| File name: | LuaToolsInstaller.exe |
| Full analysis: | https://app.any.run/tasks/7c3f133e-1046-4af7-84a1-7458e8c73304 |
| Verdict: | Malicious activity |
| Analysis date: | November 02, 2025, 18:03:11 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (console) x86-64, for MS Windows, 7 sections |
| MD5: | E4CA3CC01975928DE6B75748A1306807 |
| SHA1: | D218DFF5964DDD06AB7752FFC6F6A7108CD2BFAE |
| SHA256: | FE1EB6F9EED30D64AB24A59B7BC8491FE9DACDD570B1E67CB6B61596032D99BD |
| SSDEEP: | 98304:hCjw5HX7kSb/ncNCmDw/H+MJNAnYRO4Y6ZhkDQet54netUjZUj0vRD9o8V59s3gP:3swJe6881mwe/kiGHZwVIA |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2025:09:30 01:17:16+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.44 |
| CodeSize: | 184832 |
| InitializedDataSize: | 157184 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xcf30 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 592 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4968 -prefsLen 45116 -prefMapHandle 4972 -prefMapSize 273045 -ipcHandle 4872 -initialChannelId {93c53b7b-40c4-4f0b-a72e-befa0a7fc4ea} -parentPid 7736 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7736" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 136.0 Modules
| |||||||||||||||
| 668 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | LuaToolsInstaller.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 916 | "C:\Users\admin\Desktop\LuaToolsInstaller.exe" | C:\Users\admin\Desktop\LuaToolsInstaller.exe | — | LuaToolsInstaller.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1140 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | LuaToolsInstaller.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5216 -prefsLen 39120 -prefMapHandle 5236 -prefMapSize 273045 -jsInitHandle 5260 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5220 -initialChannelId {addd2e39-5364-4df3-a815-354512f1aeff} -parentPid 7736 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7736" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 2276 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3332 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6124 -prefsLen 39283 -prefMapHandle 6116 -prefMapSize 273045 -jsInitHandle 5332 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5664 -initialChannelId {6332f8af-35cc-4915-91f6-3164185193ba} -parentPid 7736 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7736" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 11 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 3448 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 1244 -prefsLen 39283 -prefMapHandle 1252 -prefMapSize 273045 -jsInitHandle 1256 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5776 -initialChannelId {1ff886eb-3b82-47a9-b660-fa983c3ef5e5} -parentPid 7736 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7736" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 3468 | "C:\Users\admin\Desktop\LuaToolsInstaller.exe" | C:\Users\admin\Desktop\LuaToolsInstaller.exe | — | LuaToolsInstaller.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 4736 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4216 -prefsLen 45014 -prefMapHandle 4220 -prefMapSize 273045 -jsInitHandle 4224 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4188 -initialChannelId {ce3cfaea-2411-4bc7-a0fc-228742ddfa53} -parentPid 7736 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7736" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| (PID) Process: | (8632) st-setup-1.8.17r2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools |
| Operation: | write | Name: | DisplayName |
Value: SteamTools | |||
| (PID) Process: | (8632) st-setup-1.8.17r2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\SteamTools\Uninstall.exe" | |||
| (PID) Process: | (8632) st-setup-1.8.17r2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools |
| Operation: | write | Name: | QuietUninstallString |
Value: "C:\Program Files\SteamTools\Uninstall.exe" /S | |||
| (PID) Process: | (8632) st-setup-1.8.17r2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\SteamTools | |||
| (PID) Process: | (8632) st-setup-1.8.17r2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\SteamTools\SteamTools.exe,0 | |||
| (PID) Process: | (8632) st-setup-1.8.17r2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (8632) st-setup-1.8.17r2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
| (PID) Process: | (8632) st-setup-1.8.17r2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\SteamTools |
| Operation: | write | Name: | Language |
Value: 1033 | |||
| (PID) Process: | (8912) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (9024) SteamTools.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Valve\Steamtools |
| Operation: | write | Name: | SteamPath |
Value: C:/Program Files/SteamTools | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\_asyncio.pyd | executable | |
MD5:56F958EEBBC62305B4BF690D61C78E28 | SHA256:50631361EF074BE42D788818AF91D0301D22FA24A970F41F496D8272B92CFE31 | |||
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\VCRUNTIME140_1.dll | executable | |
MD5:C0C0B4C611561F94798B62EB43097722 | SHA256:497A280550443E3E9F89E428E51CB795139CA8944D5DEDD54A7083C00E7164E5 | |||
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\VCRUNTIME140.dll | executable | |
MD5:32DA96115C9D783A0769312C0482A62D | SHA256:8B10C53241726B0ACC9F513157E67FCB01C166FEC69E5E38CA6AADA8F9A3619F | |||
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\_brotli.cp313-win_amd64.pyd | executable | |
MD5:5ED46A7126DBDB70F3C60530E35BA035 | SHA256:67DFA82DCAED04ED3F358D84B18D1375D59126161DE92E00164D36087B179D4D | |||
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\_bz2.pyd | executable | |
MD5:684D656AADA9F7D74F5A5BDCF16D0EDB | SHA256:A5DFB4A663DEF3D2276B88866F6D220F6D30CC777B5D841CF6DBB15C6858017C | |||
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\_ctypes.pyd | executable | |
MD5:29873384E13B0A78EE9857604161514B | SHA256:3CC8500A958CC125809B0467930EBCCE88A09DCC0CEDD7A45FACF3E332F7DB33 | |||
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\api-ms-win-core-console-l1-1-0.dll | executable | |
MD5:E13943D717A1F374973CFD6C3BD95DD6 | SHA256:C2855050CD382F49B184AA456087A03CA8DCBF6E3EA97303ED55D65F43E6ACAE | |||
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\_multiprocessing.pyd | executable | |
MD5:807DD90BE59EA971DAC06F3AAB4F2A7E | SHA256:B20DD6F5FAB31476D3D8D7F40CB5AB098117FA5612168C0FF4044945B6156D47 | |||
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\api-ms-win-core-debug-l1-1-0.dll | executable | |
MD5:02DC783F95C6BAB869820720CBE8C1C7 | SHA256:A41690A67915B081067975D500291AA09E296793F93359EE96E8DD0D4BDDC37B | |||
| 7484 | LuaToolsInstaller.exe | C:\Users\admin\AppData\Local\Temp\_MEI74842\_queue.pyd | executable | |
MD5:CC0F4A77CCFE39EFC8019FA8B74C06D0 | SHA256:DEE7D19A9FCAB0DF043DC56F2CDC32F1A2A968AB229679B38B378C61CA0CBA53 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7736 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
7736 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://o.pki.goog/s/wr3/25s | unknown | — | — | whitelisted |
7736 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
7736 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://o.pki.goog/s/wr3/prs | unknown | — | — | whitelisted |
7736 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
7736 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://o.pki.goog/s/wr3/prs | unknown | — | — | whitelisted |
7736 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
7736 | firefox.exe | POST | — | 142.250.74.195:80 | http://o.pki.goog/s/wr3/prs | unknown | — | — | whitelisted |
7736 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
7736 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4384 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5596 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3236 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7736 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | whitelisted |
7736 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
7736 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
7736 | firefox.exe | 151.101.193.91:443 | firefox.settings.services.mozilla.com | FASTLY | US | whitelisted |
7736 | firefox.exe | 142.250.74.195:80 | o.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
content-signature-2.cdn.mozilla.net |
| whitelisted |
content-signature-chains.prod.autograph.services.mozaws.net |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7736 | firefox.exe | Not Suspicious Traffic | INFO [ANY.RUN] Global content delivery network (unpkg .com) |
2276 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
2276 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
2276 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
9024 | SteamTools.exe | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
2276 | svchost.exe | Misc activity | ET INFO DNS Query to Alibaba Cloud CDN Domain (aliyuncs .com) |
9024 | SteamTools.exe | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
— | — | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
SteamTools.exe | QCoreApplication::applicationFilePath: Please instantiate the QApplication object first
|
SteamTools.exe | "steamPath:"
|
SteamTools.exe | ?????????????? "Host steamtools.info not found"
|
SteamTools.exe | ?????????????? "Unknown error"
|