URL:

https://mega.nz/file/AysQBK7a#GTZDWKD-SJBuUzotz3_zni2d5A4VMFMMpcOM4Z3qCEE

Full analysis: https://app.any.run/tasks/02900f0f-4067-4718-82b7-8ecce7ff4635
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: August 07, 2024, 11:25:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
lumma
stealer
Indicators:
MD5:

D9C89A2ECD8A080DC3E79C4D2B1F89B2

SHA1:

1256C2033B0C3A16A8782F9826389D3F63CA5215

SHA256:

A406EEDAE349ECFDE76D0B2D14685ACB8020A0D114DD11A25489333FD350701C

SSDEEP:

3:N8X/i23Hb1wXBjoT8Xg:2QjY8Xg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Setup.exe (PID: 7528)
      • more.com (PID: 8036)
    • LUMMA has been detected (YARA)

      • KeptHamlet.au3 (PID: 7488)
    • Stealers network behavior

      • KeptHamlet.au3 (PID: 7488)
    • LUMMA has been detected (SURICATA)

      • KeptHamlet.au3 (PID: 7488)
    • Actions looks like stealing of personal data

      • KeptHamlet.au3 (PID: 7488)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7468)
      • WinRAR.exe (PID: 904)
      • WinRAR.exe (PID: 6676)
      • WinRAR.exe (PID: 1216)
    • Application launched itself

      • WinRAR.exe (PID: 7468)
      • WinRAR.exe (PID: 6676)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 904)
      • WinRAR.exe (PID: 1216)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 7528)
      • more.com (PID: 8036)
    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 7468)
    • Starts application with an unusual extension

      • more.com (PID: 8036)
      • Setup.exe (PID: 7528)
    • Searches for installed software

      • KeptHamlet.au3 (PID: 7488)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 6404)
      • msedge.exe (PID: 6160)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 6404)
      • WinRAR.exe (PID: 7468)
      • msedge.exe (PID: 6160)
    • The process uses the downloaded file

      • msedge.exe (PID: 6160)
      • msedge.exe (PID: 6404)
      • WinRAR.exe (PID: 7468)
      • WinRAR.exe (PID: 6676)
    • Reads the computer name

      • identity_helper.exe (PID: 7728)
      • Setup.exe (PID: 7528)
      • StrCmp.exe (PID: 7488)
      • more.com (PID: 8036)
      • identity_helper.exe (PID: 8116)
      • KeptHamlet.au3 (PID: 7488)
      • Setup.exe (PID: 7136)
    • Checks supported languages

      • identity_helper.exe (PID: 7728)
      • Setup.exe (PID: 7528)
      • StrCmp.exe (PID: 7488)
      • more.com (PID: 8036)
      • KeptHamlet.au3 (PID: 7488)
      • identity_helper.exe (PID: 8116)
      • Setup.exe (PID: 7136)
    • Reads Environment values

      • identity_helper.exe (PID: 7728)
      • identity_helper.exe (PID: 8116)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 904)
      • WinRAR.exe (PID: 1216)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 904)
      • WinRAR.exe (PID: 1216)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 7528)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 7736)
    • Manual execution by a user

      • WinRAR.exe (PID: 6676)
    • Create files in a temporary directory

      • Setup.exe (PID: 7528)
      • more.com (PID: 8036)
    • Reads the software policy settings

      • KeptHamlet.au3 (PID: 7488)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Lumma

(PID) Process(7488) KeptHamlet.au3
C2 (9)boattyownerwrv.shop
definitonizmnx.shop
assumedtribsosp.shop
chippyfroggsyhz.shop
budgetttysnzm.shop
creepydxzoxmj.shop
boillingyskop.shop
empiredzmwnx.shop
rainbowmynsjn.shop
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
222
Monitored processes
83
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe no specs winrar.exe msedge.exe no specs msedge.exe no specs setup.exe no specs setup.exe strcmp.exe no specs more.com conhost.exe no specs msedge.exe no specs notepad.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs #LUMMA kepthamlet.au3 rundll32.exe no specs winrar.exe no specs winrar.exe msedge.exe setup.exe no specs setup.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
376"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5640 --field-trial-handle=2628,i,712580755336198491,6924796371290292551,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
640"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5684 --field-trial-handle=2628,i,712580755336198491,6924796371290292551,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
904"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa7468.30029\#!!SetUp_2244_PassW0rd$.rarC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1216"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa6676.34728\#!!SetUp_2244_PassW0rd$.rarC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1432"C:\Users\admin\AppData\Local\Temp\Rar$EXb1216.35429\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1216.35429\Setup.exeWinRAR.exe
User:
admin
Company:
IObit
Integrity Level:
MEDIUM
Description:
IObit RttHlp
Exit code:
3221226540
Version:
11.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1216.35429\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1492"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4196 --field-trial-handle=2352,i,5258000364640674791,8797026182494033911,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1688"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=4904 --field-trial-handle=2352,i,5258000364640674791,8797026182494033911,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
1692"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5992 --field-trial-handle=2352,i,5258000364640674791,8797026182494033911,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2128"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6388 --field-trial-handle=2628,i,712580755336198491,6924796371290292551,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2128"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2348 --field-trial-handle=2352,i,5258000364640674791,8797026182494033911,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
43 453
Read events
43 143
Write events
305
Delete events
5

Modification events

(PID) Process:(6404) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6404) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6404) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(6404) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(6404) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6404) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(6404) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6404) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge
Operation:writeName:UsageStatsInSample
Value:
1
(PID) Process:(6404) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
C653A273AC7D2F00
(PID) Process:(6404) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:usagestats
Value:
0
Executable files
45
Suspicious files
334
Text files
343
Unknown types
137

Dropped files

PID
Process
Filename
Type
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFe69b2.TMP
MD5:
SHA256:
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFe69b2.TMP
MD5:
SHA256:
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFe69b2.TMP
MD5:
SHA256:
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFe69b2.TMP
MD5:
SHA256:
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFe6a1f.TMP
MD5:
SHA256:
6404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
97
DNS requests
83
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5300
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5300
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8144
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6236
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7832
svchost.exe
HEAD
200
138.113.27.176:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a8381623-5b08-479e-aab0-f1075e82bccf?P1=1723621393&P2=404&P3=2&P4=DXtV1APvdEGf4LQUiAujsbTnXzsEA%2b7SvnrwfJC%2b1ZGkDAY8ZZbn4u1JPSrF3eanyKdLOIis28713vJ%2fLoAQHQ%3d%3d
unknown
whitelisted
7832
svchost.exe
GET
206
138.113.27.176:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a8381623-5b08-479e-aab0-f1075e82bccf?P1=1723621393&P2=404&P3=2&P4=DXtV1APvdEGf4LQUiAujsbTnXzsEA%2b7SvnrwfJC%2b1ZGkDAY8ZZbn4u1JPSrF3eanyKdLOIis28713vJ%2fLoAQHQ%3d%3d
unknown
whitelisted
7832
svchost.exe
GET
206
138.113.27.176:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a8381623-5b08-479e-aab0-f1075e82bccf?P1=1723621393&P2=404&P3=2&P4=DXtV1APvdEGf4LQUiAujsbTnXzsEA%2b7SvnrwfJC%2b1ZGkDAY8ZZbn4u1JPSrF3eanyKdLOIis28713vJ%2fLoAQHQ%3d%3d
unknown
whitelisted
7832
svchost.exe
GET
206
138.113.27.176:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a8381623-5b08-479e-aab0-f1075e82bccf?P1=1723621393&P2=404&P3=2&P4=DXtV1APvdEGf4LQUiAujsbTnXzsEA%2b7SvnrwfJC%2b1ZGkDAY8ZZbn4u1JPSrF3eanyKdLOIis28713vJ%2fLoAQHQ%3d%3d
unknown
whitelisted
7832
svchost.exe
GET
206
138.113.27.176:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a8381623-5b08-479e-aab0-f1075e82bccf?P1=1723621393&P2=404&P3=2&P4=DXtV1APvdEGf4LQUiAujsbTnXzsEA%2b7SvnrwfJC%2b1ZGkDAY8ZZbn4u1JPSrF3eanyKdLOIis28713vJ%2fLoAQHQ%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1860
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
2872
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
6788
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
whitelisted
6404
msedge.exe
239.255.255.250:1900
whitelisted
6788
msedge.exe
13.107.246.67:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6788
msedge.exe
31.216.144.5:443
mega.nz
Datacenter Luxembourg S.A.
LU
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.238
  • 142.250.181.238
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
mega.nz
  • 31.216.144.5
  • 31.216.145.5
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.67
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
www.bing.com
  • 92.123.104.19
  • 92.123.104.26
  • 92.123.104.21
  • 92.123.104.28
  • 92.123.104.22
  • 92.123.104.23
  • 92.123.104.14
  • 92.123.104.13
  • 92.123.104.17
  • 92.123.104.58
  • 92.123.104.50
  • 92.123.104.61
  • 92.123.104.60
  • 92.123.104.54
  • 92.123.104.63
  • 92.123.104.47
  • 92.123.104.62
  • 92.123.104.59
  • 2.23.209.141
  • 2.23.209.131
  • 2.23.209.140
  • 2.23.209.136
  • 2.23.209.142
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.139
  • 2.23.209.143
whitelisted
bzib.nelreports.net
  • 184.24.77.43
  • 184.24.77.33
whitelisted
eu.static.mega.co.nz
  • 89.44.169.132
  • 66.203.124.37
shared

Threats

PID
Process
Class
Message
6788
msedge.exe
Misc activity
ET INFO File Sharing Related Domain in DNS Lookup (mega .nz)
6788
msedge.exe
Misc activity
ET INFO File Sharing Related Domain in DNS Lookup (mega .nz)
6788
msedge.exe
Misc activity
ET INFO File Sharing Domain Observed in TLS SNI (mega .nz)
6788
msedge.exe
Misc activity
ET INFO Observed DNS Query to Filesharing Service (mega .co .nz)
6788
msedge.exe
Misc activity
ET INFO Observed DNS Query to Filesharing Service (mega .co .nz)
6788
msedge.exe
Misc activity
ET INFO File Sharing Domain Observed in TLS SNI (mega .nz)
6788
msedge.exe
Misc activity
ET INFO Observed DNS Query to Filesharing Service (mega .co .nz)
6788
msedge.exe
Misc activity
ET INFO Observed DNS Query to Filesharing Service (mega .co .nz)
6788
msedge.exe
Misc activity
ET INFO File Sharing Related Domain in DNS Lookup (mega .nz)
6788
msedge.exe
Misc activity
ET INFO File Sharing Related Domain in DNS Lookup (mega .nz)
No debug info