🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 006c3e59e32dc5f56cfa6b911e4e4fc171d681e614f3ec48edf232460814d31f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: 006c3e59e32dc5f56cfa6b911e4e4fc171d681e614f3ec48edf232460814d31f
SHA3-384 hash: ed7201a2928f796edd4b47a12fb5d2a4fb3c1c2d2a3d7815de41a047e5591e458d91b98106d4372cb165d4585379d46e
SHA1 hash: ba46ec010b096b2f3a3220da7a1967dc2bb33bd4
MD5 hash: 6830e8ef2e3abe892f37e7831982b75d
humanhash: william-potato-march-robin
File name:2024__is__Pa$$words.rar
Download: download sample
Signature LummaStealer
File size:3'840'078 bytes
First seen:2024-01-22 18:18:46 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: 2024
ssdeep 49152:geR3WIkiKCfh+ktqtQTG8Talg+Z+MLIhWhauiv36mNww/Cr0rn2D9NBI+xjIRjn2:WIyoqWSny+oM+OauiP//F29owr0WvI+
TLSH T1CB06332401B42056D64372D34A76DC2798A9F13DBC2EE79935E7301C6FE45EFA029ECA
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter Cryptolaemus1
Tags:2024 KjGtqi lumma LummaStealer rar ViaCrackSite WHISKEY

Intelligence


File Origin
# of uploads :
1
# of downloads :
167
Origin country :
US US
File Archive Information

This file archive contains 28 file(s), sorted by their relevance:

File name:api-ms-win-core-synch-l1-2-0.dll
File size:18'384 bytes
SHA256 hash: 9ac63682e03d55a5d18405d336634af080dd0003b565d12a39d6d71aaa989f48
MD5 hash: 659e4febc208545a2e23c0c8b881a30d
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-timezone-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: a108a8f20ded00e742a1f818ef00eb425990b6b24a2bcd060dea4d7f06d3f165
MD5 hash: 69df2cce4528c9e38d04a461ba1f992b
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-profile-l1-1-0.dll
File size:17'360 bytes
SHA256 hash: d00a0edace14715bf79dbd17b715d8a74a2300f0adb1f3fc137edfb7074c9b0a
MD5 hash: 6ee66dca31c5cce57740d677c85b4ce7
MIME type:application/x-dosexec
Signature LummaStealer
File name:AppSetup.exe
File size:457'544 bytes
SHA256 hash: 12c22ba646232d5d5087d0300d5cfd46fed424f26143a02dc866f1bfceab3c10
MD5 hash: 485008b43f0edceba0e0d3ca04bc1c1a
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-process-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 542a22540cdb7df46d957a0208d50507916f7c737bea833931239d56ebe8d68c
MD5 hash: 66f4e530a19ed2f6862b5ce946437875
MIME type:application/x-dosexec
Signature LummaStealer
File name:tradingnetworkingsockets.dll
File size:4'249'928 bytes
SHA256 hash: fc4a65ff603bf1f4bfe323de1866145ae1e006aa656799fd134dfa63d92d47c1
MD5 hash: 3cf26ce759c5e261fe3ecc6451b8b08e
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-private-l1-1-0.dll
File size:70'608 bytes
SHA256 hash: 696c10112d8b86a46e5057cbd0bf40728e79c6bb49cda1f2c67fe45d0fc1258d
MD5 hash: ad8d9a6ea592a6c8a78c67a805cec952
MIME type:application/x-dosexec
Signature LummaStealer
File name:AsIO.dll
File size:123'744 bytes
SHA256 hash: 1db2efa7e75409fddec371b01f0a380e42e563ca278305f4f29cda7ba8906813
MD5 hash: 55f7e5ac1b1f69e76b15266d03607012
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-heap-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 0166edfb23cfc77519c97862a538a69b5d805d6a17d6e235f46927af5c04b3c9
MD5 hash: 9c373c00ac3138233bdf1655c7be8e86
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-util-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 68bd9c086d210eb14e78f00988ba88ceaf9056c8f10746ab024990f8512a2296
MD5 hash: c6553959aecd5bac01c0673cfdf86b68
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-synch-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 8bb38a7a59fbaa792b3d5f34f94580429588c8c592929cbd307afd5579762abc
MD5 hash: 979c67ba244e5328a1a2e588ff748e86
MIME type:application/x-dosexec
Signature LummaStealer
File name:ASUS_WMI.dll
File size:229'848 bytes
SHA256 hash: 6523b44da6fa7078c7795b7705498e487b0625e28e15aec2d270c6e4a909b5a5
MD5 hash: 3f109a02c8d642e8003a1188df40d861
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-math-l1-1-0.dll
File size:27'088 bytes
SHA256 hash: c7115159babdaa1f52e478e67b4e612da2332fda4e4036999b29425fe303b6e8
MD5 hash: bc418a3461c5fdfa1a0d75f7e03d08a7
MIME type:application/x-dosexec
Signature LummaStealer
File name:helve.psd
File size:69'945 bytes
SHA256 hash: 3e1a0c0fcd43deff30ce03f77caa09cf193fc3603c4cff6ace7a7a93c6b88110
MD5 hash: 84686ce3f54b801ec684abe8b22508dc
MIME type:application/octet-stream
Signature LummaStealer
File name:api-ms-win-core-rtlsupport-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: d11093fdc1d5c9213b9b2886ce91db3ded17ef8dae1615a8c7ffbc55b8e3f79b
MD5 hash: 0069fd29263c0dd90314c48bbce852ef
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-filesystem-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 85b1b189ce9e3c6f4d2efdd4cd82b0807f681bea2d28851caaf545990de99000
MD5 hash: 14f407d94c77b1b0039ae2c89b07a2ff
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-conio-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 4aeeae0ac9f6c1b0b8835067ea3b7fc429f353565f18de7858f4ea5d6f72072e
MD5 hash: 7190cbfad2d7773d3b88ccc25533a651
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-processthreads-l1-1-1.dll
File size:18'384 bytes
SHA256 hash: e5ea2c21fb225090f7d0db6c6990d67b1558d8e834e86513bc8ba7a43c4e7b36
MD5 hash: 29001f316ccfc800e2246743df9b15b3
MIME type:application/x-dosexec
Signature LummaStealer
File name:trading_api64.dll
File size:289'568 bytes
SHA256 hash: f1eb582e607a1e43cdb1654bfb7cb29ad46f6728b3fb89a14f7727e0e8daab69
MD5 hash: 2bca4e2c047ec969cb3cff277e7fc184
MIME type:application/x-dosexec
Signature LummaStealer
File name:compost.zip
File size:1'520'006 bytes
SHA256 hash: c99ff7adbd3cf51978d736fc651c40bd2452e722d7d50077ed16358050a00278
MD5 hash: dc13106119f25b0fd0a78ea7c3080dce
MIME type:application/octet-stream
Signature LummaStealer
File name:api-ms-win-core-sysinfo-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 1fe918979f1653d63bb713d4716910d192cd09f50017a6ecb4ce026ed6285df9
MD5 hash: cef4b9f680faae322170b961a3421c5b
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-convert-l1-1-0.dll
File size:21'968 bytes
SHA256 hash: 77b69e829bdc26c7b2474be6b8a2382345b2957e23046897e40992a8157a7ba1
MD5 hash: 3e415147ccd7c712618868bdd7a200cd
MIME type:application/x-dosexec
Signature LummaStealer
File name:ks_tyres.ini
File size:10'077 bytes
SHA256 hash: 894d3c57598ecb22c769cc3ea8219859a95e22740e72394a474012ea2119b3d9
MD5 hash: 47f6571c7884da6c743551ac724186d4
MIME type:text/plain
Signature LummaStealer
File name:ATKEX.dll
File size:86'344 bytes
SHA256 hash: c8b16f1c6883a23021da37d9116a757f971fe919d64ef8f9dba17a7d8dd39adb
MD5 hash: e68562f63265e1a70881446b4b9dc455
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-locale-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: f16447b5fc7fe6fb8a6699a3cef1b2b8ba92d408579bcc272d3dd76acd801e2a
MD5 hash: c5d747f96237b6e9aa85c58745d30c80
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-environment-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: 6c9c0dc7b36afe07dfb07dd373fc757ff25df4793e6384d7a6021471a474f0b9
MD5 hash: ad0cbb9978fcf60d9e9ca45de6a28d30
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-core-string-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 3807db7acf1b40c797e4d4c14a12c3806346ae56b25e205e600be3e635c18d4f
MD5 hash: 2e5c29fc652f432b89a1afe187736c4d
MIME type:application/x-dosexec
Signature LummaStealer
File name:api-ms-win-crt-multibyte-l1-1-0.dll
File size:26'064 bytes
SHA256 hash: c6b4e1d903b3cc83bfaffbe4e82eee634cff8f97f12217caa45b464ddc4e1455
MD5 hash: 9e9c6f83a015029808f5257f7b7e39c6
MIME type:application/x-dosexec
Signature LummaStealer
Vendor Threat Intelligence
Gathering data
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LummaStealer

rar 006c3e59e32dc5f56cfa6b911e4e4fc171d681e614f3ec48edf232460814d31f

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
Cryptolaemus commented on 2024-01-22 18:19:12 UTC

Sandbox: https://tria.ge/240122-ws439scdf4