| URL: | https://dpa.org.sg/download-kmspico_setup-exe-windows-10/ |
| Full analysis: | https://app.any.run/tasks/a28e392b-8d16-4489-9d89-a7e3c734f530 |
| Verdict: | Malicious activity |
| Threats: | HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses. |
| Analysis date: | December 27, 2025, 20:42:40 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 32B5515173712607CA1CD8220C3CB862 |
| SHA1: | 4591448D54B319E56DFC63F08EFE73BAFB1BF41F |
| SHA256: | E0BBF3F6967F8E59904096A3186D4949BFAC1B9B772F6CA382CFDA39FE60130D |
| SSDEEP: | 3:N8N5IWCkLkOISB7ALSKBJzn:20W9I9Skzn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 748 | "C:\𝗦𝗘𝗧𝗨𝗣.exe" | C:\𝗦𝗘𝗧𝗨𝗣.exe | explorer.exe | ||||||||||||
User: admin Company: ASCOMP Software GmbH Integrity Level: HIGH Description: Backup Software Exit code: 0 Version: 8.3.1.1 Modules
| |||||||||||||||
| 3548 | "C:\Program Files\WinRAR\WinRAR.exe" -elevate8708 | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 4752 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | FrameMoni.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 5728 | C:\ProgramData\FrameMoni.exe | C:\ProgramData\FrameMoni.exe | 𝗦𝗘𝗧𝗨𝗣.exe | ||||||||||||
User: admin Company: Jumping Bytes Integrity Level: HIGH Description: PureSync Volume Shadow Copy Service Version: 1.2.3 Modules
| |||||||||||||||
| 5772 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4000 -prefsLen 45009 -prefMapHandle 4004 -prefMapSize 273045 -jsInitHandle 4008 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4012 -initialChannelId {10de4cbb-4410-4f16-89f3-043126956e27} -parentPid 7684 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7684" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 6272 | C:\Users\admin\AppData\Roaming\devshield_net45_win64\QNQVTZPMUYFQIEHHUX\CoPortal.exe | C:\Users\admin\AppData\Roaming\devshield_net45_win64\QNQVTZPMUYFQIEHHUX\CoPortal.exe | — | 𝗦𝗘𝗧𝗨𝗣.exe | |||||||||||
User: admin Company: ASCOMP Software GmbH Integrity Level: HIGH Description: Backup Software Exit code: 0 Version: 8.3.1.1 Modules
| |||||||||||||||
| 6892 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4680 -prefsLen 45116 -prefMapHandle 4676 -prefMapSize 273045 -ipcHandle 4712 -initialChannelId {1f878c03-08cf-4618-b258-dbf72fe98dda} -parentPid 7684 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7684" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7028 | "C:\WINDOWS\system32\taskmgr.exe" /4 | C:\Windows\System32\Taskmgr.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Manager Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7244 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4768 -prefsLen 45168 -prefMapHandle 4772 -prefMapSize 273045 -jsInitHandle 4804 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4828 -initialChannelId {85343458-8f2d-41b8-ab35-a4af1e9fb22f} -parentPid 7684 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7684" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7308 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5036 -prefsLen 39120 -prefMapHandle 5040 -prefMapSize 273045 -jsInitHandle 5044 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4908 -initialChannelId {350dc323-5d4b-4e31-9706-6b054f982707} -parentPid 7684 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7684" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| (PID) Process: | (7580) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (7580) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (7580) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (7580) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\Installer_wtb_X64_x86_2025.zip | |||
| (PID) Process: | (7580) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (7580) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (7580) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (7580) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (8708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (8708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7684 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 7684 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 7684 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 7684 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:B30329D7D2CF4258C22F500CBEA218FF | SHA256:C5E20431B116E1DABD383C6855A36E6DAF13E1CC125B83D59EF68B4BCEFB02E6 | |||
| 7684 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.bin | binary | |
MD5:E749F6B3C81C5220331BAD005C21FF65 | SHA256:DC2A48D0C62020AF212D840EBA19CB3A05B1AAEF06D51640C5F8685DD86CFD91 | |||
| 7684 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.bin | binary | |
MD5:5152D8F49F1AD4219D935611EFE18437 | SHA256:9A6E50715E3C49A43E3D622EDE7E37ECF0767342B3039B8B0AE25BBE4FF6F66E | |||
| 7684 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\activity-stream.contile.json.tmp | text | |
MD5:6A3A606426D79853CB9F524A07795C1C | SHA256:D2E60F9E3CCC8C79DC93681746147B1B26290F2B30DD446AEC655A52E3D7DCFC | |||
| 7684 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 7684 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 7684 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.bin | binary | |
MD5:041ABD9D336935F565B8CD5A9D6AA5BF | SHA256:21B56DD3BE7E45146A77FFE3C9F468A9255BC642A683578CEE91F53ADA84E218 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7684 | firefox.exe | GET | 101 | 34.107.243.93:443 | https://push.services.mozilla.com/ | US | — | — | unknown |
7684 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/s/wr3/peI | US | binary | 472 b | whitelisted |
7684 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | unknown |
7684 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | unknown |
7684 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | unknown |
7684 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/we2 | US | binary | 279 b | whitelisted |
7684 | firefox.exe | GET | 200 | 34.160.144.191:443 | https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2025-11-08-08-20-52.chain | US | text | 5.18 Kb | unknown |
7684 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/we2 | US | binary | 279 b | whitelisted |
7684 | firefox.exe | GET | 200 | 34.160.144.191:443 | https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2025-11-08-08-20-52.chain | US | text | 5.18 Kb | unknown |
7684 | firefox.exe | GET | 200 | 151.101.129.91:443 | https://firefox.settings.services.mozilla.com/v1/ | US | text | 1.20 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
3276 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6320 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
7684 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
7684 | firefox.exe | 103.138.189.66:443 | dpa.org.sg | WHG-SGP | GB | unknown |
7684 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
7684 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
7684 | firefox.exe | 151.101.129.91:443 | firefox.settings.services.mozilla.com | FASTLY | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
content-signature-2.cdn.mozilla.net |
| whitelisted |
dpa.org.sg |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
mc.prod.ads.prod.webservices.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
7684 | firefox.exe | Potentially Bad Traffic | ET HUNTING Observed Let's Encrypt Certificate for Suspicious TLD (.xyz) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
— | — | Generic Protocol Command Decode | SURICATA HTTP URI terminated by non-compliant character |
— | — | Generic Protocol Command Decode | SURICATA HTTP request field missing colon |
— | — | Generic Protocol Command Decode | SURICATA HTTP request header invalid |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Websocket Upgrade Request |