Click to jump to signature section
Source: QlyOUFGIFB.exe | ReversingLabs: Detection: 52% |
Source: Submited Sample | Integrated Neural Analysis Model: Matched 94.5% probability |
Source: QlyOUFGIFB.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: | Binary string: C:\Users\Brand\Desktop\Downloads\Internal\x64\Release\NX.pdb source: Luna.dll.0.dr |
Source: Joe Sandbox View | IP Address: 20.233.83.146 20.233.83.146 |
Source: Joe Sandbox View | IP Address: 20.233.83.145 20.233.83.145 |
Source: Joe Sandbox View | IP Address: 185.199.111.133 185.199.111.133 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /repos/suffz/luna/releases/latest HTTP/1.1Host: api.github.comUser-Agent: Go-http-client/1.1Accept-Encoding: gzip |
Source: global traffic | HTTP traffic detected: GET /suffz/luna/releases/download/v1.6.4-b2/Luna.zip HTTP/1.1Host: github.comUser-Agent: Go-http-client/1.1Accept-Encoding: gzip |
Source: global traffic | HTTP traffic detected: GET /github-production-release-asset-2e65be/872150778/49e98dea-334c-4a4e-a52e-d40125a3b3b1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=releaseassetproduction%2F20241206%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20241206T143254Z&X-Amz-Expires=300&X-Amz-Signature=16973e492b73c2f00f28b30243e7e235c548062790d6abb0d3158bb9d6283a90&X-Amz-SignedHeaders=host&response-content-disposition=attachment%3B%20filename%3DLuna.zip&response-content-type=application%2Foctet-stream HTTP/1.1Host: objects.githubusercontent.comUser-Agent: Go-http-client/1.1Referer: https://github.com/suffz/luna/releases/download/v1.6.4-b2/Luna.zipAccept-Encoding: gzip |
Source: global traffic | DNS traffic detected: DNS query: api.github.com |
Source: global traffic | DNS traffic detected: DNS query: github.com |
Source: global traffic | DNS traffic detected: DNS query: objects.githubusercontent.com |
Source: Luna.exe.0.dr | String found in binary or memory: http://earth.google.com/kml/2.0 |
Source: Luna.exe.0.dr | String found in binary or memory: http://earth.google.com/kml/2.1 |
Source: Luna.exe.0.dr | String found in binary or memory: http://earth.google.com/kml/2.2 |
Source: Luna.exe.0.dr | String found in binary or memory: http://wails.localhost/runtime.WindowReload();msSmartScreenProtectionbad |
Source: Luna.exe.0.dr | String found in binary or memory: http://www.ibm.com/data/dtd/v11/ibmxhtml1-transitional.dtdAn |
Source: Luna.exe.0.dr | String found in binary or memory: http://www.topografix.com/GPX/1/1 |
Source: QlyOUFGIFB.exe | String found in binary or memory: https://api.github.com/repos/%s/%s/releases/latestnet/http: |
Source: QlyOUFGIFB.exe, 00000000.00000003.2087734924.000000C000216000.00000004.00001000.00020000.00000000.sdmp, QlyOUFGIFB.exe, 00000000.00000003.2087666746.000000C000230000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://api.github.com/repos/suffz/luna/releases/latest |
Source: Luna.exe.0.dr | String found in binary or memory: https://apis.roblox.com/search-api/omni-search?verticalType=user&searchQuery=%v&pageToken=&globalSes |
Source: Luna.exe.0.dr | String found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/monaco-editor/0.26.1/min/vs/loader.min.js |
Source: Luna.exe.0.dr | String found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/monaco-editor/0.33.0/min/vs |
Source: Luna.exe.0.dr | String found in binary or memory: https://fonts.googleapis.com/css2?family=Outfit:wght |
Source: Luna.exe.0.dr | String found in binary or memory: https://github.com/gin-gonic/gin/blob/master/docs/doc.md#dont-trust-all-proxies |
Source: Luna.exe.0.dr | String found in binary or memory: https://github.com/golang/protobuf/issues/1609): |
Source: QlyOUFGIFB.exe, 00000000.00000002.3304507229.000000C0001FD000.00000004.00001000.00020000.00000000.sdmp, QlyOUFGIFB.exe, 00000000.00000002.3304507229.000000C000016000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://github.com/suffz/luna/releases/download/v1.6.4-b2/Luna.zip |
Source: QlyOUFGIFB.exe, 00000000.00000002.3304507229.000000C000210000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://objects.githubusercontent.com/github-production-release-asset-2e65be/872150778/49e98dea-334c |
Source: Luna.exe.0.dr | String found in binary or memory: https://pkg.go.dev/github.com/gin-gonic/gin#readme-don-t-trust-all-proxies |
Source: Luna.exe.0.dr | String found in binary or memory: https://sweetalert2.github.io/#ajax-request |
Source: Luna.exe.0.dr | String found in binary or memory: https://thumbnails.roblox.com/v1/users/avatar-headshot?userIds=%d&size=150x150&format=Png&isCircular |
Source: Luna.exe.0.dr | String found in binary or memory: https://tr.rbxcdn.com/30DAY-AvatarHeadshot-768C0AD1061FB65545E5FF8D66815094-Png/150/150/AvatarHeadsh |
Source: QlyOUFGIFB.exe, 00000000.00000002.3304507229.000000C000302000.00000004.00001000.00020000.00000000.sdmp, QlyOUFGIFB.exe, 00000000.00000002.3304507229.000000C000155000.00000004.00001000.00020000.00000000.sdmp, Luna.exe.0.dr | String found in binary or memory: https://wails.io) |
Source: Luna.exe.0.dr | String found in binary or memory: https://wails.io/docs/reference/runtime/introcrypto/tls: |
Source: Luna.exe.0.dr | String found in binary or memory: https://www.roblox.com/download/client?os=wincontext: |
Source: unknown | Network traffic detected: HTTP traffic on port 49706 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49705 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49704 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49706 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49705 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49704 |
Source: Luna.exe.0.dr | Binary or memory string: unexpected EOSlen of type %s^[a-zA-Z0-9]+$^[0-9a-f]{32}$^[0-9a-f]{64}$^[0-9a-f]{96}$^[0-9a-f]{40}$^[0-9a-f]{48}$eq_ignore_casene_ignore_case%04d-%02d-%02d%02d:%02d:%02ddocument startsequence startunknown node: data truncatedimage/x-ms-bmpaudio/musepackaudio/vnd.wavevideo/x-ms-asfvideo/x-ms-wmvimage/vnd.djvuprotobuf errorreserved_rangefield_presenceexpected 'inf'expected 'nan'CoTaskMemAllocv1 invalid: %wv2 invalid: %wKnownStructs: MEDIANEXTTRACKMEDIAPLAYPAUSE"MultiPolygon"GetPixelFormatDragQueryPointSetWindowTextWGetWindowTextWCallNextHookExAlt+Ctrl+ShiftBrowserForwardBrowserRefreshMediaNextTrackMediaPrevTrackMediaPlayPauseMS Shell Dlg 2failed SetMenuDisplayVersion[AssetServer] 192.0.2.1:1234fedistantlightfegaussianblurlineargradientradialgradientfeDistantLightfeGaussianBlurlinearGradientradialGradientprimitiveunitssystemlanguageprimitiveUnitssystemLanguagexl/worksheets/frontend/build/not implementedHalfClosedLocalapplication/pdfapplication/oggfont/collectionapplication/zipnegative updateaccept-encodingaccept-languagex-forwarded-fortrailers_pseudobad_path_methodAccept-Encodingrecv_rststream_Idempotency-KeyPartial ContentRequest TimeoutLength RequiredNot ImplementedGateway Timeoutunexpected typebad trailer keywrite error: %wGetProcessTimesDuplicateHandlenegative offsetinvalid argSize<invalid Value>advertise errorkey has expirednetwork is downno medium foundno such processGetAdaptersInfoCreateHardLinkWDeviceIoControlFlushViewOfFileGetCommandLineWGetStartupInfoWProcess32FirstWUnmapViewOfFileFailed to load Failed to find : cannot parse ,M3.2.0,M11.1.0NtResumeProcessExcludeClipRectGetEnhMetaFileWGetTextMetricsWPlayEnhMetaFileNotTrueTypeFontProfileNotFoundGdiplusShutdownGetThreadLocaleOleUninitializewglGetCurrentDCDragAcceptFilesCallWindowProcWCreatePopupMenuCreateWindowExWDialogBoxParamWGetActiveWindowGetDpiForWindowGetMonitorInfoWGetRawInputDataInsertMenuItemWIsWindowEnabledIsWindowVisiblePostQuitMessageSetActiveWindowSetWinEventHookTrackMouseEventWindowFromPointDrawThemeTextExwails:file-dropGetSecurityInfoImpersonateSelfOpenThreadTokenSetSecurityInfoAddDllDirectoryFindNextVolumeWFindVolumeCloseGetCommTimeoutsIsWow64Process2QueryDosDeviceWSetCommTimeoutsSetVolumeLabelWRtlDefaultNpAclCLSIDFromStringStringFromGUID2IsWindowUnicodetimeBeginPeriodnot a directory476837158203125[^a-zA-Z0-9/-]+X-Forwarded-For' in new path 'general failuredata before FINbad close code reflectlite.SetHanifi_RohingyaPsalter_Pahlavix509keypairleafrecord overfl |