| File name: | ONE1.exe |
| Full analysis: | https://app.any.run/tasks/2544e364-f64f-44d6-919e-a9b112c83012 |
| Verdict: | Malicious activity |
| Threats: | Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat. |
| Analysis date: | October 03, 2025, 17:54:15 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | E71E864B2CEBDF9856B28CAE9D82D38B |
| SHA1: | 323D0933F4DE08A149B8CF09934EBD5001A10857 |
| SHA256: | A02AE43D5C1E4003A2400D0A9F91FE4BDAD517685A5FEADB675A81D4FC2DF619 |
| SSDEEP: | 49152:gKwZBmGdsdupF886B4pD5nc06b7LPXa3nWuorTcsKxaIFARK2HE/QcenYS2L+RcP:gKwfmddupFCBQNc06b7DXaGuzEfbcU25 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2014:12:13 01:43:31+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 28672 |
| InitializedDataSize: | 445952 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x39e3 |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 708 | C:\Users\admin\AppData\Local\Temp\565177\Mixed.scr | C:\Users\admin\AppData\Local\Temp\565177\Mixed.scr | explorer.exe | ||||||||||||
User: admin Company: AutoIt Team Integrity Level: MEDIUM Description: AutoIt v3 Script (Beta) Exit code: 3221225512 Version: 3, 3, 17, 0 Modules
| |||||||||||||||
| 2092 | Mixed.scr s | C:\Users\admin\AppData\Local\Temp\565177\Mixed.scr | — | cmd.exe | |||||||||||
User: admin Company: AutoIt Team Integrity Level: MEDIUM Description: AutoIt v3 Script (Beta) Exit code: 0 Version: 3, 3, 17, 0 Modules
| |||||||||||||||
| 2164 | tasklist | C:\Windows\SysWOW64\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Lists the current running tasks Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2428 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2944 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3552 | C:\WINDOWS\system32\WerFault.exe -u -p 708 -s 640 | C:\Windows\System32\WerFault.exe | — | Mixed.scr | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4364 | cmd.exe /c cmd < Punishment.mdb | C:\Windows\SysWOW64\cmd.exe | — | ONE1.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4452 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4472 | findstr "bdservicehost ekrn AvastUI SophosHealth AVGUI nsWscSvc" | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4960 | extrac32 /Y Concentrate.mdb *.* | C:\Windows\SysWOW64\extrac32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® CAB File Extract Utility Exit code: 0 Version: 5.00 (WinBuild.160101.0800) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6292 | ONE1.exe | C:\Users\admin\AppData\Local\Temp\Violence.mdb | binary | |
MD5:6246BF23CE1EC6B135420A47ACB7131B | SHA256:BF2557C9B17AF7C30C43D7F20B7686BB1666254304F9A3D040746C8D07A3547F | |||
| 6292 | ONE1.exe | C:\Users\admin\AppData\Local\Temp\Pocket.mdb | binary | |
MD5:CF8853E08EC2FC4B15FEA5508425C87E | SHA256:0937CCDEE7B098933674E0FC455DAAD7DDEBC6D812290D8509ADE68A3EC482EB | |||
| 6292 | ONE1.exe | C:\Users\admin\AppData\Local\Temp\Punishment.mdb | text | |
MD5:D66D63E38D665A72844571FF9BB2B6A3 | SHA256:4403CB4F561F62BFD7EC1D6BB530630E59A35F3AFCEFB8585D47BC5D11D1D8A1 | |||
| 6292 | ONE1.exe | C:\Users\admin\AppData\Local\Temp\Concentrate.mdb | binary | |
MD5:1AF62D13E62A9C79B6CB468E0487C74B | SHA256:C2A466442F47E05B6D0F0189201F48143E164E1E56A0B9939196B7F5F0419328 | |||
| 4960 | extrac32.exe | C:\Users\admin\AppData\Local\Temp\Lingerie | binary | |
MD5:A2D08A6DFE9CEC331E2CC67357674AA5 | SHA256:AE907F3A8FB1D4EEEA4212AE57E39B3E47F9733CB07BC45D52B54EBD714BF13B | |||
| 6292 | ONE1.exe | C:\Users\admin\AppData\Local\Temp\Shortcuts.mdb | binary | |
MD5:9641EEE7B75E664232D88AFA2411E787 | SHA256:3E6C648938094BA8EAAC2900A48610A71198EC59DC3D2659875D4AF03F7B04C8 | |||
| 6292 | ONE1.exe | C:\Users\admin\AppData\Local\Temp\nsb1F61.tmp\nsExec.dll | executable | |
MD5:08E9796CA20C5FC5076E3AC05FB5709A | SHA256:8165C7AEF7DE3D3E0549776535BEDC380AD9BE7BB85E60AD6436F71528D092AF | |||
| 6292 | ONE1.exe | C:\Users\admin\AppData\Local\Temp\Experiencing.mdb | binary | |
MD5:754072E6447320AF0E08B8F626C6CD80 | SHA256:4B4FEE11D34FC8E872448FEC43E88B96259DA9CF0D5267BF890AB4E5A8D9CF84 | |||
| 4960 | extrac32.exe | C:\Users\admin\AppData\Local\Temp\Procedures | binary | |
MD5:51BD0004D28631D47C16FF2DEED26BDD | SHA256:0E299083081F33212FEFE7C426BCC9EB623441C7B6222751FF094976017BB9F7 | |||
| 4960 | extrac32.exe | C:\Users\admin\AppData\Local\Temp\Solo | binary | |
MD5:D78A20FD8BAA4A83E59A4552884C9853 | SHA256:F8AB6FA8D94CB9C31F26A5ECC4487233CAA60848F1501DCCFBAFC24B06FCC374 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 204 | 23.192.36.142:443 | https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1 | US | — | — | unknown |
— | — | POST | 200 | 20.190.159.23:443 | https://login.live.com/RST2.srf | US | xml | 11.1 Kb | unknown |
— | — | POST | 200 | 20.190.159.23:443 | https://login.live.com/RST2.srf | US | xml | 11.0 Kb | unknown |
— | — | POST | 200 | 20.190.159.23:443 | https://login.live.com/RST2.srf | US | xml | 11.2 Kb | unknown |
— | — | POST | 200 | 20.190.159.73:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | POST | 200 | 20.190.159.71:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | GET | 200 | 23.192.36.142:443 | https://www.bing.com/th?id=ODSWG.8229b0e5-fa8c-4e4a-af74-69717698b903&pid=dsb | US | — | — | unknown |
— | — | GET | 200 | 23.192.36.137:443 | https://www.bing.com/th?id=ODSWG.31bcf3d1-4df8-4c6a-9b3a-447ced8d6c39&pid=dsb | US | — | — | unknown |
— | — | GET | 200 | 23.192.36.142:443 | https://www.bing.com/client/config?cc=US&setlang=en-US | US | binary | 2.15 Kb | unknown |
— | — | GET | 200 | 20.31.169.57:443 | https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=88000045&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:AC7699B0-48EA-FD22-C8DC-06A02098A0F0&ctry=US&time=20251003T175431Z&lc=en-US&pl=en-US&idtp=mid&uid=9115d6d1-9f4e-4053-9297-2a8c833b3912&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=1f8f64eae6e842b7afbf5a8b1e175b78&ctmode=MultiSession&arch=x64&betaedgever=0.0.0.0&canedgever=0.0.0.0&cdm=1&cdmver=10.0.19041.3636&currsel=137271744000000000&devedgever=0.0.0.0&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.19045.4046&disphorzres=1360&dispsize=16.3&dispvertres=768&fosver=16299&isu=0&lo=4245713&metered=false&nettype=ethernet&npid=sc-88000045&oemName=DELL&oemid=DELL&ossku=Professional&prevosver=15063&smBiosDm=DELL&stabedgever=133.0.3065.92&tl=2&tsu=1636243&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing=&svoffered=2 | US | binary | 3.21 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6332 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5948 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5224 | SearchApp.exe | 23.192.36.142:443 | www.bing.com | AKAMAI-AS | US | whitelisted |
8068 | svchost.exe | 20.190.159.131:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3464 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
4956 | backgroundTaskHost.exe | 23.192.36.142:443 | www.bing.com | AKAMAI-AS | US | whitelisted |
6332 | backgroundTaskHost.exe | 20.31.169.57:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
VuwmcinBctvAcbHrRWz.VuwmcinBctvAcbHrRWz |
| unknown |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2428 | svchost.exe | A Network Trojan was detected | MALWARE [ANY.RUN] Win32/Lumma DNS Activity observed |
— | — | A Network Trojan was detected | MALWARE [ANY.RUN] Win32/Rhadamanthys Stage Payload HTTP Request outbound |