File name:

lum_sdk32.dll

Full analysis: https://app.any.run/tasks/95166148-1795-4465-b068-84a907774f59
Verdict: Malicious activity
Analysis date: April 30, 2024, 13:40:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5:

A5F5DFA3D90CCC8D115EFE6F0AB3A786

SHA1:

0F6285EF1206C0C8799445C417659CAD4B6C0953

SHA256:

7F6CDF7CF5BB90A59D7D70D38F95BBE15DBE27384D6F165E95759BD524CFE705

SSDEEP:

98304:B54Z1nf80/JBr1RS4Vuz8zRErkFG7huImD5i:K9r1s

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 3972)
    • Unusual connection from system programs

      • rundll32.exe (PID: 3972)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • rundll32.exe (PID: 3972)
    • Executable content was dropped or overwritten

      • rundll32.exe (PID: 3972)
    • Detected use of alternative data streams (AltDS)

      • rundll32.exe (PID: 3972)
    • The process drops C-runtime libraries

      • rundll32.exe (PID: 3972)
  • INFO

    • Creates files in the program directory

      • rundll32.exe (PID: 3972)
    • Reads the machine GUID from the registry

      • test_wpf.exe (PID: 3980)
    • Reads the computer name

      • test_wpf.exe (PID: 3980)
      • wmpnscfg.exe (PID: 1024)
    • Checks supported languages

      • test_wpf.exe (PID: 3980)
      • wmpnscfg.exe (PID: 1024)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:14 19:46:59+00:00
ImageFileCharacteristics: Executable, 32-bit, DLL
PEType: PE32
LinkerVersion: 12
CodeSize: 181760
InitializedDataSize: 8547840
UninitializedDataSize: -
EntryPoint: 0xb7d2
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.429.308.0
ProductVersionNumber: 1.429.308.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BrightData Ltd.
FileDescription: Bright SDK
FileVersion: 1.429.308
InternalName: lum_sdk.dll
LegalCopyright: Copyright © 2023
OriginalFileName: lum_sdk.dll
ProductName: Bright SDK
ProductVersion: 1.429.308
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe test_wpf.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1024"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3972"C:\Windows\System32\rundll32.exe" C:\Users\admin\AppData\Local\Temp\lum_sdk32.dll, #1C:\Windows\System32\rundll32.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3980C:\ProgramData\BrightData\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\test_wpf.exeC:\ProgramData\BrightData\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\test_wpf.exerundll32.exe
User:
admin
Company:
BrightData Ltd.
Integrity Level:
MEDIUM
Description:
test_wpf
Exit code:
0
Version:
1.429.308
Modules
Images
c:\programdata\brightdata\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\test_wpf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 219
Read events
1 219
Write events
0
Delete events
0

Modification events

No data
Executable files
3
Suspicious files
0
Text files
2
Unknown types
2

Dropped files

PID
Process
Filename
Type
3972rundll32.exeC:\ProgramData\BrightData\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\msvcr120.dllexecutable
MD5:034CCADC1C073E4216E9466B720F9849
SHA256:86E39B5995AF0E042FCDAA85FE2AEFD7C9DDC7AD65E6327BD5E7058BC3AB615F
3972rundll32.exeC:\ProgramData\BrightData\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\test_wpf.exeexecutable
MD5:0BBFCD9D525EC710B386E2EFB3669B4E
SHA256:1B67B0BC187BF45A43C28B768B39E6EA5B657AFD5433DB0661F49CE7A3061D1A
3972rundll32.exeC:\ProgramData\BrightData\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\kbasnthasciateuhant98437uaubinary
MD5:0CC175B9C0F1B6A831C399E269772661
SHA256:
3972rundll32.exeC:\ProgramData\BrightData\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\brd_sdk32_clr.dllexecutable
MD5:C6030E74A4597DA324A77DA97CB33ADA
SHA256:44147C861E95842B7CF885AFDD84935E28566514B3DCCF6A1F8FB97DF21AA21C
3972rundll32.exeC:\ProgramData\BrightData\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\lum_sdk_session_id:LUM:$DATAtext
MD5:02CD6B892E50679B84F56DA6402E129D
SHA256:FEC9F5EE4C576746C945B93FBDBC1196C8C43C2C3E29C8E5623D942EB4FB6035
3972rundll32.exeC:\ProgramData\BrightData\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\lum_sdk_session_idtext
MD5:66F634F0FB29D902F2EE70AB207155AB
SHA256:F603D30CD383701991CBBD9E56862AC5FFAEECCC6925896605D62722FD250441
3972rundll32.exeC:\ProgramData\BrightData\c34ae0b0f243e2c9f9972702788bd7fe7bfec696\db\conf.jsonbinary
MD5:9F04FEF727D34A94A09D24C756505330
SHA256:2E5A1351BC68F73636BC792216FADA530B507F9DC00B35D389D561497E815C6B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3972
rundll32.exe
192.81.214.145:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
perr.lum-sdk.io
  • 192.81.214.145
  • 206.189.231.23
  • 159.223.133.120
  • 161.35.48.195
unknown

Threats

No threats detected
No debug info