Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 23, 2024, 8:05 p.m. | Aug. 23, 2024, 8:08 p.m. |
-
-
LumuUpdate.exe "C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuUpdate.exe" /installsource taggedmi /install "appguid={F29544FA-DF33-470F-90E9-B19EF24DF010}&appname=LumuAgent&needsadmin=True&usagestats=1"
2632-
LumuUpdate.exe "C:\Program Files (x86)\Lumu\Update\LumuUpdate.exe" /regsvc
2708 -
-
LumuUpdateComRegisterShell64.exe "C:\Program Files (x86)\Lumu\Update\1.3.107.1\LumuUpdateComRegisterShell64.exe"
2876 -
LumuUpdateComRegisterShell64.exe "C:\Program Files (x86)\Lumu\Update\1.3.107.1\LumuUpdateComRegisterShell64.exe"
2932 -
LumuUpdateComRegisterShell64.exe "C:\Program Files (x86)\Lumu\Update\1.3.107.1\LumuUpdateComRegisterShell64.exe"
2988
-
-
LumuUpdate.exe "C:\Program Files (x86)\Lumu\Update\LumuUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xMDcuMSIgc2hlbGxfdmVyc2lvbj0iMS4zLjEwNy4xIiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0iezBDRTBEQkJCLUMwRTgtNEU4OC05RDI2LTk0Q0JCNjUwN0ZGNn0iIHVzZXJpZD0ie0NGMjYzODI5LTBFOTgtNDAxNC05NDJGLTcyRTNBQkMxNjY2RX0iIGluc3RhbGxzb3VyY2U9InRhZ2dlZG1pIiB0ZXN0c291cmNlPSJhdXRvIiByZXF1ZXN0aWQ9InswQzA1MzBGOS0xNjc2LTQ4MzgtOTRCQi0xMDZGNUY4MEU0NDV9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IHBoeXNtZW1vcnk9IjUiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjAiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDY0Ii8-PGFwcCBhcHBpZD0iezgwODZCRDkzLTJFNzItNDk2QS05QUJDLUI5NEFGNkE2QzlDRn0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xMDcuMSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSIyNzUwIi8-PC9hcHA-PC9yZXF1ZXN0Pg
3056 -
LumuUpdate.exe "C:\Program Files (x86)\Lumu\Update\LumuUpdate.exe" /handoff "appguid={F29544FA-DF33-470F-90E9-B19EF24DF010}&appname=LumuAgent&needsadmin=True&usagestats=1" /installsource taggedmi /sessionid "{0CE0DBBB-C0E8-4E88-9D26-94CBB6507FF6}"
1152
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
client-updates.lumu.io | 3.229.137.113 | |
lumu-updates.s3.amazonaws.com |
CNAME
s3-1-w.amazonaws.com
|
54.231.203.249 |
x1.i.lencr.org | 23.207.177.83 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49175 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49179 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49173 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49188 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49205 54.231.194.33:443 |
C=US, O=Amazon, CN=Amazon RSA 2048 M01 | CN=*.s3.amazonaws.com | 57:fe:c9:73:13:31:ca:2c:91:7f:05:c3:3b:16:ff:3f:1b:d8:7d:e2 |
TLS 1.2 192.168.56.101:49191 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49178 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49189 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49192 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49214 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49213 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49215 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49216 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
pdb_path | mi_exe_stub.pdb |
resource name | B |
resource name | GOOGLEUPDATE |
suspicious_features | POST method with no referer header | suspicious_request | POST http://client-updates.lumu.io/service/update2 | ||||||
suspicious_features | POST method with no referer header | suspicious_request | POST http://client-updates.lumu.io/service/update2?cup2key=1:aiyktIlMWjC_YDIJkn6k3-6XqffwkP2DaBfamURTQIA&cup2hreq=a4125a8074c9af063159ba78027272f9671c42488dea9878a9c5f20b4b7c8dc7 |
request | GET http://x1.i.lencr.org/ |
request | POST http://client-updates.lumu.io/service/update2 |
request | POST http://client-updates.lumu.io/service/update2?cup2key=1:aiyktIlMWjC_YDIJkn6k3-6XqffwkP2DaBfamURTQIA&cup2hreq=a4125a8074c9af063159ba78027272f9671c42488dea9878a9c5f20b4b7c8dc7 |
request | GET https://lumu-updates.s3.amazonaws.com/build/Agent/win/2203318943744/desktop_single_agent-d47545d41d.exe |
request | POST http://client-updates.lumu.io/service/update2 |
request | POST http://client-updates.lumu.io/service/update2?cup2key=1:aiyktIlMWjC_YDIJkn6k3-6XqffwkP2DaBfamURTQIA&cup2hreq=a4125a8074c9af063159ba78027272f9671c42488dea9878a9c5f20b4b7c8dc7 |
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x001176e8 | size | 0x000001a6 |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_pt-PT.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_it.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuUpdateComRegisterShell64.exe |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_bn.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sl.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_nl.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ml.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_hu.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_fi.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_lv.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ko.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_fr.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_tr.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_de.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_pl.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_es.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ja.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_hr.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_no.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuCrashHandler.exe |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_fa.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sk.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\psmachine.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_is.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdate.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_vi.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_en-GB.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sv.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_cs.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\psuser_64.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_kn.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_en.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_uk.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\psmachine_64.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_hi.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_et.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuUpdate.exe |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_iw.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuUpdateCore.exe |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_bg.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\psuser.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_el.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_id.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ar.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_th.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_te.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_pt-BR.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sr.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_mr.dll |
file | C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sw.dll |
section | {u'size_of_data': u'0x000f6200', u'virtual_address': u'0x00022000', u'entropy': 7.983104756681283, u'name': u'.rsrc', u'virtual_size': u'0x000f60f0'} | entropy | 7.98310475668 | description | A section with a high entropy has been found | |||||||||
entropy | 0.887736699729 | description | Overall entropy of this PE file is high |
cmdline | "C:\Program Files (x86)\Lumu\Update\LumuUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xMDcuMSIgc2hlbGxfdmVyc2lvbj0iMS4zLjEwNy4xIiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0iezBDRTBEQkJCLUMwRTgtNEU4OC05RDI2LTk0Q0JCNjUwN0ZGNn0iIHVzZXJpZD0ie0NGMjYzODI5LTBFOTgtNDAxNC05NDJGLTcyRTNBQkMxNjY2RX0iIGluc3RhbGxzb3VyY2U9InRhZ2dlZG1pIiB0ZXN0c291cmNlPSJhdXRvIiByZXF1ZXN0aWQ9InswQzA1MzBGOS0xNjc2LTQ4MzgtOTRCQi0xMDZGNUY4MEU0NDV9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IHBoeXNtZW1vcnk9IjUiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjAiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDY0Ii8-PGFwcCBhcHBpZD0iezgwODZCRDkzLTJFNzItNDk2QS05QUJDLUI5NEFGNkE2QzlDRn0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xMDcuMSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSIyNzUwIi8-PC9hcHA-PC9yZXF1ZXN0Pg |
service_name | lumu | service_path | C:\Program Files (x86)\Lumu\Update\1.3.107.1\"C:\Program Files (x86)\Lumu\Update\LumuUpdate.exe" \svc | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5391887A-B2A6-4ED8-BFF9-5F0F497CE1CB}\InprocServer32\(Default) | reg_value | C:\Program Files (x86)\Lumu\Update\1.3.107.1\psmachine_64.dll | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E62DAFC-CBA5-45A8-B69A-6730467A94C2}\InprocServer32\(Default) | reg_value | C:\Program Files (x86)\Lumu\Update\1.3.107.1\psmachine_64.dll | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D81A6C20-7794-49AC-A20E-1218FC0E12A8}\InProcServer32\(Default) | reg_value | C:\Program Files (x86)\Lumu\Update\1.3.107.1\psmachine_64.dll | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5391887A-B2A6-4ED8-BFF9-5F0F497CE1CB}\InprocServer32\(Default) | reg_value | C:\Program Files (x86)\Lumu\Update\1.3.107.1\psmachine_64.dll | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E62DAFC-CBA5-45A8-B69A-6730467A94C2}\InprocServer32\(Default) | reg_value | C:\Program Files (x86)\Lumu\Update\1.3.107.1\psmachine_64.dll | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D81A6C20-7794-49AC-A20E-1218FC0E12A8}\InProcServer32\(Default) | reg_value | C:\Program Files (x86)\Lumu\Update\1.3.107.1\psmachine_64.dll | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5391887A-B2A6-4ED8-BFF9-5F0F497CE1CB}\InprocServer32\(Default) | reg_value | C:\Program Files (x86)\Lumu\Update\1.3.107.1\psmachine_64.dll | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E62DAFC-CBA5-45A8-B69A-6730467A94C2}\InprocServer32\(Default) | reg_value | C:\Program Files (x86)\Lumu\Update\1.3.107.1\psmachine_64.dll | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D81A6C20-7794-49AC-A20E-1218FC0E12A8}\InProcServer32\(Default) | reg_value | C:\Program Files (x86)\Lumu\Update\1.3.107.1\psmachine_64.dll |