File name:

ChatGPT-5 Version 2024 .rar

Full analysis: https://app.any.run/tasks/bb6e94f1-2c77-4ca6-882c-2f1d554213c6
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: January 14, 2025, 23:35:48
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
lumma
stealer
netreactor
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

9F572E86FD993863387ABA91013A3AAC

SHA1:

722B5CA0ED060C9EB300CF157C689D46F2EBBBAB

SHA256:

30BAE88AD4F8ACCA701FBFD5CE1126821C7FFD0BBE63B91F56C6D8D1F33C5047

SSDEEP:

98304:4W9jQY2nLDp4GeDBl9gE16t0mzVA1LEuFYIqWUzs+7DVPRLW9iuV0ah3fn9V7IP8:l6Zpq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6380)
    • Executing a file with an untrusted certificate

      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • aNByg82UQR.exe (PID: 4556)
      • aNByg82UQR.exe (PID: 5308)
    • Create files in the Startup directory

      • P3D2zDTO7Y.exe (PID: 5320)
    • LUMMA mutex has been found

      • aNByg82UQR.exe (PID: 5308)
    • Actions looks like stealing of personal data

      • aNByg82UQR.exe (PID: 5308)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6380)
    • Application launched itself

      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • aNByg82UQR.exe (PID: 4556)
    • Executable content was dropped or overwritten

      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • P3D2zDTO7Y.exe (PID: 5320)
    • Reads security settings of Internet Explorer

      • ChatGPT-5 Version 2024 .exe (PID: 5528)
    • Executes application which crashes

      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • aNByg82UQR.exe (PID: 4556)
    • The process creates files with name similar to system file names

      • P3D2zDTO7Y.exe (PID: 5320)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6380)
      • ChatGPT-5 Version 2024 .exe (PID: 5528)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6380)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6380)
    • Manual execution by a user

      • ChatGPT-5 Version 2024 .exe (PID: 828)
    • Reads the computer name

      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • aNByg82UQR.exe (PID: 4556)
      • P3D2zDTO7Y.exe (PID: 5320)
      • aNByg82UQR.exe (PID: 5308)
    • Checks supported languages

      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • aNByg82UQR.exe (PID: 4556)
      • aNByg82UQR.exe (PID: 5308)
      • P3D2zDTO7Y.exe (PID: 5320)
    • Creates files or folders in the user directory

      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • P3D2zDTO7Y.exe (PID: 5320)
      • WerFault.exe (PID: 5992)
      • WerFault.exe (PID: 4076)
    • Process checks computer location settings

      • ChatGPT-5 Version 2024 .exe (PID: 5528)
    • .NET Reactor protector has been detected

      • ChatGPT-5 Version 2024 .exe (PID: 828)
    • Reads the software policy settings

      • WerFault.exe (PID: 4076)
    • Checks proxy server information

      • WerFault.exe (PID: 4076)
      • WerFault.exe (PID: 5992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 730160
UncompressedSize: 816240
OperatingSystem: Win32
ArchivedFileName: ChatGPT-5 Version 2024 .exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
8
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe chatgpt-5 version 2024 .exe chatgpt-5 version 2024 .exe werfault.exe p3d2zdto7y.exe anbyg82uqr.exe #LUMMA anbyg82uqr.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
828"C:\Users\admin\Desktop\ChatGPT-5 Version 2024 .exe" C:\Users\admin\Desktop\ChatGPT-5 Version 2024 .exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Handler
Exit code:
3221226505
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\chatgpt-5 version 2024 .exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4076C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4556 -s 824C:\Windows\SysWOW64\WerFault.exe
aNByg82UQR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
4556"C:\Users\admin\AppData\Roaming\aNByg82UQR.exe" C:\Users\admin\AppData\Roaming\aNByg82UQR.exe
ChatGPT-5 Version 2024 .exe
User:
admin
Integrity Level:
MEDIUM
Description:
Handler
Exit code:
3221226505
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\anbyg82uqr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5308"C:\Users\admin\AppData\Roaming\aNByg82UQR.exe"C:\Users\admin\AppData\Roaming\aNByg82UQR.exe
aNByg82UQR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Handler
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\anbyg82uqr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
5320"C:\Users\admin\AppData\Roaming\P3D2zDTO7Y.exe" C:\Users\admin\AppData\Roaming\P3D2zDTO7Y.exe
ChatGPT-5 Version 2024 .exe
User:
admin
Company:
Microsoft Windows
Integrity Level:
MEDIUM
Description:
system32
Version:
15.6.13.6
Modules
Images
c:\users\admin\appdata\roaming\p3d2zdto7y.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5528"C:\Users\admin\Desktop\ChatGPT-5 Version 2024 .exe"C:\Users\admin\Desktop\ChatGPT-5 Version 2024 .exe
ChatGPT-5 Version 2024 .exe
User:
admin
Integrity Level:
MEDIUM
Description:
Handler
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\chatgpt-5 version 2024 .exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
5992C:\WINDOWS\SysWOW64\WerFault.exe -u -p 828 -s 828C:\Windows\SysWOW64\WerFault.exe
ChatGPT-5 Version 2024 .exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6380"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ChatGPT-5 Version 2024 .rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
8 788
Read events
8 770
Write events
18
Delete events
0

Modification events

(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ChatGPT-5 Version 2024 .rar
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
7
Suspicious files
6
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
4076WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_aNByg82UQR.exe_59dc1b16fc9448d170acd4bb4afd970442c9f_c5ee0bdb_fd90b6d7-53fa-45af-bc41-3b8397abd885\Report.wer
MD5:
SHA256:
5992WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_ChatGPT-5 Versio_202c5bd92a2c2a557c59622821554da5fb1db591_d072290b_4432dbba-27b1-4559-9636-5ce52c19eaf9\Report.wer
MD5:
SHA256:
4076WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\aNByg82UQR.exe.4556.dmp
MD5:
SHA256:
5992WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\ChatGPT-5 Version 2024 .exe.828.dmp
MD5:
SHA256:
6380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6380.8738\README.txttext
MD5:CF041446161E0D724FB4BB93EA17EE66
SHA256:7B0EBC9F3511D66177B0EB75E5EB94037562AB6F5042E0E78DF800834D362117
6380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6380.8738\NL7Models0804.dllexecutable
MD5:65525C7B89204D241120B7638934A0D2
SHA256:18F7F52F14986133F9A9676D5AB959349377A53C0936CEA6EB9880E72F85BC54
5528ChatGPT-5 Version 2024 .exeC:\Users\admin\AppData\Roaming\P3D2zDTO7Y.exeexecutable
MD5:5AFB8CE4DD3923219BD69BD7B5168D91
SHA256:F727BBA8D917FA3F129D71745E0741A8511F940B1A6817FF5130AA2F3AE85C79
5992WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERC0D4.tmp.xmlxml
MD5:F0595A2128B0D03C281CA6D2CA3C3C39
SHA256:0CA74DD7C01A3916576ACC92B344ED77BE189E8AB74F9A02E4DABDF359805309
6380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6380.8738\NlsData004a.dllexecutable
MD5:BE007B645B9D1332E3346107727320D9
SHA256:7B128BE8D77398CBC3BB789A34E21AFC984C2E87276907A01326F8FB4504E9DA
5320P3D2zDTO7Y.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svhost.exeexecutable
MD5:5AFB8CE4DD3923219BD69BD7B5168D91
SHA256:F727BBA8D917FA3F129D71745E0741A8511F940B1A6817FF5130AA2F3AE85C79
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
47
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6600
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5460
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5460
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4076
WerFault.exe
GET
200
184.24.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5992
WerFault.exe
GET
200
184.24.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4076
WerFault.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
5496
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.72
  • 184.24.77.37
  • 184.24.77.35
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.73
  • 20.190.159.2
  • 20.190.159.68
  • 20.190.159.64
  • 20.190.159.71
  • 40.126.31.69
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info