Resubmissions

30-06-2024 09:10

240630-k459xsyfkq 10

30-06-2024 09:09

240630-k4fz2avhqa 6

General

  • Target

    https://github.com/solaraofficial/Solara-Executor?tab=readme-ov-file

  • Sample

    240630-k459xsyfkq

Score
10/10

Malware Config

Extracted

Credentials

  • Protocol:
    ftp
  • Host:
    94.156.8.173
  • Port:
    21
  • Username:
    anonymous
  • Password:
    anonymous@

Extracted

Family

lumma

C2

https://contintnetksows.shop/api

https://potterryisiw.shop/api

https://foodypannyjsud.shop/api

https://reinforcedirectorywd.shop/api

Targets

    • Target

      https://github.com/solaraofficial/Solara-Executor?tab=readme-ov-file

    Score
    10/10
    • Lumma Stealer

      An infostealer written in C++ first seen in August 2022.

    • Executes dropped EXE

    • Legitimate hosting services abused for malware hosting/C2

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Command and Control

Web Service

1
T1102

Tasks