File name:

02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exe

Full analysis: https://app.any.run/tasks/af53712d-1e80-4237-b1f3-f33dda565f6a
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: September 03, 2025, 17:48:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
telegram
lumma
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 8 sections
MD5:

483208958A2041F4CFE497027EEF415B

SHA1:

51FB181D083DCFCBADEAA142A50A213DC598BECA

SHA256:

02C22CB54244B9A05B47CE93046DBDBDEE3724AE33E63799163975EAAD85C698

SSDEEP:

98304:tixSnwOifvGXoe1gBLODGIxob5q+derIr19a3K63k0002rXSlcYA8O0/zyOVwdfL:zbsD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LUMMA mutex has been found

      • MSBuild.exe (PID: 6224)
    • Steals credentials from Web Browsers

      • MSBuild.exe (PID: 6224)
    • Actions looks like stealing of personal data

      • MSBuild.exe (PID: 6224)
    • LUMMA has been detected (YARA)

      • MSBuild.exe (PID: 6224)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • 02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exe (PID: 3656)
    • Reads the date of Windows installation

      • 02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exe (PID: 3656)
    • Start notepad (likely ransomware note)

      • 02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exe (PID: 3656)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • MSBuild.exe (PID: 6224)
    • There is functionality for taking screenshot (YARA)

      • MSBuild.exe (PID: 6224)
    • Searches for installed software

      • MSBuild.exe (PID: 6224)
  • INFO

    • Reads the computer name

      • MSBuild.exe (PID: 6224)
      • 02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exe (PID: 3656)
    • Checks supported languages

      • 02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exe (PID: 3656)
      • MSBuild.exe (PID: 6224)
    • Reads the machine GUID from the registry

      • MSBuild.exe (PID: 6224)
    • Reads the software policy settings

      • MSBuild.exe (PID: 6224)
      • slui.exe (PID: 6388)
    • Reads Microsoft Office registry keys

      • 02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exe (PID: 3656)
    • Process checks computer location settings

      • 02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exe (PID: 3656)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 1132)
    • Application launched itself

      • chrome.exe (PID: 6304)
      • msedge.exe (PID: 4684)
      • msedge.exe (PID: 4892)
      • msedge.exe (PID: 6876)
      • msedge.exe (PID: 7084)
      • msedge.exe (PID: 1864)
      • msedge.exe (PID: 3672)
      • chrome.exe (PID: 3688)
      • chrome.exe (PID: 6412)
      • chrome.exe (PID: 2428)
    • Checks proxy server information

      • slui.exe (PID: 6388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Lumma

(PID) Process(6224) MSBuild.exe
C2 (10)backab.ru/lkdo
eigwos.ru/wqex
epitherd.ru/zadw
georgej.ru/plnb
https://t.me/quincyplayer6
kimmenkiz.ru/zldw
mastwin.in/qsaz
noggs.ru/yopd
oneflof.ru/tids
starexs.bet/tskx
ChaCha20
key9ofQqnxe5mzjO73uTC/XUpVEI/PtnG8FhJfoA+Ap7xk=
nonceSln2fS5bDO4=
counter0
key9ofQqnxe5mzjO73uTC/XUpVEI/PtnG8FhJfoA+Ap7xk=
nonceSln2fS5bDO4=
counter2
Strings (17)/dp.txt
/leveldb
Content-Disposition: form-data; name="
Content-Type: multipart/form-data; boundary=
DCFEttt|l
HQJKTUVOPIRS<M>7XaZ[def_`Ybc ]
LFLJDFDBLFLJ4F42LFLJDFDBLFLJ
\IndexedDB\chrome-extension_
\Local Extension Settings\
\Local State
\Local Storage\leveldb
\Microsoft\Windows Mail\Local Folders
\Packages
\Sync Extension Settings\
dcfehgjilknmporqtsvuxwzy|{~}
dpapi.dll
winhttp.dll
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:09:03 17:35:54+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14
CodeSize: 3604992
InitializedDataSize: 104960
UninitializedDataSize: -
EntryPoint: 0x34ae74
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
200
Monitored processes
66
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3184,i,113276685036165114,8962598581466279263,262144 --variations-seed-version --mojo-platform-channel-handle=3192 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1132"notepad.exe" "C:\Users\admin\Desktop\sample.apx"C:\Windows\System32\notepad.exe02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1164"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2400,i,6087239067567958923,14963035470878763041,262144 --variations-seed-version --mojo-platform-channel-handle=2396 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1232"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3220,i,2555117418802017948,7441870376454835345,262144 --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3232 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1336"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=3968,i,2555117418802017948,7441870376454835345,262144 --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=4696 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1568"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=2004,i,16606476987178579043,14294136910017302837,262144 --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=2000 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1740"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2252,i,6087239067567958923,14963035470878763041,262144 --variations-seed-version --mojo-platform-channel-handle=2628 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1864"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMSBuild.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1964"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --instant-process --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3572,i,11850729225687502719,8427596450350233789,262144 --variations-seed-version --mojo-platform-channel-handle=3612 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2148"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --edge-skip-compat-layer-relaunchC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
23 128
Read events
23 073
Write events
55
Delete events
0

Modification events

(PID) Process:(3656) 02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
121
(PID) Process:(3656) 02c22cb54244b9a05b47ce93046dbdbdee3724ae33e63799163975eaad85c698.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apx\OpenWithProgids
Operation:writeName:AutoProx.File
Value:
(PID) Process:(6304) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6304) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6304) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6304) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6304) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
Executable files
12
Suspicious files
129
Text files
160
Unknown types
0

Dropped files

PID
Process
Filename
Type
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RF191340.TMP
MD5:
SHA256:
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF19134f.TMP
MD5:
SHA256:
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\LOG.old~RF19135f.TMP
MD5:
SHA256:
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\LOG.old
MD5:
SHA256:
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RF19135f.TMP
MD5:
SHA256:
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF19135f.TMP
MD5:
SHA256:
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old
MD5:
SHA256:
6304chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\LOG.old~RF19136f.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
141
TCP/UDP connections
179
DNS requests
133
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5944
MoUsoCoreWorker.exe
GET
200
95.101.171.173:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
BR
binary
825 b
whitelisted
1268
svchost.exe
GET
200
95.101.171.173:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
BR
binary
825 b
whitelisted
5432
RUXIMICS.exe
GET
200
95.101.171.173:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
BR
binary
825 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
2.17.169.207:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
KE
binary
814 b
whitelisted
1268
svchost.exe
GET
200
2.17.169.207:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
KE
binary
814 b
whitelisted
5432
RUXIMICS.exe
GET
200
2.17.169.207:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
KE
binary
814 b
whitelisted
POST
200
20.190.159.75:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
unknown
POST
400
20.190.159.75:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
unknown
POST
400
20.190.159.129:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
unknown
POST
400
20.190.159.131:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5432
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5944
MoUsoCoreWorker.exe
95.101.171.173:80
crl.microsoft.com
Akamai International B.V.
BR
whitelisted
1268
svchost.exe
95.101.171.173:80
crl.microsoft.com
Akamai International B.V.
BR
whitelisted
5432
RUXIMICS.exe
95.101.171.173:80
crl.microsoft.com
Akamai International B.V.
BR
whitelisted
5944
MoUsoCoreWorker.exe
2.17.169.207:80
www.microsoft.com
AKAMAI-AS
KE
whitelisted
1268
svchost.exe
2.17.169.207:80
www.microsoft.com
AKAMAI-AS
KE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 172.217.23.110
whitelisted
crl.microsoft.com
  • 95.101.171.173
  • 95.101.171.144
  • 23.216.77.36
  • 23.216.77.20
  • 23.216.77.8
whitelisted
www.microsoft.com
  • 2.17.169.207
  • 88.221.169.152
whitelisted
login.live.com
  • 20.190.159.73
  • 40.126.31.2
  • 40.126.31.1
  • 20.190.159.131
  • 20.190.159.130
  • 20.190.159.129
  • 40.126.31.0
  • 40.126.31.69
whitelisted
t.me
  • 149.154.167.99
whitelisted
starexs.bet
  • 193.24.123.239
unknown
clients2.google.com
  • 142.250.181.238
whitelisted
safebrowsingohttpgateway.googleapis.com
  • 142.250.186.170
  • 172.217.18.106
  • 142.250.185.106
  • 142.250.186.74
  • 216.58.206.42
  • 216.58.206.74
  • 216.58.212.170
  • 142.250.184.234
  • 142.250.186.138
  • 172.217.18.10
  • 142.250.186.106
  • 172.217.16.202
  • 142.250.186.42
  • 142.250.185.74
  • 142.250.185.138
  • 142.250.184.202
whitelisted
clientservices.googleapis.com
  • 142.250.186.131
whitelisted

Threats

PID
Process
Class
Message
6224
MSBuild.exe
Misc activity
ET INFO Observed Telegram Domain (t .me in TLS SNI)
Malware Command and Control Activity Detected
MALWARE [ANY.RUN] Win32/Lumma CnC HTTP Activity observed
Malware Command and Control Activity Detected
MALWARE [ANY.RUN] Win32/Lumma CnC HTTP Activity observed
No debug info