URL:

https://mato-camp-v1.b-cdn.net/kesty

Full analysis: https://app.any.run/tasks/576379e2-39ad-4e8d-a72b-7667314eb685
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: August 05, 2024, 23:15:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
lumma
stealer
Indicators:
MD5:

B9C3BB3259A5A0A779AE38ABB1686922

SHA1:

FA99FAAC418B5299783040F702C469AAA0362145

SHA256:

E9034E64F3A552D50E1726D4EF7BE8B4D8E6E95FE94BC53CA82BD7B605DBC917

SSDEEP:

3:N8mIT0uqbn:2mITRgn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • mshta.exe (PID: 7928)
      • powershell.exe (PID: 8008)
      • BitLockerToGo.exe (PID: 1636)
      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
    • Changes powershell execution policy (Unrestricted)

      • mshta.exe (PID: 7928)
    • Scans artifacts that could help determine the target

      • mshta.exe (PID: 7928)
    • Gets or sets the symmetric key that is used for encryption and decryption (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 8008)
    • Uses AES cipher (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Downloads the requested resource (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Gets or sets the initialization vector for the symmetric algorithm (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 8008)
    • LUMMA has been detected (YARA)

      • ashampoo.exe (PID: 3164)
    • Changes the autorun value in the registry

      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
    • Actions looks like stealing of personal data

      • BitLockerToGo.exe (PID: 1636)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • chrome.exe (PID: 4704)
      • mshta.exe (PID: 7928)
      • powershell.exe (PID: 8008)
    • Detected use of alternative data streams (AltDS)

      • powershell.exe (PID: 7536)
    • Executable content was dropped or overwritten

      • mshta.exe (PID: 7928)
      • powershell.exe (PID: 8008)
      • BitLockerToGo.exe (PID: 1636)
      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
    • Probably obfuscated PowerShell command line is found

      • mshta.exe (PID: 7928)
    • The process bypasses the loading of PowerShell profile settings

      • mshta.exe (PID: 7928)
    • Cryptography encrypted command line is found

      • powershell.exe (PID: 8008)
    • Starts POWERSHELL.EXE for commands execution

      • mshta.exe (PID: 7928)
    • Extracts files to a directory (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Writes data into a file (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Gets file extension (POWERSHELL)

      • powershell.exe (PID: 8008)
    • The process drops C-runtime libraries

      • powershell.exe (PID: 8008)
    • Searches for installed software

      • BitLockerToGo.exe (PID: 1636)
    • Starts itself from another location

      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
    • Changes internet zones settings

      • 1C05CB940DFB3E6E1CDBC63A18737937.exe (PID: 3980)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 4704)
    • Reads Microsoft Office registry keys

      • chrome.exe (PID: 4704)
      • OpenWith.exe (PID: 7728)
    • Checks supported languages

      • TextInputHost.exe (PID: 8124)
      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
      • ashampoo.exe (PID: 3164)
      • BitLockerToGo.exe (PID: 1636)
      • 1C05CB940DFB3E6E1CDBC63A18737937.exe (PID: 3980)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 4704)
    • Reads the computer name

      • TextInputHost.exe (PID: 8124)
      • BitLockerToGo.exe (PID: 1636)
      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
      • 1C05CB940DFB3E6E1CDBC63A18737937.exe (PID: 3980)
    • Drops the executable file immediately after the start

      • chrome.exe (PID: 4704)
    • The process uses the downloaded file

      • chrome.exe (PID: 6636)
    • Manual execution by a user

      • powershell.exe (PID: 7536)
    • Checks current location (POWERSHELL)

      • powershell.exe (PID: 7536)
    • Checks proxy server information

      • mshta.exe (PID: 7928)
      • powershell.exe (PID: 8008)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 7928)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 8008)
    • Disables trace logs

      • powershell.exe (PID: 8008)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 8008)
    • The executable file from the user directory is run by the Powershell process

      • ashampoo.exe (PID: 3164)
    • Reads the software policy settings

      • BitLockerToGo.exe (PID: 1636)
    • Create files in a temporary directory

      • BitLockerToGo.exe (PID: 1636)
    • Reads the machine GUID from the registry

      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
      • 1C05CB940DFB3E6E1CDBC63A18737937.exe (PID: 3980)
    • Creates files or folders in the user directory

      • P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe (PID: 360)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Lumma

(PID) Process(3164) ashampoo.exe
C2 (9)boattyownerwrv.shop
definitonizmnx.shop
assumedtribsosp.shop
chippyfroggsyhz.shop
budgetttysnzm.shop
creepydxzoxmj.shop
sulphurhsum.shop
empiredzmwnx.shop
rainbowmynsjn.shop
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
170
Monitored processes
28
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs rundll32.exe no specs openwith.exe no specs textinputhost.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs mshta.exe powershell.exe conhost.exe no specs chrome.exe no specs #LUMMA ashampoo.exe no specs chrome.exe no specs bitlockertogo.exe chrome.exe p4jwj9vl9yudsygf8r789jyc2u7lv3.exe 1c05cb940dfb3e6e1cdbc63a18737937.exe dllhost.exe chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
360"C:\Users\admin\AppData\Local\Temp\P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe"C:\Users\admin\AppData\Local\Temp\P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe
BitLockerToGo.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
Norton Antivirus Installer
Exit code:
0
Version:
24.7.9311.0
Modules
Images
c:\users\admin\appdata\local\temp\p4jwj9vl9yudsygf8r789jyc2u7lv3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\rpcrt4.dll
c:\windows\syswow64\shell32.dll
1636C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exeC:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe
ashampoo.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
BitLocker To Go Reader
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\bitlockerdiscoveryvolumecontents\bitlockertogo.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
1948"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4964 --field-trial-handle=1836,i,24272941490306792,5687300753898504604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3164"C:\Users\admin\AppData\Local\Temp\ashampoo.exe" C:\Users\admin\AppData\Local\Temp\ashampoo.exe
powershell.exe
User:
admin
Company:
Ashampoo GmbH & Co. KG
Integrity Level:
MEDIUM
Description:
Ashampoo UnInstaller 14 Setup
Exit code:
666
Version:
14.00.12
Modules
Images
c:\users\admin\appdata\local\temp\ashampoo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\powrprof.dll
Lumma
(PID) Process(3164) ashampoo.exe
C2 (9)boattyownerwrv.shop
definitonizmnx.shop
assumedtribsosp.shop
chippyfroggsyhz.shop
budgetttysnzm.shop
creepydxzoxmj.shop
sulphurhsum.shop
empiredzmwnx.shop
rainbowmynsjn.shop
3980"C:\Users\admin\AppData\Roaming\1C05CB940DFB3E6E1CDBC63A18737937\1C05CB940DFB3E6E1CDBC63A18737937.exe"C:\Users\admin\AppData\Roaming\1C05CB940DFB3E6E1CDBC63A18737937\1C05CB940DFB3E6E1CDBC63A18737937.exe
P4JWJ9VL9YUDSYGF8R789JYC2U7LV3.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
Norton Antivirus Installer
Exit code:
0
Version:
24.7.9311.0
Modules
Images
c:\users\admin\appdata\roaming\1c05cb940dfb3e6e1cdbc63a18737937\1c05cb940dfb3e6e1cdbc63a18737937.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\rpcrt4.dll
c:\windows\syswow64\shell32.dll
4236"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoABAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=4172 --field-trial-handle=1836,i,24272941490306792,5687300753898504604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4704"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "https://mato-camp-v1.b-cdn.net/kesty"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6164"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x21c,0x220,0x224,0x1f8,0x228,0x7fffd645dc40,0x7fffd645dc4c,0x7fffd645dc58C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6296"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgABAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1832 --field-trial-handle=1836,i,24272941490306792,5687300753898504604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6308"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2104 --field-trial-handle=1836,i,24272941490306792,5687300753898504604,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
40 440
Read events
40 100
Write events
334
Delete events
6

Modification events

(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(4704) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(4704) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:metricsid
Value:
Executable files
17
Suspicious files
160
Text files
31
Unknown types
4

Dropped files

PID
Process
Filename
Type
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFe6482.TMP
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RFe64a1.TMP
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Variationsbinary
MD5:961E3604F228B0D10541EBF921500C86
SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED
4704chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.datbinary
MD5:FC81892AC822DCBB09441D3B58B47125
SHA256:FB077C966296D02D50CCBF7F761D2A3311A206A784A7496F331C2B0D6AD205C8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
87
DNS requests
46
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2272
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2272
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1344
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5552
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7804
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j34nie4a4fcbmkpxeier5vlipq_2024.8.3.1/jflhchccmppkfebkiaminageehmchikm_2024.08.03.01_all_aszb4ufo52gnimffv76qbbt7rm.crx3
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
7804
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j34nie4a4fcbmkpxeier5vlipq_2024.8.3.1/jflhchccmppkfebkiaminageehmchikm_2024.08.03.01_all_aszb4ufo52gnimffv76qbbt7rm.crx3
unknown
whitelisted
7804
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j34nie4a4fcbmkpxeier5vlipq_2024.8.3.1/jflhchccmppkfebkiaminageehmchikm_2024.08.03.01_all_aszb4ufo52gnimffv76qbbt7rm.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
5512
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4100
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4704
chrome.exe
239.255.255.250:1900
whitelisted
6308
chrome.exe
108.177.127.84:443
accounts.google.com
GOOGLE
US
unknown
6308
chrome.exe
138.199.36.9:443
mato-camp-v1.b-cdn.net
Datacamp Limited
DE
unknown
6308
chrome.exe
142.250.184.206:443
sb-ssl.google.com
GOOGLE
US
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.206
  • 142.250.186.174
whitelisted
mato-camp-v1.b-cdn.net
  • 138.199.36.9
  • 169.150.247.40
whitelisted
accounts.google.com
  • 108.177.127.84
whitelisted
sb-ssl.google.com
  • 142.250.184.206
whitelisted
www.google.com
  • 142.250.184.196
whitelisted
www.bing.com
  • 92.123.104.47
  • 92.123.104.28
  • 92.123.104.33
  • 92.123.104.59
  • 92.123.104.34
  • 92.123.104.32
  • 92.123.104.11
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.64
  • 40.126.31.71
  • 20.190.159.23
  • 40.126.31.73
  • 20.190.159.0
  • 20.190.159.2
  • 20.190.159.68
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

No threats detected
No debug info