General

  • Target

    Setup.exe

  • Size

    951KB

  • Sample

    240701-q9xgvsvgkg

  • MD5

    e86d9ad8b70cdb49b54bcd969b724d19

  • SHA1

    966b40f9c5493d356bea4d16c5e90728c9e8cee2

  • SHA256

    3bf3a7653abce050a672207777f823b5bfee766a18a597ae8a63184323980e85

  • SHA512

    d096adbf6f6fe1d8bfd660509c1905a6c17be7bbb460058130db0e500ee617a7424b1cf101dc03a52dee2f9c0c8a52aadd256469d32f351d352f3715928044bc

  • SSDEEP

    24576:C+qodQCtw8QEZWBiMUp736I5Zqiwul6teKj16ffJmyMW:jw8QEZWBTXSZqiwY6tD6n4yT

Score
10/10

Malware Config

Extracted

Family

lumma

C2

https://groundsmooors.shop/api

https://potterryisiw.shop/api

https://foodypannyjsud.shop/api

https://contintnetksows.shop/api

https://reinforcedirectorywd.shop/api

Targets

    • Target

      Setup.exe

    • Size

      951KB

    • MD5

      e86d9ad8b70cdb49b54bcd969b724d19

    • SHA1

      966b40f9c5493d356bea4d16c5e90728c9e8cee2

    • SHA256

      3bf3a7653abce050a672207777f823b5bfee766a18a597ae8a63184323980e85

    • SHA512

      d096adbf6f6fe1d8bfd660509c1905a6c17be7bbb460058130db0e500ee617a7424b1cf101dc03a52dee2f9c0c8a52aadd256469d32f351d352f3715928044bc

    • SSDEEP

      24576:C+qodQCtw8QEZWBiMUp736I5Zqiwul6teKj16ffJmyMW:jw8QEZWBTXSZqiwY6tD6n4yT

    Score
    10/10
    • Lumma Stealer

      An infostealer written in C++ first seen in August 2022.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Tasks