URL:

https://mato-camp-v1.b-cdn.net/kesty

Full analysis: https://app.any.run/tasks/576379e2-39ad-4e8d-a72b-7667314eb685
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: August 05, 2024, 23:15:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
lumma
stealer
Indicators:
MD5:

B9C3BB3259A5A0A779AE38ABB1686922

SHA1:

FA99FAAC418B5299783040F702C469AAA0362145

SHA256:

E9034E64F3A552D50E1726D4EF7BE8B4D8E6E95FE94BC53CA82BD7B605DBC917

SSDEEP:

3:N8mIT0uqbn:2mITRgn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes powershell execution policy (Unrestricted)

      • mshta.exe (PID: 7928)
    • Drops the executable file immediately after the start

      • mshta.exe (PID: 7928)
      • powershell.exe (PID: 8008)
      • BitLockerToGo.exe (PID: 1636)
      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
    • Scans artifacts that could help determine the target

      • mshta.exe (PID: 7928)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 8008)
    • Gets or sets the initialization vector for the symmetric algorithm (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Downloads the requested resource (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Uses AES cipher (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 8008)
    • LUMMA has been detected (YARA)

      • ashampoo.exe (PID: 3164)
    • Changes the autorun value in the registry

      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
    • Gets or sets the symmetric key that is used for encryption and decryption (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Actions looks like stealing of personal data

      • BitLockerToGo.exe (PID: 1636)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • chrome.exe (PID: 4704)
      • mshta.exe (PID: 7928)
      • powershell.exe (PID: 8008)
    • Detected use of alternative data streams (AltDS)

      • powershell.exe (PID: 7536)
    • Probably obfuscated PowerShell command line is found

      • mshta.exe (PID: 7928)
    • The process bypasses the loading of PowerShell profile settings

      • mshta.exe (PID: 7928)
    • Starts POWERSHELL.EXE for commands execution

      • mshta.exe (PID: 7928)
    • Executable content was dropped or overwritten

      • mshta.exe (PID: 7928)
      • powershell.exe (PID: 8008)
      • BitLockerToGo.exe (PID: 1636)
      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
    • Cryptography encrypted command line is found

      • powershell.exe (PID: 8008)
    • Extracts files to a directory (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Gets file extension (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Writes data into a file (POWERSHELL)

      • powershell.exe (PID: 8008)
    • The process drops C-runtime libraries

      • powershell.exe (PID: 8008)
    • Searches for installed software

      • BitLockerToGo.exe (PID: 1636)
    • Starts itself from another location

      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
    • Changes internet zones settings

      • 1C05CB940DFB3E6E1CDBC63A18737937.exe (PID: 3980)
  • INFO

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 4704)
    • The process uses the downloaded file

      • chrome.exe (PID: 6636)
    • Reads the computer name

      • TextInputHost.exe (PID: 8124)
      • BitLockerToGo.exe (PID: 1636)
      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
      • 1C05CB940DFB3E6E1CDBC63A18737937.exe (PID: 3980)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 7728)
      • chrome.exe (PID: 4704)
    • Manual execution by a user

      • powershell.exe (PID: 7536)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 7928)
    • Checks current location (POWERSHELL)

      • powershell.exe (PID: 7536)
    • Drops the executable file immediately after the start

      • chrome.exe (PID: 4704)
    • Application launched itself

      • chrome.exe (PID: 4704)
    • Checks supported languages

      • TextInputHost.exe (PID: 8124)
      • ashampoo.exe (PID: 3164)
      • BitLockerToGo.exe (PID: 1636)
      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
      • 1C05CB940DFB3E6E1CDBC63A18737937.exe (PID: 3980)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Checks proxy server information

      • powershell.exe (PID: 8008)
      • mshta.exe (PID: 7928)
    • Create files in a temporary directory

      • BitLockerToGo.exe (PID: 1636)
    • Reads the machine GUID from the registry

      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
      • 1C05CB940DFB3E6E1CDBC63A18737937.exe (PID: 3980)
    • Reads the software policy settings

      • BitLockerToGo.exe (PID: 1636)
    • Creates files or folders in the user directory

      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
    • Disables trace logs

      • powershell.exe (PID: 8008)
    • The executable file from the user directory is run by the Powershell process

      • ashampoo.exe (PID: 3164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Lumma

(PID) Process(3164) ashampoo.exe
C2 (9)boattyownerwrv.shop
definitonizmnx.shop
assumedtribsosp.shop
chippyfroggsyhz.shop
budgetttysnzm.shop
creepydxzoxmj.shop
sulphurhsum.shop
empiredzmwnx.shop
rainbowmynsjn.shop
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
170
Monitored processes
28
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs rundll32.exe no specs openwith.exe no specs textinputhost.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs mshta.exe powershell.exe conhost.exe no specs chrome.exe no specs #LUMMA ashampoo.exe no specs chrome.exe no specs bitlockertogo.exe chrome.exe p4jwj9vl9yudsygf8r789jyc2u7lv3.exe 1c05cb940dfb3e6e1cdbc63a18737937.exe dllhost.exe chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
360"C:\Users\admin\AppData\Local\Temp\P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe"C:\Users\admin\AppData\Local\Temp\P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe
BitLockerToGo.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
Norton Antivirus Installer
Exit code:
0
Version:
24.7.9311.0
Modules
Images
c:\users\admin\appdata\local\temp\p4jwj9vl9yudsygf8r789jyc2u7lv3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\rpcrt4.dll
c:\windows\syswow64\shell32.dll
1636C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exeC:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe
ashampoo.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
BitLocker To Go Reader
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\bitlockerdiscoveryvolumecontents\bitlockertogo.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
1948"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4964 --field-trial-handle=1836,i,24272941490306792,5687300753898504604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3164"C:\Users\admin\AppData\Local\Temp\ashampoo.exe" C:\Users\admin\AppData\Local\Temp\ashampoo.exe
powershell.exe
User:
admin
Company:
Ashampoo GmbH & Co. KG
Integrity Level:
MEDIUM
Description:
Ashampoo UnInstaller 14 Setup
Exit code:
666
Version:
14.00.12
Modules
Images
c:\users\admin\appdata\local\temp\ashampoo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\powrprof.dll
Lumma
(PID) Process(3164) ashampoo.exe
C2 (9)boattyownerwrv.shop
definitonizmnx.shop
assumedtribsosp.shop
chippyfroggsyhz.shop
budgetttysnzm.shop
creepydxzoxmj.shop
sulphurhsum.shop
empiredzmwnx.shop
rainbowmynsjn.shop
3980"C:\Users\admin\AppData\Roaming\1C05CB940DFB3E6E1CDBC63A18737937\1C05CB940DFB3E6E1CDBC63A18737937.exe"C:\Users\admin\AppData\Roaming\1C05CB940DFB3E6E1CDBC63A18737937\1C05CB940DFB3E6E1CDBC63A18737937.exe
P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
Norton Antivirus Installer
Exit code:
0
Version:
24.7.9311.0
Modules
Images
c:\users\admin\appdata\roaming\1c05cb940dfb3e6e1cdbc63a18737937\1c05cb940dfb3e6e1cdbc63a18737937.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\rpcrt4.dll
c:\windows\syswow64\shell32.dll
4236"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoABAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=4172 --field-trial-handle=1836,i,24272941490306792,5687300753898504604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4704"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "https://mato-camp-v1.b-cdn.net/kesty"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6164"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x21c,0x220,0x224,0x1f8,0x228,0x7fffd645dc40,0x7fffd645dc4c,0x7fffd645dc58C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6296"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgABAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1832 --field-trial-handle=1836,i,24272941490306792,5687300753898504604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6308"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2104 --field-trial-handle=1836,i,24272941490306792,5687300753898504604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
40 440
Read events
40 100
Write events
334
Delete events
6

Modification events

(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(4704) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:metricsid
Value:
Executable files
17
Suspicious files
160
Text files
31
Unknown types
4

Dropped files

PID
Process
Filename
Type
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFe6482.TMP
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RFe64a1.TMP
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ef4f45e1-4b5a-4b54-9884-fbb2299409a7.tmpbinary
MD5:5058F1AF8388633F609CADB75A75DC9D
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.oldtext
MD5:F96D0EF8D63094D714514A441F8CD3FB
SHA256:2083625CA1E32D366F0B664D9B87B591791EF2EA2B770F4FA6ABE13FECA01196
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
87
DNS requests
46
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2272
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1344
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5552
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
7804
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaldksiunzh56452py2db5mnbpa_120.0.6050.0/jamhcnnkihinmdlkakkaopbjbbcngflc_120.0.6050.0_all_dgzfpknn7v3zslsbhrwu6bt44e.crx3
unknown
whitelisted
7804
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j34nie4a4fcbmkpxeier5vlipq_2024.8.3.1/jflhchccmppkfebkiaminageehmchikm_2024.08.03.01_all_aszb4ufo52gnimffv76qbbt7rm.crx3
unknown
whitelisted
7804
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j34nie4a4fcbmkpxeier5vlipq_2024.8.3.1/jflhchccmppkfebkiaminageehmchikm_2024.08.03.01_all_aszb4ufo52gnimffv76qbbt7rm.crx3
unknown
whitelisted
7804
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j34nie4a4fcbmkpxeier5vlipq_2024.8.3.1/jflhchccmppkfebkiaminageehmchikm_2024.08.03.01_all_aszb4ufo52gnimffv76qbbt7rm.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
5512
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4100
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4704
chrome.exe
239.255.255.250:1900
whitelisted
6308
chrome.exe
108.177.127.84:443
accounts.google.com
GOOGLE
US
unknown
6308
chrome.exe
138.199.36.9:443
mato-camp-v1.b-cdn.net
Datacamp Limited
DE
unknown
6308
chrome.exe
142.250.184.206:443
sb-ssl.google.com
GOOGLE
US
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.206
  • 142.250.186.174
whitelisted
mato-camp-v1.b-cdn.net
  • 138.199.36.9
  • 169.150.247.40
whitelisted
accounts.google.com
  • 108.177.127.84
whitelisted
sb-ssl.google.com
  • 142.250.184.206
whitelisted
www.google.com
  • 142.250.184.196
whitelisted
www.bing.com
  • 92.123.104.47
  • 92.123.104.28
  • 92.123.104.33
  • 92.123.104.59
  • 92.123.104.34
  • 92.123.104.32
  • 92.123.104.11
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.64
  • 40.126.31.71
  • 20.190.159.23
  • 40.126.31.73
  • 20.190.159.0
  • 20.190.159.2
  • 20.190.159.68
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

No threats detected
No debug info