download:

/suffz/luna/raw/refs/heads/main/Bootstrapper.zip

Full analysis: https://app.any.run/tasks/711118ab-71c5-4f0c-ac72-4f97315dd927
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: December 11, 2024, 01:20:57
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
auto
sliverfox
arch-exec
github
golang
crypto-regex
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

9BA94AC44294258328B5B23E6FBCAF4A

SHA1:

3EF50DA71C5800F02680733B184BB11BB0CA309B

SHA256:

A9E76B770FB8A61F793A61CA6701E1F76EA95282D5A3647D8DFCCF1B560F401A

SSDEEP:

98304:T8WkMQF7kSEqTrIiukIw2MyLx3CyMpLlFq/uZvFVdcm6MjF0lES3WNm6IUG6Qz3i:17HJ3NE43TU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6544)
    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 4308)
    • SLIVERFOX has been found (auto)

      • WinRAR.exe (PID: 6544)
    • The DLL Hijacking

      • msedgewebview2.exe (PID: 6488)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Bootstrapper.exe (PID: 6820)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5732)
      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • Luna.exe (PID: 4160)
      • MicrosoftEdge_X64_131.0.2903.86.exe (PID: 524)
      • setup.exe (PID: 7064)
    • Application launched itself

      • Luna.exe (PID: 4804)
      • setup.exe (PID: 7064)
      • MicrosoftEdgeUpdate.exe (PID: 3188)
      • msedgewebview2.exe (PID: 5472)
    • Process drops legitimate windows executable

      • Luna.exe (PID: 4160)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5732)
      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • MicrosoftEdge_X64_131.0.2903.86.exe (PID: 524)
      • setup.exe (PID: 7064)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5732)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 4308)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 4716)
      • MicrosoftEdgeUpdate.exe (PID: 5740)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5472)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5252)
    • Found regular expressions for crypto-addresses (YARA)

      • Luna.exe (PID: 4804)
      • Luna.exe (PID: 4160)
    • Potential Corporate Privacy Violation

      • svchost.exe (PID: 5316)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 3188)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • MicrosoftEdgeUpdate.exe (PID: 3188)
      • msedgewebview2.exe (PID: 5472)
    • Creates a software uninstall entry

      • setup.exe (PID: 7064)
    • Searches for installed software

      • setup.exe (PID: 7064)
      • msedgewebview2.exe (PID: 5472)
  • INFO

    • Checks supported languages

      • Bootstrapper.exe (PID: 6820)
      • Luna.exe (PID: 4804)
      • Luna.exe (PID: 4160)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5732)
      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • MicrosoftEdgeUpdate.exe (PID: 5740)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 4716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5472)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5252)
      • MicrosoftEdgeUpdate.exe (PID: 5696)
      • MicrosoftEdgeUpdate.exe (PID: 5460)
      • MicrosoftEdgeUpdate.exe (PID: 3188)
      • setup.exe (PID: 7064)
      • setup.exe (PID: 7072)
      • MicrosoftEdge_X64_131.0.2903.86.exe (PID: 524)
      • MicrosoftEdgeUpdate.exe (PID: 2324)
      • msedgewebview2.exe (PID: 5472)
      • msedgewebview2.exe (PID: 5536)
      • msedgewebview2.exe (PID: 6948)
      • msedgewebview2.exe (PID: 6488)
      • msedgewebview2.exe (PID: 1512)
      • msedgewebview2.exe (PID: 432)
      • msedgewebview2.exe (PID: 6252)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6544)
    • Reads the machine GUID from the registry

      • Bootstrapper.exe (PID: 6820)
      • Luna.exe (PID: 4804)
      • Luna.exe (PID: 4160)
      • MicrosoftEdgeUpdate.exe (PID: 3188)
      • msedgewebview2.exe (PID: 5472)
    • Manual execution by a user

      • Bootstrapper.exe (PID: 6820)
    • Reads the software policy settings

      • Bootstrapper.exe (PID: 6820)
      • Luna.exe (PID: 4804)
      • Luna.exe (PID: 4160)
      • MicrosoftEdgeUpdate.exe (PID: 3188)
      • MicrosoftEdgeUpdate.exe (PID: 5696)
      • MicrosoftEdgeUpdate.exe (PID: 2324)
    • Reads the computer name

      • Bootstrapper.exe (PID: 6820)
      • Luna.exe (PID: 4804)
      • Luna.exe (PID: 4160)
      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • MicrosoftEdgeUpdate.exe (PID: 5740)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 4716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5252)
      • MicrosoftEdgeUpdate.exe (PID: 5696)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5472)
      • MicrosoftEdgeUpdate.exe (PID: 5460)
      • MicrosoftEdgeUpdate.exe (PID: 3188)
      • MicrosoftEdge_X64_131.0.2903.86.exe (PID: 524)
      • setup.exe (PID: 7064)
      • MicrosoftEdgeUpdate.exe (PID: 2324)
      • msedgewebview2.exe (PID: 5472)
      • msedgewebview2.exe (PID: 6488)
      • msedgewebview2.exe (PID: 6948)
    • Reads Environment values

      • Luna.exe (PID: 4804)
      • Luna.exe (PID: 4160)
      • MicrosoftEdgeUpdate.exe (PID: 5696)
      • MicrosoftEdgeUpdate.exe (PID: 2324)
      • msedgewebview2.exe (PID: 5472)
    • Create files in a temporary directory

      • Luna.exe (PID: 4160)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5732)
      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • svchost.exe (PID: 5316)
      • msedgewebview2.exe (PID: 5472)
    • The sample compiled with english language support

      • Luna.exe (PID: 4160)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5732)
      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • svchost.exe (PID: 5316)
      • MicrosoftEdge_X64_131.0.2903.86.exe (PID: 524)
      • setup.exe (PID: 7064)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • MicrosoftEdgeUpdate.exe (PID: 3188)
      • MicrosoftEdge_X64_131.0.2903.86.exe (PID: 524)
      • setup.exe (PID: 7072)
      • setup.exe (PID: 7064)
      • msedgewebview2.exe (PID: 5472)
      • msedgewebview2.exe (PID: 5536)
      • msedgewebview2.exe (PID: 6948)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 4308)
      • setup.exe (PID: 7064)
      • msedgewebview2.exe (PID: 5472)
      • msedgewebview2.exe (PID: 432)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 5696)
      • MicrosoftEdgeUpdate.exe (PID: 3188)
      • MicrosoftEdgeUpdate.exe (PID: 2324)
      • msedgewebview2.exe (PID: 5472)
    • Application based on Golang

      • Luna.exe (PID: 4804)
      • Luna.exe (PID: 4160)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6544)
    • Sends debugging messages

      • msedgewebview2.exe (PID: 5472)
      • Luna.exe (PID: 4160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:11:07 20:00:52
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Luna/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
27
Malicious processes
11
Suspicious processes
2

Behavior graph

Click at the process to see the details
start #SLIVERFOX winrar.exe rundll32.exe no specs bootstrapper.exe conhost.exe no specs luna.exe luna.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe svchost.exe microsoftedge_x64_131.0.2903.86.exe setup.exe setup.exe no specs microsoftedgeupdate.exe msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
432"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\131.0.2903.86\msedgewebview2.exe" --type=renderer --string-annotations=is-enterprise-managed=no --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Roaming\Luna.exe\EBWebView" --webview-exe-name=Luna.exe --webview-exe-version=1.0.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=" --field-trial-handle=3472,i,1186703456668985548,17644674700872542533,262144 --disable-features=msSmartScreenProtection --variations-seed-version --mojo-platform-channel-handle=3520 /prefetch:1C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\131.0.2903.86\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Version:
131.0.2903.86
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\131.0.2903.86\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\131.0.2903.86\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
524"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{ABDCC78A-B6B4-4E8F-AB7D-4CB110C63DF5}\MicrosoftEdge_X64_131.0.2903.86.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{ABDCC78A-B6B4-4E8F-AB7D-4CB110C63DF5}\MicrosoftEdge_X64_131.0.2903.86.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
131.0.2903.86
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{abdcc78a-b6b4-4e8f-ab7d-4cb110c63df5}\microsoftedge_x64_131.0.2903.86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1512"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\131.0.2903.86\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Roaming\Luna.exe\EBWebView" --webview-exe-name=Luna.exe --webview-exe-version=1.0.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=2440,i,1186703456668985548,17644674700872542533,262144 --disable-features=msSmartScreenProtection --variations-seed-version --mojo-platform-channel-handle=2456 /prefetch:8C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\131.0.2903.86\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Version:
131.0.2903.86
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\131.0.2903.86\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\131.0.2903.86\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2324"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuMzkiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7MEZFMDZBQ0YtOUI0My00MkY3LThBODQtRTk4RUE2RTUzQzRGfSIgdXNlcmlkPSJ7MDQzOTVFOEUtODIyNy00NENDLUI0M0YtQjVFNUU1ODBDRDY1fSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0ie0U3RTYzN0FCLTdGMDEtNEUxMi05MERDLUMyMEY5MTlGNEZBNH0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgbG9naWNhbF9jcHVzPSI0IiBwaHlzbWVtb3J5PSI0IiBkaXNrX3R5cGU9IjIiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjEwLjAuMTkwNDUuNDA0NiIgc3A9IiIgYXJjaD0ieDY0IiBwcm9kdWN0X3R5cGU9IjQ4IiBpc193aXA9IjAiIGlzX2luX2xvY2tkb3duX21vZGU9IjAiLz48b2VtIHByb2R1Y3RfbWFudWZhY3R1cmVyPSJERUxMIiBwcm9kdWN0X25hbWU9IkRFTEwiLz48ZXhwIGV0YWc9IiZxdW90O3N6bE5CSnU5eURzemZrOUJRZ2htaEUyYkI3TTJ6Ry9DMUJaOHlBL2tZYjQ9JnF1b3Q7Ii8-PGFwcCBhcHBpZD0ie0YzMDE3MjI2LUZFMkEtNDI5NS04QkRGLTAwQzNBOUE3RTRDNX0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEzMS4wLjI5MDMuODYiIGxhbmc9ImVuIiBicmFuZD0iIiBjbGllbnQ9IiIgZXhwZXJpbWVudHM9ImNvbnNlbnQ9ZmFsc2UiIGluc3RhbGxhZ2U9Ii0xIiBpbnN0YWxsZGF0ZT0iLTEiPjx1cGRhdGVjaGVjay8-PGV2ZW50IGV2ZW50dHlwZT0iOSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTI5NjIwNDY1ODQiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSIxMjk2MjIwMzM1MiIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjE0MDU5MzY5MTI5IiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIiBkb3dubG9hZGVyPSJiaXRzIiB1cmw9Imh0dHA6Ly9tc2VkZ2UuZi50bHUuZGwuZGVsaXZlcnkubXAubWljcm9zb2Z0LmNvbS9maWxlc3RyZWFtaW5nc2VydmljZS9maWxlcy8wOTcwNWViMi0xY2Y0LTQ2YmYtYmQxMi04MTA5YjMwYzMyMjc_UDE9MTczNDQ4NDg5NSZhbXA7UDI9NDA0JmFtcDtQMz0yJmFtcDtQND1JSGJ6d0NlU3diUXdiR2dnRE92anZGd2RVaSUyZlVSYnc1ayUyZjhKYktDb3dWMERvbVJvbDBHeTh6aEloSUZscldHdVdBdUI3STY4Sm5FazVhMFVLOTdVWXclM2QlM2QiIHNlcnZlcl9pcF9oaW50PSIiIGNkbl9jaWQ9Ii0xIiBjZG5fY2NjPSIiIGNkbl9tc2VkZ2VfcmVmPSIiIGNkbl9henVyZV9yZWZfb3JpZ2luX3NoaWVsZD0iIiBjZG5fY2FjaGU9IiIgY2RuX3AzcD0iIiBkb3dubG9hZGVkPSIxNzY2NzY0MDgiIHRvdGFsPSIxNzY2NzY0MDgiIGRvd25sb2FkX3RpbWVfbXM9IjEwNDkyMCIvPjxldmVudCBldmVudHR5cGU9IjEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjE0MDU5NjgyNzUyIiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTQwODAxNTMxMDgiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIxOTY3NTciIHN5c3RlbV91cHRpbWVfdGlja3M9IjE0NDU4MDEwMzE2IiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIiB1cGRhdGVfY2hlY2tfdGltZV9tcz0iMjUwIiBkb3dubG9hZF90aW1lX21zPSIxMDk3NDgiIGRvd25sb2FkZWQ9IjE3NjY3NjQwOCIgdG90YWw9IjE3NjY3NjQwOCIgcGFja2FnZV9jYWNoZV9yZXN1bHQ9IjAiIGluc3RhbGxfdGltZV9tcz0iMzc3ODYiLz48L2FwcD48L3JlcXVlc3Q-C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
3188"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4160C:\Users\admin\Desktop\Luna\luna\Luna.exeC:\Users\admin\Desktop\Luna\luna\Luna.exe
Luna.exe
User:
admin
Company:
Luna
Integrity Level:
MEDIUM
Description:
Luna
Modules
Images
c:\users\admin\desktop\luna\luna\luna.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\umpdc.dll
4308C:\Users\admin\AppData\Local\Temp\EUBBF0.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EUBBF0.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.39
Modules
Images
c:\users\admin\appdata\local\temp\eubbf0.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4716"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.39\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.39\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.39\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4804luna\Luna.exeC:\Users\admin\Desktop\Luna\luna\Luna.exe
Bootstrapper.exe
User:
admin
Company:
Luna
Integrity Level:
MEDIUM
Description:
Luna
Modules
Images
c:\users\admin\desktop\luna\luna\luna.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\umpdc.dll
5252"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.39\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.39\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.39\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
27 866
Read events
23 491
Write events
4 307
Delete events
68

Modification events

(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\Bootstrapper.zip
(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(6544) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
207
Suspicious files
90
Text files
35
Unknown types
34

Dropped files

PID
Process
Filename
Type
5732MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUBBF0.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:D6092C49ADBE6E336129589DB40DD865
SHA256:6474D531F1B8788451F9A0D9E421DFA236279466C09D783C3E6BDADF7306B909
6820Bootstrapper.exeC:\Users\admin\Desktop\Luna\downloads\Luna.zipcompressed
MD5:A877BF4F170F756BEA431920A30E5092
SHA256:F1BC5BCEB0BAB204ED16B1D7EDCACF722D67731B0CB6F1B879C678C0C9934EDD
6544WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6544.38370\Luna\Bootstrapper.exeexecutable
MD5:F2A6133B7F38FC49F792AE799D1B4750
SHA256:37BDE6655E1272E159B9C2E3A7EEE3F4E9A837C0F04240645D3991D112287F8D
6820Bootstrapper.exeC:\Users\admin\Desktop\Luna\luna\Luna.exeexecutable
MD5:B6E9C7F31447FCD62840F00D823E9700
SHA256:F3113224B1C2DF51A239AD27B90CDE97D92AD33861056E859DD01C1BA32677F0
5732MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUBBF0.tmp\MicrosoftEdgeUpdateOnDemand.exeexecutable
MD5:811502B10ADFDF17AC87F8CE1D26628A
SHA256:20B612E7E9FEA100DD2C25F476C1BDD19223C77C642495158FE9640E28B76F45
6820Bootstrapper.exeC:\Users\admin\Desktop\Luna\config.jsonbinary
MD5:EF11C9449C32AB65F2694FB9CB2ECE7B
SHA256:5A9E1F97B09A766A9DFB39F743E6D35807B953BD3393EAA5FCC40B27ADFB69A7
5732MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUBBF0.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:6513BF6501B147F7A6BB78F543C4A104
SHA256:829FE05CCF8C87A8B428BAE43CAFCA9434551EE5C80718C737D22548C9E7F342
6820Bootstrapper.exeC:\Users\admin\Desktop\Luna\luna\Luna.dllexecutable
MD5:4B9871B258627394D9E20A0F4D3EC67B
SHA256:C63D1A09CA48F9F27397C3E54E2442696458789ACE343CD8ACABB0D7B771E212
5732MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUBBF0.tmp\msedgeupdate.dllexecutable
MD5:3F84AC83FA44FB5E069640648E1660E7
SHA256:17C62E9ED5BEBDCCE2AC0CB41A255C5F63F6544FB5AB148B6810617B854F6319
5732MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUBBF0.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:D09470F63C3B544D68480425950C6954
SHA256:16F4836DFD0647421E492B789928B5AA116F74B85CA91B46BA5873890D008334
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
52
DNS requests
43
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
444
svchost.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
444
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6192
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4708
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4708
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5316
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/fb6dd03b-99d7-4cc8-a878-91c8e655c2d3?P1=1734256744&P2=404&P3=2&P4=kjjewvt0kIfdE39taFGuB8MLefnhVb8r0KtpWI2lu3A50cfLWZjkVMy%2b5byO%2bhP%2bvw984L1F4REROG5tcMthdQ%3d%3d
unknown
whitelisted
5316
svchost.exe
GET
200
199.232.214.172:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/09705eb2-1cf4-46bf-bd12-8109b30c3227?P1=1734484895&P2=404&P3=2&P4=IHbzwCeSwbQwbGggDOvjvFwdUi%2fURbw5k%2f8JbKCowV0DomRol0Gy8zhIhIFlrWGuWAuB7I68JnEk5a0UK97UYw%3d%3d
unknown
whitelisted
5316
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/09705eb2-1cf4-46bf-bd12-8109b30c3227?P1=1734484895&P2=404&P3=2&P4=IHbzwCeSwbQwbGggDOvjvFwdUi%2fURbw5k%2f8JbKCowV0DomRol0Gy8zhIhIFlrWGuWAuB7I68JnEk5a0UK97UYw%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
444
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
444
svchost.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.16.204.161:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1176
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
google.com
  • 142.250.184.206
whitelisted
www.bing.com
  • 2.16.204.161
  • 2.16.204.141
whitelisted
login.live.com
  • 40.126.32.138
  • 20.190.160.14
  • 40.126.32.68
  • 40.126.32.134
  • 20.190.160.22
  • 40.126.32.140
  • 40.126.32.133
  • 20.190.160.20
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
api.github.com
  • 140.82.121.5
whitelisted
github.com
  • 140.82.121.3
shared

Threats

PID
Process
Class
Message
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
5316
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
6948
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
6948
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Process
Message
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming directory exists )
Luna.exe
Warning: AddWebResourceRequestedFilter without SourceKind parameter is deprecated! It does not behave as expected for iframes.Please use AddWebResourceRequestedFilterWithRequestSourceKinds instead. For more information, please see https://go.microsoft.com/fwlink/?linkid=2286319