General

  • Target

    Setup.exe

  • Size

    11.2MB

  • Sample

    240702-nqyvgazgpb

  • MD5

    8cc723573ea25e383dde086292cea276

  • SHA1

    256f4ff972f9851859471f0b9bcf3ef716bea7f0

  • SHA256

    7f73c93a769b51b149066e92ba8d518712c6c78ec1a8984aba156b757d13fcd8

  • SHA512

    19e4d06fa0d476e09e47173ebd08001bcf862b992b147de0b9c4db8f2508036e7adc19ee04ccd46bf6fbbc8077e4d57ee947e811685cf792c1373176f6fd0ac6

  • SSDEEP

    98304:l2TeFKyXsfAtYOMxy3J060mU/ja+X4JEXXav6Fc01:syFOfwYOMxy5F0mULa+X4KXh

Malware Config

Extracted

Family

lumma

C2

https://arritswpoewroso.shop/api

https://potterryisiw.shop/api

https://foodypannyjsud.shop/api

https://contintnetksows.shop/api

https://reinforcedirectorywd.shop/api

Targets

    • Target

      Setup.exe

    • Size

      11.2MB

    • MD5

      8cc723573ea25e383dde086292cea276

    • SHA1

      256f4ff972f9851859471f0b9bcf3ef716bea7f0

    • SHA256

      7f73c93a769b51b149066e92ba8d518712c6c78ec1a8984aba156b757d13fcd8

    • SHA512

      19e4d06fa0d476e09e47173ebd08001bcf862b992b147de0b9c4db8f2508036e7adc19ee04ccd46bf6fbbc8077e4d57ee947e811685cf792c1373176f6fd0ac6

    • SSDEEP

      98304:l2TeFKyXsfAtYOMxy3J060mU/ja+X4JEXXav6Fc01:syFOfwYOMxy5F0mULa+X4KXh

    Score
    10/10
    • Lumma Stealer

      An infostealer written in C++ first seen in August 2022.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Hide Artifacts

1
T1564

Resource Forking

1
T1564.009

Tasks