File name:

SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070

Full analysis: https://app.any.run/tasks/4d2d4955-5699-4c76-aa0f-4faf5bfb4e28
Verdict: Malicious activity
Analysis date: August 01, 2024, 11:39:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

94048307163C44F9BF90D97A66BBB971

SHA1:

F1EE4726BBB346021ECD77C78CEECE71B3EEF876

SHA256:

3FCF907314F1AC7B2E4E564A1783306D6E4356C15E2DCAF193CBC5BACD4356A1

SSDEEP:

98304:717924Hk3l3E7YIlzYREpIMxODzs7r87RjsNrQtqYF0zwgcT/s1aDtyFIvnUo+xi:ECrCTdSFVA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
    • Reads security settings of Internet Explorer

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
    • Creates a software uninstall entry

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
    • Reads the date of Windows installation

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
    • Reads Internet Explorer settings

      • hh.exe (PID: 6724)
    • Reads Microsoft Outlook installation path

      • hh.exe (PID: 6724)
  • INFO

    • Checks supported languages

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
      • EarthTime.exe (PID: 6672)
    • Creates files in the program directory

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
      • EarthTime.exe (PID: 6672)
    • Reads the computer name

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
      • EarthTime.exe (PID: 6672)
    • Creates files or folders in the user directory

      • EarthTime.exe (PID: 6672)
      • hh.exe (PID: 6724)
    • Process checks computer location settings

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
    • Create files in a temporary directory

      • SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe (PID: 6384)
      • hh.exe (PID: 6724)
    • Reads security settings of Internet Explorer

      • hh.exe (PID: 6724)
    • Reads the machine GUID from the registry

      • EarthTime.exe (PID: 6672)
    • Reads Microsoft Office registry keys

      • hh.exe (PID: 6724)
    • Checks proxy server information

      • hh.exe (PID: 6724)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:30 15:50:00+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 149504
InitializedDataSize: 5847552
UninitializedDataSize: -
EntryPoint: 0xdf33
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
4
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start securiteinfo.com.bscope.trojanpsw.lumma.8517.20070.exe earthtime.exe hh.exe no specs securiteinfo.com.bscope.trojanpsw.lumma.8517.20070.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6336"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.bscope.trojanpsw.lumma.8517.20070.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6384"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.bscope.trojanpsw.lumma.8517.20070.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6672"C:\Program Files (x86)\EarthTime\EarthTime.exe"C:\Program Files (x86)\EarthTime\EarthTime.exe
SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe
User:
admin
Company:
DeskSoft
Integrity Level:
MEDIUM
Description:
EarthTime Application
Version:
6.26.12
Modules
Images
c:\program files (x86)\earthtime\earthtime.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6724"C:\WINDOWS\hh.exe" C:\Program Files (x86)\EarthTime\EarthTime.chmC:\Windows\hh.exeSecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® HTML Help Executable
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\hh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
4 724
Read events
4 688
Write events
36
Delete events
0

Modification events

(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\MHDSYS32
Operation:writeName:C2A9A8FD6
Value:
(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DeskSoft
Operation:writeName:EarthTime
Value:
010071F1725AFDA8A9C206001A00010000000000433A5C50726F6772616D2046696C65732028783836295C456172746854696D65000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000433A5C55736572735C61646D696E5C417070446174615C526F616D696E675C4465736B536F66745C456172746854696D6500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000687474703A2F2F7777772E6465736B736F66742E636F6D2F456172746854696D655F50757263686173652E68746D00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000687474703A2F2F7777772E6465736B736F66742E636F6D2F5041442F45545F5645522E545854000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000687474703A2F2F7777772E6465736B736F66742E636F6D2F456172746854696D655F446F776E6C6F61642E68746D000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
12
(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime
Operation:writeName:DisplayName
Value:
EarthTime
(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\EarthTime\EarthTime.exe,0
(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime
Operation:writeName:DisplayVersion
Value:
6.26.12
(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime
Operation:writeName:Publisher
Value:
DeskSoft
(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime
Operation:writeName:HelpLink
Value:
http://www.desksoft.com
(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime
Operation:writeName:URLInfoAbout
Value:
http://www.desksoft.com
(PID) Process:(6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime
Operation:writeName:URLUpdateInfo
Value:
http://www.desksoft.com
Executable files
2
Suspicious files
17
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
6384SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeC:\Program Files (x86)\EarthTime\EarthTime.exeexecutable
MD5:870B1AFB8F77FA84C585AA6D8854BB63
SHA256:5455A46985EA47F32B04DA25F05F88B6FEEC10DA3A6E80FC9BD8B9A96C5A8511
6384SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeC:\Program Files (x86)\EarthTime\Uninstall.exeexecutable
MD5:E6EC95C816F6AD7BDA80D7E345752AC0
SHA256:F84A96AB6140F89335BC6208EDBDD3C36DD5B1F7C7C7ACE1FB2E3DEA352461FB
6384SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeC:\Program Files (x86)\EarthTime\Timezones.txttext
MD5:212D425B4819F3DFA0ECA792FA902C3D
SHA256:E004A32F598C29F0091BEC5402C0C7AC0FDB7694E83D85713D1435F49E01C180
6384SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeC:\Program Files (x86)\EarthTime\Bell.wavbinary
MD5:B0B4C5512956D65A0D1B94B7E405AC51
SHA256:20861886CAB526264EF1FAE6AA9046BEA78730387686944049236CC2BE127239
6384SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeC:\Program Files (x86)\EarthTime\Cities.txttext
MD5:49F0CEB97C2AED28E21352DB468B4EB9
SHA256:0C434ADC4CDE8A7C829B1512176BC9B130C4957E881539C1FDF4DDB73484EB0C
6384SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeC:\Program Files (x86)\EarthTime\Clouds.intbinary
MD5:707BC948298DAECCC72448CD0DC5D51B
SHA256:B4B2572569C6CCFC57D7637D31C4BC6BA9D7A79FB027881DC2FEADE60DDD775E
6384SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeC:\Program Files (x86)\EarthTime\EarthTime.chmbinary
MD5:2B0CFD02A4ED744F12C03797BC33FB30
SHA256:C73A8D73386CDF1DFA0C8120E8C8B5DE5624210D0B278F67109847007FBAC4E0
6384SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeC:\Program Files (x86)\EarthTime\Timezones.datcompressed
MD5:608EDD39B7023B5D23E50D8E7148AEC6
SHA256:AACED5BA8E3EA7134DE286A6F5CB6E2BE0B6197BE890837CD0120C454BAC8D1C
6384SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exeC:\Users\admin\AppData\Local\Temp\Temp.lnkbinary
MD5:1DF95DD185D38445560986FE23DD015D
SHA256:3169FE8C51EEAF1380987BE7762E5792DC8876B63FFA6269CC1C12765B9FFE91
6672EarthTime.exeC:\Users\admin\AppData\Roaming\DeskSoft\EarthTime\(DFC)Cmd.dcf_tmpbinary
MD5:93B885ADFE0DA089CDF634904FD59F71
SHA256:6E340B9CFFB37A989CA544E6BB780A2C78901D3FB33738768511A30617AFA01D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
89
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6672
EarthTime.exe
GET
301
188.68.47.244:80
http://www.desksoft.com/PAD/ET_VER.TXT
unknown
unknown
6672
EarthTime.exe
GET
401
146.185.153.16:80
http://api.openweathermap.org/data/2.5/weather?lat=34.052200&lon=-118.244003&units=metric&APPID=
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
644
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
644
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7040
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6972
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6672
EarthTime.exe
GET
401
146.185.153.16:80
http://api.openweathermap.org/data/2.5/weather?lat=34.052200&lon=-118.244003&units=metric&APPID=
unknown
whitelisted
6672
EarthTime.exe
GET
401
146.185.153.16:80
http://api.openweathermap.org/data/2.5/weather?lat=34.052200&lon=-118.244003&units=metric&APPID=
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1128
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3972
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
6672
EarthTime.exe
188.68.47.244:80
www.desksoft.com
netcup GmbH
DE
unknown
6672
EarthTime.exe
188.68.47.244:443
www.desksoft.com
netcup GmbH
DE
unknown
6672
EarthTime.exe
146.185.153.16:80
api.openweathermap.org
DIGITALOCEAN-ASN
NL
unknown
6672
EarthTime.exe
13.107.246.60:443
www.aviationweather.gov
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.238
whitelisted
www.desksoft.com
  • 188.68.47.244
unknown
api.openweathermap.org
  • 146.185.153.16
whitelisted
www.aviationweather.gov
  • 13.107.246.60
whitelisted
aviationweather.gov
  • 13.107.246.44
  • 13.107.246.64
whitelisted
www.bing.com
  • 95.100.146.27
  • 95.100.146.16
  • 95.100.146.25
  • 95.100.146.17
  • 95.100.146.26
  • 95.100.146.32
  • 95.100.146.35
  • 95.100.146.33
  • 95.100.146.19
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.23
  • 40.126.31.67
  • 20.190.159.71
  • 20.190.159.4
  • 20.190.159.75
  • 40.126.31.73
  • 20.190.159.2
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

No threats detected
No debug info