File name:

Setup.exe

Full analysis: https://app.any.run/tasks/36bf3af6-7bc7-422b-b485-ee62fcc5f5a7
Verdict: Malicious activity
Threats:

HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses.

Analysis date: July 21, 2024, 00:44:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
hijackloader
loader
lumma
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive
MD5:

60250D444207E665A278070A76DC811C

SHA1:

306DD3DDEA6D5DA2A4D10E1B85DA1D9E5F2E05E5

SHA256:

979F393C1F1EF1D302B93004DE949810B98FD2544E3CECA2630FA1A60D159C65

SSDEEP:

98304:U+FNSy3lQB/R60c1kPMkEJrcLgIh7buT7FfjFYh9oxlo7ODrtoifS9bUhsva7l+E:v0gicU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • rta.exe (PID: 6348)
      • Setup.exe (PID: 6940)
      • Setup.exe (PID: 2116)
      • PoplarNegligee.pif (PID: 8044)
      • cmd.exe (PID: 1764)
      • Bush.pif (PID: 3628)
    • LUMMA has been detected (YARA)

      • netsh.exe (PID: 7636)
      • netsh.exe (PID: 6576)
    • HIJACKLOADER has been detected (YARA)

      • netsh.exe (PID: 7636)
      • netsh.exe (PID: 6576)
    • Stealers network behavior

      • PoplarNegligee.pif (PID: 8044)
    • LUMMA has been detected (SURICATA)

      • PoplarNegligee.pif (PID: 8044)
    • Antivirus name has been found in the command line (generic signature)

      • findstr.exe (PID: 5720)
      • findstr.exe (PID: 2868)
    • Actions looks like stealing of personal data

      • PoplarNegligee.pif (PID: 8044)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 6688)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 7464)
      • powershell.exe (PID: 5464)
    • Changes powershell execution policy (Bypass)

      • PoplarNegligee.pif (PID: 8044)
    • Create files in the Startup directory

      • cmd.exe (PID: 5244)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Setup.exe (PID: 2116)
      • rta.exe (PID: 6348)
      • Setup.exe (PID: 6940)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 2116)
      • rta.exe (PID: 6348)
      • Setup.exe (PID: 6940)
      • netsh.exe (PID: 7636)
      • PoplarNegligee.pif (PID: 8044)
      • cmd.exe (PID: 1764)
      • Bush.pif (PID: 3628)
    • The process drops C-runtime libraries

      • Setup.exe (PID: 2116)
      • rta.exe (PID: 6348)
      • Setup.exe (PID: 6940)
    • Suspicious use of NETSH.EXE

      • rta.exe (PID: 6348)
      • rta.exe (PID: 2860)
    • Drops a file with a rarely used extension (PIF)

      • netsh.exe (PID: 7636)
      • cmd.exe (PID: 1764)
      • Bush.pif (PID: 3628)
    • Starts application with an unusual extension

      • netsh.exe (PID: 7636)
      • netsh.exe (PID: 6576)
      • cmd.exe (PID: 1764)
    • Searches for installed software

      • PoplarNegligee.pif (PID: 8044)
    • Reads security settings of Internet Explorer

      • 8NTHES43T8MUJ6M8A.exe (PID: 7404)
    • Reads the date of Windows installation

      • 8NTHES43T8MUJ6M8A.exe (PID: 7404)
    • Executing commands from ".cmd" file

      • 8NTHES43T8MUJ6M8A.exe (PID: 7404)
    • Starts CMD.EXE for commands execution

      • 8NTHES43T8MUJ6M8A.exe (PID: 7404)
      • cmd.exe (PID: 1764)
      • O69NELIRKI2JXE6H90FSHNDP22SUI2E.exe (PID: 6440)
    • Get information on the list of running processes

      • cmd.exe (PID: 1764)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 1764)
    • Application launched itself

      • cmd.exe (PID: 1764)
    • Suspicious file concatenation

      • cmd.exe (PID: 6880)
    • The executable file from the user directory is run by the CMD process

      • Bush.pif (PID: 3628)
    • Starts POWERSHELL.EXE for commands execution

      • PoplarNegligee.pif (PID: 8044)
    • The process executes Powershell scripts

      • PoplarNegligee.pif (PID: 8044)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 1764)
  • INFO

    • Checks supported languages

      • Setup.exe (PID: 2116)
      • rta.exe (PID: 6348)
      • Bt.exe (PID: 6928)
      • Setup.exe (PID: 6940)
      • rta.exe (PID: 2860)
      • Bt.exe (PID: 7032)
      • 8NTHES43T8MUJ6M8A.exe (PID: 7404)
      • PoplarNegligee.pif (PID: 6176)
      • PoplarNegligee.pif (PID: 8044)
      • Bush.pif (PID: 3628)
      • O69NELIRKI2JXE6H90FSHNDP22SUI2E.exe (PID: 6440)
    • Create files in a temporary directory

      • Setup.exe (PID: 2116)
      • Setup.exe (PID: 6940)
      • rta.exe (PID: 6348)
      • rta.exe (PID: 2860)
      • netsh.exe (PID: 7636)
      • netsh.exe (PID: 6576)
      • PoplarNegligee.pif (PID: 8044)
      • 8NTHES43T8MUJ6M8A.exe (PID: 7404)
      • O69NELIRKI2JXE6H90FSHNDP22SUI2E.exe (PID: 6440)
    • Reads the computer name

      • rta.exe (PID: 6348)
      • Bt.exe (PID: 6928)
      • rta.exe (PID: 2860)
      • Bt.exe (PID: 7032)
      • PoplarNegligee.pif (PID: 8044)
      • PoplarNegligee.pif (PID: 6176)
      • 8NTHES43T8MUJ6M8A.exe (PID: 7404)
      • Bush.pif (PID: 3628)
      • O69NELIRKI2JXE6H90FSHNDP22SUI2E.exe (PID: 6440)
    • Creates files or folders in the user directory

      • rta.exe (PID: 6348)
      • Bush.pif (PID: 3628)
    • Manual execution by a user

      • Setup.exe (PID: 6940)
      • cmd.exe (PID: 5244)
      • cmd.exe (PID: 6688)
    • Drops the executable file immediately after the start

      • netsh.exe (PID: 7636)
    • Reads the software policy settings

      • PoplarNegligee.pif (PID: 8044)
    • Reads mouse settings

      • Bush.pif (PID: 3628)
    • Process checks computer location settings

      • 8NTHES43T8MUJ6M8A.exe (PID: 7404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Lumma

(PID) Process(7636) netsh.exe
C2 (9)upknittsoappz.shop
callosallsaospz.shop
outpointsozp.shop
shepherdlyopzc.shop
unseaffarignsk.shop
accessibledpzp.shop
indexterityszcoxp.shop
liernessfornicsa.shop
lariatedzugspd.shop
(PID) Process(6576) netsh.exe
C2 (9)upknittsoappz.shop
callosallsaospz.shop
outpointsozp.shop
shepherdlyopzc.shop
unseaffarignsk.shop
accessibledpzp.shop
indexterityszcoxp.shop
liernessfornicsa.shop
lariatedzugspd.shop
No Malware configuration.

TRiD

.exe | InstallShield setup (25)
.exe | Win32 EXE PECompact compressed (generic) (24.2)
.exe | Win32 Executable MS Visual C++ (generic) (18.1)
.exe | Win64 Executable (generic) (16)
.scr | Windows screen saver (7.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:26 19:41:05+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.38
CodeSize: 40960
InitializedDataSize: 51200
UninitializedDataSize: 295936
EntryPoint: 0x4b62
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
173
Monitored processes
37
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup.exe rta.exe bt.exe no specs setup.exe #LUMMA netsh.exe conhost.exe no specs rta.exe no specs bt.exe no specs slui.exe no specs #LUMMA netsh.exe no specs conhost.exe no specs #LUMMA poplarnegligee.pif poplarnegligee.pif no specs 8nthes43t8muj6m8a.exe no specs cmd.exe conhost.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs bush.pif timeout.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe conhost.exe no specs schtasks.exe no specs o69nelirki2jxe6h90fshndp22sui2e.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
844\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
884findstr /V "DEUTSCHCOMEDYCONDITIONSMINDS" Clips C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\user32.dll
1212\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1284\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1764"C:\Windows\System32\cmd.exe" /k copy Nerve Nerve.cmd & Nerve.cmd & exitC:\Windows\SysWOW64\cmd.exe
8NTHES43T8MUJ6M8A.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2116"C:\Users\admin\Desktop\Setup.exe" C:\Users\admin\Desktop\Setup.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2704cmd /c md 484309C:\Windows\SysWOW64\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2860"C:\Users\admin\AppData\Local\Temp\nsyBBED.tmp\rta.exe"C:\Users\admin\AppData\Local\Temp\nsyBBED.tmp\rta.exeSetup.exe
User:
admin
Company:
IncrediMail, Ltd.
Integrity Level:
MEDIUM
Description:
IncrediMail Notifier
Exit code:
1
Version:
6, 3, 9, 5274
Modules
Images
c:\users\admin\appdata\local\temp\nsybbed.tmp\rta.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2868findstr /I "avastui.exe avgui.exe bdservicehost.exe nswscsvc.exe sophoshealth.exe" C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\user32.dll
3628484309\Bush.pif 484309\g C:\Users\admin\AppData\Local\Temp\484309\Bush.pif
cmd.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
AutoIt v3 Script
Version:
3, 3, 14, 4
Modules
Images
c:\users\admin\appdata\local\temp\484309\bush.pif
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\psapi.dll
c:\windows\syswow64\user32.dll
Total events
17 580
Read events
17 570
Write events
10
Delete events
0

Modification events

(PID) Process:(6348) rta.exeKey:HKEY_CURRENT_USER\SOFTWARE\IncrediMail
Operation:writeName:ApplicationPath
Value:
C:\Users\admin\AppData\Local\IM
(PID) Process:(6348) rta.exeKey:HKEY_CURRENT_USER\SOFTWARE\IncrediMail
Operation:writeName:ApplicationPathBackup
Value:
C:\Users\admin\AppData\Local\IM
(PID) Process:(7404) 8NTHES43T8MUJ6M8A.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(7404) 8NTHES43T8MUJ6M8A.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(7404) 8NTHES43T8MUJ6M8A.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(7404) 8NTHES43T8MUJ6M8A.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
57
Suspicious files
43
Text files
17
Unknown types
1

Dropped files

PID
Process
Filename
Type
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\mfc80u.zipcompressed
MD5:4E8459373EC6E32D15E901D0029293BA
SHA256:290B6BC67EA07B6E815F86E1260E06483894A613C5011A940D753A63B1B59961
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\plugins\NvStWizexecutable
MD5:9E82E3B658393BED3F7E4F090DF1FBE7
SHA256:C2AD5BD189DF04B39BE18DEC5CD251CF79B066010706AD26D99DF7E49FD07762
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\plugins\lang-1049.dllexecutable
MD5:0AC98A4BFC717523E344010A42C2F4BA
SHA256:68546336232AA2BE277711AFA7C1F08ECD5FCC92CC182F90459F0C61FB39507F
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\plugins\StartupHelperexecutable
MD5:14934CACA84D5FE0288F27EFB31DCBF8
SHA256:7FA86147035627BAE39576BCBE619D045E94A48C4DB8CA131968C20BB4DE4A36
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\ImNtUtilU.dllexecutable
MD5:BB326FE795E2C1C19CD79F320E169FD3
SHA256:A8E1B0E676DCE9556037D29FD96521EC814858404BA4CFDD0DB0EDBE22C87BC7
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\IMHttpComm.dllexecutable
MD5:A70D91A9FD7B65BAA0355EE559098BD8
SHA256:96D6264B26DECF6595CA6F0584A1B60589EC5DACDF03DDF5FBB6104A6AFC9E7A
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\ImUtilsU.dllexecutable
MD5:A7EABA8BC12B2B7EC2A41A4D9E45008A
SHA256:914B1E53451B8BE2C362D62514F28BDEF46A133535D959B13F3F4BF3BC63DF3A
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\ImLookU.dllexecutable
MD5:3EA6D805A18715F7368363DEA3CD3F4C
SHA256:A6766C524497144D585EFA4FE384B516B563203427003508F7C8F6BFFA7C928D
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\mfc80u.dllexecutable
MD5:CCC2E312486AE6B80970211DA472268B
SHA256:18BE5D3C656236B7E3CD6D619D62496FE3E7F66BF2859E460F8AC3D1A6BDAA9A
2116Setup.exeC:\Users\admin\AppData\Local\Temp\nss955A.tmp\ImWrappU.dllexecutable
MD5:CBF4827A5920A5F02C50F78ED46D0319
SHA256:7187903A9E4078F4D31F4B709A59D24EB6B417EA289F4F28EABCE1EA2E713DCE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
42
DNS requests
17
Threats
3

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4716
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5620
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7856
svchost.exe
4.209.33.156:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4
System
192.168.100.255:138
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
2760
svchost.exe
40.113.103.199:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3404
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4716
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4716
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.159.64
  • 20.190.159.0
  • 40.126.31.69
  • 40.126.31.73
  • 20.190.159.68
  • 20.190.159.4
  • 20.190.159.23
  • 20.190.159.71
  • 20.190.159.2
  • 40.126.31.71
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.238
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted
www.bing.com
  • 104.126.37.136
  • 104.126.37.139
  • 104.126.37.163
  • 104.126.37.178
  • 104.126.37.171
  • 104.126.37.130
  • 104.126.37.131
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted
accessibledpzp.shop
  • 188.114.96.3
  • 188.114.97.3
unknown

Threats

PID
Process
Class
Message
8044
PoplarNegligee.pif
A Network Trojan was detected
STEALER [ANY.RUN] Lumma Stealer TLS Connection
2168
svchost.exe
Misc activity
ET INFO Pastebin Service Domain in DNS Lookup (rentry .co)
8044
PoplarNegligee.pif
Misc activity
ET INFO Observed Pastebin Service Domain (rentry .co in TLS SNI)
No debug info