URL:

https://downloadprofull.cfd/page?71c8cf138463faa1db6d?6ab71e40=3

Full analysis: https://app.any.run/tasks/4a818121-4276-486f-9e9a-f74c87494ffe
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: January 14, 2026, 12:00:09
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
fingerprinting
phishing
lumma
stealer
Indicators:
MD5:

B9C9BEAC702CAFF6C5A6223BC0217C9E

SHA1:

4BFD76EAFD22751D11622620D7584D578650B3AD

SHA256:

34E445D108B71A5C447F71E170904293329D7619F8C7C09344790160E7C9B16C

SSDEEP:

3:N8SE7NLYOEC/GCIEjoTEgz7:2SUvr/jOEM7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LUMMA has been detected (YARA)

      • explorer.exe (PID: 4940)
    • LUMMA mutex has been found

      • explorer.exe (PID: 4940)
    • LUMMA has been detected (SURICATA)

      • chrome.exe (PID: 8616)
    • Steals credentials from Web Browsers

      • explorer.exe (PID: 4940)
    • Actions looks like stealing of personal data

      • explorer.exe (PID: 4940)
  • SUSPICIOUS

    • Canvas fingerprinting is present

      • chrome.exe (PID: 6320)
      • chrome.exe (PID: 9168)
      • chrome.exe (PID: 5628)
    • WebGL fingerprinting is present

      • chrome.exe (PID: 8428)
    • Possible stealing from 2fa

      • explorer.exe (PID: 4940)
    • Contacting a server suspected of hosting an CnC

      • chrome.exe (PID: 8616)
    • There is functionality for taking screenshot (YARA)

      • explorer.exe (PID: 4940)
    • Possible stealing from password managers

      • explorer.exe (PID: 4940)
    • Possible stealing from notes

      • explorer.exe (PID: 4940)
    • Possible stealing from browsers

      • explorer.exe (PID: 4940)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 792)
      • TextInputHost.exe (PID: 8252)
      • application.exe (PID: 4540)
    • Reads Environment values

      • identity_helper.exe (PID: 792)
    • Application launched itself

      • msedge.exe (PID: 7568)
      • chrome.exe (PID: 8428)
      • chrome.exe (PID: 9168)
      • chrome.exe (PID: 6320)
      • chrome.exe (PID: 5628)
    • Reads the computer name

      • identity_helper.exe (PID: 792)
      • TextInputHost.exe (PID: 8252)
    • Manual execution by a user

      • WinRAR.exe (PID: 9012)
      • application.exe (PID: 4540)
    • Checks proxy server information

      • slui.exe (PID: 1188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Lumma

(PID) Process(4940) explorer.exe
C2 (9)basilicros.su/asdasq
broguenko.su/asfase
familyriwo.su/fssdaw
hammernew.su/asdase
heavylussy.su/ccvfd
homuncloud.su/ascasef
izzardtow.su/cascasc
possuhb.cyou
whitepepper.su/asds
ChaCha20
keyn/zAIrxTdMMdwhOpZz7V/5N3gNkIhjCiw9+navaeztQ=
nonce+K8gisCIhRw=
counter0
keyn/zAIrxTdMMdwhOpZz7V/5N3gNkIhjCiw9+navaeztQ=
nonce+K8gisCIhRw=
counter2
Strings (26)%ProgramFiles%\
./,-
547698;:=<?>A@CB%
8g6W
Account
ChromeBuildTools
Content-Disposition: form-data; name="
Content-Disposition: form-data; name="file"; filename="
Content-Type: multipart/form-data; boundary=
Cookie: __cf_mw_byp=
DisplayName
PPPP
Password
QPSR
Software.txt
Wallets/
Web Data
\KnownDlls\
\Microsoft\Windows Mail\Local Folders
\Packages
\storage\default\moz-extension+++
_^]\
cmd.exe "start /min cmd.exe "/c timeout /t 3 /nobreak & del "
dpapi.dll
name="atok" value="
zzzz
C2 (9)basilicros.su/asdasq
broguenko.su/asfase
familyriwo.su/fssdaw
hammernew.su/asdase
heavylussy.su/ccvfd
homuncloud.su/ascasef
izzardtow.su/cascasc
possuhb.cyou
whitepepper.su/asds
ChaCha20
keyn/zAIrxTdMMdwhOpZz7V/5N3gNkIhjCiw9+navaeztQ=
nonce+K8gisCIhRw=
counter2
keyn/zAIrxTdMMdwhOpZz7V/5N3gNkIhjCiw9+navaeztQ=
nonce+K8gisCIhRw=
counter0
Strings (26)%ProgramFiles%\
./,-
547698;:=<?>A@CB%
8g6W
Account
ChromeBuildTools
Content-Disposition: form-data; name="
Content-Disposition: form-data; name="file"; filename="
Content-Type: multipart/form-data; boundary=
Cookie: __cf_mw_byp=
DisplayName
PPPP
Password
QPSR
Software.txt
Wallets/
Web Data
\KnownDlls\
\Microsoft\Windows Mail\Local Folders
\Packages
\storage\default\moz-extension+++
_^]\
cmd.exe "start /min cmd.exe "/c timeout /t 3 /nobreak & del "
dpapi.dll
name="atok" value="
zzzz
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
226
Monitored processes
75
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs textinputhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs application.exe #LUMMA explorer.exe chrome.exe chrome.exe no specs chrome.exe no specs #LUMMA chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs slui.exe chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
756"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5764,i,7432665912037801932,16097581393279365072,262144 --variations-seed-version --mojo-platform-channel-handle=5744 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
792"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6572,i,7432665912037801932,16097581393279365072,262144 --variations-seed-version --mojo-platform-channel-handle=6896 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
800"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=6024,i,7432665912037801932,16097581393279365072,262144 --variations-seed-version --mojo-platform-channel-handle=6136 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1188C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1204"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --disable-quic --string-annotations --field-trial-handle=4644,i,4668982156180442247,18366510688882931880,262144 --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=4596 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1572"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3168,i,8133724453917489415,4480254307285707545,262144 --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3312 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2308"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=2248,i,17752682531847472832,8339006319787195023,262144 --variations-seed-version --mojo-platform-channel-handle=2244 /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2452"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=3616,i,3229501924935132301,13807433340597735730,262144 --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=4760 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2760"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4268,i,7432665912037801932,16097581393279365072,262144 --variations-seed-version --mojo-platform-channel-handle=4280 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3348"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=1160,i,7432665912037801932,16097581393279365072,262144 --variations-seed-version --mojo-platform-channel-handle=7792 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
7 776
Read events
7 771
Write events
5
Delete events
0

Modification events

(PID) Process:(9012) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(9012) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(9012) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(9012) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(9012) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
35
Text files
110
Unknown types
179

Dropped files

PID
Process
Filename
Type
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFfdb24.TMP
MD5:
SHA256:
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFfdb34.TMP
MD5:
SHA256:
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFfdb43.TMP
MD5:
SHA256:
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFfdb43.TMP
MD5:
SHA256:
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFfdb53.TMP
MD5:
SHA256:
7568msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
118
TCP/UDP connections
127
DNS requests
136
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7900
msedge.exe
OPTIONS
200
35.190.80.1:443
https://a.nel.cloudflare.com/report/v4?s=PA5RN%2FiUqMD4ka%2BROUc7wu9uXAtAmyXt%2B47D6Cbxg4ktvCEfjcmjg%2BYvuXwzRWvvBqeQU973iDV12UCS2WGh8uEowvLnZVdjr%2BpxGoqg10Q8PUo%3D
US
unknown
7900
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:9IUeGZ9rkx1kRVE5whaPNEQ0XlsKijpTz_eDKS8x2x0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
binary
98 b
whitelisted
4700
svchost.exe
POST
200
20.190.159.0:443
https://login.live.com/RST2.srf
US
binary
11.1 Kb
whitelisted
7900
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=EdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=65&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1741678270&lafgdate=0
US
binary
892 b
whitelisted
7900
msedge.exe
GET
200
150.171.28.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
text
446 b
whitelisted
7900
msedge.exe
GET
200
104.18.22.222:443
https://copilot.microsoft.com/c/api/user/eligibility
US
text
25 b
whitelisted
7900
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=65&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1768392015&lafgdate=0
US
binary
4.83 Kb
whitelisted
7900
msedge.exe
GET
200
188.114.97.3:443
https://downloadprofull.cfd/page?71c8cf138463faa1db6d?6e66e656=4
US
binary
3.54 Kb
unknown
7900
msedge.exe
GET
200
188.114.97.3:443
https://downloadprofull.cfd/page?71c8cf138463faa1db6d?6ab71e40=3
US
binary
3.54 Kb
unknown
7900
msedge.exe
GET
200
2.16.204.134:443
https://www.bing.com/bloomfilterfiles/ExpandedDomainsFilterGlobal.json
NL
text
128 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1156
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4472
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7900
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7900
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7900
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7900
msedge.exe
104.18.22.222:443
copilot.microsoft.com
CLOUDFLARENET
US
whitelisted
7900
msedge.exe
188.114.97.3:443
downloadprofull.cfd
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
downloadprofull.cfd
  • 188.114.97.3
  • 188.114.96.3
unknown
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted
www.bing.com
  • 2.16.204.134
  • 2.16.204.158
  • 2.16.204.160
  • 2.16.204.132
  • 2.16.204.161
  • 2.16.204.136
  • 2.16.204.135
  • 2.16.204.137
  • 2.16.204.159
  • 2.20.142.184
  • 2.20.142.179
  • 2.20.142.182
  • 92.122.215.2
  • 2.20.142.181
  • 2.20.143.113
  • 2.20.142.4
  • 2.20.142.180
  • 92.122.215.3
whitelisted
a.nel.cloudflare.com
  • 35.190.80.1
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
fantastryrenninsperlection.com
  • 188.114.96.3
  • 188.114.97.3
whitelisted
media.megafilehub4.pics
  • 172.67.178.39
  • 104.21.43.109
unknown

Threats

PID
Process
Class
Message
7900
msedge.exe
Misc activity
ET INFO Observed DNS Query to .cfd TLD
7900
msedge.exe
Misc activity
ET INFO Observed DNS Query to .cfd TLD
7900
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
7900
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Collected Data observed in HTTP POST request
Possible Social Engineering Attempted
ET PHISHING Javascript Browser Fingerprinting POST Request
8616
chrome.exe
Malware Command and Control Activity Detected
ET MALWARE Lumma Stealer Victim Fingerprinting Activity
No debug info