URL:

https://www.mediafire.com/download/i4g2r5jefs244hq/tdork.zip

Full analysis: https://app.any.run/tasks/6bfab56f-9517-4ba5-ba9c-c6e3ea571285
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: April 07, 2026, 08:10:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
fingerprinting
lumma
stealer
github
telegram
Indicators:
MD5:

D3A2530BD5706C4C103758AECB71CD3D

SHA1:

504F6F2CA44D382AD4D44C0D2F5C6FDCB000DD4C

SHA256:

E9726D8AD82020801908E9937AADBE2A1E9DBABD000B30F3BBE19E2259B173E0

SSDEEP:

3:N8DSLw3eGWKLQO3QRAKnMkfUn:2OLw3eGNTg9Qn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Run PowerShell with an invisible window

      • powershell.exe (PID: 8916)
      • powershell.exe (PID: 10712)
    • Create files in the Startup directory

      • crack.exe (PID: 9028)
      • powershell.exe (PID: 10712)
      • update1.exe (PID: 10644)
    • LUMMA has been detected (SURICATA)

      • svchost.exe (PID: 2232)
    • Steals credentials from Web Browsers

      • svchost.exe (PID: 1788)
      • vshost.exe (PID: 8868)
    • Adds path to the Windows Defender exclusion list

      • svchost.exe (PID: 1788)
    • Changes Windows Defender settings

      • svchost.exe (PID: 1788)
    • Changes settings for real-time protection

      • powershell.exe (PID: 8188)
      • powershell.exe (PID: 7432)
    • Changes antivirus protection settings for downloading files from the Internet (IOAVProtection)

      • powershell.exe (PID: 8188)
    • Changes settings for checking scripts for malicious actions

      • powershell.exe (PID: 8188)
    • Changes settings for protection against network attacks (IPS)

      • powershell.exe (PID: 8188)
  • SUSPICIOUS

    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 8392)
    • The process creates files with name similar to system file names

      • tdork.exe (PID: 8872)
      • winmde.exe (PID: 9072)
      • twain.exe (PID: 7780)
    • The process executes files with name similar to system file names

      • tdork.exe (PID: 8872)
      • winmde.exe (PID: 9072)
      • twain.exe (PID: 7780)
    • Uses ATTRIB.EXE to modify file attributes

      • svchost.exe (PID: 8956)
    • Uses REG/REGEDIT.EXE to modify or delete registry entries

      • svchost.exe (PID: 8956)
    • Starts POWERSHELL.EXE for commands execution

      • svchost.exe (PID: 8956)
      • svchost.exe (PID: 1788)
    • Contacting a server suspected of hosting an CnC

      • svchost.exe (PID: 2232)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 8940)
      • cmd.exe (PID: 8808)
      • cmd.exe (PID: 9188)
    • The executable file from the user directory is run by the CMD process

      • winmde.exe (PID: 9072)
      • twain.exe (PID: 7780)
    • Starts itself from another location

      • winmde.exe (PID: 9072)
      • twain.exe (PID: 7780)
      • svchost.exe (PID: 8956)
    • Browser headless start

      • chrome.exe (PID: 10084)
      • chrome.exe (PID: 9704)
      • chrome.exe (PID: 7636)
    • Runs WScript without displaying logo

      • wscript.exe (PID: 11028)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 11028)
    • Reads browser cookies

      • svchost.exe (PID: 1788)
      • vshost.exe (PID: 8868)
    • Possible stealing of messenger data

      • svchost.exe (PID: 1788)
      • vshost.exe (PID: 8868)
    • Application launched itself

      • update1.exe (PID: 10644)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • svchost.exe (PID: 1788)
    • Possible stealing from crypto wallets

      • vshost.exe (PID: 8868)
    • Script disables Windows Defender's behavior monitoring

      • svchost.exe (PID: 1788)
    • Disables Windows Defender IPS (POWERSHELL)

      • svchost.exe (PID: 1788)
    • Starts CMD.EXE with output disabled

      • cmd.exe (PID: 9188)
    • Starts CMD.EXE with special quote handling

      • cmd.exe (PID: 9188)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 9188)
    • Disables Windows Defender real-time protection (POWERSHELL)

      • svchost.exe (PID: 1788)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 8104)
      • tdork.exe (PID: 8808)
      • tdork.exe (PID: 8872)
      • winmde.exe (PID: 8792)
      • twain.exe (PID: 8876)
      • crack.exe (PID: 9028)
      • svchost.exe (PID: 8956)
      • twain.exe (PID: 7780)
      • winmde.exe (PID: 9072)
      • svchost.exe (PID: 1788)
      • vshost.exe (PID: 8868)
      • update1.exe (PID: 10644)
      • OneDriveUpdate.exe (PID: 11080)
      • OneDriveUpdate.exe (PID: 11088)
      • update1.exe (PID: 11012)
      • update2.exe (PID: 9900)
    • Application launched itself

      • msedge.exe (PID: 7096)
      • chrome.exe (PID: 10084)
      • chrome.exe (PID: 7636)
    • Reads the computer name

      • identity_helper.exe (PID: 8104)
      • tdork.exe (PID: 8808)
      • tdork.exe (PID: 8872)
      • crack.exe (PID: 9028)
      • winmde.exe (PID: 8792)
      • twain.exe (PID: 8876)
      • vshost.exe (PID: 8868)
      • svchost.exe (PID: 1788)
      • update1.exe (PID: 10644)
      • update1.exe (PID: 11012)
      • update2.exe (PID: 9900)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 7096)
    • Reads Environment values

      • identity_helper.exe (PID: 8104)
    • Create files in a temporary directory

      • tdork.exe (PID: 8808)
      • tdork.exe (PID: 8872)
      • crack.exe (PID: 9028)
      • twain.exe (PID: 7780)
      • update1.exe (PID: 10644)
    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 8392)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 8756)
      • WinRAR.exe (PID: 8392)
      • tdork.exe (PID: 8872)
      • twain.exe (PID: 8876)
      • winmde.exe (PID: 8792)
    • Process checks computer location settings

      • tdork.exe (PID: 8872)
      • twain.exe (PID: 8876)
      • winmde.exe (PID: 8792)
    • Creates files or folders in the user directory

      • crack.exe (PID: 9028)
      • svchost.exe (PID: 8956)
      • winmde.exe (PID: 9072)
      • svchost.exe (PID: 1788)
      • update1.exe (PID: 10644)
      • vshost.exe (PID: 8868)
    • Launching a file from a Registry key

      • reg.exe (PID: 8828)
      • reg.exe (PID: 7580)
      • reg.exe (PID: 7624)
    • Launching a file from the Startup directory

      • crack.exe (PID: 9028)
      • powershell.exe (PID: 10712)
      • update1.exe (PID: 10644)
    • Attempting to use instant messaging service

      • svchost.exe (PID: 1788)
      • svchost.exe (PID: 2232)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 8916)
      • powershell.exe (PID: 2684)
      • powershell.exe (PID: 7432)
      • powershell.exe (PID: 8188)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 8916)
      • powershell.exe (PID: 2684)
      • powershell.exe (PID: 7432)
      • powershell.exe (PID: 8188)
    • Reads the machine GUID from the registry

      • update1.exe (PID: 10644)
      • update2.exe (PID: 9900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
276
Monitored processes
137
Malicious processes
12
Suspicious processes
6

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe no specs tdork.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs notepad.exe no specs tdork.exe no specs crack.exe svchost.exe no specs twain.exe no specs attrib.exe no specs conhost.exe no specs winmde.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cmd.exe conhost.exe no specs msedge.exe no specs cmd.exe msedge.exe no specs conhost.exe no specs msedge.exe no specs winmde.exe no specs msedge.exe no specs twain.exe no specs svchost.exe msedge.exe no specs msedge.exe no specs vshost.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs chrome.exe chrome.exe no specs msedge.exe no specs msedge.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs update1.exe powershell.exe conhost.exe no specs attrib.exe no specs conhost.exe no specs wscript.exe no specs onedriveupdate.exe no specs onedriveupdate.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs update1.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs timeout.exe no specs powershell.exe no specs conhost.exe no specs update2.exe no specs powershell.exe no specs conhost.exe no specs #LUMMA svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
204"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3608,i,8141966233440479412,6264508279382574665,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3632 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1404"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4708,i,8141966233440479412,6264508279382574665,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=4952 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1728\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1788"C:\Users\admin\AppData\Roaming\4yRcKI2oMLi1wdSy\svchost.exe"C:\Users\admin\AppData\Roaming\4yRcKI2oMLi1wdSy\svchost.exe
winmde.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\roaming\4yrcki2omli1wdsy\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
1980"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=15 --always-read-main-dll --field-trial-handle=6720,i,8141966233440479412,6264508279382574665,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6028 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2092"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=43 --always-read-main-dll --field-trial-handle=6460,i,8141966233440479412,6264508279382574665,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6996 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2156"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=16 --always-read-main-dll --field-trial-handle=6704,i,8141966233440479412,6264508279382574665,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6208 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2232C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2652"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x294,0x298,0x29c,0x28c,0x2a4,0x7ffe2392f208,0x7ffe2392f214,0x7ffe2392f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2684powershell.exe -Command "[Console]::OutputEncoding = [System.Text.Encoding]::UTF8; Add-MpPreference -ExclusionPath 'C:\'"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\oleaut32.dll
Total events
40 281
Read events
40 251
Write events
26
Delete events
4

Modification events

(PID) Process:(8392) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(8392) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(8392) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(8392) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\tdork.zip
(PID) Process:(8392) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(8392) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(8392) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(8392) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(8392) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@C:\Windows\System32\ieframe.dll,-10046
Value:
Internet Shortcut
(PID) Process:(8392) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
Operation:writeName:txtfile
Value:
Executable files
0
Suspicious files
29
Text files
218
Unknown types
1 093

Dropped files

PID
Process
Filename
Type
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFdffcd.TMP
MD5:
SHA256:
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFdffdc.TMP
MD5:
SHA256:
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFdffdc.TMP
MD5:
SHA256:
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFdffec.TMP
MD5:
SHA256:
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RFdfffc.TMP
MD5:
SHA256:
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
7096msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFdffec.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
754
TCP/UDP connections
965
DNS requests
1 040
Threats
119

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7160
msedge.exe
GET
302
104.17.148.83:443
https://www.mediafire.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
US
unknown
7160
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
US
binary
4.42 Kb
whitelisted
7160
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:CaRQ_AyTHXrqfrGwfkw-rfYJpGAbvfPIsFEPpXB8__E&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
binary
100 b
whitelisted
7160
msedge.exe
GET
200
150.171.28.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
binary
446 b
whitelisted
7160
msedge.exe
GET
200
104.17.148.83:443
https://www.mediafire.com/download/i4g2r5jefs244hq/tdork.zip
US
binary
325 Kb
unknown
7160
msedge.exe
GET
200
104.18.22.222:443
https://copilot.microsoft.com/c/api/user/eligibility
US
text
25 b
whitelisted
7160
msedge.exe
GET
200
172.67.199.186:443
https://cmp.gatekeeperconsent.com/min.js
US
binary
1.03 Kb
unknown
7160
msedge.exe
GET
200
13.107.253.44:443
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US
US
binary
82 b
whitelisted
7160
msedge.exe
GET
200
172.67.199.186:443
https://privacy.gatekeeperconsent.com/tcf2_stub.js
US
binary
1.32 Kb
unknown
7160
msedge.exe
GET
200
172.67.199.186:443
https://the.gatekeeperconsent.com/cmp.min.js
US
binary
7.70 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5484
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7160
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7160
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7160
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7160
msedge.exe
104.17.148.83:443
www.mediafire.com
CLOUDFLARENET
US
whitelisted
7160
msedge.exe
13.107.253.44:443
api.edgeoffer.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.124.78.146
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.251.208.174
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
www.mediafire.com
  • 104.17.148.83
  • 104.17.147.83
whitelisted
api.edgeoffer.microsoft.com
  • 13.107.253.44
  • 13.107.226.44
whitelisted
copilot.microsoft.com
  • 104.18.22.222
  • 104.18.23.222
whitelisted
www.bing.com
  • 2.16.204.146
  • 2.16.204.157
  • 2.16.204.158
  • 2.16.204.150
  • 2.16.204.149
  • 2.16.204.145
  • 2.16.204.160
  • 2.16.204.153
  • 2.16.204.155
  • 2.16.204.161
  • 2.16.204.135
  • 2.16.204.143
  • 2.16.204.141
  • 2.16.204.138
  • 2.16.204.148
  • 2.16.204.134
whitelisted
cmp.gatekeeperconsent.com
  • 172.67.199.186
  • 104.21.42.32
unknown

Threats

PID
Process
Class
Message
7160
msedge.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
7160
msedge.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
7160
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7160
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7160
msedge.exe
Potentially Bad Traffic
ET FILE_SHARING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
7160
msedge.exe
Potentially Bad Traffic
ET FILE_SHARING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
7160
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7160
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7160
msedge.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
7160
msedge.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
Process
Message
chrome.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\Google\Chrome\User Data directory exists )
chrome.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\Google\Chrome\User Data directory exists )