URL: | https://dclouddwnldfrz.xyz/?code=cQle2GxTRdCsj&uid=281&sid=280 |
Full analysis: | https://app.any.run/tasks/8a33c30f-1d55-4c70-9002-a67ebb13285c |
Verdict: | Malicious activity |
Threats: | Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat. |
Analysis date: | July 05, 2025, 21:23:03 |
OS: | Ubuntu 22.04.2 |
Tags: | |
Indicators: | |
MD5: | 154CCB343DF4EA343BABF369E50C5A69 |
SHA1: | 64166D30FE90A9B466356B5A43EF0855BFB41C6C |
SHA256: | BEBCFDDFC713237B3247F8F31D9C8062BDAB8FD4B30828EF80A00D89487C5C57 |
SSDEEP: | 3:N8e5BK1XhFNs1d2UAVn:2efKdjTUAV |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
445 | /lib/systemd/systemd-resolved | /usr/lib/systemd/systemd-resolved | systemd | ||||||||||||
User: systemd-resolve Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41393 | /bin/sh -c "DISPLAY=:0 sudo -iu user google-chrome https://dclouddwnldfrz\.xyz/?code=cQle2GxTRdCsj&uid=281&sid=280 " | /usr/bin/dash | — | UbvyYXL4x2mYa65Q | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41394 | sudo -iu user google-chrome https://dclouddwnldfrz.xyz/?code=cQle2GxTRdCsj | /usr/bin/sudo | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41395 | /bin/sh -c "DISPLAY=:0 sudo -iu user google-chrome https://dclouddwnldfrz\.xyz/?code=cQle2GxTRdCsj&uid=281&sid=280 " | /usr/bin/dash | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 | |||||||||||||||
41396 | /usr/bin/google-chrome https://dclouddwnldfrz.xyz/?code=cQle2GxTRdCsj | /opt/google/chrome/chrome | — | sudo | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41397 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41398 | readlink -f /usr/bin/google-chrome | /usr/bin/readlink | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41399 | dirname /opt/google/chrome/google-chrome | /usr/bin/dirname | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41400 | mkdir -p /home/user/.local/share/applications | /usr/bin/mkdir | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41401 | cat | /usr/bin/cat | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
41396 | chrome | /home/user/.config/google-chrome/ShaderCache/data_0 | binary | |
MD5:— | SHA256:— | |||
41396 | chrome | /home/user/.config/google-chrome/ShaderCache/data_3 | binary | |
MD5:— | SHA256:— | |||
41396 | chrome | /home/user/.config/google-chrome/ShaderCache/data_2 | binary | |
MD5:— | SHA256:— | |||
41396 | chrome | /home/user/.config/google-chrome/Default/GPUCache/data_3 | binary | |
MD5:— | SHA256:— | |||
41396 | chrome | /home/user/.config/google-chrome/Default/GPUCache/data_2 | binary | |
MD5:— | SHA256:— | |||
41396 | chrome | /home/user/.config/google-chrome/Default/GPUCache/data_0 | binary | |
MD5:— | SHA256:— | |||
41441 | chrome | /home/user/.cache/mesa_shader_cache/index | binary | |
MD5:— | SHA256:— | |||
41538 | chrome | /home/user/.cache/mesa_shader_cache/index | binary | |
MD5:— | SHA256:— | |||
41396 | chrome | /home/user/.config/google-chrome/Default/History | sqlite | |
MD5:— | SHA256:— | |||
41396 | chrome | /home/user/.config/google-chrome/Default/DawnGraphiteCache/data_3 | binary | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 185.125.190.96:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 185.125.190.96:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
— | — | 91.189.91.48:80 | connectivity-check.ubuntu.com | Canonical Group Limited | US | whitelisted |
484 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
1178 | snap-store | 37.19.194.81:443 | odrs.gnome.org | Datacamp Limited | DE | whitelisted |
512 | snapd | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
512 | snapd | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
512 | snapd | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
512 | snapd | 185.125.188.57:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
41443 | chrome | 188.114.96.3:443 | dclouddwnldfrz.xyz | — | — | unknown |
41443 | chrome | 142.250.184.227:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
api.snapcraft.io |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
safebrowsingohttpgateway.googleapis.com |
| whitelisted |
dclouddwnldfrz.xyz |
| unknown |
accounts.google.com |
| whitelisted |
8.100.168.192.in-addr.arpa |
| unknown |
update.googleapis.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
— | — | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |