General
-
Target
301394de0a1858f4e7b20244ec2d938cce91c61e7c9e224b4fa00177b6bf9cec.exe
-
Size
4.6MB
-
Sample
240624-bfvzlssbme
-
MD5
f3633e3e1bc67dd770d72c79d1e1f665
-
SHA1
47443903cfbcd8fefb314c1b29324b7909142634
-
SHA256
301394de0a1858f4e7b20244ec2d938cce91c61e7c9e224b4fa00177b6bf9cec
-
SHA512
f7211899a4dfa6979f3bd0d797e55e32e264212635f4569c7aee4cba63c3ca0fe2ec27b86d2e27b36f4b28b7ff50a0202116d0e44a0fbe684ef814e96d4e2a35
-
SSDEEP
98304:KrLVoBkwXnc+AdMIm8r3ctMmKCOQhMCTgeZ1lcvdq:IhIkwt+x31/CICj1lg
Static task
static1
Behavioral task
behavioral1
Sample
301394de0a1858f4e7b20244ec2d938cce91c61e7c9e224b4fa00177b6bf9cec.exe
Resource
win7-20240419-en
Malware Config
Extracted
lumma
https://composepayyersellew.shop/api
https://publicitycharetew.shop/api
https://computerexcudesp.shop/api
https://leafcalfconflcitw.shop/api
https://injurypiggyoewirog.shop/api
https://bargainnygroandjwk.shop/api
https://disappointcredisotw.shop/api
https://doughtdrillyksow.shop/api
https://facilitycoursedw.shop/api
Targets
-
-
Target
301394de0a1858f4e7b20244ec2d938cce91c61e7c9e224b4fa00177b6bf9cec.exe
-
Size
4.6MB
-
MD5
f3633e3e1bc67dd770d72c79d1e1f665
-
SHA1
47443903cfbcd8fefb314c1b29324b7909142634
-
SHA256
301394de0a1858f4e7b20244ec2d938cce91c61e7c9e224b4fa00177b6bf9cec
-
SHA512
f7211899a4dfa6979f3bd0d797e55e32e264212635f4569c7aee4cba63c3ca0fe2ec27b86d2e27b36f4b28b7ff50a0202116d0e44a0fbe684ef814e96d4e2a35
-
SSDEEP
98304:KrLVoBkwXnc+AdMIm8r3ctMmKCOQhMCTgeZ1lcvdq:IhIkwt+x31/CICj1lg
-
UPX dump on OEP (original entry point)
-
XMRig Miner payload
-
Command and Scripting Interpreter: PowerShell
Run Powershell to modify Windows Defender settings to add exclusions for file extensions, paths, and processes.
-
Creates new service(s)
-
Executes dropped EXE
-
Loads dropped DLL
-
Power Settings
powercfg controls all configurable power system settings on a Windows system and can be abused to prevent an infected host from locking or shutting down.
-
Drops file in System32 directory
-
Suspicious use of NtSetInformationThreadHideFromDebugger
-
Suspicious use of SetThreadContext
-