File name:

lumma.exe

Full analysis: https://app.any.run/tasks/5849a46d-d79d-4167-ab9b-6c943a68cbdd
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: January 08, 2025, 10:12:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
lumma
stealer
opendir
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

5BFFEC5B786B54B8FE06990047BC093D

SHA1:

D00B98ED1046B04E04B90FC79F3DC97D9B92ACF2

SHA256:

25B251A6B74D9D65060CBCF1FCB404252F0146F884039346960C28C369062A2E

SSDEEP:

98304:vhvla/0/18J1+3lh5KDHMk+vyibPenLxkafigws7PbSQ2mkNtxoIllWdyKi0KCxT:uJtShV0j8xzOYo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Setup.exe (PID: 3544)
    • LUMMA mutex has been found

      • Setup.exe (PID: 3544)
    • Actions looks like stealing of personal data

      • Setup.exe (PID: 3544)
    • Steals credentials from Web Browsers

      • Setup.exe (PID: 3544)
    • LUMMA has been detected (SURICATA)

      • Setup.exe (PID: 3544)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • lumma.exe (PID: 2676)
    • Executable content was dropped or overwritten

      • lumma.exe (PID: 2676)
    • Process drops legitimate windows executable

      • lumma.exe (PID: 2676)
    • Reads security settings of Internet Explorer

      • lumma.exe (PID: 2676)
  • INFO

    • Checks supported languages

      • lumma.exe (PID: 2676)
      • identity_helper.exe (PID: 3700)
      • Setup.exe (PID: 3544)
    • Reads the computer name

      • lumma.exe (PID: 2676)
      • identity_helper.exe (PID: 3700)
      • Setup.exe (PID: 3544)
    • The process uses the downloaded file

      • lumma.exe (PID: 2676)
      • msedge.exe (PID: 8188)
    • The sample compiled with english language support

      • lumma.exe (PID: 2676)
    • Create files in a temporary directory

      • lumma.exe (PID: 2676)
    • Manual execution by a user

      • msedge.exe (PID: 6744)
      • msedge.exe (PID: 4244)
      • msedge.exe (PID: 7016)
      • msedge.exe (PID: 6952)
      • msedge.exe (PID: 6880)
      • msedge.exe (PID: 7124)
      • msedge.exe (PID: 2804)
      • msedge.exe (PID: 7520)
      • msedge.exe (PID: 1572)
      • msedge.exe (PID: 432)
      • msedge.exe (PID: 7224)
      • msedge.exe (PID: 7384)
      • msedge.exe (PID: 7848)
      • msedge.exe (PID: 5888)
    • Process checks computer location settings

      • lumma.exe (PID: 2676)
    • Reads Environment values

      • identity_helper.exe (PID: 3700)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 3544)
    • Reads the software policy settings

      • Setup.exe (PID: 3544)
    • Application launched itself

      • msedge.exe (PID: 4244)
    • Sends debugging messages

      • msedge.exe (PID: 8044)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:11 13:00:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 107520
InitializedDataSize: 32768
UninitializedDataSize: -
EntryPoint: 0x19e3c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 24.8.0.0
ProductVersionNumber: 24.8.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 24.08
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2024 Igor Pavlov
OriginalFileName: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 24.08
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
190
Monitored processes
70
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start lumma.exe #LUMMA setup.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs svchost.exe lumma.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2572 --field-trial-handle=2364,i,5172855917469867858,14939879740799581269,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
432"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://cran.r-project.org/package=rlecuyerC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1200"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=34 --mojo-platform-channel-handle=5524 --field-trial-handle=2364,i,5172855917469867858,14939879740799581269,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1572"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://cran.r-project.org/package=bootC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1740"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2356 --field-trial-handle=2364,i,5172855917469867858,14939879740799581269,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2088"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2772 --field-trial-handle=2364,i,5172855917469867858,14939879740799581269,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2676"C:\Users\admin\Desktop\lumma.exe" C:\Users\admin\Desktop\lumma.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7z Setup SFX
Exit code:
0
Version:
24.08
Modules
Images
c:\users\admin\desktop\lumma.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2680"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=29 --mojo-platform-channel-handle=7068 --field-trial-handle=2364,i,5172855917469867858,14939879740799581269,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2804"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://en.wikipedia.org/wiki/Fork_(operating_system)C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
10 207
Read events
10 122
Write events
85
Delete events
0

Modification events

(PID) Process:(4244) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(4244) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
409E4763C5892F00
(PID) Process:(4244) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(4244) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(4244) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(4244) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
A6604F63C5892F00
(PID) Process:(4244) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328160
Operation:writeName:WindowTabManagerFileMappingId
Value:
{E05C9616-9126-44F3-8E7D-7B54BFBC4E11}
(PID) Process:(4244) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328160
Operation:writeName:WindowTabManagerFileMappingId
Value:
{F1D94315-0014-4201-8D3A-10C43105CB82}
(PID) Process:(6744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6744) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
Executable files
6
Suspicious files
180
Text files
133
Unknown types
3

Dropped files

PID
Process
Filename
Type
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\basename_basic.phpttext
MD5:3EFD7C903578564055BAAB694E0ADE79
SHA256:09BC603C893B2C487F7E6023003FE210FF425D808A4C1A7D42FB2E5B12D59586
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\gh16829_2.inctext
MD5:2F5285430DBFD0D8EA2A06874C719EED
SHA256:8DE806AEA30482F9C674967BC84912496262D623C5FB400FB3CA9AB2EC6A345F
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\contains_element_direct_descendent.phpttext
MD5:F2F6726E72E344139C14F57651B82990
SHA256:2FF05001837D2D6D6CE0996559FAC16387DDAB9E19558EEA00F3EF528C45C4C2
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\array_chunk2.phpttext
MD5:8FE5D970030A74AA1FC9825D3B5DE1C7
SHA256:A85E02D4C396A945AFE1E81558689EB439A7F83EB15F4DE79C9BD5BC88C4F16C
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\bug75318.phpttext
MD5:35C2A0E11C9848B0D1B25E85B4ED8F73
SHA256:3A30ED866B7E84E53CA618090710E3420DB746A2E624EA1EDF8E545A406B6761
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\button_element.ctext
MD5:9322B075AF482BF9C4F1656A850DFC2B
SHA256:2BFC9F1B0F51843B82C7900CA34BBD83A6E1E816BFA07862381A57CE5B643802
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\bug79191.phpttext
MD5:6D247ACF9D28FAB348F3BA5B1459996D
SHA256:1F39F502FF5F1E7860A9BC23B0AB203B1ED61078E0D680BEF7C7F158E32A3BB4
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\bug77024.phpttext
MD5:4BD6C6A6178A045BE1D276F9F67FA1CE
SHA256:3346EEE325EA7D3F490029A6D1791E655C385987B4BFD0E438507F128EB5D5E6
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\doc_comment_internal_symbols2.phpttext
MD5:B95ACF233CC6A551A4E08FC89C64612C
SHA256:AC60679BBADA6C81632C9D2BA7753F16F6219B937A3EE22A32A3F2131F035A92
2676lumma.exeC:\Users\admin\AppData\Local\Temp\7zS47A66A43\Data\date_modify_basic1.phpttext
MD5:A6143429262B999AE70BC5BEC63A40C8
SHA256:CDDAEFB0D61EEDFABB42F89416FF056CB88DB44110E4A4DF788F9A65D400CCB8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
118
TCP/UDP connections
85
DNS requests
80
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.10.249.17:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
104.90.25.175:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
OPTIONS
503
2.19.126.152:443
https://bzib.nelreports.net/api/report?cat=bingbusiness
unknown
unknown
GET
200
137.208.57.37:443
https://cran.r-project.org/web/orcid.svg
unknown
image
983 b
whitelisted
GET
200
137.208.57.37:443
https://cran.r-project.org/web/orcid.svg
unknown
image
983 b
unknown
GET
200
13.107.42.16:443
https://config.edge.skype.com/config/v1/Edge/122.0.2365.59?clientId=4489578223053569932&agents=EdgeRuntime%2CEdgeRuntimeConfig%2CEdgeDomainActions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=44&mngd=0&installdate=1661339457&edu=0&bphint=2&soobedate=1504771245&fg=1
unknown
binary
43.2 Kb
whitelisted
GET
200
137.208.57.37:443
https://cran.r-project.org/web/packages/multicore/index.html
unknown
html
945 b
whitelisted
GET
200
13.107.246.45:443
https://xpaywalletcdn.azureedge.net/mswallet/ExpressCheckout/v2/GetEligibleSites?version=0&type=topSite&IsStable=false
unknown
binary
497 b
whitelisted
GET
200
137.208.57.37:443
https://cran.r-project.org/favicon.ico
unknown
image
5.30 Kb
whitelisted
GET
303
137.208.57.37:443
https://cran.r-project.org/package=lattice
unknown
html
334 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
904
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:138
unknown
4712
MoUsoCoreWorker.exe
23.10.249.17:80
crl.microsoft.com
Akamai International B.V.
CH
whitelisted
4712
MoUsoCoreWorker.exe
104.90.25.175:80
www.microsoft.com
AKAMAI-AS
BE
whitelisted
904
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4244
msedge.exe
239.255.255.250:1900
whitelisted
2088
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 23.10.249.17
  • 23.10.249.24
whitelisted
www.microsoft.com
  • 104.90.25.175
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
cran.r-project.org
  • 137.208.57.37
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.253.45
whitelisted
bzib.nelreports.net
  • 2.19.126.152
  • 2.19.126.145
whitelisted

Threats

PID
Process
Class
Message
3544
Setup.exe
A Network Trojan was detected
STEALER [ANY.RUN] Lumma Stealer TLS Connection
No debug info