๐Ÿคฒ๐Ÿผ NEW | abuse.ch Community Hub! Earn recognition ๐Ÿ… for the malware intelligence you share, climb the leaderboards ๐Ÿ“ˆ, and connect with like-minded contributors who share your hunting focus ๐Ÿค. Ready to unlock your profile? Go to the Community Hub โ†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 000abc24d378fefbbee9e4466a200f4088e63c941bb7ecba18af54d6e23fecfa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 4


Intelligence 4 IOCs YARA 55 File information Comments

SHA256 hash: 000abc24d378fefbbee9e4466a200f4088e63c941bb7ecba18af54d6e23fecfa
SHA3-384 hash: fa1d5f32619c7b257d0d8178ed8e84d84de7d4c8423e3bebdb2194f9444d7e670dc735f66b1b732bb56e9aceea6a5b8c
SHA1 hash: 02642e3420c81693bd712fe3244e5e662640d176
MD5 hash: 4324432c547b9d272033e7b4483b0bb3
humanhash: eighteen-virginia-eighteen-zebra
File name:WlIOIjPU.zip
Download: download sample
Signature LummaStealer
File size:40'305'948 bytes
First seen:2024-11-22 20:36:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 786432:K6gNbvIgQlCdY+rSb074YJ3jJoyzJ0Op0Btz6KjvJQR8afCcHI80:K6gNbvI5QdY+17dV2OqBZ6Uh3a6ck
TLSH T12A9733DE76C16CAC5E7F0255C9079F0DAE1BA24FCC48094A4DA927722DC37DE392CA19
TrID 66.6% (.FB2K-COMPONENT) foobar2000 component (8000/1/2)
33.3% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter ramirezrick2
Tags:lumma LummaStealer zip


Avatar
ramirezrick2
https://tria.ge/241122-y3jw7axrgs/behavioral1

Intelligence


File Origin
# of uploads :
1
# of downloads :
135
Origin country :
US US
File Archive Information

This file archive contains 38 file(s), sorted by their relevance:

File name:QtGui4.dll
File size:8'581'632 bytes
SHA256 hash: d2c8c8b6cc783e4c00a5ef3365457d776dfc1205a346b676915e39d434f5a52d
MD5 hash: 831ba3a8c9d9916bdf82e07a3e8338cc
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-synch-l1-2-0.dll
File size:18'384 bytes
SHA256 hash: 9ac63682e03d55a5d18405d336634af080dd0003b565d12a39d6d71aaa989f48
MD5 hash: 659e4febc208545a2e23c0c8b881a30d
MIME type:application/x-dosexec
Signature LummaStealer
File name:Set-up.exe
File size:6'487'736 bytes
SHA256 hash: 421e36788bfcb4433178c657d49aa711446b3a783f7697a4d7d402a503c1f273
MD5 hash: 11c8962675b6d535c018a63be0821e4c
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-timezone-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: a108a8f20ded00e742a1f818ef00eb425990b6b24a2bcd060dea4d7f06d3f165
MD5 hash: 69df2cce4528c9e38d04a461ba1f992b
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-profile-l1-1-0.dll
File size:17'360 bytes
SHA256 hash: d00a0edace14715bf79dbd17b715d8a74a2300f0adb1f3fc137edfb7074c9b0a
MD5 hash: 6ee66dca31c5cce57740d677c85b4ce7
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-process-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 542a22540cdb7df46d957a0208d50507916f7c737bea833931239d56ebe8d68c
MD5 hash: 66f4e530a19ed2f6862b5ce946437875
MIME type:application/x-dosexec
Signature LummaStealer
File name:nmprwjs
File size:806'258 bytes
SHA256 hash: 4ec0eef7ce80b0181dbf5d946c7a2d40067b9bf89292b27f7496482e2f7a80a1
MD5 hash: 7ab8ef9419f402c83e0cd0346d9a1a67
MIME type:application/octet-stream
Signature LummaStealer
File name:QtCore4.dll
File size:2'598'912 bytes
SHA256 hash: 94c1395153d7758900979351e633ab68d22ae9b306ef8e253b712a1aab54c805
MD5 hash: fecc62a37d37d9759e6b02041728aa23
MIME type:application/x-dosexec
Signature LummaStealer
File name:tradingnetworkingsockets.dll
File size:4'249'928 bytes
SHA256 hash: fc4a65ff603bf1f4bfe323de1866145ae1e006aa656799fd134dfa63d92d47c1
MD5 hash: 3cf26ce759c5e261fe3ecc6451b8b08e
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-private-l1-1-0.dll
File size:70'608 bytes
SHA256 hash: 696c10112d8b86a46e5057cbd0bf40728e79c6bb49cda1f2c67fe45d0fc1258d
MD5 hash: ad8d9a6ea592a6c8a78c67a805cec952
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-heap-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 0166edfb23cfc77519c97862a538a69b5d805d6a17d6e235f46927af5c04b3c9
MD5 hash: 9c373c00ac3138233bdf1655c7be8e86
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-util-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 68bd9c086d210eb14e78f00988ba88ceaf9056c8f10746ab024990f8512a2296
MD5 hash: c6553959aecd5bac01c0673cfdf86b68
MIME type:application/x-dosexec
Signature LummaStealer
File name:opengl64.dll
File size:18'578'896 bytes
SHA256 hash: dd575f3c64382193610815909bd2c52490244ecbbb9bba6eef5fe4f0bb43bb4d
MD5 hash: 0a84667145e7efef026c888d4b768126
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-synch-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 8bb38a7a59fbaa792b3d5f34f94580429588c8c592929cbd307afd5579762abc
MD5 hash: 979c67ba244e5328a1a2e588ff748e86
MIME type:application/x-dosexec
Signature LummaStealer
File name:nvptxJitCompiler32.dll
File size:17'375'864 bytes
SHA256 hash: caa6ae6c505e54875761443171c229ed367b2e51e448a9034b81be062b961847
MD5 hash: 3ea5205d6831ddc3670ab8eeacb853f5
MIME type:application/x-dosexec
Signature LummaStealer
File name:QtNetwork4.dll
File size:1'053'696 bytes
SHA256 hash: 52ae07d1d6a467283055a3512d655b6a43a42767024e57279784701206d97003
MD5 hash: 8a2e025fd3ddd56c8e4f63416e46e2ec
MIME type:application/x-dosexec
Signature LummaStealer
File name:AbRoot.dll
File size:364'496 bytes
SHA256 hash: 9fbeab4bcfcec34dc13cad90609101b2ea099069ab173555635f174597e4ea09
MD5 hash: 530957a391c6bc978ae7179179594b12
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-math-l1-1-0.dll
File size:27'088 bytes
SHA256 hash: c7115159babdaa1f52e478e67b4e612da2332fda4e4036999b29425fe303b6e8
MD5 hash: bc418a3461c5fdfa1a0d75f7e03d08a7
MIME type:application/x-dosexec
Signature LummaStealer
File name:nvdisps.dll
File size:11'656'736 bytes
SHA256 hash: 77173b4b61b59eca507ca3ece87a77a87e4e77a48dd162ba813d61cb0513421d
MD5 hash: da3e5ecda1487fdbcc6d7db314815696
MIME type:application/x-dosexec
Signature LummaStealer
File name:StarBurn.dll
File size:664'064 bytes
SHA256 hash: 39f8082f72067be64270647f899919582438a0c7461c439174767b139406abd8
MD5 hash: bbf0b66f271322a7c5701d5488d6a6dd
MIME type:application/x-dosexec
Signature LummaStealer
File name:msvcr100.dll
File size:770'384 bytes
SHA256 hash: 1221a09484964a6f38af5e34ee292b9afefccb3dc6e55435fd3aaf7c235d9067
MD5 hash: 67ec459e42d3081dd8fd34356f7cafc1
MIME type:application/x-dosexec
Signature LummaStealer
File name:QtXml4.dll
File size:356'352 bytes
SHA256 hash: c9b2a31bfe75d1b25efcc44e1df773ab62d6d5c85ec5d0bc2dfe64129f8eab5e
MD5 hash: e9a9411d6f4c71095c996a406c56129d
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-rtlsupport-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: d11093fdc1d5c9213b9b2886ce91db3ded17ef8dae1615a8c7ffbc55b8e3f79b
MD5 hash: 0069fd29263c0dd90314c48bbce852ef
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-filesystem-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 85b1b189ce9e3c6f4d2efdd4cd82b0807f681bea2d28851caaf545990de99000
MD5 hash: 14f407d94c77b1b0039ae2c89b07a2ff
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-conio-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 4aeeae0ac9f6c1b0b8835067ea3b7fc429f353565f18de7858f4ea5d6f72072e
MD5 hash: 7190cbfad2d7773d3b88ccc25533a651
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-processthreads-l1-1-1.dll
File size:18'384 bytes
SHA256 hash: e5ea2c21fb225090f7d0db6c6990d67b1558d8e834e86513bc8ba7a43c4e7b36
MD5 hash: 29001f316ccfc800e2246743df9b15b3
MIME type:application/x-dosexec
Signature LummaStealer
File name:trading_api64.dll
File size:289'568 bytes
SHA256 hash: f1eb582e607a1e43cdb1654bfb7cb29ad46f6728b3fb89a14f7727e0e8daab69
MD5 hash: 2bca4e2c047ec969cb3cff277e7fc184
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-sysinfo-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 1fe918979f1653d63bb713d4716910d192cd09f50017a6ecb4ce026ed6285df9
MD5 hash: cef4b9f680faae322170b961a3421c5b
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-convert-l1-1-0.dll
File size:21'968 bytes
SHA256 hash: 77b69e829bdc26c7b2474be6b8a2382345b2957e23046897e40992a8157a7ba1
MD5 hash: 3e415147ccd7c712618868bdd7a200cd
MIME type:application/x-dosexec
Signature LummaStealer
File name:msvcp100.dll
File size:421'200 bytes
SHA256 hash: a3ba6421991241bea9c8334b62c3088f8f131ab906c3cc52113945d05016a35f
MD5 hash: 03e9314004f504a14a61c3d364b62f66
MIME type:application/x-dosexec
Signature LummaStealer
File name:2
File size:346 bytes
SHA256 hash: 49a60be4b95b6d30da355a0c124af82b35000bce8f24f957d1c09ead47544a1e
MD5 hash: 24d3b502e1846356b0263f945ddd5529
MIME type:text/plain
Signature LummaStealer
File name:ks_tyres.ini
File size:10'077 bytes
SHA256 hash: 894d3c57598ecb22c769cc3ea8219859a95e22740e72394a474012ea2119b3d9
MD5 hash: 47f6571c7884da6c743551ac724186d4
MIME type:text/plain
Signature LummaStealer
File name:api-ms-win-crt-locale-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: f16447b5fc7fe6fb8a6699a3cef1b2b8ba92d408579bcc272d3dd76acd801e2a
MD5 hash: c5d747f96237b6e9aa85c58745d30c80
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-environment-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: 6c9c0dc7b36afe07dfb07dd373fc757ff25df4793e6384d7a6021471a474f0b9
MD5 hash: ad0cbb9978fcf60d9e9ca45de6a28d30
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-string-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 3807db7acf1b40c797e4d4c14a12c3806346ae56b25e205e600be3e635c18d4f
MD5 hash: 2e5c29fc652f432b89a1afe187736c4d
MIME type:application/x-dosexec
Signature LummaStealer
File name:ovaw
File size:23'929 bytes
SHA256 hash: 2c373d4495aa2e52a9f27039998bb42f3a5139929ec8d8e8963c30d3f558cc57
MD5 hash: 90284f3d3121827201d9233a4d7cd97d
MIME type:application/octet-stream
Signature LummaStealer
File name:nvdispsr.dll
File size:11'575'304 bytes
SHA256 hash: 0681d4e92b84d238b3e3fb118b0a359be1aba83528b94f7fde2d9101d8163417
MD5 hash: d74d7dca89d97bc912a376a5c34172b1
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-multibyte-l1-1-0.dll
File size:26'064 bytes
SHA256 hash: c6b4e1d903b3cc83bfaffbe4e82eee634cff8f97f12217caa45b464ddc4e1455
MD5 hash: 9e9c6f83a015029808f5257f7b7e39c6
MIME type:application/x-dosexec
Signature LummaStealer
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Check_OutputDebugStringA_iat
Rule name:CHM_File_Executes_JS_Via_PowerShell
Author:daniyyell
Description:Detects a Microsoft Compiled HTML Help (CHM) file that executes embedded JavaScript to launch a messagebox via PowerShell
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercรชs
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Glasses
Author:Seth Hardy
Description:Glasses family
Rule name:GlassesCode
Author:Seth Hardy
Description:Glasses code features
Rule name:golang
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:RansomPyShield_Antiransomware
Author:XiAnzheng
Description:Check for Suspicious String and Import combination that Ransomware mostly abuse(can create FP)
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:RSharedStrings
Author:Katie Kleemola
Description:identifiers for remote and gmremote
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LummaStealer

zip 000abc24d378fefbbee9e4466a200f4088e63c941bb7ecba18af54d6e23fecfa

(this sample)

  
Dropping
Lumma
  
Delivery method
Distributed via web download

Comments