General

  • Target

    github.software.1.2.5.7z

  • Size

    2.2MB

  • Sample

    240628-ynezpazhkb

  • MD5

    aa2b5594c68671d9bb900a384289b66c

  • SHA1

    5db615ee5abf2bc3312b7609bc72d37464f1355e

  • SHA256

    024392527ceed45f4c6f552ee92a35339f4c21be1710dc233f66dce245420787

  • SHA512

    822c8e6e55abecdbac22af4344ea7945b8c90713ac587eac2374bf464327894c7c487214f5a0c6f9632dbffa0ccf2078506c2a53a4794ba91814d992a895537b

  • SSDEEP

    49152:/7SU9cpw+yScb6mPqvkLXtTsXJO52HOWIbOU:/7SJcbGSdwHujiU

Score
10/10

Malware Config

Extracted

Family

lumma

C2

https://piedsiggnycliquieaw.shop/api

https://potterryisiw.shop/api

https://foodypannyjsud.shop/api

https://contintnetksows.shop/api

https://reinforcedirectorywd.shop/api

Targets

    • Target

      github.software.1.2.5.exe

    • Size

      521KB

    • MD5

      3395544e3a6d54c372f0f0121f7f47db

    • SHA1

      1d7c3f910abd7f7e0f0c2f8826f36d6ab90bf6d3

    • SHA256

      c52a78552d29308b8fedb868e09be677aaacf9a6395349b30e3150f817d6d190

    • SHA512

      0157c319875b7f9ca4ca8ca0c0f5474f1aead7d0ba06c333ba628064a8559c9feecd3531d52db6f82c6422a50bd4cd43959ec10d8d647ae0049f6942f36d3127

    • SSDEEP

      12288:s3gVK31bhVXlO1sORicGc2spnLtu0pGQ7G:sw0lbDla/Rb2shLtuYGE

    Score
    10/10
    • Lumma Stealer

      An infostealer written in C++ first seen in August 2022.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks