General

  • Target

    roblox_executor.htm

  • Size

    30KB

  • Sample

    240624-pjgs2s1hje

  • MD5

    073999097b3431c6fe7d3f970c4cbf0e

  • SHA1

    71cabf814ac5a25af4ddb05b7737369beef3eb55

  • SHA256

    642d05b7267e3d355fe7c01c112604f7f0af3aa20ea0477d153c11a6b60b7cfa

  • SHA512

    4a2265f8e3264d3b2f8b965e799307e0be37325d913392228aff2ea3ea2e52d752e76532948ad74fe77d9f2719b43a702bc7954fd3d1089106f585fa3c1713ec

  • SSDEEP

    384:9S9jaVJQj0HJ6uJn9jqbIEE6SB7k0F0dmX0p+BgSCsXW3NCu:9S9jaVJQO4uJnQDSB7LFw+BgRn3z

Score
10/10

Malware Config

Extracted

Family

lumma

C2

https://archidoveryusk.shop/api

https://publicitycharetew.shop/api

https://computerexcudesp.shop/api

https://leafcalfconflcitw.shop/api

https://injurypiggyoewirog.shop/api

https://bargainnygroandjwk.shop/api

https://disappointcredisotw.shop/api

https://doughtdrillyksow.shop/api

https://facilitycoursedw.shop/api

Targets

    • Target

      roblox_executor.htm

    • Size

      30KB

    • MD5

      073999097b3431c6fe7d3f970c4cbf0e

    • SHA1

      71cabf814ac5a25af4ddb05b7737369beef3eb55

    • SHA256

      642d05b7267e3d355fe7c01c112604f7f0af3aa20ea0477d153c11a6b60b7cfa

    • SHA512

      4a2265f8e3264d3b2f8b965e799307e0be37325d913392228aff2ea3ea2e52d752e76532948ad74fe77d9f2719b43a702bc7954fd3d1089106f585fa3c1713ec

    • SSDEEP

      384:9S9jaVJQj0HJ6uJn9jqbIEE6SB7k0F0dmX0p+BgSCsXW3NCu:9S9jaVJQO4uJnQDSB7LFw+BgRn3z

    Score
    10/10
    • Lumma Stealer

      An infostealer written in C++ first seen in August 2022.

    • Executes dropped EXE

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

2
T1012

System Information Discovery

1
T1082

Tasks