General
-
Target
cf2ef8eaab958f358b6f1adaaa60c1e94f3817e8a57cccd8b988af007fa8a57d
-
Size
507KB
-
Sample
240704-2p62cawcqg
-
MD5
0f9b8c6500c040df8aee110cac74225a
-
SHA1
51892cdff9f9afa873c096e372053f669792bb70
-
SHA256
cf2ef8eaab958f358b6f1adaaa60c1e94f3817e8a57cccd8b988af007fa8a57d
-
SHA512
651a7e9580880ba8ece3d345555f0765ed3ded259d88dd40501ccde326bebc01128c1d3653cda721c7fec3f7091781feb43c7be29ac54d1c1070caae4bd71fa9
-
SSDEEP
12288:KLo2tQgRiP9bu1ircdlgkXfzYJvNrXWoaVS4SZn:ikOiRzQdRuNLWoaVS4S
Static task
static1
Behavioral task
behavioral1
Sample
cf2ef8eaab958f358b6f1adaaa60c1e94f3817e8a57cccd8b988af007fa8a57d.exe
Resource
win7-20240419-en
Malware Config
Extracted
lumma
https://bitchsafettyudjwu.shop/api
Targets
-
-
Target
cf2ef8eaab958f358b6f1adaaa60c1e94f3817e8a57cccd8b988af007fa8a57d
-
Size
507KB
-
MD5
0f9b8c6500c040df8aee110cac74225a
-
SHA1
51892cdff9f9afa873c096e372053f669792bb70
-
SHA256
cf2ef8eaab958f358b6f1adaaa60c1e94f3817e8a57cccd8b988af007fa8a57d
-
SHA512
651a7e9580880ba8ece3d345555f0765ed3ded259d88dd40501ccde326bebc01128c1d3653cda721c7fec3f7091781feb43c7be29ac54d1c1070caae4bd71fa9
-
SSDEEP
12288:KLo2tQgRiP9bu1ircdlgkXfzYJvNrXWoaVS4SZn:ikOiRzQdRuNLWoaVS4S
-
Accesses cryptocurrency files/wallets, possible credential harvesting
-
Checks installed software on the system
Looks up Uninstall key entries in the registry to enumerate software on the system.
-
Suspicious use of SetThreadContext
-