| File name: | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070 |
| Full analysis: | https://app.any.run/tasks/4d2d4955-5699-4c76-aa0f-4faf5bfb4e28 |
| Verdict: | Malicious activity |
| Analysis date: | August 01, 2024, 11:39:29 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 94048307163C44F9BF90D97A66BBB971 |
| SHA1: | F1EE4726BBB346021ECD77C78CEECE71B3EEF876 |
| SHA256: | 3FCF907314F1AC7B2E4E564A1783306D6E4356C15E2DCAF193CBC5BACD4356A1 |
| SSDEEP: | 98304:717924Hk3l3E7YIlzYREpIMxODzs7r87RjsNrQtqYF0zwgcT/s1aDtyFIvnUo+xi:ECrCTdSFVA |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:04:30 15:50:00+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.39 |
| CodeSize: | 149504 |
| InitializedDataSize: | 5847552 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xdf33 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6336 | "C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe" | C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 6384 | "C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe" | C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 6672 | "C:\Program Files (x86)\EarthTime\EarthTime.exe" | C:\Program Files (x86)\EarthTime\EarthTime.exe | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | ||||||||||||
User: admin Company: DeskSoft Integrity Level: MEDIUM Description: EarthTime Application Version: 6.26.12 Modules
| |||||||||||||||
| 6724 | "C:\WINDOWS\hh.exe" C:\Program Files (x86)\EarthTime\EarthTime.chm | C:\Windows\hh.exe | — | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® HTML Help Executable Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\MHDSYS32 |
| Operation: | write | Name: | C2A9A8FD6 |
Value: | |||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DeskSoft |
| Operation: | write | Name: | EarthTime |
Value: 010071F1725AFDA8A9C206001A00010000000000433A5C50726F6772616D2046696C65732028783836295C456172746854696D65000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000433A5C55736572735C61646D696E5C417070446174615C526F616D696E675C4465736B536F66745C456172746854696D6500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000687474703A2F2F7777772E6465736B736F66742E636F6D2F456172746854696D655F50757263686173652E68746D00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000687474703A2F2F7777772E6465736B736F66742E636F6D2F5041442F45545F5645522E545854000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000687474703A2F2F7777772E6465736B736F66742E636F6D2F456172746854696D655F446F776E6C6F61642E68746D000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 12 | |||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime |
| Operation: | write | Name: | DisplayName |
Value: EarthTime | |||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files (x86)\EarthTime\EarthTime.exe,0 | |||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime |
| Operation: | write | Name: | DisplayVersion |
Value: 6.26.12 | |||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime |
| Operation: | write | Name: | Publisher |
Value: DeskSoft | |||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime |
| Operation: | write | Name: | HelpLink |
Value: http://www.desksoft.com | |||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime |
| Operation: | write | Name: | URLInfoAbout |
Value: http://www.desksoft.com | |||
| (PID) Process: | (6384) SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\EarthTime |
| Operation: | write | Name: | URLUpdateInfo |
Value: http://www.desksoft.com | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6384 | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | C:\Program Files (x86)\EarthTime\EarthTime.exe | executable | |
MD5:870B1AFB8F77FA84C585AA6D8854BB63 | SHA256:5455A46985EA47F32B04DA25F05F88B6FEEC10DA3A6E80FC9BD8B9A96C5A8511 | |||
| 6384 | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | C:\Program Files (x86)\EarthTime\Uninstall.exe | executable | |
MD5:E6EC95C816F6AD7BDA80D7E345752AC0 | SHA256:F84A96AB6140F89335BC6208EDBDD3C36DD5B1F7C7C7ACE1FB2E3DEA352461FB | |||
| 6384 | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | C:\Program Files (x86)\EarthTime\Timezones.txt | text | |
MD5:212D425B4819F3DFA0ECA792FA902C3D | SHA256:E004A32F598C29F0091BEC5402C0C7AC0FDB7694E83D85713D1435F49E01C180 | |||
| 6384 | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | C:\Program Files (x86)\EarthTime\Bell.wav | binary | |
MD5:B0B4C5512956D65A0D1B94B7E405AC51 | SHA256:20861886CAB526264EF1FAE6AA9046BEA78730387686944049236CC2BE127239 | |||
| 6384 | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | C:\Program Files (x86)\EarthTime\Cities.txt | text | |
MD5:49F0CEB97C2AED28E21352DB468B4EB9 | SHA256:0C434ADC4CDE8A7C829B1512176BC9B130C4957E881539C1FDF4DDB73484EB0C | |||
| 6384 | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | C:\Program Files (x86)\EarthTime\Clouds.int | binary | |
MD5:707BC948298DAECCC72448CD0DC5D51B | SHA256:B4B2572569C6CCFC57D7637D31C4BC6BA9D7A79FB027881DC2FEADE60DDD775E | |||
| 6384 | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | C:\Program Files (x86)\EarthTime\EarthTime.chm | binary | |
MD5:2B0CFD02A4ED744F12C03797BC33FB30 | SHA256:C73A8D73386CDF1DFA0C8120E8C8B5DE5624210D0B278F67109847007FBAC4E0 | |||
| 6384 | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | C:\Program Files (x86)\EarthTime\Timezones.dat | compressed | |
MD5:608EDD39B7023B5D23E50D8E7148AEC6 | SHA256:AACED5BA8E3EA7134DE286A6F5CB6E2BE0B6197BE890837CD0120C454BAC8D1C | |||
| 6384 | SecuriteInfo.com.BScope.TrojanPSW.Lumma.8517.20070.exe | C:\Users\admin\AppData\Local\Temp\Temp.lnk | binary | |
MD5:1DF95DD185D38445560986FE23DD015D | SHA256:3169FE8C51EEAF1380987BE7762E5792DC8876B63FFA6269CC1C12765B9FFE91 | |||
| 6672 | EarthTime.exe | C:\Users\admin\AppData\Roaming\DeskSoft\EarthTime\(DFC)Cmd.dcf_tmp | binary | |
MD5:93B885ADFE0DA089CDF634904FD59F71 | SHA256:6E340B9CFFB37A989CA544E6BB780A2C78901D3FB33738768511A30617AFA01D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6672 | EarthTime.exe | GET | 301 | 188.68.47.244:80 | http://www.desksoft.com/PAD/ET_VER.TXT | unknown | — | — | unknown |
6672 | EarthTime.exe | GET | 401 | 146.185.153.16:80 | http://api.openweathermap.org/data/2.5/weather?lat=34.052200&lon=-118.244003&units=metric&APPID= | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
644 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
644 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7040 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6972 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6672 | EarthTime.exe | GET | 401 | 146.185.153.16:80 | http://api.openweathermap.org/data/2.5/weather?lat=34.052200&lon=-118.244003&units=metric&APPID= | unknown | — | — | whitelisted |
6672 | EarthTime.exe | GET | 401 | 146.185.153.16:80 | http://api.openweathermap.org/data/2.5/weather?lat=34.052200&lon=-118.244003&units=metric&APPID= | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1128 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3972 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6672 | EarthTime.exe | 188.68.47.244:80 | www.desksoft.com | netcup GmbH | DE | unknown |
6672 | EarthTime.exe | 188.68.47.244:443 | www.desksoft.com | netcup GmbH | DE | unknown |
6672 | EarthTime.exe | 146.185.153.16:80 | api.openweathermap.org | DIGITALOCEAN-ASN | NL | unknown |
6672 | EarthTime.exe | 13.107.246.60:443 | www.aviationweather.gov | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.desksoft.com |
| unknown |
api.openweathermap.org |
| whitelisted |
www.aviationweather.gov |
| whitelisted |
aviationweather.gov |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |