General

  • Target

    e1fe2761d7bcfe273cc2787e5810450b67140a851796987574f9fbee8907dcad.zip

  • Size

    18.2MB

  • Sample

    240704-cjsjbsyepm

  • MD5

    5d5dd0102521e3a7fb991382594875c9

  • SHA1

    4e095553f113cbe648572e93f2caedb8d1e4d47b

  • SHA256

    e1fe2761d7bcfe273cc2787e5810450b67140a851796987574f9fbee8907dcad

  • SHA512

    42bc77dd4970995ca8d5c1cb4d2f4bb1fba6cb4361e9a15b14cbdde1b6e44aa1722276d5d1b8a54174b367e388010dbb282f694ab171a8690bd44e37755ea8c1

  • SSDEEP

    393216:fsRsgaYRGU22AVqUjHi3qVJ3RPo28BiyK1LrFQND/iA0uLYv7X3xaQwkjR/xiRJ:fsKBYRGOTU+g3RWBm+9iPdaojziH

Score
10/10

Malware Config

Extracted

Family

lumma

C2

https://bouncedgowp.shop/api

https://bannngwko.shop/api

https://bargainnykwo.shop/api

https://affecthorsedpo.shop/api

https://radiationnopp.shop/api

https://answerrsdo.shop/api

https://publicitttyps.shop/api

https://benchillppwo.shop/api

https://reinforcedirectorywd.shop/api

Targets

    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/SdAppServices_x64.dll

    • Size

      1.3MB

    • MD5

      117e96e2f16d083771c9b99dc7a3ee72

    • SHA1

      971af08e2ba30da9c3c98293d1b42e274eff974c

    • SHA256

      729a12cd14151ddc0c5f7c95a2225547d6b27ff3718980405306550a0cb7a6aa

    • SHA512

      3e793d3ba6897c6a030a532f2a5d906acdd8d514466b69772b1582b576a3588eda2fcd06883a46a14916bc2d4f677c8308f4016e6dea06163a642cb5c53a5905

    • SSDEEP

      24576:E1FCKisuEMfumVLFMnGC786aQkh4lZ181gkOrPdIdXn:MCRsuOsunGC7cXIZWQrPdUXn

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/Setup.exe

    • Size

      4.3MB

    • MD5

      4cba82135c6e44265dfb2a4845dff950

    • SHA1

      7dbce4c16cbd045ce8a3c2ea15df7fee3df10bcc

    • SHA256

      e6d5ef67201ef8ed953a36a6fb44aaafb40dec7a4002efb7ebe6c20f35244495

    • SHA512

      81441841a5fb6fc9507407ea9f07c16d98a1a3ca7c5eb4dabe92cc6fb93f0641ac681906dabf7aedab32a3cb6289cc2922e03bb33210eac72170797e82df60cc

    • SSDEEP

      49152:w8mxtRio/dXZg+KXXI7QKS/++2+UEaipCiPdCQIhdwIxKoZqD6uoZqUO3HoaPgoR:M92/++2+/pDNB3HokjGbc

    Score
    10/10
    • Lumma Stealer

      An infostealer written in C++ first seen in August 2022.

    • Loads dropped DLL

    • Suspicious use of SetThreadContext

    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/libvlc.dll

    • Size

      172KB

    • MD5

      96214b94b796bffc48d63289854ae5a2

    • SHA1

      383bde4b3a861d47794aa4f03479a48c10a644dd

    • SHA256

      528c416cfb4813ee5f1da52743ef4adb20043171230098b27e25d1dd90e3f288

    • SHA512

      5243dd7153793ae33c3a25f2a92579c4e31813545680de9a0abab36e61d42655db4796a6f47606b47d6dce0d3f47754fd29fbfd18b973b029df0c543915750f3

    • SSDEEP

      3072:mZ6EqHx7iXIb/WmRJKn9llPMBq4tNyupwPU0sG0:mZ6E+x7iYiiMn9llP8q4tNyuusc0

    Score
    3/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/libvlccore.dll

    • Size

      2.6MB

    • MD5

      e25413bb41c2f239ffdd3569f76e74b0

    • SHA1

      073e2a86c5c24ede4c4ad2d8614261121a8d2661

    • SHA256

      9126d9abf91585456000fffd9336478e91b9ea07ed2a25806a4e2e0437f96d29

    • SHA512

      37b8339555dcf825a2e27464eb1d101f8e4b56460d1b78161e99ba6761f1a967668f11ba888a712c878d468f419a455dbc5e8e55e7fb9d4fbc87cb78f500ea9f

    • SSDEEP

      49152:hDWA3C12sNU/wEz2tMEjv9DZWtxfc1lVG3QNVBAUZLYasUpGaXBuQQ9umM:t3O2wEz2tMEj1lWtOrVG3QNVBAUZLX/

    Score
    3/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/lua/chrome_[1MB]_[1].exe

    • Size

      1.9MB

    • MD5

      068cf70414b79cd8bc078497553389ed

    • SHA1

      d9778170404ad0435ab82ebba3fb5515831dd17e

    • SHA256

      c532ffa77b220ac54083dffb2286c526c2873131448e3a37fe29dbee6aa028b4

    • SHA512

      89b69a9c53530605573d7816eb625840404251e9407fa6041492fa5ad21bfe21206f2fa5bb21f4b85017c5a39daabe13f51c615f54ce08fffaeeb5556bdb45ad

    • SSDEEP

      49152:9b8W92V8WpGaPIgI0GW5VuwHDoTZyMB0q7ug52I8:mW08WpNPLGY4wHDoTZyMjSF

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/access/libfilesystem_plugin.dll

    • Size

      59KB

    • MD5

      8fac15d2a2da66abdf345afa45ac5e3b

    • SHA1

      553d4c9f39726d8aadb15fed7c904048928049e0

    • SHA256

      66ef741a9282b420b09b940fbdbf666cd1625a8da18daaece036fcc4e1a74d38

    • SHA512

      f756e3b3368245d4670cf0f86a6727858e3ead983b3e10c11d9b13e67d86b632703f44df70e648bb8edcad295744c763a268f4eb02ace0055405c3e9af124548

    • SSDEEP

      768:D2y9ohNIged8Yy0NBdeOWxRPxYoWE487KcxN5ZEUUaDGFheDGFhW:D2yyhkKYloRPuEUcxHZEUUe

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/access/libimem_plugin.dll

    • Size

      30KB

    • MD5

      b0770c82314e94afd0d793774d66290b

    • SHA1

      79b280cda1ca944478ebad7778f642d415de523a

    • SHA256

      a5c2f2030e2cb70837d35e434d9793cafa04132e1823430ebcfbd4d985899637

    • SHA512

      21f4780a6da31c84fbc0fe117eef11cbd796d837b7fa38ec8c5e025c8b318f0b925775a7dec1e909ee14da77d800a01115758e803ddeb605e1da0ccbff047133

    • SSDEEP

      384:hfMDy/41Zo4M+7IXo8LPA2W9oPuyrPjvDGjoe0ghavDGjoe0ghs/:hb41m4t78xL439onDGFhMDGFhe

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/audio_output/libdirectsound_plugin.dll

    • Size

      51KB

    • MD5

      077990f957556e8a72a37f0ee09a2083

    • SHA1

      371908e5515adb53a57f8d2bda47d59a7346fc1b

    • SHA256

      412f9ec13da17b2f2269567b8397b587352070ce77a641ae40b7a243e26c57ef

    • SHA512

      420d536532ccd474176e2ad2421e655708e0835faa1a60f9b2a70f8a54fdd8d787567c30f478639a367d913b5b34e4e0a81c1c38d95d14351affb25abc536770

    • SSDEEP

      768:htDcW2X9vjCOdZLae3hhwoOzHtdvQEarpDGFhcs3yDGFhed4:ht+X9vj/tJOYrVs1

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/audio_output/libwasapi_plugin.dll

    • Size

      50KB

    • MD5

      d217e0144d8d9237d284a38f9c3e6340

    • SHA1

      fdf9f0edeecb0759fd8b502cd5314511e60f6347

    • SHA256

      94eb16ffd5526836c715d0a1eedada03f0a1061920cbfd44fd4daee3dfabd1af

    • SHA512

      22f7b1b05035011b95f3bf3f1ce4aeb43f8baaa8dde2f2d565dfbf83a9b0a00adaae9c941cd5a2ad4633444d9fe1410accb97a1dd16396afbe84679758738227

    • SSDEEP

      768:Ldd4RCuijvRJQ3liXsC0Fdk/1dLNR7cDGFhGDGFhtN:LHrQ3M4k3LbN

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/codec/libavcodec_plugin.dll

    • Size

      15.0MB

    • MD5

      fad5798d2177993c88072f28581750e9

    • SHA1

      029bb1a51e948f649ed8af73bb54b99493b7e233

    • SHA256

      ab10e941252965e338b8b9351902c8eec98c71fa23dd431769a732ca109b5f22

    • SHA512

      def4e1de52122ed8826b46f00067bbd3420e2591bb854310aad05e2e4f01923dec5400ad242ce3e3a71ae344794688ebb084fa534ba50f946f2e6ad0d0649161

    • SSDEEP

      196608:mYci4iRQRGBBYqB0z6PLSEdEHq0BU4N22VrBnq6WT93f7xvMLbBZ4OflOfB62wss:pcK0BUj2VrX6wjA0/bsfXWpjf

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/codec/libd3d11va_plugin.dll

    • Size

      267KB

    • MD5

      1137f05e3030ce4031dfa68731650f25

    • SHA1

      c1e78b9ad6c834d71b0f42ca0f4932f37b7b1579

    • SHA256

      c5cea8862585850e651cbcc5883c70ce7d54e1871b53905b210b55ed9bc1fab1

    • SHA512

      7b03d88f75a30cea02c766741550fb781f7a9a9472145558989e90cb8294f58d7104c79f94f2775fdb90edd38580d189816e63e56aa7c5f022e85d8bcab20a2c

    • SSDEEP

      3072:66Auodqwn3PeCVFB5D9vQh9elVlUfJ36XkGF16EuEt75P7gKwO:6puodqe3RH5pvQHelVlJk81rZt1zgKT

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/video_output/libdirect3d11_plugin.dll

    • Size

      327KB

    • MD5

      267237343345265fe20a9688bd840de2

    • SHA1

      99fee276074a4671e2b5ccceeaf71ec951df45e5

    • SHA256

      0732c8978869bcbf11fa63f8cfbb5d6c75dfd8d34d176cae2dac99a261bcf2dd

    • SHA512

      e354a8c0ec8c32792b6c356dc519d41319684ea2d20d18b61e19eeb8133a049db93ac6845e9ca7978f2933be9bf37eb3f608b81277dc14e3d7d240b206392196

    • SSDEEP

      6144:bNQ3sPH66UG6wIt1YfZlfALhmUvzOFiFvxUg/G:bNQcPSt+fZlYLhmUvzOFgG

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/video_output/libdirect3d9_plugin.dll

    • Size

      250KB

    • MD5

      f910aee501d6fe100096dcdf9bd4b525

    • SHA1

      c3aaf9ce5643695822cfa6935eefd4e39eaf3d14

    • SHA256

      77a79184b2c81da3b98d501632fc8e5c8af6d078dd29414ae693906f51c343aa

    • SHA512

      05fc6297fb44ef9e60cb975d941d98dd7bea9fbfea1e48723168725a887b1e1e8e00f97d8a5faf419039ee791c2f14404db61e65b40c767e17a1dcc2f6f84940

    • SSDEEP

      3072:9qmAgP5gT5jgwWmy3A66o3VgKtbYD+7xwy7SeHZOP8ATA5j7EfCUgTRXMPba8:Ym3BQj66o3VgKtb8kS6Oxy0CUgTRXMe8

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/video_output/libdrawable_plugin.dll

    • Size

      30KB

    • MD5

      defb6d6c7bfbddafd3d48d47a69d47a8

    • SHA1

      787c35fa991694f54834d007c13646a219ba43e4

    • SHA256

      aa8cdd685be3ffecb848dd4264061536d562b784c473c3ad1abc1fc3527ac1f5

    • SHA512

      2284fdaec89b819b695db72c493f59b11d60eeab24450c500b0972ee097eae0e51578c0a3044ed100c8ea29e389e46183400ab17140407eebb86a418e04b005f

    • SSDEEP

      384:8SvFL5cokCvUip8Jp8kryYR5dhXveLvDGjoe0ghhH4vDGjoe0ghb:8G7bUHk4p5oDGFhUDGFhb

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/plugins/video_output/libvmem_plugin.dll

    • Size

      33KB

    • MD5

      30afe05b0f7f8dbcb10fb9533b189754

    • SHA1

      e92e194b6c0b9b3abdf16f2d6a80081e61f3af65

    • SHA256

      2062d5c42d295e8f01cf0d1c8402460597f1e2b9ba9f86cdad22014364a92782

    • SHA512

      1ac4386671dd47fc9826b718b345295ae2b1a35a1198f4a0d9c0003a3983940df118e440ae9b02e7ff1d821e38eedbdfe1650d6dd02ef39da4c08ace4b17d634

    • SSDEEP

      384:rS+8eWncmzOg/q+cdo93eCbtl8eI6EV2cHNpux+50zvDGjoe0ghK7vDGjoe0ghf:J8eW1dlXOejcHNv5yDGFhKLDGFhf

    Score
    1/10
    • Target

      !!!#SetUp_22334_Pa$sW0rd$$/vcruntime140.dll

    • Size

      94KB

    • MD5

      11d9ac94e8cb17bd23dea89f8e757f18

    • SHA1

      d4fb80a512486821ad320c4fd67abcae63005158

    • SHA256

      e1d6f78a72836ea120bd27a33ae89cbdc3f3ca7d9d0231aaa3aac91996d2fa4e

    • SHA512

      aa6afd6bea27f554e3646152d8c4f96f7bcaaa4933f8b7c04346e410f93f23cfa6d29362fd5d51ccbb8b6223e094cd89e351f072ad0517553703f5bf9de28778

    • SSDEEP

      1536:yDHLG4SsAzAvadZw+1Hcx8uIYNUzUnHg4becbK/zJrCT:yDrfZ+jPYNznHg4becbK/Fr

    Score
    1/10

MITRE ATT&CK Matrix

Tasks