General

  • Target

    !!SetUp_!PaS$Kḙy$!_60814.zip

  • Size

    14.2MB

  • Sample

    240703-yexhdavdll

  • MD5

    34d313d321f156375b0c3f94ea9e4936

  • SHA1

    78450c7f1133106f206a8abeb111ca4e448ba4e2

  • SHA256

    5cf127ccb4d461cd11701d8b949ed45af04f6ca188a24c482cefc2a26583c721

  • SHA512

    6c578110b1d2c1d5d150182af4a5949ae63bf7c0c622ce519df83c954b3a8710596ec1546dbb01ea300fe408533f0c51604604720195d44947cca9b246bd4b52

  • SSDEEP

    393216:T6m4tr0MMMp/Ms3txYv0hAXV0rFQND/iA0uLyw:m9t4MZ/MyxYcWXW+9iBw

Score
10/10

Malware Config

Extracted

Family

lumma

C2

https://bouncedgowp.shop/api

https://bannngwko.shop/api

https://bargainnykwo.shop/api

https://affecthorsedpo.shop/api

https://radiationnopp.shop/api

https://answerrsdo.shop/api

https://publicitttyps.shop/api

https://benchillppwo.shop/api

https://reinforcedirectorywd.shop/api

Targets

    • Target

      !!SetUp_!PaS$Kḙy$!_60814/Setup.exe

    • Size

      1.1MB

    • MD5

      f975a2d83d63a473fa2fc5206b66bb79

    • SHA1

      e49d21f112ab27ae0953aff30ae122440cf164b9

    • SHA256

      6a2d3876003f6c68f824df4f0033564d8c230716908ba2e6c06ea1dd6d5f98e8

    • SHA512

      4af4ce56bf131432d488ed112f8858c1e1392d013c6ac0603f2fd70ed513091e35854c0f678efeab7fa9a551517c6b9698f40a92729112de4b852fa3c0c69d64

    • SSDEEP

      12288:IbCylcTVPbi7vT1K7n6HpVkg8KHIo5u0K1VmMxEnbuvuY2jTU+LHMA+nk2oG1ts:4lcTVPbikTMkg8KH/mmMxnvfphx8

    Score
    10/10
    • Lumma Stealer

      An infostealer written in C++ first seen in August 2022.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks