| File name: | PDF To Excel Converter.exe |
| Full analysis: | https://app.any.run/tasks/922b1428-fc15-43d1-9d0c-485bdf9417a5 |
| Verdict: | Malicious activity |
| Threats: | Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat. |
| Analysis date: | August 29, 2024, 00:12:54 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BE1A4EB4ABFA66C168B8B947AFBFA6CA |
| SHA1: | 50930E854A16328C5C8DD1A00F44546E34012BC1 |
| SHA256: | 47479BC42637EB820441881004AF25426680879670D2D027C59B9B6137E25917 |
| SSDEEP: | 98304:32WiRktbn6dBbtow2BCqkMXNQ9EUvp9swyLmfdlcPErzVKXKs8EVnXoysiE3AKTq:EpcxCbpG |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 0000:00:00 00:00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 3 |
| CodeSize: | 9100800 |
| InitializedDataSize: | 1549312 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x77920 |
| OSVersion: | 6.1 |
| ImageVersion: | 1 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.9.2.0 |
| ProductVersionNumber: | 4.9.2.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | https://www.PDFExcelConverter.com |
| FileDescription: | PDF To Excel Converter Setup |
| FileVersion: | 4.9.2 |
| LegalCopyright: | https://www.PDFExcelConverter.com |
| ProductName: | PDF To Excel Converter |
| ProductVersion: | 4.9.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2040 | "C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe" | C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe | PDF To Excel Converter.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: BitLocker To Go Reader Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
Lumma(PID) Process(2040) BitLockerToGo.exe C2 (9)traineiwnqo.shop stagedchheiqwo.shop condedqpwqm.shop scenarriotdpq.shop stamppreewntnq.shop locatedblsoqp.shop caffegclasiqwp.shop millyscroqwp.shop evoliutwoqm.shop | |||||||||||||||
| 4316 | "C:\ProgramData\MenuOneDrive\USOPrivateCache.exe" | C:\ProgramData\MenuOneDrive\USOPrivateCache.exe | — | BitLockerToGo.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: BitLocker To Go Reader Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4444 | "C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe" | C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe | H8NFL0FBX4JQ00LZBNCRL.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: BitLocker To Go Reader Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6180 | "C:\Users\admin\AppData\Local\Temp\H8NFL0FBX4JQ00LZBNCRL.exe" | C:\Users\admin\AppData\Local\Temp\H8NFL0FBX4JQ00LZBNCRL.exe | — | BitLockerToGo.exe | |||||||||||
User: admin Company: Auslogics Integrity Level: MEDIUM Description: Auslogics ServiceCommander Exit code: 666 Version: 2.x Modules
| |||||||||||||||
| 6960 | "C:\Users\admin\AppData\Local\Temp\PDF To Excel Converter.exe" | C:\Users\admin\AppData\Local\Temp\PDF To Excel Converter.exe | explorer.exe | ||||||||||||
User: admin Company: https://www.PDFExcelConverter.com Integrity Level: MEDIUM Description: PDF To Excel Converter Setup Exit code: 666 Version: 4.9.2 Modules
| |||||||||||||||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-462 |
Value: Afghanistan Standard Time | |||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-461 |
Value: Afghanistan Daylight Time | |||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-222 |
Value: Alaskan Standard Time | |||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-221 |
Value: Alaskan Daylight Time | |||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-2392 |
Value: Aleutian Standard Time | |||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-2391 |
Value: Aleutian Daylight Time | |||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-2162 |
Value: Altai Standard Time | |||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-2161 |
Value: Altai Daylight Time | |||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-392 |
Value: Arab Standard Time | |||
| (PID) Process: | (6960) PDF To Excel Converter.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | C:\WINDOWS\system32\,@tzres.dll,-391 |
Value: Arab Daylight Time | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2040 | BitLockerToGo.exe | C:\Users\admin\AppData\Local\Temp\H8NFL0FBX4JQ00LZBNCRL.exe | executable | |
MD5:99D729B31262AB0F880F905FE50BFD32 | SHA256:4B9265FE98DAF4D8EAFCEAAB2417AC6A45D25E7A2F55418CDE096A5ED0072370 | |||
| 4444 | BitLockerToGo.exe | C:\ProgramData\MenuOneDrive\USOPrivateCache.exe | executable | |
MD5:A64BEAB5D4516BECA4C40B25DC0C1CD8 | SHA256:36FB87F4E3048659D91FB4250D07582BBBEDA35A7A5839CA61AA0D85DC1BD63C | |||
| 6960 | PDF To Excel Converter.exe | C:\Users\admin\AppData\Local\Temp\fake_useragent_0.2.0.json | binary | |
MD5:0AF58ABD8A3FD21EB8C012A05A58AD0E | SHA256:12A537681364542407E0E1A7BF52D51B213335F28BF8253A4871C2599FF55602 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2180 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
2180 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2024 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 52.191.219.104:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3260 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6960 | PDF To Excel Converter.exe | 185.199.109.133:443 | raw.githubusercontent.com | FASTLY | US | shared |
2040 | BitLockerToGo.exe | 188.114.97.3:443 | scenarriotdpq.shop | CLOUDFLARENET | NL | malicious |
2040 | BitLockerToGo.exe | 185.166.143.48:443 | bitbucket.org | AMAZON-02 | NL | shared |
2040 | BitLockerToGo.exe | 54.231.232.129:443 | bbuseruploads.s3.amazonaws.com | AMAZON-02 | US | shared |
2180 | SIHClient.exe | 40.68.123.157:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2180 | SIHClient.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
raw.githubusercontent.com |
| shared |
scenarriotdpq.shop |
| malicious |
bitbucket.org |
| shared |
bbuseruploads.s3.amazonaws.com |
| shared |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
2040 | BitLockerToGo.exe | A Network Trojan was detected | STEALER [ANY.RUN] Lumma Stealer TLS Connection |