File name:

Paysafecard Checker 2024 version.rar

Full analysis: https://app.any.run/tasks/543a2fdc-f6e8-4d3b-aa87-e74d66139888
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: January 27, 2025, 14:23:49
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
lumma
stealer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

274D3019B9A62DBCD1EA3564FD9B28AC

SHA1:

EBC2D8583F0B5EE9D0EA851D2286CDFE2C11D245

SHA256:

061B1F65DF3B9CD8B3C683FF87041822E970B0EA74971170492992F5E8F94320

SSDEEP:

98304:2jhiPk3ygUIMEqoKrZAZmoL3SUjTghck08KopAj0wpFf7o2e1hHTHt072v0Fb1fi:qH8ZB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LUMMA mutex has been found

      • RGGmHSFtnA.exe (PID: 4576)
    • Actions looks like stealing of personal data

      • RGGmHSFtnA.exe (PID: 4576)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2800)
      • WinRAR.exe (PID: 6492)
    • Application launched itself

      • Paysafecard Checker 2024 version.exe (PID: 6968)
      • RGGmHSFtnA.exe (PID: 7156)
    • Executable content was dropped or overwritten

      • Paysafecard Checker 2024 version.exe (PID: 7000)
      • A4NYx3VxAt.exe (PID: 7136)
    • Reads security settings of Internet Explorer

      • Paysafecard Checker 2024 version.exe (PID: 7000)
    • Executes application which crashes

      • Paysafecard Checker 2024 version.exe (PID: 6968)
      • RGGmHSFtnA.exe (PID: 7156)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 6492)
      • Paysafecard Checker 2024 version.exe (PID: 6968)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6492)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2800)
      • WinRAR.exe (PID: 6492)
    • Creates files or folders in the user directory

      • Paysafecard Checker 2024 version.exe (PID: 7000)
      • WerFault.exe (PID: 2380)
    • Reads the computer name

      • Paysafecard Checker 2024 version.exe (PID: 7000)
      • RGGmHSFtnA.exe (PID: 7156)
      • RGGmHSFtnA.exe (PID: 4576)
    • Process checks computer location settings

      • Paysafecard Checker 2024 version.exe (PID: 7000)
    • Checks supported languages

      • Paysafecard Checker 2024 version.exe (PID: 7000)
      • A4NYx3VxAt.exe (PID: 7136)
      • RGGmHSFtnA.exe (PID: 7156)
      • RGGmHSFtnA.exe (PID: 4576)
    • Reads the software policy settings

      • RGGmHSFtnA.exe (PID: 4576)
      • WerFault.exe (PID: 2380)
      • WerFault.exe (PID: 7096)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 835522
UncompressedSize: 948736
OperatingSystem: Win32
ArchivedFileName: Paysafecard Checker 2024 version.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
11
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe rundll32.exe no specs paysafecard checker  2024 version.exe paysafecard checker  2024 version.exe werfault.exe a4nyx3vxat.exe rggmhsftna.exe #LUMMA rggmhsftna.exe werfault.exe svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2380C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7156 -s 812C:\Windows\SysWOW64\WerFault.exe
RGGmHSFtnA.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2800"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Paysafecard Checker 2024 version.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4576"C:\Users\admin\AppData\Roaming\RGGmHSFtnA.exe"C:\Users\admin\AppData\Roaming\RGGmHSFtnA.exe
RGGmHSFtnA.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Fortune
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\rggmhsftna.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6492"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Paysafecard Checker 2024 version.rar" "?\"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6924C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6968"C:\Users\admin\Desktop\Paysafecard Checker 2024 version\Paysafecard Checker 2024 version.exe" C:\Users\admin\Desktop\Paysafecard Checker 2024 version\Paysafecard Checker 2024 version.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Fortune
Exit code:
3221226505
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\paysafecard checker 2024 version\paysafecard checker 2024 version.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7000"C:\Users\admin\Desktop\Paysafecard Checker 2024 version\Paysafecard Checker 2024 version.exe"C:\Users\admin\Desktop\Paysafecard Checker 2024 version\Paysafecard Checker 2024 version.exe
Paysafecard Checker 2024 version.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Fortune
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\paysafecard checker 2024 version\paysafecard checker 2024 version.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
7096C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6968 -s 840C:\Windows\SysWOW64\WerFault.exe
Paysafecard Checker 2024 version.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7136"C:\Users\admin\AppData\Roaming\A4NYx3VxAt.exe" C:\Users\admin\AppData\Roaming\A4NYx3VxAt.exe
Paysafecard Checker 2024 version.exe
User:
admin
Company:
Microsoft Windows
Integrity Level:
MEDIUM
Description:
system32
Version:
15.6.13.6
Modules
Images
c:\users\admin\appdata\roaming\a4nyx3vxat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
9 782
Read events
9 744
Write events
25
Delete events
13

Modification events

(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Paysafecard Checker 2024 version.rar
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
7
Suspicious files
8
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2380WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_RGGmHSFtnA.exe_1f2a6d3424be61e9da94b719f4b472c5f665df4_3b7a425a_40f4ae4b-e3a8-47ad-b99c-8f2ccd2c2e29\Report.wer
MD5:
SHA256:
7096WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Paysafecard Chec_c6dcc85c5b9e81fb605238a2f2423d9ecca85864_0cb06e96_213ee172-353d-49f8-b350-4f50736369b8\Report.wer
MD5:
SHA256:
2380WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\RGGmHSFtnA.exe.7156.dmp
MD5:
SHA256:
7096WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\Paysafecard Checker 2024 version.exe.6968.dmp
MD5:
SHA256:
6492WinRAR.exeC:\Users\admin\Desktop\Paysafecard Checker 2024 version\Paysafecard Checker 2024 version.exeexecutable
MD5:E02F161B67D93F9D6838F7DD2D7AFF1E
SHA256:23A6CFA29F63C5705DA170C07FEE9088DE24A6FF3E9D61E190E164B38FF9DD37
7000Paysafecard Checker 2024 version.exeC:\Users\admin\AppData\Roaming\A4NYx3VxAt.exeexecutable
MD5:3A96573C06D0D2479145387C10A27082
SHA256:ED6731C5D5DE872E56816984FAF9BB056E4D3E3282862F2F626D2DF75B38D6DA
7096WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERAA4D.tmp.dmpbinary
MD5:95A4D751CB875B026207AC51F4109918
SHA256:59DCE183F35FB4CF1BF401BD101A36DC9A87BA79C1229724D80252DB56656047
2380WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERABD3.tmp.dmpbinary
MD5:33FC3DBBC4C0218EAE18EAB4C0EE187F
SHA256:D507D6E4BBD14AF8003727919EEBA9833110C263598C3661D1E60287263160D5
7000Paysafecard Checker 2024 version.exeC:\Users\admin\AppData\Roaming\RGGmHSFtnA.exeexecutable
MD5:740940254F9BCC3EAA9570C50FEA2C88
SHA256:27C5C7BFA16376C67E7827473AF4A667E659AEBBA81C2CFFA6519D7C76679A45
2380WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:FA84E4BCC92AA5DB735AB50711040CDE
SHA256:6D7205E794FDE4219A62D9692ECDDF612663A5CF20399E79BE87B851FCA4CA33
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
41
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4328
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4400
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4400
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6604
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7096
WerFault.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2380
WerFault.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2380
WerFault.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.23.227.208:443
Ooredoo Q.S.C.
QA
unknown
4328
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4328
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.246.101
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.74
  • 20.190.160.14
  • 40.126.32.76
  • 20.190.160.20
  • 40.126.32.136
  • 40.126.32.138
  • 20.190.160.17
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
classyhelped.net
  • 104.21.16.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.96.1
  • 104.21.112.1
  • 104.21.80.1
  • 104.21.64.1
malicious
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info