| File name: | lama.exe |
| Full analysis: | https://app.any.run/tasks/e3e72af6-6aab-4181-908c-df8a6dababda |
| Verdict: | Malicious activity |
| Analysis date: | July 06, 2025, 07:23:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, 2 sections |
| MD5: | DD4A8881D89EC0104F01B67E5258CF3E |
| SHA1: | A4DFC6999FDCCC0BF842D61B9AF76E08B63A31D5 |
| SHA256: | B740FC42697FDC1DCA91D1A99C3F2384746742D7277D364ADADD7A0EC1B6E676 |
| SSDEEP: | 49152:kKtB/vk7v0t6Az6BivIXfOvcLWRQ0KwqODqYz6TUoKZuqppRvHhsMFS3YFW6EmDx:kIB/uv0tnIXfOvmWR3pqwteyfPNhsaSE |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:07:06 07:22:08+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit, No debug |
| PEType: | PE32 |
| LinkerVersion: | 14.43 |
| CodeSize: | 2379776 |
| InitializedDataSize: | 2280448 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x47425e |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3504 | "C:\Users\admin\AppData\Local\Temp\lama.exe" | C:\Users\admin\AppData\Local\Temp\lama.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| (PID) Process: | (3504) lama.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3504 | lama.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:77B20B5CD41BC6BB475CCA3F91AE6E3C | SHA256:5511A9B9F9144ED7BDE4CCB074733B7C564D918D2A8B10D391AFC6BE5B3B1509 | |||
| 3504 | lama.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:964EEEE1CFB286823FC595BFDC71814F | SHA256:4C847E0C28733ED319BA0DAF9FEC19CB289E39E1AADE5BA698978121D8B2005F | |||
| 3504 | lama.exe | C:\Users\admin\AppData\Local\Temp\Tar7C14.tmp | binary | |
MD5:AF5E72529C6AB3E9DD85150155483CC2 | SHA256:21CFD197DCD8D8097606A3CA2774B832D0C7737498FE95CB12DD632EBF5B5E68 | |||
| 3504 | lama.exe | C:\Users\admin\AppData\Local\Temp\TmpF59A.tmp | binary | |
MD5:037C697F1EBECB43FE0957ECE0E2B26E | SHA256:7627A821B49655D59B2F1EF7D022692DEC665726E42375B7341236F86F6E7083 | |||
| 3504 | lama.exe | C:\Users\admin\AppData\Local\Temp\Cab7C13.tmp | compressed | |
MD5:964EEEE1CFB286823FC595BFDC71814F | SHA256:4C847E0C28733ED319BA0DAF9FEC19CB289E39E1AADE5BA698978121D8B2005F | |||
| 3504 | lama.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:44CE01C32C198ACA814C06D4E0A34DD2 | SHA256:51C3C5E0B7E4290FDB08AC286665673D9605AEC9374AC2635C3DEB276094BC88 | |||
| 3504 | lama.exe | C:\Users\admin\AppData\Local\Temp\Tmp77EB.tmp | binary | |
MD5:4048C1724AB3F48AA2902503EC7D42A9 | SHA256:D4E5D22986F67249094C506F2AD121EDA06171170F253D1E32EB70FF80B4980E | |||
| 3504 | lama.exe | C:\Users\admin\AppData\Local\Temp\Tmp143E.tmp | binary | |
MD5:D93FCB38632785CAB17A099F1FE26194 | SHA256:82F3002C0221388B9C1675C7FDB52B71A2B7059A64A73C047C62BFBF38E02701 | |||
| 3504 | lama.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:40EBB5E67CB1E50BA51A951BFAA9D63B | SHA256:78BC32968B036A90D9ECA36909F5203CA7B2F9CD0D810A47D376D148F353C97A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3504 | lama.exe | GET | 200 | 208.89.74.21:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?eb364d15dfef2c80 | unknown | — | — | whitelisted |
3504 | lama.exe | GET | 200 | 208.89.74.21:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0e911b067ec79cf2 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3504 | lama.exe | 147.185.221.28:36653 | — | PLAYIT-GG | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3504 | lama.exe | 208.89.74.21:80 | ctldl.windowsupdate.com | — | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |