File name:

ChatGPT-5 Version 2024 .rar

Full analysis: https://app.any.run/tasks/bb6e94f1-2c77-4ca6-882c-2f1d554213c6
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: January 14, 2025, 23:35:48
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
lumma
stealer
netreactor
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

9F572E86FD993863387ABA91013A3AAC

SHA1:

722B5CA0ED060C9EB300CF157C689D46F2EBBBAB

SHA256:

30BAE88AD4F8ACCA701FBFD5CE1126821C7FFD0BBE63B91F56C6D8D1F33C5047

SSDEEP:

98304:4W9jQY2nLDp4GeDBl9gE16t0mzVA1LEuFYIqWUzs+7DVPRLW9iuV0ah3fn9V7IP8:l6Zpq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6380)
    • Executing a file with an untrusted certificate

      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • aNByg82UQR.exe (PID: 4556)
      • aNByg82UQR.exe (PID: 5308)
    • Create files in the Startup directory

      • P3D2zDTO7Y.exe (PID: 5320)
    • LUMMA mutex has been found

      • aNByg82UQR.exe (PID: 5308)
    • Actions looks like stealing of personal data

      • aNByg82UQR.exe (PID: 5308)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6380)
    • Application launched itself

      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • aNByg82UQR.exe (PID: 4556)
    • Reads security settings of Internet Explorer

      • ChatGPT-5 Version 2024 .exe (PID: 5528)
    • Executable content was dropped or overwritten

      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • P3D2zDTO7Y.exe (PID: 5320)
    • Executes application which crashes

      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • aNByg82UQR.exe (PID: 4556)
    • The process creates files with name similar to system file names

      • P3D2zDTO7Y.exe (PID: 5320)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6380)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6380)
      • ChatGPT-5 Version 2024 .exe (PID: 5528)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6380)
    • Creates files or folders in the user directory

      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • P3D2zDTO7Y.exe (PID: 5320)
      • WerFault.exe (PID: 5992)
      • WerFault.exe (PID: 4076)
    • Checks supported languages

      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • aNByg82UQR.exe (PID: 4556)
      • P3D2zDTO7Y.exe (PID: 5320)
      • aNByg82UQR.exe (PID: 5308)
    • Reads the computer name

      • ChatGPT-5 Version 2024 .exe (PID: 5528)
      • ChatGPT-5 Version 2024 .exe (PID: 828)
      • P3D2zDTO7Y.exe (PID: 5320)
      • aNByg82UQR.exe (PID: 4556)
      • aNByg82UQR.exe (PID: 5308)
    • Manual execution by a user

      • ChatGPT-5 Version 2024 .exe (PID: 828)
    • Process checks computer location settings

      • ChatGPT-5 Version 2024 .exe (PID: 5528)
    • Checks proxy server information

      • WerFault.exe (PID: 5992)
      • WerFault.exe (PID: 4076)
    • .NET Reactor protector has been detected

      • ChatGPT-5 Version 2024 .exe (PID: 828)
    • Reads the software policy settings

      • WerFault.exe (PID: 4076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 730160
UncompressedSize: 816240
OperatingSystem: Win32
ArchivedFileName: ChatGPT-5 Version 2024 .exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
8
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe chatgpt-5 version 2024 .exe chatgpt-5 version 2024 .exe werfault.exe p3d2zdto7y.exe anbyg82uqr.exe #LUMMA anbyg82uqr.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
828"C:\Users\admin\Desktop\ChatGPT-5 Version 2024 .exe" C:\Users\admin\Desktop\ChatGPT-5 Version 2024 .exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Handler
Exit code:
3221226505
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\chatgpt-5 version 2024 .exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4076C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4556 -s 824C:\Windows\SysWOW64\WerFault.exe
aNByg82UQR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
4556"C:\Users\admin\AppData\Roaming\aNByg82UQR.exe" C:\Users\admin\AppData\Roaming\aNByg82UQR.exe
ChatGPT-5 Version 2024 .exe
User:
admin
Integrity Level:
MEDIUM
Description:
Handler
Exit code:
3221226505
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\anbyg82uqr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5308"C:\Users\admin\AppData\Roaming\aNByg82UQR.exe"C:\Users\admin\AppData\Roaming\aNByg82UQR.exe
aNByg82UQR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Handler
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\anbyg82uqr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
5320"C:\Users\admin\AppData\Roaming\P3D2zDTO7Y.exe" C:\Users\admin\AppData\Roaming\P3D2zDTO7Y.exe
ChatGPT-5 Version 2024 .exe
User:
admin
Company:
Microsoft Windows
Integrity Level:
MEDIUM
Description:
system32
Version:
15.6.13.6
Modules
Images
c:\users\admin\appdata\roaming\p3d2zdto7y.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5528"C:\Users\admin\Desktop\ChatGPT-5 Version 2024 .exe"C:\Users\admin\Desktop\ChatGPT-5 Version 2024 .exe
ChatGPT-5 Version 2024 .exe
User:
admin
Integrity Level:
MEDIUM
Description:
Handler
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\chatgpt-5 version 2024 .exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
5992C:\WINDOWS\SysWOW64\WerFault.exe -u -p 828 -s 828C:\Windows\SysWOW64\WerFault.exe
ChatGPT-5 Version 2024 .exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6380"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ChatGPT-5 Version 2024 .rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
8 788
Read events
8 770
Write events
18
Delete events
0

Modification events

(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ChatGPT-5 Version 2024 .rar
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(6380) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
7
Suspicious files
6
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
4076WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_aNByg82UQR.exe_59dc1b16fc9448d170acd4bb4afd970442c9f_c5ee0bdb_fd90b6d7-53fa-45af-bc41-3b8397abd885\Report.wer
MD5:
SHA256:
5992WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_ChatGPT-5 Versio_202c5bd92a2c2a557c59622821554da5fb1db591_d072290b_4432dbba-27b1-4559-9636-5ce52c19eaf9\Report.wer
MD5:
SHA256:
4076WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\aNByg82UQR.exe.4556.dmp
MD5:
SHA256:
5992WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\ChatGPT-5 Version 2024 .exe.828.dmp
MD5:
SHA256:
5992WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERC096.tmp.WERInternalMetadata.xmlxml
MD5:CE6A9B3308CFC9B34838E3541C5DA250
SHA256:77EE20B58A36B38426815DBAD9C7C8E66556A312FA27A85BE8FA060FBBCBA6A0
6380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6380.8738\ChatGPT-5 Version 2024 .exeexecutable
MD5:5DCAD19D36E676074DDE4A916BB8971B
SHA256:80FB3DE057CB6FE6982362B59AB22AAAB2F5DEDA3DBA1F4281106FA2CFC76F41
5992WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERBF1D.tmp.dmpbinary
MD5:AB122A903697E34B6C24C2B7E069C25A
SHA256:99B8B26518E256DA7866EB2572F32F2D93E1D05900C7A1E0D2F86613508FEAB7
6380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6380.8738\README.txttext
MD5:CF041446161E0D724FB4BB93EA17EE66
SHA256:7B0EBC9F3511D66177B0EB75E5EB94037562AB6F5042E0E78DF800834D362117
4076WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERC095.tmp.WERInternalMetadata.xmlxml
MD5:D38CDB721E25F36C65977F151BFE6D54
SHA256:BE47F116E19B33D317F07E07216AEA751D51007004F8075A7AA30C02205C7019
5528ChatGPT-5 Version 2024 .exeC:\Users\admin\AppData\Roaming\P3D2zDTO7Y.exeexecutable
MD5:5AFB8CE4DD3923219BD69BD7B5168D91
SHA256:F727BBA8D917FA3F129D71745E0741A8511F940B1A6817FF5130AA2F3AE85C79
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
47
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6600
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5460
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5460
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5992
WerFault.exe
GET
200
184.24.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4076
WerFault.exe
GET
200
184.24.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4076
WerFault.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
5496
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.72
  • 184.24.77.37
  • 184.24.77.35
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.73
  • 20.190.159.2
  • 20.190.159.68
  • 20.190.159.64
  • 20.190.159.71
  • 40.126.31.69
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info