General

  • Target

    b395211b60d6186e7a831098ae4d8d84.bin

  • Size

    11.8MB

  • Sample

    240623-dpckqsxfqc

  • MD5

    ef28caed47cd962a737398019ee647b9

  • SHA1

    4bb58f6622da1edc72414494fb6c0e6c908c9106

  • SHA256

    3a7ad3d6436b345e4229b659cbff25f75afe949aa9dca89cbc117290b7d11eab

  • SHA512

    5a2851a19f13f172ce15f49566217cc8a1d9629e5a997ef159984737a0adfa9da49d6cded01078f44b6199865105cdb9c65f7c9caf3ff0c86ec85a594f5a7a53

  • SSDEEP

    196608:248zQ7uVUcwg42YudcD9MxNUC/a05gBpObq+HvJsXNyB8xw7EBHEuHLZHcGFEt5e:248zQ7uVigZda9MxCb0yBEJBhkNcZtw

Malware Config

Extracted

Family

lumma

C2

https://sailorshelfquids.shop/api

https://publicitycharetew.shop/api

https://computerexcudesp.shop/api

https://leafcalfconflcitw.shop/api

https://injurypiggyoewirog.shop/api

https://bargainnygroandjwk.shop/api

https://disappointcredisotw.shop/api

https://doughtdrillyksow.shop/api

https://facilitycoursedw.shop/api

Targets

    • Target

      files/Setup.exe

    • Size

      8.5MB

    • MD5

      98169506fec94c2b12ba9930ad704515

    • SHA1

      bce662a9fb94551f648ba2d7e29659957fd6a428

    • SHA256

      9b8a5b0a45adf843e24214b46c285e44e73bc6eaf9e2a3b2c14a6d93ae541363

    • SHA512

      7f4f7ac2326a1a8b7afc72822dae328753578eb0a4ffcec5adb4e4fb0c49703070f71e7411df221ee9f44d6b43a0a94921fe530877c5d5e71640b807e96def30

    • SSDEEP

      196608:vdoUox8PFOegKz+qE1cnuyHgv3eZaOxqeXY4K:vC0O9m7EWEvbOxqetK

    • Banload

      Banload variants download malicious files, then install and execute the files.

    • Lumma Stealer

      An infostealer written in C++ first seen in August 2022.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Event Triggered Execution: Component Object Model Hijacking

      Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.

    • Suspicious use of SetThreadContext

    • Target

      files/acdbase.dll

    • Size

      2.9MB

    • MD5

      dace23695dcfa0f7309b65366ac75bc0

    • SHA1

      c5b1bad2dec36852fae90f81f0dbd00518479c01

    • SHA256

      cf8b85beeff99b13d06ed15c79e555ab74e30dfa1491a36c4332f54ed09887e4

    • SHA512

      0e1e5fc158fb39c3c3c7733226cb846407cd01ca1c49800fb7668134ebef129ab43030f2768a8b149b5ba9a18b2d1b0f8bf23d1a8de487a482e9268e0b679bbb

    • SSDEEP

      49152:yQzvI/48LzIpH2aTZ70W6pVLOVicH+4T7snimYvtgbgwvWgfFv5COWaUsz7XapvL:yrIpHGpVL7nimatSgSWhOWaUsz7XapvL

    Score
    1/10
    • Target

      files/api-ms-win-crt-convert-l1-1-0.dll

    • Size

      25KB

    • MD5

      9f812bd3815909e559b15cb13489f294

    • SHA1

      df751c956f59b4e3c82496d86895adc7cc1a1619

    • SHA256

      ce6fcc2ddf21720c92bee04f5736a4787acffa970a1b0dbeea39ff5efec52c75

    • SHA512

      0a360e8b81bf80cb6bdf240d627ddcf71b1a4ca42759de61b2d27fab521a8e6e3afa308cc69caf5a7c8b14d98d3d448f0d400ae1826cbe7d0f0ceafd14682064

    • SSDEEP

      192:j9cyRWhhWnWGxVA6VWQ4cRWstTmz56CqRqNX01k9z3A8oX9l3zX:2yRWhhWfxdlvC5DNR9zrGnb

    Score
    1/10
    • Target

      files/api-ms-win-crt-environment-l1-1-0.dll

    • Size

      21KB

    • MD5

      1a72e5f24214eb723e03a22ff53f8a22

    • SHA1

      578d1dbfb22e9ff3b10c095d6a06acaf15469709

    • SHA256

      fda46141c236a11054d4d3756a36da4412c82dd7877daad86cb65bf53d81ca1a

    • SHA512

      530e693daecc7c7080b21e39b856c538bb755516aafdb6839a23768f40bcfc38d71b19586e8c8e37bb1c2b7a7c31fcb8e24a2315a8dd90f50fec22f973d86cb4

    • SSDEEP

      192:CWhhWzWvkJ0f5AbVWQ4mWluxFlZNKd2kQX01k9z3Ad4M6tyOM:CWhhW3aabtF3NNPR9zw4JtyOM

    Score
    1/10
    • Target

      files/api-ms-win-crt-heap-l1-1-0.dll

    • Size

      21KB

    • MD5

      9d136bbecf98a931e6371346059b5626

    • SHA1

      2466e66bfd88dd66c1c693cbb95ea8a91b9558cd

    • SHA256

      7617838af1b589f57e4fe9fee1e1412101878e6d3287cdc52a51cd03e3983717

    • SHA512

      8c720c798d2a06f48b106a0a1ef38be9b4a2aebe2a657c8721278afa9fdbab9da2a672f47b7996ca1ce7517015d361d77963c686e0ae637a98c32fd75e5d0610

    • SSDEEP

      192:9vh8Y17aFBRUWhhW1WGxVA6VWQ4cRWKksNQlO8X01k9z3AenWcK:RLRWhhWhxdl/KlO8R9zh4

    Score
    1/10
    • Target

      files/api-ms-win-crt-runtime-l1-1-0.dll

    • Size

      25KB

    • MD5

      6b39d005deb6c5ef2c9dd9e013b32252

    • SHA1

      79a0736454befd88ba8d6bd88794d07712e38a67

    • SHA256

      b0e50572eb82a46ed499775e95bfde7cb25c498957432c18c20cf930f332efd0

    • SHA512

      50bc1f669499589a480379d72166dae701914427d51223994d63a0363420ca6fdde07010803270a62451afea9e4ae55206d8a4c00ca4680e7a9120cd33f99a0f

    • SSDEEP

      192:lmGqX8mPrpJhhf4AN5/Ki9WhhWjmWGxVA6VWQ4cRW1XZ56CqRqNX01k9z3A8oXil:lysyr7LWhhWWxdl0Z5DNR9zrG25

    Score
    1/10
    • Target

      files/api-ms-win-crt-stdio-l1-1-0.dll

    • Size

      25KB

    • MD5

      97f24295c9bd6e1acae0c391e68a64cf

    • SHA1

      75700dce304c45ec330a9405523f0f22e5dcbb18

    • SHA256

      189d551fb3cba3dbb9b9c1797e127a52ac486d996f0ac7cba864fe35984a8d28

    • SHA512

      cac75f623545c41b2597a25c14f2af7eb93e3e768b345d3b0e1928d8fd1f12bec39b18b8277f9550aa6a66d9cfe1bf6c3db93ae1eb2a6c07019d4f210b3e5998

    • SSDEEP

      192:6uV2OlkuWYFxEpah/WhhWQWGxVA6VWQ4cRWqfyMbNQlO8X01k9z3Aen2yMJ:DV2oFVh/WhhWoxdlH6GKlO8R9zh2yi

    Score
    1/10
    • Target

      files/api-ms-win-crt-string-l1-1-0.dll

    • Size

      25KB

    • MD5

      d282a4fa046d05d40d138cc68c518914

    • SHA1

      d5012090399f405ffe7d2fed09650e3544528322

    • SHA256

      8b1471101145343da5f2c5981c515da4dfae783622ed71d40693fe59c3088d7a

    • SHA512

      718926e728627f67ba60a391339b784accd861a15596f90d7f4e6292709ac3d170bcbca3cbf6267635136cb00b4f93da7dfd219fa0beee0cf8d95ce7090409e4

    • SSDEEP

      768:mCV5yguNvZ5VQgx3SbwA71IkFlRzoOQ9zrg:h5yguNvZ5VQgx3SbwA71IuRzez

    Score
    1/10
    • Target

      files/api-ms-win-crt-time-l1-1-0.dll

    • Size

      21KB

    • MD5

      6d35a57a6d8d569f870b96e00e7f1f4d

    • SHA1

      8407bdb3cd5ec15b2ce738b3dbd704aa289ce3e1

    • SHA256

      f41511e477a164eb9451ca51fb3810437f3b15f21e6f5c6ce0956e84ec823723

    • SHA512

      4317b86d32ca93e5f0d832819cf1ab8af68e853a19eb07dd1fa4d168a0b2a8eab309194884ed3a613b09fc6d511be872a053f76f00ea443499006cdd226fea8f

    • SSDEEP

      192:mm3hwD2WhhWq4WGxVA6VWQ4cRWY9y56CqRqNX01k9z3A8oXTlxWBR:HWhhWVxdlG5DNR9zrG/0R

    Score
    1/10
    • Target

      files/api-ms-win-crt-utility-l1-1-0.dll

    • Size

      21KB

    • MD5

      8ed70910380aa0b28317512d72762cc0

    • SHA1

      0421518370f24f9559f96459d0798d98b81ea732

    • SHA256

      f15af0db93d9385ff9d8efdc06aacd0729d0dfcb66e91ca0243bb160f2ed89d0

    • SHA512

      b31ef07eaac310fdd3df3546246e7dc696595b8e92141e3db79a44ddc3358b12129e3829a53c76d0fef214e3f29dba77fa5d556211830a140ea34ff62258d9d7

    • SSDEEP

      192:Z/fHQduzWhhWqzWvkJ0f5AbVWQ42WIknbx6IVnKaQwP7yX01k9z3AcK:Z/fFWhhWq3aabObx6zaHeR9zTK

    Score
    1/10
    • Target

      files/libmmd.dll

    • Size

      4.0MB

    • MD5

      19c31c58313c58fc88cf27e77befb0c3

    • SHA1

      b0711e10ef98b86e76ad28665285598d8809ae36

    • SHA256

      c2684b143c3417c588a3c0ae0a9c4329e71a04fc304aa3a69eae61ede1d0b290

    • SHA512

      97c954d009d10aed8fdbe02efe3b8d74840c2dce03da8fe5a5001d390afb4598a5bb3d74dacb740dec10e86aadc54b792bcc3c6815b2dfff036f14dace31ac86

    • SSDEEP

      98304:0JLi7X0J2iGkPyxtZPk8joEGIbQOpv3VzGIsJQQJ:OyqCtZM8UEtb5yIs24

    Score
    1/10
    • Target

      files/vcruntime140.dll

    • Size

      116KB

    • MD5

      699dd61122d91e80abdfcc396ce0ec10

    • SHA1

      7b23a6562e78e1d4be2a16fc7044bdcea724855e

    • SHA256

      f843cd00d9aff9a902dd7c98d6137639a10bd84904d81a085c28a3b29f8223c1

    • SHA512

      2517e52f7f03580afd8f928c767d264033a191e831a78eed454ea35c9514c0f0df127f49a306088d766908af7880f713f5009c31ce6b0b1e4d0b67e49447bfff

    • SSDEEP

      1536:KqvQFDdwFBHKaPX8YKpWgeQqbekRG7MP4ddbsecbWcmpCGa3QFzFtjXzp:KqvQFDUXqWn7CkRG7YecbWb9a3kDX9

    Score
    1/10
    • Target

      files/vcruntime140_app.dll

    • Size

      21KB

    • MD5

      c0f29bd3b0eb4d8795d609a0c52e0926

    • SHA1

      2f1958696d66edaf38079e370dcc2b41c7474122

    • SHA256

      813a447192c4fa7d25d0716b769399546f8bf6b31269dd8ad47f9812008d79e6

    • SHA512

      02bc56ad129a7d6382ba8d68b68a52fa70ace9bce68aae56d901bc60451982e358805e950ab49ae3d0c052c2ac6d44a6f5ab3679cd4ce2fbb205e4a8c7d7b670

    • SSDEEP

      384:K0g/dJiHlDoeuczbaj7wTfzvg55dHRN7ooiFWSlGs4kz:w/d8lDoeuczbaj7Cg9jHPs

    Score
    3/10
    • Target

      files/x86/HDHelper_[0MB]_[1].exe

    • Size

      566KB

    • MD5

      8a179892518a2c4e8a63afa91de7bdce

    • SHA1

      e9b095c966ccc4c4900b4cf741c067d2a0f43cd4

    • SHA256

      72ece91f65a461c5023695bf5f31b5b6b5bd629dba8407524e8144f6d1e160e8

    • SHA512

      91abb220c222a89a2df27818b8385b4015128a35b7d4c43d0f497717a4e5a55dfb9dc1da3f47a49a2400ea8300d41d52277331a6c7c3437ac5cb867a4027b220

    • SSDEEP

      12288:voJoMf8uSKkd/kAseRy/M96oQD08WjWYatid4TwzSxK/G8kHcL:CEKkd/wXMwoQJW6Ya5TwzUKeH8L

    Score
    1/10
    • Target

      files/x86/NvStereoUtilityOGL_[1MB]_[1].exe

    • Size

      1.1MB

    • MD5

      017cd77d01314e72a973ff0c7882453d

    • SHA1

      288238159cf18418149f5cd3475a6ebb9f45a631

    • SHA256

      c2c71318a17f7f767e5d203d22b48f27eecae46a4f37082d7b413c51da6183b3

    • SHA512

      b1d4c87e7d8585c16aa50499398c9a04d90bcd32ab36fbf7a357bc15abce0cd802a259cc7431de9fe2ca77aa68298aab5041157308be4601f7f7aa0c3c180b03

    • SSDEEP

      24576:zCVnoQHgdFnJhVaqajA4+ubDaSKYqSpamUbSBe:zgnoFFnJjaqajA4+yaSK5SpamUbSBe

    Score
    3/10
    • Target

      files/x86/VSLauncher_[0MB]_[1].exe

    • Size

      281KB

    • MD5

      7a7bb3b0e57e4fb32c57b74e78e657ad

    • SHA1

      f1dee943b1b6238b1466d83325c4099d189cd4b5

    • SHA256

      87048cff2227d2901314760618d23917cfbc5cc15fc22dc355e803c5ee5fb211

    • SHA512

      ef0c9985b640189ed9991b301cfbf9771df961e1bf67bf68c5833667db53977c9745bcfb42e059d8bb5bcd7a88253a715d86f65612dccc33514ccda3baaf24c2

    • SSDEEP

      3072:Dawahjy56hh65Ndqp9ikqtPLy0gJmU/3j41IGvQC2mCILuCW+VoNDRUiuDhJoueT:dLlavj41nDlDOO9uunwiLWyIE2n

    Score
    1/10
    • Target

      files/x86/api-ms-win-core-processthreads-l1-1-1.dll

    • Size

      17KB

    • MD5

      29001f316ccfc800e2246743df9b15b3

    • SHA1

      dc734266648d3463c1f8d88c1ce7d900a4e3b26c

    • SHA256

      e5ea2c21fb225090f7d0db6c6990d67b1558d8e834e86513bc8ba7a43c4e7b36

    • SHA512

      4cffc0c6f94fcd1155909993c622b9103abd7a7bce88742a10abd6a3496a334d667a39bb601f99eb174aa847d7dae056e0d9769754ca86320579b262a20a6599

    • SSDEEP

      384:WRtwDfIe9jWfhWC+Y3DGk8ZpH3GCJErra8o7Q+Y3DGUKn8JN77hhET:ape9A5DGkiRBEXaR70DGa3hqT

    Score
    1/10
    • Target

      files/x86/api-ms-win-core-profile-l1-1-0.dll

    • Size

      16KB

    • MD5

      6ee66dca31c5cce57740d677c85b4ce7

    • SHA1

      8969db03f98f9548caf8e2d8c7f2f5cd7071f333

    • SHA256

      d00a0edace14715bf79dbd17b715d8a74a2300f0adb1f3fc137edfb7074c9b0a

    • SHA512

      592e3b6c689a0d6c87079c54c3e13e6ee1fc0c5c770abc854040e85464687c46f0a558be22f8759dbc4a100810386ee379ffe4359cf9091d9afae548bc597be2

    • SSDEEP

      384:WiIWfhWx+Y3DGk8ZpH3GCJErcx3l/r7+Y3DGU78JN77hhC6UHR:doDGkiRBEWV/rxDGT3h06UHR

    Score
    1/10
    • Target

      files/x86/api-ms-win-core-rtlsupport-l1-1-0.dll

    • Size

      17KB

    • MD5

      0069fd29263c0dd90314c48bbce852ef

    • SHA1

      dfb99c850a69e67e85f0a0985659f325bd8f84fc

    • SHA256

      d11093fdc1d5c9213b9b2886ce91db3ded17ef8dae1615a8c7ffbc55b8e3f79b

    • SHA512

      71965e8dd2fd81d0c6dba4dbec8d2d1bfd4a644ef6bba4f6027de4bcdf9c07da16f27f2156c21b52e678c75f0a93a4bcbc3e1942f0a73f1eea5ff64b70662f70

    • SSDEEP

      384:WCGeVxWfhWD+Y3DGk8ZpH3GCJErYtN+Y3DGUO8JN77hhTew:3GeVmyDGkiRBEojDGa3h9ew

    Score
    1/10
    • Target

      files/x86/api-ms-win-core-string-l1-1-0.dll

    • Size

      17KB

    • MD5

      2e5c29fc652f432b89a1afe187736c4d

    • SHA1

      96f8480b9339411d5d8c94918e983523b1a55c56

    • SHA256

      3807db7acf1b40c797e4d4c14a12c3806346ae56b25e205e600be3e635c18d4f

    • SHA512

      fe1135532e18127f2cfefaaa4a19020d6c790374f648dc93383d58ee52b147d1451af01b8624234bd5d77abe2451eb3e15cbe72a19d283f00cf78c05c43041df

    • SSDEEP

      384:W4yMv9WfhWx+Y3DGk8ZpH3GCJEr4ey/+Y3DGU888JN77hhnY1:DyMvaIDGkiRBEsnDGX3hxY1

    Score
    1/10
    • Target

      files/x86/api-ms-win-core-synch-l1-1-0.dll

    • Size

      19KB

    • MD5

      979c67ba244e5328a1a2e588ff748e86

    • SHA1

      4c709ce527550eb7534cb6362afdb3623c98254e

    • SHA256

      8bb38a7a59fbaa792b3d5f34f94580429588c8c592929cbd307afd5579762abc

    • SHA512

      49f3c3319aa462b445c6a0b816e10034f6e5a9cf1250ea30b348cfa1ef71525e9f62e2f13253f61375f51fc574847de0d509cffa95103771be356327d5fef90d

    • SSDEEP

      384:Wjdv3V0dfpkXc0vVaCWfhWt+Y3DGk8ZpH3GCJErHZpn+Y3DGUrUN8JN77hhYl:Wdv3VqpkXc0vVabkDGkiRBEtplDGEUq8

    Score
    1/10
    • Target

      files/x86/api-ms-win-core-synch-l1-2-0.dll

    • Size

      17KB

    • MD5

      659e4febc208545a2e23c0c8b881a30d

    • SHA1

      11b890cc05c1e7c95f59eda4bb8ce8bc12b81591

    • SHA256

      9ac63682e03d55a5d18405d336634af080dd0003b565d12a39d6d71aaa989f48

    • SHA512

      010ab6d3971fabd2a956f891b8d9d20ef487e722443b2882a1a329830dc5c80d262e03a844cd3f5c3e4efcfbad72b9e1fbbf7d9dc6cf85ed034d84726946ce07

    • SSDEEP

      384:WHtZ36WfhW8+Y3DGk8ZpH3GCJEFxMDD+Y3DGEC8q8JN77hhFGT:EbDGkiRBEsJDGS13hj+

    Score
    1/10
    • Target

      files/x86/api-ms-win-core-sysinfo-l1-1-0.dll

    • Size

      18KB

    • MD5

      cef4b9f680faae322170b961a3421c5b

    • SHA1

      dd89a2d355df989bbd8648789472bfe9c14afcd5

    • SHA256

      1fe918979f1653d63bb713d4716910d192cd09f50017a6ecb4ce026ed6285df9

    • SHA512

      f56617290d4ac25231631d708a6c8b003bdd358bae9672f7dee539a96b292c13e04c65ba5f05937c52f73288eb3dd7cba479ed030942a0d9d3a15512548fa4a9

    • SSDEEP

      384:WBTnWfhWt+Y3DGk8ZpH3GCJEFxqIDh/h+Y3DGER6vJ8JN77hhHWT:0TsIDGkiRBE+IxfDGM6vW3h5WT

    Score
    1/10
    • Target

      files/x86/api-ms-win-core-timezone-l1-1-0.dll

    • Size

      17KB

    • MD5

      69df2cce4528c9e38d04a461ba1f992b

    • SHA1

      bb1d0da76cf696acf2e0f4e03e6d63fbad4325aa

    • SHA256

      a108a8f20ded00e742a1f818ef00eb425990b6b24a2bcd060dea4d7f06d3f165

    • SHA512

      4d02eecdda0fffc10d5509830079984c7a887b4ca3a80359aa56117b302dcfa594b0710c9f415c823d1674b5c689d31aade44f21750ccd7d53010e67f0b6f0d2

    • SSDEEP

      384:WGOWfhWc+Y3DGk8ZpH3GCJEFxi+3T7Tu+Y3DGEu8JN77hh2KI:5XDGkiRBEm+uDGQ3h7I

    Score
    1/10

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Component Object Model Hijacking

1
T1546.015

Privilege Escalation

Event Triggered Execution

1
T1546

Component Object Model Hijacking

1
T1546.015

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

2
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

1
T1082

Tasks

static1

Score
1/10

behavioral1

banloaddownloaderdropperevasionpersistenceprivilege_escalationtrojan
Score
10/10

behavioral2

banloadlummadownloaderdropperevasionpersistenceprivilege_escalationstealertrojan
Score
10/10

behavioral3

Score
1/10

behavioral4

Score
1/10

behavioral5

Score
1/10

behavioral6

Score
1/10

behavioral7

Score
1/10

behavioral8

Score
1/10

behavioral9

Score
1/10

behavioral10

Score
1/10

behavioral11

Score
1/10

behavioral12

Score
1/10

behavioral13

Score
1/10

behavioral14

Score
1/10

behavioral15

Score
1/10

behavioral16

Score
1/10

behavioral17

Score
3/10

behavioral18

Score
3/10

behavioral19

Score
1/10

behavioral20

Score
1/10

behavioral21

Score
1/10

behavioral22

Score
3/10

behavioral23

Score
1/10

behavioral24

Score
1/10

behavioral25

Score
1/10

behavioral26

Score
1/10

behavioral27

Score
1/10

behavioral28

Score
1/10

behavioral29

Score
1/10

behavioral30

Score
1/10

behavioral31

Score
1/10

behavioral32

Score
1/10