File name:

Mlw.zip

Full analysis: https://app.any.run/tasks/8b8ed3f7-36b5-464f-921f-3f709de91d71
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: April 26, 2025, 00:16:27
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
telegram
lumma
stealer
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

001AE1C4784D712194C9879700DAEC83

SHA1:

C1CD9699D07E14EF2CCF312A9C4F77253C2AEE5F

SHA256:

E7F3C3D7877358557DA7A9F817B9821427E32B18983BF3647ADA52C768C0F1AD

SSDEEP:

98304:EWtuQZqEVaPSSwhlhK2jzJBKW/9/yB2ZepbOrTz6bhgf93OlEmP53QlukkWovvWh:eGm9mD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LUMMA mutex has been found

      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5504)
    • Actions looks like stealing of personal data

      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5504)
    • Steals credentials from Web Browsers

      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5504)
  • SUSPICIOUS

    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5504)
    • Searches for installed software

      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5504)
  • INFO

    • Checks supported languages

      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 6192)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5504)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 2772)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 6676)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 2240)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5400)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 1096)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 4188)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 1040)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 3008)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5964)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5132)
    • Manual execution by a user

      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5504)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 2772)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 6676)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 2240)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 6192)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5400)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 1096)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 4188)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 1040)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 3008)
      • cmd.exe (PID: 1272)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5964)
    • Reads the software policy settings

      • slui.exe (PID: 6724)
      • slui.exe (PID: 4628)
      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5504)
    • Checks proxy server information

      • slui.exe (PID: 4628)
    • Reads the computer name

      • A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe (PID: 5504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2025:04:20 13:51:58
ZipCRC: 0x8cecfeab
ZipCompressedSize: 4200616
ZipUncompressedSize: 785870336
ZipFileName: A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
19
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs sppextcomobj.exe no specs slui.exe #LUMMA a minecraft movie 2025.1080p.hd.x264.dual.yg.exe a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs slui.exe a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs cmd.exe no specs conhost.exe no specs rundll32.exe no specs a minecraft movie 2025.1080p.hd.x264.dual.yg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1040"C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe" C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exeexplorer.exe
User:
admin
Company:
MbeasSMly Software
Integrity Level:
MEDIUM
Description:
CentrmopomIus
Version:
58.66.100.1
Modules
Images
c:\users\admin\desktop\a minecraft movie 2025.1080p.hd.x264.dual.yg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
1096"C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe" C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exeexplorer.exe
User:
admin
Company:
MbeasSMly Software
Integrity Level:
MEDIUM
Description:
CentrmopomIus
Version:
58.66.100.1
Modules
Images
c:\users\admin\desktop\a minecraft movie 2025.1080p.hd.x264.dual.yg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
1272"C:\WINDOWS\system32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\wldp.dll
2240"C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe" C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exeexplorer.exe
User:
admin
Company:
MbeasSMly Software
Integrity Level:
MEDIUM
Description:
CentrmopomIus
Version:
58.66.100.1
Modules
Images
c:\users\admin\desktop\a minecraft movie 2025.1080p.hd.x264.dual.yg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
2340"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\Mlw.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2772"C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe" C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exeexplorer.exe
User:
admin
Company:
MbeasSMly Software
Integrity Level:
MEDIUM
Description:
CentrmopomIus
Version:
58.66.100.1
Modules
Images
c:\users\admin\desktop\a minecraft movie 2025.1080p.hd.x264.dual.yg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
3008"C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe" C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exeexplorer.exe
User:
admin
Company:
MbeasSMly Software
Integrity Level:
MEDIUM
Description:
CentrmopomIus
Version:
58.66.100.1
Modules
Images
c:\users\admin\desktop\a minecraft movie 2025.1080p.hd.x264.dual.yg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
3024C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3268C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
4188"C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe" C:\Users\admin\Desktop\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exeexplorer.exe
User:
admin
Company:
MbeasSMly Software
Integrity Level:
MEDIUM
Description:
CentrmopomIus
Version:
58.66.100.1
Modules
Images
c:\users\admin\desktop\a minecraft movie 2025.1080p.hd.x264.dual.yg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
Total events
3 058
Read events
3 050
Write events
8
Delete events
0

Modification events

(PID) Process:(2340) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2340) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2340) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2340) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Mlw.zip
(PID) Process:(2340) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2340) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2340) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2340) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2340WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2340.40920\A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
41
DNS requests
21
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5892
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5892
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.0
  • 40.126.31.129
  • 20.190.159.68
  • 20.190.159.131
  • 40.126.31.130
  • 20.190.159.23
  • 40.126.31.128
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

PID
Process
Class
Message
5504
A Minecraft Movie 2025.1080p.HD.X264.Dual.YG.exe
Misc activity
ET INFO Observed Telegram Domain (t .me in TLS SNI)
No debug info