modules
| |||||||||||||||
| 1416 | "C:\Users\admin\AppData\Local\4727b00c-1718-4271-b23c-c5704a46cb32\ImApp.exe" | C:\Users\admin\AppData\Local\4727b00c-1718-4271-b23c-c5704a46cb32\ImApp.exe | dllhost.exe | ||||||||||||
User: admin Company: IncrediMail, Ltd. Integrity Level: HIGH Description: IncrediMail Tray Application Exit code: 0 Version: 6, 3, 9, 5274 Modules
| |||||||||||||||
| 1576 | C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7} | C:\Windows\SysWOW64\dllhost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2412 | "C:\Users\admin\Desktop\mal4\Setup.exe" | C:\Users\admin\Desktop\mal4\Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Mozilla Thunderbird Exit code: 1 Version: 1.8.1.19: 2008120920 Modules
| |||||||||||||||
| 2796 | C:\Users\admin\AppData\Roaming\amd64_4c10eeff886a3251\ImApp.exe | C:\Users\admin\AppData\Roaming\amd64_4c10eeff886a3251\ImApp.exe | — | ImApp.exe | |||||||||||
User: admin Company: IncrediMail, Ltd. Integrity Level: HIGH Description: IncrediMail Tray Application Exit code: 1 Version: 6, 3, 9, 5274 Modules
| |||||||||||||||
| 3416 | C:\WINDOWS\SysWOW64\explorer.exe | C:\Windows\SysWOW64\explorer.exe | — | more.com | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3436 | powershell -exec bypass -f "C:\Users\admin\AppData\Local\Temp\VV5EKW6OKPEVEAF6OB4.ps1" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | Emma.com | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3744 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | more.com | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4136 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4872 | C:\WINDOWS\SysWOW64\more.com | C:\Windows\SysWOW64\more.com | Setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: More Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6876) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6876) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6876) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6876) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\mal4.7z | |||
| (PID) Process: | (6876) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6876) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6876) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6876) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (5472) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (5472) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6876 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6876.33046\mal4\nss3.dll | executable | |
MD5:0E845C5A84427B1AF9B577C122BC4E23 | SHA256:F9E1F2A9A88A5D5CA748A84784D56A65D5E611785AA1D3638C07E9B36624BC73 | |||
| 6876 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6876.33046\mal4\irikyg | binary | |
MD5:BC28369723889A65E0CD37F4BCFF732C | SHA256:5B948A608E39D2E7DA540482C03B6F3158C7E58339DD36A46AFE6ABB75C2B8A1 | |||
| 6876 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6876.33046\mal4\softokn3.dll | executable | |
MD5:DA7C7F8681BC177CC5CC1A5564BD6CE5 | SHA256:656D3FFB58F3F75F0506595D5D818CECC59AA51DE492B21665ECAA0FF8966CE0 | |||
| 6876 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6876.33046\mal4\nsldappr32v50.dll | executable | |
MD5:B8019E6A4DCF1037AB4FB3EA74FFF91D | SHA256:8377A1BABBDB38611C7BBBAF05AC5108C1C6539104B160CB1DBFCBB7638F3AE8 | |||
| 2412 | Setup.exe | C:\Users\admin\AppData\Roaming\tamd64\nss3.dll | executable | |
MD5:0E845C5A84427B1AF9B577C122BC4E23 | SHA256:F9E1F2A9A88A5D5CA748A84784D56A65D5E611785AA1D3638C07E9B36624BC73 | |||
| 6876 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6876.33046\mal4\plc4.dll | executable | |
MD5:9ED02E151C4F5417C10594A19EEEB034 | SHA256:FA4BEBED44856339E1D65A670ECBCE8487EC95851B1CF278D40B442E5E118F71 | |||
| 6876 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6876.33046\mal4\plds4.dll | executable | |
MD5:5D35EE582ED616947ADE1002F25682CA | SHA256:ED79346AF0BD7276039E011D72B7C817E2015EDDF91224E08DAF3B2A041CA5AD | |||
| 6876 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6876.33046\mal4\smime3.dll | executable | |
MD5:05FF877978A22599F8675344AFF7E9AC | SHA256:B8F3022392E3BD755B4D3BAE4011303EEA6ACAF5369AE987F33F654A30AEB5C2 | |||
| 6876 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6876.33046\mal4\ssl3.dll | executable | |
MD5:FDF29B3A596524ADCC11C6031E682E16 | SHA256:F5B17B9122EA779DA6E1C303F7D2D16096970E840A5FE072A65371FCFC9A8D34 | |||
| 6876 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6876.33046\mal4\xpcom_compat.dll | executable | |
MD5:DD03A9F6BD3652FEEBC5B8E21F8F4379 | SHA256:0E561CC712E9B2ECA7080B24E5B0B8CEAB09FB3406880A85EDCBCCD8F5B4988D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.98:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1684 | svchost.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6400 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
2844 | SIHClient.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2844 | SIHClient.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.16.164.98:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
1684 | svchost.exe | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 2.23.209.132:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1176 | svchost.exe | 40.126.32.138:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2192 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Online Pastebin Text Storage |