URL:

https://loaderware.cc/unloader

Full analysis: https://app.any.run/tasks/7f07aee7-d5c9-49e9-8faf-d003dc6958cb
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: January 10, 2025, 18:35:39
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
lumma
stealer
netreactor
Indicators:
MD5:

FCCE35A627E4993A26C32F922BDD6818

SHA1:

0DD4483E45F4383E32D07D967263A062B0A22A89

SHA256:

6CE8AAD34E8FAF1F7DABDA40C454B844823A7D92C77830D377539F4A9D54C04F

SSDEEP:

3:N8KdCNKWpyn:2KdH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • UnLoader.exe (PID: 2120)
      • UnLoader.exe (PID: 6068)
      • UnLoader.exe (PID: 6096)
      • UnLoader.exe (PID: 2428)
    • LUMMA mutex has been found

      • UnLoader.exe (PID: 2120)
      • UnLoader.exe (PID: 6068)
      • UnLoader.exe (PID: 6096)
      • UnLoader.exe (PID: 7872)
      • UnLoader.exe (PID: 7296)
      • UnLoader.exe (PID: 7508)
      • UnLoader.exe (PID: 4944)
      • UnLoader.exe (PID: 2428)
      • UnLoader.exe (PID: 7464)
      • UnLoader.exe (PID: 7144)
      • UnLoader.exe (PID: 1228)
      • UnLoader.exe (PID: 7276)
      • UnLoader.exe (PID: 8452)
      • UnLoader.exe (PID: 7208)
      • UnLoader.exe (PID: 8164)
      • UnLoader.exe (PID: 8628)
      • UnLoader.exe (PID: 8400)
      • UnLoader.exe (PID: 9536)
      • UnLoader.exe (PID: 9524)
      • UnLoader.exe (PID: 9448)
      • UnLoader.exe (PID: 4520)
    • LUMMA has been detected (YARA)

      • UnLoader.exe (PID: 2120)
    • Steals credentials from Web Browsers

      • UnLoader.exe (PID: 6068)
      • UnLoader.exe (PID: 2428)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • UnLoader.exe (PID: 7568)
      • UnLoader.exe (PID: 2120)
      • UnLoader.exe (PID: 3092)
      • UnLoader.exe (PID: 4672)
      • UnLoader.exe (PID: 6068)
      • UnLoader.exe (PID: 7872)
      • UnLoader.exe (PID: 1616)
      • UnLoader.exe (PID: 6096)
      • UnLoader.exe (PID: 7908)
      • UnLoader.exe (PID: 7508)
      • UnLoader.exe (PID: 3060)
      • UnLoader.exe (PID: 2428)
      • UnLoader.exe (PID: 3864)
      • UnLoader.exe (PID: 3220)
      • UnLoader.exe (PID: 4392)
      • UnLoader.exe (PID: 7296)
      • UnLoader.exe (PID: 7464)
      • UnLoader.exe (PID: 4944)
      • UnLoader.exe (PID: 7896)
      • UnLoader.exe (PID: 6312)
      • UnLoader.exe (PID: 7492)
      • UnLoader.exe (PID: 4580)
      • UnLoader.exe (PID: 7848)
      • UnLoader.exe (PID: 1616)
      • UnLoader.exe (PID: 7812)
      • UnLoader.exe (PID: 7144)
      • UnLoader.exe (PID: 4980)
      • UnLoader.exe (PID: 8168)
      • UnLoader.exe (PID: 2076)
      • UnLoader.exe (PID: 3920)
      • UnLoader.exe (PID: 6396)
      • UnLoader.exe (PID: 3888)
      • UnLoader.exe (PID: 4360)
      • UnLoader.exe (PID: 4512)
      • UnLoader.exe (PID: 6440)
      • UnLoader.exe (PID: 6196)
      • UnLoader.exe (PID: 7880)
      • UnLoader.exe (PID: 7276)
      • UnLoader.exe (PID: 1172)
      • UnLoader.exe (PID: 640)
      • UnLoader.exe (PID: 6084)
      • UnLoader.exe (PID: 736)
      • UnLoader.exe (PID: 1228)
      • UnLoader.exe (PID: 4804)
      • UnLoader.exe (PID: 8580)
      • UnLoader.exe (PID: 8628)
      • UnLoader.exe (PID: 7208)
      • UnLoader.exe (PID: 8164)
      • UnLoader.exe (PID: 6304)
      • UnLoader.exe (PID: 8204)
      • UnLoader.exe (PID: 8292)
      • UnLoader.exe (PID: 8452)
      • UnLoader.exe (PID: 8920)
      • UnLoader.exe (PID: 9124)
      • UnLoader.exe (PID: 9112)
      • UnLoader.exe (PID: 9196)
      • UnLoader.exe (PID: 8972)
      • UnLoader.exe (PID: 9168)
      • UnLoader.exe (PID: 9088)
      • UnLoader.exe (PID: 8984)
      • UnLoader.exe (PID: 8256)
      • UnLoader.exe (PID: 7472)
      • UnLoader.exe (PID: 8176)
      • UnLoader.exe (PID: 9036)
      • UnLoader.exe (PID: 8688)
      • UnLoader.exe (PID: 8736)
      • UnLoader.exe (PID: 6876)
      • UnLoader.exe (PID: 8372)
      • UnLoader.exe (PID: 6332)
      • UnLoader.exe (PID: 8904)
      • UnLoader.exe (PID: 7964)
      • UnLoader.exe (PID: 8584)
      • UnLoader.exe (PID: 7136)
      • UnLoader.exe (PID: 8300)
      • UnLoader.exe (PID: 4804)
      • UnLoader.exe (PID: 8448)
      • UnLoader.exe (PID: 3488)
      • UnLoader.exe (PID: 8800)
      • UnLoader.exe (PID: 1296)
      • UnLoader.exe (PID: 8348)
      • UnLoader.exe (PID: 7488)
      • UnLoader.exe (PID: 8912)
      • UnLoader.exe (PID: 8400)
      • UnLoader.exe (PID: 7896)
      • UnLoader.exe (PID: 7596)
      • UnLoader.exe (PID: 8556)
      • UnLoader.exe (PID: 5788)
      • UnLoader.exe (PID: 732)
      • UnLoader.exe (PID: 7908)
      • UnLoader.exe (PID: 8424)
      • UnLoader.exe (PID: 7092)
      • UnLoader.exe (PID: 8532)
      • UnLoader.exe (PID: 8952)
      • UnLoader.exe (PID: 9108)
      • UnLoader.exe (PID: 8796)
      • UnLoader.exe (PID: 6364)
      • UnLoader.exe (PID: 8908)
      • UnLoader.exe (PID: 4052)
      • UnLoader.exe (PID: 5720)
      • UnLoader.exe (PID: 9232)
      • UnLoader.exe (PID: 9264)
      • UnLoader.exe (PID: 8928)
      • UnLoader.exe (PID: 9428)
      • UnLoader.exe (PID: 9832)
      • UnLoader.exe (PID: 8392)
      • UnLoader.exe (PID: 10156)
      • UnLoader.exe (PID: 9604)
      • UnLoader.exe (PID: 10024)
      • UnLoader.exe (PID: 9940)
      • UnLoader.exe (PID: 9904)
      • UnLoader.exe (PID: 10200)
      • UnLoader.exe (PID: 10212)
      • UnLoader.exe (PID: 9388)
      • UnLoader.exe (PID: 9040)
      • UnLoader.exe (PID: 2092)
      • UnLoader.exe (PID: 9524)
      • UnLoader.exe (PID: 9536)
      • UnLoader.exe (PID: 9552)
      • UnLoader.exe (PID: 9236)
      • UnLoader.exe (PID: 10120)
      • UnLoader.exe (PID: 9952)
      • UnLoader.exe (PID: 10100)
      • UnLoader.exe (PID: 9812)
      • UnLoader.exe (PID: 9956)
      • UnLoader.exe (PID: 9656)
      • UnLoader.exe (PID: 9896)
      • UnLoader.exe (PID: 1520)
      • UnLoader.exe (PID: 7088)
      • UnLoader.exe (PID: 9176)
      • UnLoader.exe (PID: 9380)
      • UnLoader.exe (PID: 9448)
      • UnLoader.exe (PID: 8396)
      • UnLoader.exe (PID: 10044)
      • UnLoader.exe (PID: 9768)
      • UnLoader.exe (PID: 10228)
      • UnLoader.exe (PID: 4980)
      • UnLoader.exe (PID: 9912)
      • UnLoader.exe (PID: 7228)
      • UnLoader.exe (PID: 1684)
      • UnLoader.exe (PID: 8412)
      • UnLoader.exe (PID: 10136)
      • UnLoader.exe (PID: 4520)
      • UnLoader.exe (PID: 2012)
      • UnLoader.exe (PID: 7096)
      • UnLoader.exe (PID: 9744)
      • UnLoader.exe (PID: 6940)
      • UnLoader.exe (PID: 7092)
      • UnLoader.exe (PID: 10096)
      • UnLoader.exe (PID: 9888)
      • UnLoader.exe (PID: 8548)
    • Application launched itself

      • UnLoader.exe (PID: 7568)
      • UnLoader.exe (PID: 3092)
      • UnLoader.exe (PID: 4672)
      • UnLoader.exe (PID: 1616)
      • UnLoader.exe (PID: 7908)
      • UnLoader.exe (PID: 3060)
      • UnLoader.exe (PID: 4392)
      • UnLoader.exe (PID: 7896)
      • UnLoader.exe (PID: 6312)
      • UnLoader.exe (PID: 7492)
      • UnLoader.exe (PID: 4580)
      • UnLoader.exe (PID: 4980)
      • UnLoader.exe (PID: 6396)
      • UnLoader.exe (PID: 2076)
      • UnLoader.exe (PID: 8168)
      • UnLoader.exe (PID: 4360)
      • UnLoader.exe (PID: 736)
      • UnLoader.exe (PID: 8204)
      • UnLoader.exe (PID: 3920)
      • UnLoader.exe (PID: 6084)
      • UnLoader.exe (PID: 4804)
      • UnLoader.exe (PID: 8580)
      • UnLoader.exe (PID: 6304)
      • UnLoader.exe (PID: 1172)
      • UnLoader.exe (PID: 640)
      • UnLoader.exe (PID: 8292)
      • UnLoader.exe (PID: 9112)
      • UnLoader.exe (PID: 9124)
      • UnLoader.exe (PID: 8348)
      • UnLoader.exe (PID: 8176)
      • UnLoader.exe (PID: 7472)
      • UnLoader.exe (PID: 8372)
      • UnLoader.exe (PID: 7964)
      • UnLoader.exe (PID: 8904)
      • UnLoader.exe (PID: 8556)
      • UnLoader.exe (PID: 8532)
      • UnLoader.exe (PID: 7092)
      • UnLoader.exe (PID: 8392)
      • UnLoader.exe (PID: 8928)
      • UnLoader.exe (PID: 6364)
      • UnLoader.exe (PID: 732)
      • UnLoader.exe (PID: 7908)
      • UnLoader.exe (PID: 8796)
      • UnLoader.exe (PID: 5720)
      • UnLoader.exe (PID: 10156)
      • UnLoader.exe (PID: 8424)
      • UnLoader.exe (PID: 4052)
      • UnLoader.exe (PID: 10024)
      • UnLoader.exe (PID: 1520)
      • UnLoader.exe (PID: 9812)
      • UnLoader.exe (PID: 9656)
      • UnLoader.exe (PID: 10044)
      • UnLoader.exe (PID: 7228)
      • UnLoader.exe (PID: 9896)
      • UnLoader.exe (PID: 1684)
      • UnLoader.exe (PID: 9380)
      • UnLoader.exe (PID: 2012)
      • UnLoader.exe (PID: 9744)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 5968)
    • Executes application which crashes

      • UnLoader.exe (PID: 7568)
      • UnLoader.exe (PID: 3092)
      • UnLoader.exe (PID: 4672)
      • UnLoader.exe (PID: 1616)
      • UnLoader.exe (PID: 7908)
      • UnLoader.exe (PID: 4392)
      • UnLoader.exe (PID: 3060)
      • UnLoader.exe (PID: 6312)
      • UnLoader.exe (PID: 7896)
      • UnLoader.exe (PID: 4580)
      • UnLoader.exe (PID: 7492)
      • UnLoader.exe (PID: 4980)
      • UnLoader.exe (PID: 9124)
      • UnLoader.exe (PID: 7472)
      • UnLoader.exe (PID: 8348)
      • UnLoader.exe (PID: 5720)
  • INFO

    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 6212)
    • Reads Environment values

      • identity_helper.exe (PID: 5640)
    • Checks supported languages

      • identity_helper.exe (PID: 5640)
      • UnLoader.exe (PID: 7568)
      • UnLoader.exe (PID: 2120)
      • UnLoader.exe (PID: 3092)
      • UnLoader.exe (PID: 6068)
      • UnLoader.exe (PID: 7872)
      • UnLoader.exe (PID: 6096)
      • UnLoader.exe (PID: 7296)
      • UnLoader.exe (PID: 6312)
    • Reads the computer name

      • identity_helper.exe (PID: 5640)
      • UnLoader.exe (PID: 7568)
      • UnLoader.exe (PID: 2120)
      • UnLoader.exe (PID: 4672)
      • UnLoader.exe (PID: 6096)
      • UnLoader.exe (PID: 7908)
      • UnLoader.exe (PID: 3060)
      • UnLoader.exe (PID: 6312)
    • The process uses the downloaded file

      • msedge.exe (PID: 3808)
      • WinRAR.exe (PID: 5968)
      • WinRAR.exe (PID: 5464)
    • Application launched itself

      • msedge.exe (PID: 6212)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5968)
      • WinRAR.exe (PID: 5464)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 5968)
      • WinRAR.exe (PID: 5464)
    • Reads the software policy settings

      • UnLoader.exe (PID: 2120)
      • WerFault.exe (PID: 5856)
      • UnLoader.exe (PID: 7872)
      • UnLoader.exe (PID: 7508)
      • UnLoader.exe (PID: 7848)
    • Checks proxy server information

      • WerFault.exe (PID: 6084)
      • WerFault.exe (PID: 8188)
    • Manual execution by a user

      • WinRAR.exe (PID: 7132)
      • WinRAR.exe (PID: 5464)
      • UnLoader.exe (PID: 3092)
      • UnLoader.exe (PID: 4672)
      • UnLoader.exe (PID: 1616)
      • UnLoader.exe (PID: 3060)
      • UnLoader.exe (PID: 7908)
      • UnLoader.exe (PID: 4392)
      • UnLoader.exe (PID: 7896)
      • UnLoader.exe (PID: 6312)
      • UnLoader.exe (PID: 7492)
      • UnLoader.exe (PID: 4580)
      • UnLoader.exe (PID: 4980)
      • UnLoader.exe (PID: 6396)
      • UnLoader.exe (PID: 8168)
      • UnLoader.exe (PID: 3920)
      • UnLoader.exe (PID: 4360)
      • UnLoader.exe (PID: 2076)
      • UnLoader.exe (PID: 6084)
      • UnLoader.exe (PID: 736)
      • UnLoader.exe (PID: 1172)
      • UnLoader.exe (PID: 640)
      • UnLoader.exe (PID: 4804)
      • UnLoader.exe (PID: 8204)
      • UnLoader.exe (PID: 6304)
      • UnLoader.exe (PID: 8292)
      • UnLoader.exe (PID: 8580)
      • UnLoader.exe (PID: 9124)
      • UnLoader.exe (PID: 9112)
      • UnLoader.exe (PID: 8904)
      • UnLoader.exe (PID: 8176)
      • UnLoader.exe (PID: 8348)
      • UnLoader.exe (PID: 8372)
      • UnLoader.exe (PID: 7472)
      • UnLoader.exe (PID: 7964)
      • UnLoader.exe (PID: 8556)
      • UnLoader.exe (PID: 8424)
      • UnLoader.exe (PID: 732)
      • UnLoader.exe (PID: 7908)
      • UnLoader.exe (PID: 7092)
      • UnLoader.exe (PID: 8532)
      • UnLoader.exe (PID: 8796)
      • UnLoader.exe (PID: 8928)
      • UnLoader.exe (PID: 4052)
      • UnLoader.exe (PID: 5720)
      • UnLoader.exe (PID: 6364)
      • UnLoader.exe (PID: 8392)
      • UnLoader.exe (PID: 10024)
      • UnLoader.exe (PID: 10156)
      • UnLoader.exe (PID: 9812)
      • UnLoader.exe (PID: 10044)
      • UnLoader.exe (PID: 9656)
      • UnLoader.exe (PID: 9896)
      • UnLoader.exe (PID: 1520)
      • UnLoader.exe (PID: 1684)
      • UnLoader.exe (PID: 7228)
      • UnLoader.exe (PID: 9380)
      • UnLoader.exe (PID: 9744)
      • UnLoader.exe (PID: 2012)
    • .NET Reactor protector has been detected

      • UnLoader.exe (PID: 2120)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 1228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
478
Monitored processes
288
Malicious processes
35
Suspicious processes
20

Behavior graph

Click at the process to see the details
start iexplore.exe no specs msedge.exe svchost.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe msedge.exe no specs unloader.exe conhost.exe no specs #LUMMA unloader.exe werfault.exe msedge.exe no specs msedge.exe no specs winrar.exe no specs msedge.exe no specs winrar.exe msedge.exe no specs msedge.exe no specs unloader.exe conhost.exe no specs #LUMMA unloader.exe werfault.exe unloader.exe conhost.exe no specs #LUMMA unloader.exe werfault.exe unloader.exe conhost.exe no specs #LUMMA unloader.exe werfault.exe unloader.exe conhost.exe no specs unloader.exe conhost.exe no specs #LUMMA unloader.exe werfault.exe unloader.exe no specs #LUMMA unloader.exe werfault.exe msedge.exe no specs unloader.exe conhost.exe no specs unloader.exe no specs #LUMMA unloader.exe werfault.exe unloader.exe conhost.exe no specs #LUMMA unloader.exe werfault.exe msedge.exe no specs unloader.exe conhost.exe no specs #LUMMA unloader.exe unloader.exe conhost.exe no specs unloader.exe conhost.exe no specs werfault.exe unloader.exe no specs unloader.exe unloader.exe no specs #LUMMA unloader.exe werfault.exe werfault.exe unloader.exe conhost.exe no specs unloader.exe no specs conhost.exe no specs unloader.exe unloader.exe no specs conhost.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs werfault.exe unloader.exe no specs unloader.exe no specs unloader.exe #LUMMA unloader.exe unloader.exe no specs conhost.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs #LUMMA unloader.exe #LUMMA unloader.exe conhost.exe no specs #LUMMA unloader.exe conhost.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs conhost.exe no specs conhost.exe no specs unloader.exe no specs conhost.exe no specs conhost.exe no specs #LUMMA unloader.exe conhost.exe no specs unloader.exe no specs conhost.exe no specs #LUMMA unloader.exe unloader.exe unloader.exe unloader.exe unloader.exe unloader.exe no specs unloader.exe conhost.exe no specs conhost.exe no specs unloader.exe unloader.exe unloader.exe unloader.exe unloader.exe unloader.exe no specs unloader.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs unloader.exe no specs conhost.exe no specs unloader.exe unloader.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe conhost.exe no specs werfault.exe unloader.exe no specs unloader.exe no specs unloader.exe unloader.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe #LUMMA unloader.exe unloader.exe unloader.exe no specs unloader.exe conhost.exe no specs werfault.exe unloader.exe unloader.exe no specs conhost.exe no specs unloader.exe no specs werfault.exe conhost.exe no specs unloader.exe no specs unloader.exe no specs conhost.exe no specs unloader.exe no specs conhost.exe no specs conhost.exe no specs unloader.exe no specs unloader.exe unloader.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs conhost.exe no specs unloader.exe conhost.exe no specs conhost.exe no specs conhost.exe no specs unloader.exe no specs unloader.exe unloader.exe no specs unloader.exe conhost.exe no specs conhost.exe no specs unloader.exe #LUMMA unloader.exe unloader.exe no specs unloader.exe unloader.exe unloader.exe unloader.exe unloader.exe unloader.exe no specs conhost.exe no specs unloader.exe no specs unloader.exe unloader.exe conhost.exe no specs werfault.exe unloader.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe unloader.exe no specs conhost.exe no specs #LUMMA unloader.exe unloader.exe no specs conhost.exe no specs unloader.exe no specs unloader.exe unloader.exe unloader.exe no specs unloader.exe no specs unloader.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs unloader.exe no specs unloader.exe no specs unloader.exe no specs #LUMMA unloader.exe #LUMMA unloader.exe unloader.exe no specs unloader.exe