File name:

Inject.exe

Full analysis: https://app.any.run/tasks/4266a7f8-aed3-4580-a919-89f2287de8f5
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: February 17, 2025, 19:25:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
lumma
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 4 sections
MD5:

1A24B01092E9449C0BB923E04D1C92E8

SHA1:

00ED2587BEC8572040277C7F21C0FF98C7C3C183

SHA256:

278F02F32116C24FDEBB4F5C1CD1431EDCB6BDD7D569FEF088C5DB0FDB147A4C

SSDEEP:

12288:XAfnOSgS7Yo192O5B7bwdfjvF7U+Bhjh+oY8CYWxe2Vbmp:XAfOSgS7T1sO5B7ctFU+BBhPY8PWxe2I

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LUMMA mutex has been found

      • Inject.exe (PID: 4500)
    • Steals credentials from Web Browsers

      • Inject.exe (PID: 4500)
    • Actions looks like stealing of personal data

      • Inject.exe (PID: 4500)
  • SUSPICIOUS

    • Application launched itself

      • Inject.exe (PID: 4132)
    • Executes application which crashes

      • Inject.exe (PID: 4132)
    • Searches for installed software

      • Inject.exe (PID: 4500)
  • INFO

    • Checks supported languages

      • Inject.exe (PID: 4132)
      • Inject.exe (PID: 4500)
    • Reads the computer name

      • Inject.exe (PID: 4132)
      • Inject.exe (PID: 4500)
    • Checks proxy server information

      • WerFault.exe (PID: 5340)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 5340)
    • Reads the software policy settings

      • Inject.exe (PID: 4500)
      • WerFault.exe (PID: 5340)
    • Creates files in the program directory

      • Inject.exe (PID: 4500)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (81)
.dll | Win32 Dynamic Link Library (generic) (7.2)
.exe | Win32 Executable (generic) (4.9)
.exe | Win16/32 Executable Delphi generic (2.2)
.exe | Generic Win/DOS Executable (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2082:12:30 23:42:09+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 8192
InitializedDataSize: 1024
UninitializedDataSize: -
EntryPoint: 0x3a1a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start inject.exe #LUMMA inject.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
4132"C:\Users\admin\AppData\Local\Temp\Inject.exe" C:\Users\admin\AppData\Local\Temp\Inject.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226505
Modules
Images
c:\users\admin\appdata\local\temp\inject.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4500"C:\Users\admin\AppData\Local\Temp\Inject.exe"C:\Users\admin\AppData\Local\Temp\Inject.exe
Inject.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\inject.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
5340C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4132 -s 968C:\Windows\SysWOW64\WerFault.exe
Inject.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
3 622
Read events
3 622
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
19
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4500Inject.exeC:\ProgramData\05DEFC101BA27D27.dat
MD5:
SHA256:
4500Inject.exeC:\ProgramData\6D6934415E3177C7.datbinary
MD5:06AD9E737639FDC745B3B65312857109
SHA256:C8925892CA8E213746633033AE95ACFB8DD9531BC376B82066E686AC6F40A404
5340WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Inject.exe_6f3eac7aaf5c6ca5ac4ddbd33c9cc4e1fb035c6_0d54e89d_04621420-8c75-4178-a0e0-633a972b56a3\Report.wer
MD5:
SHA256:
5340WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\Inject.exe.4132.dmp
MD5:
SHA256:
5340WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER6007.tmp.xmlxml
MD5:5392634B9253FA1B098BA7EFA2E07E59
SHA256:7F3548257FEDDE4827BAB7FF57C17F62567B34962CD182C7D5E23CF833F4D594
4500Inject.exeC:\ProgramData\2446B99C208BBFA2.datbinary
MD5:C52CD961FB8188CE1B3D97815AA02978
SHA256:FE95CAC7B0F158D55188CE091428A8623DB31C927EDA38DC35411D4CB67EA71E
4500Inject.exeC:\ProgramData\01134485ABC76069.datbinary
MD5:0B2213BCE3950F1E95FEEB8E8B3B9543
SHA256:71DB3D87713A320BA9FD3043392509B430630CFCF574EE84118406D6471CFC5A
4500Inject.exeC:\ProgramData\96985D6E8282723D.datbinary
MD5:0FF3BCDD0BE077B9EB8194B5C09F453C
SHA256:225D669E47EB14D8C969799C92AAEF27B66CD984872EA09284E48DB46521E651
4500Inject.exeC:\ProgramData\D6E68678BBF247D8.datbinary
MD5:19BA68C3ECBCA72C2B90AFADDE745DC6
SHA256:8B3758EE2D2C0A07EE7003F902F0667ABE5D9667941F8617EDA3CDF94C78E7B8
4500Inject.exeC:\ProgramData\BB91CD8D4DA3B886.datbinary
MD5:DC9ADB7DE19A6753CE90AE94738BFDEF
SHA256:884B04032E2E70A002956218E8EC3491F2B753C4596CEE6E4894DC49AFA0A681
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
41
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5340
WerFault.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
1356
svchost.exe
GET
200
23.48.23.181:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
1356
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
1224
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
1224
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
5340
WerFault.exe
GET
200
23.48.23.181:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
4840
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
DE
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5580
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1356
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4500
Inject.exe
104.21.80.1:443
impactsupport.world
CLOUDFLARENET
unknown
5340
WerFault.exe
52.182.143.212:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5340
WerFault.exe
23.48.23.181:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5340
WerFault.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
1356
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
impactsupport.world
  • 104.21.80.1
  • 104.21.48.1
  • 104.21.32.1
  • 104.21.64.1
  • 104.21.16.1
  • 104.21.112.1
  • 104.21.96.1
unknown
watson.events.data.microsoft.com
  • 52.182.143.212
whitelisted
crl.microsoft.com
  • 23.48.23.181
  • 23.48.23.194
  • 23.48.23.174
  • 23.48.23.193
  • 23.48.23.188
  • 23.48.23.191
  • 23.48.23.183
  • 23.48.23.185
  • 23.48.23.137
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
www.bing.com
  • 184.86.251.20
  • 184.86.251.4
  • 184.86.251.30
  • 184.86.251.12
  • 184.86.251.27
  • 184.86.251.15
  • 184.86.251.9
  • 184.86.251.10
  • 184.86.251.24
whitelisted
login.live.com
  • 20.190.160.14
  • 20.190.160.65
  • 20.190.160.132
  • 20.190.160.3
  • 40.126.32.140
  • 40.126.32.68
  • 20.190.160.67
  • 20.190.160.130
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted

Threats

No threats detected
No debug info