Dynamic Analysis Report
Created on 2025-01-24T13:30:07+00:00
LummaC2.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00408730 |
Size Of Code | 0x00044C00 |
Size Of Initialized Data | 0x0000B200 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2025-01-02 19:58 (UTC) |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x00044B02 | 0x00044C00 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x00446000 | 0x000023EB | 0x00002400 | 0x00045000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.9 |
.data | 0x00449000 | 0x0000D57C | 0x00005200 | 0x00047400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.48 |
.reloc | 0x00457000 | 0x00003C00 | 0x00003C00 | 0x0004C600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.52 |
Imports (6)
»
KERNEL32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateProcessW | - | 0x00448044 | 0x00047F84 | 0x00046F84 | 0x000000E8 |
CreateThread | - | 0x00448048 | 0x00047F88 | 0x00046F88 | 0x000000F6 |
ExitProcess | - | 0x0044804C | 0x00047F8C | 0x00046F8C | 0x00000162 |
GetCommandLineW | - | 0x00448050 | 0x00047F90 | 0x00046F90 | 0x000001DB |
GetCurrentProcessId | - | 0x00448054 | 0x00047F94 | 0x00046F94 | 0x0000021C |
GetCurrentThreadId | - | 0x00448058 | 0x00047F98 | 0x00046F98 | 0x00000220 |
GetLogicalDrives | - | 0x0044805C | 0x00047F9C | 0x00046F9C | 0x0000026C |
GlobalLock | - | 0x00448060 | 0x00047FA0 | 0x00046FA0 | 0x00000344 |
GlobalUnlock | - | 0x00448064 | 0x00047FA4 | 0x00046FA4 | 0x0000034B |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFileInfoW | - | 0x0044806C | 0x00047FAC | 0x00046FAC | 0x0000014A |
SHGetSpecialFolderPathW | - | 0x00448070 | 0x00047FB0 | 0x00046FB0 | 0x0000016E |
USER32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | - | 0x00448078 | 0x00047FB8 | 0x00046FB8 | 0x0000004F |
GetClipboardData | - | 0x0044807C | 0x00047FBC | 0x00046FBC | 0x00000134 |
GetDC | - | 0x00448080 | 0x00047FC0 | 0x00046FC0 | 0x00000140 |
GetForegroundWindow | - | 0x00448084 | 0x00047FC4 | 0x00046FC4 | 0x00000157 |
GetSystemMetrics | - | 0x00448088 | 0x00047FC8 | 0x00046FC8 | 0x000001C6 |
GetWindowLongW | - | 0x0044808C | 0x00047FCC | 0x00046FCC | 0x000001E6 |
OpenClipboard | - | 0x00448090 | 0x00047FD0 | 0x00046FD0 | 0x00000298 |
ReleaseDC | - | 0x00448094 | 0x00047FD4 | 0x00046FD4 | 0x000002F7 |
GDI32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
BitBlt | - | 0x0044809C | 0x00047FDC | 0x00046FDC | 0x00000013 |
CreateCompatibleBitmap | - | 0x004480A0 | 0x00047FE0 | 0x00046FE0 | 0x00000030 |
CreateCompatibleDC | - | 0x004480A4 | 0x00047FE4 | 0x00046FE4 | 0x00000031 |
CreateDIBSection | - | 0x004480A8 | 0x00047FE8 | 0x00046FE8 | 0x00000037 |
DeleteDC | - | 0x004480AC | 0x00047FEC | 0x00046FEC | 0x00000183 |
DeleteObject | - | 0x004480B0 | 0x00047FF0 | 0x00046FF0 | 0x00000186 |
GetCurrentObject | - | 0x004480B4 | 0x00047FF4 | 0x00046FF4 | 0x00000276 |
GetDIBits | - | 0x004480B8 | 0x00047FF8 | 0x00046FF8 | 0x0000027D |
GetObjectW | - | 0x004480BC | 0x00047FFC | 0x00046FFC | 0x000002B0 |
GetPixel | - | 0x004480C0 | 0x00048000 | 0x00047000 | 0x000002B7 |
SelectObject | - | 0x004480C4 | 0x00048004 | 0x00047004 | 0x00000367 |
StretchBlt | - | 0x004480C8 | 0x00048008 | 0x00047008 | 0x000003A3 |
ole32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoCreateInstance | - | 0x004480D0 | 0x00048010 | 0x00047010 | 0x00000028 |
CoInitializeEx | - | 0x004480D4 | 0x00048014 | 0x00047014 | 0x0000005E |
CoInitializeSecurity | - | 0x004480D8 | 0x00048018 | 0x00047018 | 0x0000005F |
CoQueryClientBlanket | - | 0x004480DC | 0x0004801C | 0x0004701C | 0x0000006D |
CoSetProxyBlanket | - | 0x004480E0 | 0x00048020 | 0x00047020 | 0x00000084 |
CoTaskMemAlloc | - | 0x004480E4 | 0x00048024 | 0x00047024 | 0x00000088 |
CoUninitialize | - | 0x004480E8 | 0x00048028 | 0x00047028 | 0x0000008E |
OLEAUT32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocString | 0x00000002 | 0x004480F0 | 0x00048030 | 0x00047030 | - |
SysFreeString | 0x00000006 | 0x004480F4 | 0x00048034 | 0x00047034 | - |
VariantClear | 0x00000009 | 0x004480F8 | 0x00048038 | 0x00047038 | - |
VariantInit | 0x00000008 | 0x004480FC | 0x0004803C | 0x0004703C | - |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
lummac2.exe | 1 | 0x00B70000 | 0x00BCAFFF | Relevant Image | 32-bit | 0x00BAD5C0 |
...
|
||
buffer | 1 | 0x0018C000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x006CB6F0 | 0x006CD6EF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x006CFDC8 | 0x006D5317 | First Network Behavior | 32-bit | - |
...
|
||
lummac2.exe | 1 | 0x00B70000 | 0x00BCAFFF | First Network Behavior | 32-bit | 0x00B79FA0 |
...
|
||
lummac2.exe | 1 | 0x00B70000 | 0x00BCAFFF | Process Termination | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Lumma_Custom_Base64 | Lumma custom base64 decoding | Spyware |
5/5
|
...
|
7e2d66ae33fb05655329be54dc3560c2d0f596452f22193f0750a36c121b5399 | Downloaded File | HTML |
Clean
|
...
|
»
Extracted URLs (67)
»
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://store.steampowered.com/privacy_agreement/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/manifest.js?v=F357rws4wuAe&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=3W_ge11SZngF&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com/discussions/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com//public//javascript//economy.js?v=nWrdv801aW2D&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=pbdAKOcDIgbC&l=english&_cdn=cloudflare&load=effects,controls,slider,dragdrop |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com//public//javascript//economy_common.js?v=GYFVZLtXyAJC&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/modalContent.js?v=XfYrwi9zUC4b&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900 |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016 |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com//public//javascript//json2.js?v=54NKNglvGTO8&l=english&_cdn=cloudflare\ |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/webui/clientcom.js?v=4djfoCdIn7bx&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/css/promo/summer2017/stickers.css?v=INiZALwvDIbb&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/javascript/auth_refresh.js?v=w6QbwI-5-j2S&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/css/buttons.css?v=G3UTKgHH4xLD&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/main.js?v=gi31XL_wtE-U&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com/my/wishlist/ |
Show WHOIS
|
Not Available
|
- |
...
|
http://store.steampowered.com/subscriber_agreement/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/css/shared_responsive.css?v=n4_f9JKDa7wP&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com/steam_refunds/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_global.js?v=T4lGreKRux_A&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com/points/shop/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_logo.png |
Show WHOIS
|
Not Available
|
- |
...
|
https://avatars.cloudflare.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com/subscriber_agreement/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/css/applications/community/main.css?v=j2WgmlRVfmuK&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/images/skin_1/arrowDn9x5.gif |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com/market/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/modalv2.js?v=zBXEuexVQ0FZ&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1 |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com//public//css//skin_1//economy.css?v=Z47ficVHxvzU&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/promo/stickers.js?v=iGFW_JMULCcZ&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
http://www.valvesoftware.com/legal.htm |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/reportedcontent.js?v=-lZqrarogJr8&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/css/skin_1/modalContent.css?v=WXAusLHclDIt&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com/stats/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com/profiles/76561199724331900/badges |
Show WHOIS
|
Malicious
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/css/globalv2.css?v=i_iuPUaT8LXN&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=gQHVlrK4-jX-&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/javascript/tooltip.js?v=QYkT4eS5mbTN&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/libraries~b28b7af69.js?v=ZocyVvu2TTf-&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/css/motiva_sans.css?v=nc69vwog8R9p&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/prototype-1.7.js?v=npJElBnrEO6W&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png |
Show WHOIS
|
Not Available
|
- |
...
|
https://help.steampowered.com/en/ |
Show WHOIS
|
Not Available
|
- |
...
|
http://store.steampowered.com/privacy_agreement/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com/mobile |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com/news/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com//profiles//76561199724331900// |
Show WHOIS
|
Malicious
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=tvQi85mXnRZH&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
http://store.steampowered.com/account/cookiepreferences/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com/workshop/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com/legal/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/css/skin_1/profilev2.css?v=l1VAyDrxeeyo&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/css/skin_1/header.css?v=EZbG2DEumYDH&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/shared/css/shared_global.css?v=sd6kCnGQW5Ji&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com/explore/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com/profiles/76561199724331900/inventory/ |
Show WHOIS
|
Malicious
|
- |
...
|
https://community.cloudflare.steamstatic.com/public/javascript/profile.js?v=47omfdMZRDiz&l=english&_cdn=cloudflare |
Show WHOIS
|
Not Available
|
- |
...
|
https://store.steampowered.com/about/ |
Show WHOIS
|
Not Available
|
- |
...
|
https://steamcommunity.com/?subsection=broadcasts |
Show WHOIS
|
Not Available
|
- |
...
|
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback |
Show WHOIS
|
Not Available
|
- |
...
|
https://community.cloudflare.steamstatic.com//public// |
Show WHOIS
|
Not Available
|
- |
...
|
89cc4ec4d3d08e39cc94782fb19a52005add532f7ef692d3679c9cef68c2f52d | Downloaded File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\YYVN4TBXEDY7BKUXIITBJB4VU4FIL.ps1 | Downloaded File | HTML |
Clean
|
...
|
»
Extracted URLs (1)
»
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://www.googletagmanager.com/gtag/js?id=G-LLFSDKZXET |
Show WHOIS
|
Not Available
|
- |
...
|
11503cb70e6ebd3c2a7582626095db93c0a01deb82cfc3ac08ccc189efce0277 | Downloaded File | Stream |
Clean
|
...
|
»
27a22c238c66a8b5b4f58e1887119ee5f55b9cba364efb7c8372b34acad90b0b | Downloaded File | Text |
Clean
|
...
|
»
6113445002625a377f23b4b3cae970f91ee4283887b6ab19eb886456e525b425 | Downloaded File | Text |
Clean
|
...
|
»
ce528fdc5093be3f3184ffaf605c38bbaf0c892d57570e1e18e5ca2f5661be84 | Downloaded File | Text |
Clean
|
...
|
»
04339c5b1cd2339b03ffd50bc302c17f6c3ea7a39abbe96dd4ea5ad6d9796764 | Downloaded File | Text |
Clean
|
...
|
»
2689367b205c16ce32ed4200942b8b8b1e262dfc70d9bc9fbc77c49699a4f1df | Downloaded File | Text |
Clean
Known to be clean.
|
...
|
»