File name:

Paysafecard Checker 2024 version.rar

Full analysis: https://app.any.run/tasks/543a2fdc-f6e8-4d3b-aa87-e74d66139888
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: January 27, 2025, 14:23:49
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
lumma
stealer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

274D3019B9A62DBCD1EA3564FD9B28AC

SHA1:

EBC2D8583F0B5EE9D0EA851D2286CDFE2C11D245

SHA256:

061B1F65DF3B9CD8B3C683FF87041822E970B0EA74971170492992F5E8F94320

SSDEEP:

98304:2jhiPk3ygUIMEqoKrZAZmoL3SUjTghck08KopAj0wpFf7o2e1hHTHt072v0Fb1fi:qH8ZB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LUMMA mutex has been found

      • RGGmHSFtnA.exe (PID: 4576)
    • Actions looks like stealing of personal data

      • RGGmHSFtnA.exe (PID: 4576)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2800)
      • WinRAR.exe (PID: 6492)
    • Reads security settings of Internet Explorer

      • Paysafecard Checker 2024 version.exe (PID: 7000)
    • Executes application which crashes

      • Paysafecard Checker 2024 version.exe (PID: 6968)
      • RGGmHSFtnA.exe (PID: 7156)
    • Executable content was dropped or overwritten

      • Paysafecard Checker 2024 version.exe (PID: 7000)
      • A4NYx3VxAt.exe (PID: 7136)
    • Application launched itself

      • Paysafecard Checker 2024 version.exe (PID: 6968)
      • RGGmHSFtnA.exe (PID: 7156)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 6492)
      • WinRAR.exe (PID: 2800)
    • Manual execution by a user

      • WinRAR.exe (PID: 6492)
      • Paysafecard Checker 2024 version.exe (PID: 6968)
    • Creates files or folders in the user directory

      • Paysafecard Checker 2024 version.exe (PID: 7000)
      • WerFault.exe (PID: 2380)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6492)
    • Process checks computer location settings

      • Paysafecard Checker 2024 version.exe (PID: 7000)
    • Checks supported languages

      • Paysafecard Checker 2024 version.exe (PID: 7000)
      • RGGmHSFtnA.exe (PID: 7156)
      • A4NYx3VxAt.exe (PID: 7136)
      • RGGmHSFtnA.exe (PID: 4576)
    • Reads the computer name

      • Paysafecard Checker 2024 version.exe (PID: 7000)
      • RGGmHSFtnA.exe (PID: 7156)
      • RGGmHSFtnA.exe (PID: 4576)
    • Reads the software policy settings

      • WerFault.exe (PID: 7096)
      • RGGmHSFtnA.exe (PID: 4576)
      • WerFault.exe (PID: 2380)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 835522
UncompressedSize: 948736
OperatingSystem: Win32
ArchivedFileName: Paysafecard Checker 2024 version.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
11
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe rundll32.exe no specs paysafecard checker  2024 version.exe paysafecard checker  2024 version.exe werfault.exe a4nyx3vxat.exe rggmhsftna.exe #LUMMA rggmhsftna.exe werfault.exe svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2380C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7156 -s 812C:\Windows\SysWOW64\WerFault.exe
RGGmHSFtnA.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2800"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Paysafecard Checker 2024 version.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4576"C:\Users\admin\AppData\Roaming\RGGmHSFtnA.exe"C:\Users\admin\AppData\Roaming\RGGmHSFtnA.exe
RGGmHSFtnA.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Fortune
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\rggmhsftna.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6492"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Paysafecard Checker 2024 version.rar" "?\"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6924C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6968"C:\Users\admin\Desktop\Paysafecard Checker 2024 version\Paysafecard Checker 2024 version.exe" C:\Users\admin\Desktop\Paysafecard Checker 2024 version\Paysafecard Checker 2024 version.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Fortune
Exit code:
3221226505
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\paysafecard checker 2024 version\paysafecard checker 2024 version.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7000"C:\Users\admin\Desktop\Paysafecard Checker 2024 version\Paysafecard Checker 2024 version.exe"C:\Users\admin\Desktop\Paysafecard Checker 2024 version\Paysafecard Checker 2024 version.exe
Paysafecard Checker 2024 version.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Fortune
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\paysafecard checker 2024 version\paysafecard checker 2024 version.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
7096C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6968 -s 840C:\Windows\SysWOW64\WerFault.exe
Paysafecard Checker 2024 version.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7136"C:\Users\admin\AppData\Roaming\A4NYx3VxAt.exe" C:\Users\admin\AppData\Roaming\A4NYx3VxAt.exe
Paysafecard Checker 2024 version.exe
User:
admin
Company:
Microsoft Windows
Integrity Level:
MEDIUM
Description:
system32
Version:
15.6.13.6
Modules
Images
c:\users\admin\appdata\roaming\a4nyx3vxat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
9 782
Read events
9 744
Write events
25
Delete events
13

Modification events

(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Paysafecard Checker 2024 version.rar
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(2800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
7
Suspicious files
8
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2380WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_RGGmHSFtnA.exe_1f2a6d3424be61e9da94b719f4b472c5f665df4_3b7a425a_40f4ae4b-e3a8-47ad-b99c-8f2ccd2c2e29\Report.wer
MD5:
SHA256:
7096WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Paysafecard Chec_c6dcc85c5b9e81fb605238a2f2423d9ecca85864_0cb06e96_213ee172-353d-49f8-b350-4f50736369b8\Report.wer
MD5:
SHA256:
2380WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\RGGmHSFtnA.exe.7156.dmp
MD5:
SHA256:
7096WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\Paysafecard Checker 2024 version.exe.6968.dmp
MD5:
SHA256:
6492WinRAR.exeC:\Users\admin\Desktop\Paysafecard Checker 2024 version\NlsData0027.dllexecutable
MD5:DD7B568F7B0DDCB39862485DF11B7758
SHA256:DED1FBD837BE8BF6DC429035D13792C902CEA5A5AF6BAE847E4BE3BFF7258FFD
2380WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERAC62.tmp.xmlxml
MD5:E74627A3AE6EB2140A04F1F386E7D920
SHA256:BDA3A8ACA7C1D38FDC476E5E2745D6118CC7ACF6A9627FEF156F720359C0F53B
7136A4NYx3VxAt.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svhost.exeexecutable
MD5:3A96573C06D0D2479145387C10A27082
SHA256:ED6731C5D5DE872E56816984FAF9BB056E4D3E3282862F2F626D2DF75B38D6DA
2380WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERABD3.tmp.dmpbinary
MD5:33FC3DBBC4C0218EAE18EAB4C0EE187F
SHA256:D507D6E4BBD14AF8003727919EEBA9833110C263598C3661D1E60287263160D5
2380WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERAC42.tmp.WERInternalMetadata.xmlbinary
MD5:FA54DA69D418A3FA4EF89D88DF4BDB25
SHA256:19498A780D1B1814500907D5C0BC91CC92AC13DA86961D426020FB736E1075F9
2380WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:FA84E4BCC92AA5DB735AB50711040CDE
SHA256:6D7205E794FDE4219A62D9692ECDDF612663A5CF20399E79BE87B851FCA4CA33
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
41
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4328
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4400
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4400
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6604
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7096
WerFault.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2380
WerFault.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2380
WerFault.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.23.227.208:443
Ooredoo Q.S.C.
QA
unknown
4328
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4328
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.246.101
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.74
  • 20.190.160.14
  • 40.126.32.76
  • 20.190.160.20
  • 40.126.32.136
  • 40.126.32.138
  • 20.190.160.17
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
classyhelped.net
  • 104.21.16.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.96.1
  • 104.21.112.1
  • 104.21.80.1
  • 104.21.64.1
malicious
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info