File name:

ONE1.exe

Full analysis: https://app.any.run/tasks/2544e364-f64f-44d6-919e-a9b112c83012
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: October 03, 2025, 17:54:15
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
autoit
lumma
stealer
anti-evasion
rhadamanthys
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

E71E864B2CEBDF9856B28CAE9D82D38B

SHA1:

323D0933F4DE08A149B8CF09934EBD5001A10857

SHA256:

A02AE43D5C1E4003A2400D0A9F91FE4BDAD517685A5FEADB675A81D4FC2DF619

SSDEEP:

49152:gKwZBmGdsdupF886B4pD5nc06b7LPXa3nWuorTcsKxaIFARK2HE/QcenYS2L+RcP:gKwfmddupFCBQNc06b7DXaGuzEfbcU25

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • ONE1.exe (PID: 6292)
    • LUMMA has been detected (SURICATA)

      • svchost.exe (PID: 2428)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ONE1.exe (PID: 6292)
    • Starts CMD.EXE for commands execution

      • ONE1.exe (PID: 6292)
      • cmd.exe (PID: 4364)
    • Reads command from file

      • cmd.exe (PID: 4364)
    • Application launched itself

      • cmd.exe (PID: 4364)
    • Get information on the list of running processes

      • cmd.exe (PID: 6780)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 6780)
    • Starts application with an unusual extension

      • cmd.exe (PID: 6780)
    • Starts the AutoIt3 executable file

      • cmd.exe (PID: 6780)
    • The executable file from the user directory is run by the CMD process

      • Mixed.scr (PID: 2092)
    • There is functionality for taking screenshot (YARA)

      • ONE1.exe (PID: 6292)
    • The process checks if it is being run in the virtual environment

      • Mixed.scr (PID: 708)
    • Executes application which crashes

      • Mixed.scr (PID: 708)
  • INFO

    • Create files in a temporary directory

      • ONE1.exe (PID: 6292)
      • extrac32.exe (PID: 4960)
    • Reads the computer name

      • ONE1.exe (PID: 6292)
      • extrac32.exe (PID: 4960)
      • Mixed.scr (PID: 2092)
      • Mixed.scr (PID: 708)
    • Checks supported languages

      • ONE1.exe (PID: 6292)
      • extrac32.exe (PID: 4960)
      • Mixed.scr (PID: 2092)
      • Mixed.scr (PID: 708)
    • Reads mouse settings

      • Mixed.scr (PID: 2092)
    • Manual execution by a user

      • Mixed.scr (PID: 708)
    • Reads the machine GUID from the registry

      • Mixed.scr (PID: 708)
    • Checks proxy server information

      • slui.exe (PID: 4452)
    • Reads the software policy settings

      • slui.exe (PID: 4452)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:12:13 01:43:31+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 28672
InitializedDataSize: 445952
UninitializedDataSize: 16896
EntryPoint: 0x39e3
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
180
Monitored processes
13
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
708C:\Users\admin\AppData\Local\Temp\565177\Mixed.scr C:\Users\admin\AppData\Local\Temp\565177\Mixed.scr
explorer.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
AutoIt v3 Script (Beta)
Exit code:
3221225512
Version:
3, 3, 17, 0
Modules
Images
c:\users\admin\appdata\local\temp\565177\mixed.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2092Mixed.scr s C:\Users\admin\AppData\Local\Temp\565177\Mixed.scrcmd.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
AutoIt v3 Script (Beta)
Exit code:
0
Version:
3, 3, 17, 0
Modules
Images
c:\users\admin\appdata\local\temp\565177\mixed.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
2164tasklist C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2944\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3552C:\WINDOWS\system32\WerFault.exe -u -p 708 -s 640C:\Windows\System32\WerFault.exeMixed.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
4364cmd.exe /c cmd < Punishment.mdbC:\Windows\SysWOW64\cmd.exeONE1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4452C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4472findstr "bdservicehost ekrn AvastUI SophosHealth AVGUI nsWscSvc" C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4960extrac32 /Y Concentrate.mdb *.*C:\Windows\SysWOW64\extrac32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® CAB File Extract Utility
Exit code:
0
Version:
5.00 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\extrac32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
4 924
Read events
4 924
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
20
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
6292ONE1.exeC:\Users\admin\AppData\Local\Temp\Violence.mdbbinary
MD5:6246BF23CE1EC6B135420A47ACB7131B
SHA256:BF2557C9B17AF7C30C43D7F20B7686BB1666254304F9A3D040746C8D07A3547F
6292ONE1.exeC:\Users\admin\AppData\Local\Temp\Pocket.mdbbinary
MD5:CF8853E08EC2FC4B15FEA5508425C87E
SHA256:0937CCDEE7B098933674E0FC455DAAD7DDEBC6D812290D8509ADE68A3EC482EB
6292ONE1.exeC:\Users\admin\AppData\Local\Temp\Punishment.mdbtext
MD5:D66D63E38D665A72844571FF9BB2B6A3
SHA256:4403CB4F561F62BFD7EC1D6BB530630E59A35F3AFCEFB8585D47BC5D11D1D8A1
6292ONE1.exeC:\Users\admin\AppData\Local\Temp\Concentrate.mdbbinary
MD5:1AF62D13E62A9C79B6CB468E0487C74B
SHA256:C2A466442F47E05B6D0F0189201F48143E164E1E56A0B9939196B7F5F0419328
4960extrac32.exeC:\Users\admin\AppData\Local\Temp\Lingeriebinary
MD5:A2D08A6DFE9CEC331E2CC67357674AA5
SHA256:AE907F3A8FB1D4EEEA4212AE57E39B3E47F9733CB07BC45D52B54EBD714BF13B
6292ONE1.exeC:\Users\admin\AppData\Local\Temp\Shortcuts.mdbbinary
MD5:9641EEE7B75E664232D88AFA2411E787
SHA256:3E6C648938094BA8EAAC2900A48610A71198EC59DC3D2659875D4AF03F7B04C8
6292ONE1.exeC:\Users\admin\AppData\Local\Temp\nsb1F61.tmp\nsExec.dllexecutable
MD5:08E9796CA20C5FC5076E3AC05FB5709A
SHA256:8165C7AEF7DE3D3E0549776535BEDC380AD9BE7BB85E60AD6436F71528D092AF
6292ONE1.exeC:\Users\admin\AppData\Local\Temp\Experiencing.mdbbinary
MD5:754072E6447320AF0E08B8F626C6CD80
SHA256:4B4FEE11D34FC8E872448FEC43E88B96259DA9CF0D5267BF890AB4E5A8D9CF84
4960extrac32.exeC:\Users\admin\AppData\Local\Temp\Proceduresbinary
MD5:51BD0004D28631D47C16FF2DEED26BDD
SHA256:0E299083081F33212FEFE7C426BCC9EB623441C7B6222751FF094976017BB9F7
4960extrac32.exeC:\Users\admin\AppData\Local\Temp\Solobinary
MD5:D78A20FD8BAA4A83E59A4552884C9853
SHA256:F8AB6FA8D94CB9C31F26A5ECC4487233CAA60848F1501DCCFBAFC24B06FCC374
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
44
DNS requests
20
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
204
23.192.36.142:443
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1
US
unknown
POST
200
20.190.159.23:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
unknown
POST
200
20.190.159.23:443
https://login.live.com/RST2.srf
US
xml
11.0 Kb
unknown
POST
200
20.190.159.23:443
https://login.live.com/RST2.srf
US
xml
11.2 Kb
unknown
POST
200
20.190.159.73:443
https://login.live.com/RST2.srf
US
xml
11.3 Kb
unknown
POST
200
20.190.159.71:443
https://login.live.com/RST2.srf
US
xml
11.3 Kb
unknown
GET
200
23.192.36.142:443
https://www.bing.com/th?id=ODSWG.8229b0e5-fa8c-4e4a-af74-69717698b903&pid=dsb
US
unknown
GET
200
23.192.36.137:443
https://www.bing.com/th?id=ODSWG.31bcf3d1-4df8-4c6a-9b3a-447ced8d6c39&pid=dsb
US
unknown
GET
200
23.192.36.142:443
https://www.bing.com/client/config?cc=US&setlang=en-US
US
binary
2.15 Kb
unknown
GET
200
20.31.169.57:443
https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=88000045&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:AC7699B0-48EA-FD22-C8DC-06A02098A0F0&ctry=US&time=20251003T175431Z&lc=en-US&pl=en-US&idtp=mid&uid=9115d6d1-9f4e-4053-9297-2a8c833b3912&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=1f8f64eae6e842b7afbf5a8b1e175b78&ctmode=MultiSession&arch=x64&betaedgever=0.0.0.0&canedgever=0.0.0.0&cdm=1&cdmver=10.0.19041.3636&currsel=137271744000000000&devedgever=0.0.0.0&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.19045.4046&disphorzres=1360&dispsize=16.3&dispvertres=768&fosver=16299&isu=0&lo=4245713&metered=false&nettype=ethernet&npid=sc-88000045&oemName=DELL&oemid=DELL&ossku=Professional&prevosver=15063&smBiosDm=DELL&stabedgever=133.0.3065.92&tl=2&tsu=1636243&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing=&svoffered=2
US
binary
3.21 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6332
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5948
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
23.192.36.142:443
www.bing.com
AKAMAI-AS
US
whitelisted
8068
svchost.exe
20.190.159.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3464
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4956
backgroundTaskHost.exe
23.192.36.142:443
www.bing.com
AKAMAI-AS
US
whitelisted
6332
backgroundTaskHost.exe
20.31.169.57:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.78
whitelisted
VuwmcinBctvAcbHrRWz.VuwmcinBctvAcbHrRWz
unknown
www.bing.com
  • 23.192.36.142
  • 23.192.36.137
whitelisted
login.live.com
  • 20.190.159.131
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.129
  • 40.126.31.128
  • 20.190.159.71
  • 20.190.159.73
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

PID
Process
Class
Message
2428
svchost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Lumma DNS Activity observed
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Rhadamanthys Stage Payload HTTP Request outbound
No debug info