| File name: | Driver Easy Professional 6.1.2 Build 29728 Multilingual.rar |
| Full analysis: | https://app.any.run/tasks/02149975-3793-4129-b47a-653207754998 |
| Verdict: | Malicious activity |
| Threats: | Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat. |
| Analysis date: | June 20, 2025, 11:10:17 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 16B5B4558AA30C2A6436C91DCAE4FE4C |
| SHA1: | 29E7BD378261B466AA820339C7D7A3CF38A53CF9 |
| SHA256: | 2BB11D3B6E6DF436D52B1020AFBA1F5BAB66BF1A715E1A18F149075DF9AEDE28 |
| SSDEEP: | 196608:VgKAEMZfxZAjFLGsqvbSCix4eeZQ1pCVc96D:VgKoxZAtG4Ci76D |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | "C:\Program Files\Easeware\DriverEasy\Easeware.CheckScheduledScan.exe" -create "Driver Easy Scheduled Scan" "C:\Program Files\Easeware\DriverEasy\DriverEasy.exe" | C:\Program Files\Easeware\DriverEasy\Easeware.CheckScheduledScan.exe | — | Update.tmp | |||||||||||
User: admin Company: Easeware Integrity Level: HIGH Description: Easeware.CheckScheduledScan Exit code: 0 Version: 1.0.1.0 Modules
| |||||||||||||||
| 1328 | "C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exe" | C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1352 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | Easeware.ConfigLanguageFromSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2512 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2552 | "C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exe" | C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2864 | "C:\Program Files\Easeware\DriverEasy\Easeware.ConfigLanguageFromSetup.exe" DriverEasy en True True | C:\Program Files\Easeware\DriverEasy\Easeware.ConfigLanguageFromSetup.exe | — | Update.tmp | |||||||||||
User: admin Company: Easeware Integrity Level: HIGH Description: Easeware.ConfigLanguageFromSetup Exit code: 0 Version: 1.0.4.0 Modules
| |||||||||||||||
| 4012 | "C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Update.exe" /SPAWNWND=$20292 /NOTIFYWND=$902FE | C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Update.exe | Update.tmp | ||||||||||||
User: admin Company: Easeware Integrity Level: HIGH Description: Driver Easy Setup Exit code: 0 Version: 6.1.2.29728 Modules
| |||||||||||||||
| 4216 | "C:\Users\admin\AppData\Local\Temp\is-17IAG.tmp\Update.tmp" /SL5="$902FE,5886360,1001472,C:\Users\admin\Desktop\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Update.exe" | C:\Users\admin\AppData\Local\Temp\is-17IAG.tmp\Update.tmp | — | Update.exe | |||||||||||
User: admin Company: Easeware Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 4648 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4920 | C:\WINDOWS\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6188) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6188) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6188) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6188) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Driver Easy Professional 6.1.2 Build 29728 Multilingual.rar | |||
| (PID) Process: | (6188) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6188) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6188) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6188) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6188) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (4944) Update.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\drivereasy |
| Operation: | write | Name: | URL Protocol |
Value: C:\Program Files\Easeware\DriverEasy\DriverEasy.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6188 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb6188.14234\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Crack\DriverEasy.exe | executable | |
MD5:2AD4C29143EDAB662B5628B406C69997 | SHA256:C19F96F1152AF35079EB0518F1D37DF4943B487CE129D42AB06428E15056C35D | |||
| 6188 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb6188.14234\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Crack\Easeware.Driver.Core.dll | executable | |
MD5:5FBED1A129A4B373540FBC1ABB139BD1 | SHA256:1366C09D3205A0811B34505D0838AECA9BA608E536720011D894C9E0C0AD2D9C | |||
| 6188 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb6188.14234\Driver Easy Professional 6.1.2 Build 29728 Multilingual\Readme.txt | text | |
MD5:4D6EFB754425805ACB799486198AB25A | SHA256:4E7F065810DCD6BB07F91D441F5311C68F5BB05355EEFE3AA2A8A5936F022A06 | |||
| 6188 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb6188.14234\Driver Easy Professional 6.1.2 Build 29728 Multilingual\DriverEasy_Setup.exe | executable | |
MD5:508C9F6F267F8225A036A099B8EF00EA | SHA256:89EABA5095758C079AD0741FAB8265B33F2E54C59D120C3D39E2BE1E6D8DAA87 | |||
| 4944 | Update.tmp | C:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 4944 | Update.tmp | C:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\progressbar_installing_bg.png | image | |
MD5:F89C33EA10E1E74A5800825D61F2D9CB | SHA256:19E715E35AD72909E62D955D5937D64777835A29893E906778E07BC390AEF8D0 | |||
| 4944 | Update.tmp | C:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\installation_custom_bg.png | image | |
MD5:F8019142C2F57318722815C32A8A6C8A | SHA256:405061A501456495890F7FC9D68BF2F0BA14AF9CBC57A5368FE20DBD8BD9AA55 | |||
| 4944 | Update.tmp | C:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\checkbox_license_selected.png | image | |
MD5:C482CC0A34C3DB2CC13184077E5D47DB | SHA256:EA6EFC70A57E8AD44F466181BBFA5C56059E4EEB4161A2B15E8651C86A100D09 | |||
| 4944 | Update.tmp | C:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\progressbar_bg.png | image | |
MD5:3FCE8F03DC579CBCE9D449BBBF8646B7 | SHA256:61F7B00AE88F700A3D864D2B91A48F463430086B778C16C7197A5523B0A46934 | |||
| 4944 | Update.tmp | C:\Users\admin\AppData\Local\Temp\is-AIPKT.tmp\circle.png | image | |
MD5:A80F464B60816479334B6C5B39DBFF18 | SHA256:B532762A4C797E209C5DA897F4A0BCED5DFA19D34DB66BAFC7455FA019BA4E17 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3100 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.55.104.172:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7092 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7092 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4692 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
2940 | svchost.exe | GET | 200 | 23.209.209.135:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
3720 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2468 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2336 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
3100 | svchost.exe | 20.190.159.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3100 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
4944 | DriverEasy_Setup.exe | 85.90.196.155:443 | gewgb.xyz | — | UA | unknown |
5944 | MoUsoCoreWorker.exe | 23.55.104.172:80 | crl.microsoft.com | Akamai International B.V. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
gewgb.xyz |
| unknown |
nexusrules.officeapps.live.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |