MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a255b352a2c5b483f7afc34c1000616c250e213a7e16585f491187358352231. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 2


Intelligence 2 IOCs YARA 6 File information Comments

SHA256 hash: 0a255b352a2c5b483f7afc34c1000616c250e213a7e16585f491187358352231
SHA3-384 hash: 90a3b875fd6d9f0ee9a59371d8050278b228bcc320bdf287c2a4f8bd8e01e98b0cb3516d72b7a1a9ed4003d854a87cb7
SHA1 hash: 31096a5675b1d6a749ca54bfc63fd833e2905ef6
MD5 hash: 65cf6f718023fda8fd601a0c1316ff25
humanhash: glucose-helium-sierra-kentucky
File name:Setup.rar
Download: download sample
Signature LummaStealer
File size:98'990'526 bytes
First seen:2025-05-31 18:16:48 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: 2025
ssdeep 1572864:4+QUnwM/D+etA/OMZayrrv7rZK9y++kOVP+GQb3WNdZ857WDCu+wx74:4YqetdNyH7r52OVP+GGeb857Wz5x74
TLSH T1AB28331061F01FCE89D03C62AD68A3EA6DC5A72FC9F62A545ACDAF5C51392270773F12
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter aachum
Tags:file-pumped LummaStealer pw-2025 rar


Avatar
iamaachum
https://www.youtube.com/channel/UC-3vk2JBsdKAwaY4MbYsaGw/community?lb=UgkxKwT0tLUcTG7drxFQZNxaJMdYYiXB1O_K => https://sites.google.com/view/setupinstallerrr => https://drive.google.com/file/d/1ON60eM33UdHim5wA8Qf-Q66WeLudTePa/view

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
ES ES
File Archive Information

This file archive contains 53 file(s), sorted by their relevance:

File name:Accessible.tlb
File size:0 bytes
SHA256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
MD5 hash: d41d8cd98f00b204e9800998ecf8427e
MIME type:inode/x-empty
Signature LummaStealer
File name:fr.pak
File size:326'226 bytes
SHA256 hash: d37509844342371b4026b720dc00f77ff88fe2e7c2b27861e3ca66b10e76ca94
MD5 hash: 75575474726cc8d98def90e0dbddcb0f
MIME type:application/octet-stream
Signature LummaStealer
File name:fi.pak
File size:276'006 bytes
SHA256 hash: cf3b9a857c63022d671f4cc335728c270935628f085ac9a17568a2529daeb4c1
MD5 hash: f55358f58eb17b4bc6abb19592c1aba7
MIME type:application/octet-stream
Signature LummaStealer
File name:inject.dll
File size:157'085 bytes
SHA256 hash: 93af58358d1fb0b3faf592375dc1826caf172544223e8ce2ee4e63a4f6ee46b5
MD5 hash: b9845d2018ad4752641a4de3af749fc6
MIME type:text/plain
Signature LummaStealer
File name:qgenericbearer.dll
File size:89'600 bytes
SHA256 hash: a82aa3b3fe6a8f916c77ab57525de9fb7ab09ac77515b4cd9020903c8fa8b6e6
MD5 hash: 07c9ac52607af53aced1f2f42eeb8a8c
MIME type:application/x-dosexec
Signature LummaStealer
File name:de.pak
File size:300'018 bytes
SHA256 hash: 53d5743a2606d6b553e8dbff871f2f1d3d53666baeb9ecca5b1ed624d48d5835
MD5 hash: 01cc5b8a05a435482dc692baef032d3a
MIME type:application/octet-stream
Signature LummaStealer
File name:ar.pak
File size:453'773 bytes
SHA256 hash: 16782cee5dc883ec83f7b6a1c1dae488e82c97aa5c8924b083fd18c6dbb1247b
MD5 hash: 93209dbb8f1982087fbb73df7256a617
MIME type:application/octet-stream
Signature LummaStealer
File name:libcrypto-1_1.dll
File size:2'515'456 bytes
SHA256 hash: 49b26d14cf68a370de47f8f3724e46e61bff98aba7dd7b8a7c1f87e83bb44064
MD5 hash: c58b2589b88c5da34df20f737b7ac50c
MIME type:application/x-dosexec
Signature LummaStealer
File name:am.pak
File size:431'023 bytes
SHA256 hash: 73f0a7c7632313613814b3ccf5962962aff99de940e084e0b609ecbad1ec1d44
MD5 hash: 2a8ca8692a60fe8d33d51d99c9084a9d
MIME type:application/octet-stream
Signature LummaStealer
File name:Versll.cfg
File size:367'527 bytes
SHA256 hash: e7f0886d4f7b10be6ac1248a13d6b429c70c01e08eb28333f7aef41a1002a9b5
MD5 hash: 1f7ef592d9403065eaa08e788fec465d
MIME type:application/x-dosexec
Signature LummaStealer
File name:qtga.dll
File size:26'624 bytes
SHA256 hash: 011909ad23a9325f4098c91526def0db8d10e3c5207e103526a03491f85f055c
MD5 hash: 1db8885fc3740be018f818cc70f79261
MIME type:application/x-dosexec
Signature LummaStealer
File name:qtmedia_audioengine.dll
File size:67'072 bytes
SHA256 hash: 3dc7273fc6d0240f987d0d605fe357b45dc864a7fd956a498872a20b16327286
MD5 hash: c21b05335a41a27ffa9a030e7b3d9b7d
MIME type:application/x-dosexec
Signature LummaStealer
File name:en-US.pak
File size:248'791 bytes
SHA256 hash: f9e993df87cad724a36be1efb4f5a71322c9de4d0885419e5f13ca564115dce7
MD5 hash: 58a9125a8b155e4b39eb6c3aa0406e1d
MIME type:application/octet-stream
Signature LummaStealer
File name:x32d9.dll
File size:102'516 bytes
SHA256 hash: bf31dd26195b875bb45f91bc4e482eb2b1657b9357846b2ced154f23b713e0e7
MD5 hash: a969c4ddb06f8f7b82c6e1e1f5d38fe1
MIME type:text/plain
Signature LummaStealer
File name:es-419.pak
File size:296'382 bytes
SHA256 hash: 859cb8ad8666e97a47f0e24df4ae85aad80002fbf842b4e68afd0a308d6597fe
MD5 hash: f21b0783d062082ee46aa573eff68df0
MIME type:application/octet-stream
Signature LummaStealer
File name:Quadl.prx
File size:734'674 bytes
SHA256 hash: a3299f08bfd0a55ea5288539a14081906acf35e86f6e3fc0ccc85027d25a3f79
MD5 hash: f92f03586719d2997e3cf9c3d5c86f79
MIME type:application/x-dosexec
Signature LummaStealer
File name:Vsg32.dll
File size:5'219'507 bytes
SHA256 hash: 95f8082fde571e1bbb885fa6b92d67f3bb8fac66337687e9502aa73f6ac37ade
MD5 hash: a049ce8dec55021086e4231f299c470f
MIME type:application/x-ms-pdb
Signature LummaStealer
File name:ini.ini
File size:3'824'621 bytes
SHA256 hash: 2096cacb59cb1bcf9605e4d6897e02007e06f2cf1ace4cda961c0ae2b57fc8aa
MD5 hash: 971543b2412541a890ec173524db2ccf
MIME type:application/octet-stream
Signature LummaStealer
File name:eventlog_provider.dll
File size:15'760 bytes
SHA256 hash: 68b68fd320f077b28a17f6393d8be7cab0728b964779176fbb06af1c5c0489e2
MD5 hash: e33bbf6dc63bcfea39476b3694175ec4
MIME type:application/x-dosexec
Signature LummaStealer
File name:Quadv.dll
File size:560'322 bytes
SHA256 hash: 952dc4888a39c7ae027b323345996ff163af787e71103af323588df74be01f23
MD5 hash: 9591405073c6460e382343c75de477e3
MIME type:text/plain
Signature LummaStealer
File name:da.pak
File size:278'046 bytes
SHA256 hash: 94157ad608b35b29dd176a3106caa4613ed6d4c20268ce00ac4ccf13a9950f94
MD5 hash: 5eba7377be8e34dd03db766300039ed2
MIME type:application/octet-stream
Signature LummaStealer
File name:qsqlmysql.dll
File size:76'288 bytes
SHA256 hash: 634ab70e411dde87de14e5d3207a614d0f6a2f2b7d3e62072c40bddbf3b1412d
MD5 hash: a404568b72465b58b6f73691500abd20
MIME type:application/x-dosexec
Signature LummaStealer
File name:qsqlpsql.dll
File size:84'992 bytes
SHA256 hash: 5f3c4f9e5407ef1fc8b6990efd13be27f82e476fb440dc0fd38f590b694e05d4
MD5 hash: 6ddbdde4adb1d74f117fcbffa8212559
MIME type:application/x-dosexec
Signature LummaStealer
File name:qwbmp.dll
File size:25'600 bytes
SHA256 hash: e0e670dab9294df0804b91bdcb27ee1003954e9a2b110dccb3efe948ffd63bd6
MD5 hash: 1d732c1ec60c5569642590a0eeca146d
MIME type:application/x-dosexec
Signature LummaStealer
File name:et.pak
File size:268'045 bytes
SHA256 hash: ff1b0d50f6f067b291199578b6a7757797bd7fdc6b0ac472c9361076bf9eadaf
MD5 hash: 73e6f20f0c75a9beb72798167f8c6f91
MIME type:application/octet-stream
Signature LummaStealer
File name:x64d3.dll
File size:5'053'315 bytes
SHA256 hash: fea44ec1aa17a4037b5d5b6de901232fedb17e8cebaca5c85aed1a335283b5f8
MD5 hash: b744f5976b64674d00ba08631c4a07f9
MIME type:application/x-ms-pdb
Signature LummaStealer
File name:Xheu.dll
File size:88'370 bytes
SHA256 hash: 5b8835142581306c013b00c1989263e4db3f2f9940755d0a178af443393219c4
MD5 hash: e20f47fc6b9c5223478b583a73e58544
MIME type:text/plain
Signature LummaStealer
File name:libEGL.dll
File size:339'456 bytes
SHA256 hash: d5c60cd8f183698194cd224657fc3a916200adaecf4afec0dbe1f3f4168d2456
MD5 hash: d5a1d8edd220546bb28966947603c0ce
MIME type:application/x-dosexec
Signature LummaStealer
File name:ca.pak
File size:301'716 bytes
SHA256 hash: 4d583b753104ae98a1e5858bfe38dfa3195d477128441ca59c882d158d52ebf8
MD5 hash: a2c61a98fe7407ded9ece126c4c9d057
MIME type:application/octet-stream
Signature LummaStealer
File name:Xeog.ini
File size:1'469'348 bytes
SHA256 hash: bb8d508aa0e6ff6f33d28156abff10579c82e152c081245a78e0046e3ec2fc0d
MD5 hash: e2eaaa343d56c238b6dbbbf034f6d866
MIME type:application/x-dosexec
Signature LummaStealer
File name:qsvg.dll
File size:27'648 bytes
SHA256 hash: f16b98631008a93804a2c7454591cd3ce771ce14a2d4746038173b63e65c7c8b
MD5 hash: 5b12172e7a77025c147b43902993bef6
MIME type:application/x-dosexec
Signature LummaStealer
File name:qtwebengine_resources.pak
File size:2'284'161 bytes
SHA256 hash: 5f96bb8b73792ccab961dc06b1190ff2d7aa65e24bbccd806fffca24140cbe9c
MD5 hash: 14f2f9bd381fb1e1e903304af053137d
MIME type:application/octet-stream
Signature LummaStealer
File name:qico.dll
File size:35'840 bytes
SHA256 hash: 47812f285c6fa9114f4a25fb4747a4e48259c4869974dc59bc72981312fee25b
MD5 hash: a58534a6abee4634fde27d26a85ac9e2
MIME type:application/x-dosexec
Signature LummaStealer
File name:libGLESv2.dll
File size:2'438'656 bytes
SHA256 hash: 70cf3c6ed01b79764d4cbea68abbf3118c768eb766f764f614655fa9aa22ae66
MD5 hash: 23b8f6b1f7c2b3259553b146fb595c22
MIME type:application/x-dosexec
Signature LummaStealer
File name:d3dcompiler_47.dll
File size:3'466'856 bytes
SHA256 hash: efbdbbcd0d954f8fdc53467de5d89ad525e4e4a9cfff8a15d07c6fdb350c407f
MD5 hash: c5b362bce86bb0ad3149c4540201331d
MIME type:application/x-dosexec
Signature LummaStealer
File name:qgif.dll
File size:33'792 bytes
SHA256 hash: 8a819bf076b5e4106ab96fa02e78c9e2cd6007d73e8b882e405690dec5b907b1
MD5 hash: 59d7b9c41393ca7cc760abb34f68c2dc
MIME type:application/x-dosexec
Signature LummaStealer
File name:el.pak
File size:535'129 bytes
SHA256 hash: 4c2a3552e84fdd08852073d25c99727c4270160260d159572715c7d37e5861bc
MD5 hash: 26afc001a706679413f5deaa3c6603e4
MIME type:application/octet-stream
Signature LummaStealer
File name:qtwebengine_devtools_resources.pak
File size:1'594'999 bytes
SHA256 hash: 610293990ef7c0fb9af0b69937e17f4927e109b3b9090eb5afd15c5a435705d8
MD5 hash: 1918e7f7f72bbf6131a72eac21022852
MIME type:application/octet-stream
Signature LummaStealer
File name:version.dll
File size:188'160 bytes
SHA256 hash: bb83eb8a0ae75c425f6ec72af554e5f8158eb4ffa0a898e26b564fc0217c8ae5
MD5 hash: 6d7f976b644410f6251697469e25af61
MIME type:text/plain
Signature LummaStealer
File name:te.pak
File size:673'905 bytes
SHA256 hash: ee2697e8850803f08bee80e461833bd9f4232532c3f569f56521b1320c99e5e2
MD5 hash: 079fbd6adf806504199dd0b05c87c697
MIME type:application/octet-stream
Signature LummaStealer
File name:ru.pak
File size:489'334 bytes
SHA256 hash: b81a0b0175225dbdf35150dcc0c36154cfc042c1525df216d68034f0ae609057
MD5 hash: 3d28ef9e25426b08409db5379cfd55e3
MIME type:application/octet-stream
Signature LummaStealer
File name:libGLEv2.dll
File size:7'111'378 bytes
SHA256 hash: 2082c51a86bc8b7cd5e69cf5d43914efe5d939c90503539d657fde7915a95ae1
MD5 hash: 90ad3c47740fce98015444d1289af9b9
MIME type:application/octet-stream
Signature LummaStealer
File name:fa.pak
File size:432'426 bytes
SHA256 hash: b4e0d3f7cb858ce12b5a75a71ef14f2a36494cd4138181b29f6fb3d6bd386c4c
MD5 hash: f913ea1db8c9c99bff701ceeaf8138f3
MIME type:application/octet-stream
Signature LummaStealer
File name:dsengine.dll
File size:403'968 bytes
SHA256 hash: f99e42bdf4ec929c76fd54574cec5c81e4fd5f48e2c5673afc69cec3830527b9
MD5 hash: 9b2390bae2b8d5955707ef45624ba546
MIME type:application/x-dosexec
Signature LummaStealer
File name:cfg.dll
File size:5'206'379 bytes
SHA256 hash: 2b529e8afa002053744bb4e2430513e7745f91b5052446ef2d0568e91d5b1280
MD5 hash: 7bfe885d87026d0d41dba5fb4173201c
MIME type:application/x-ms-pdb
Signature LummaStealer
File name:aah32.dll
File size:564'480 bytes
SHA256 hash: 68810e83425efae5727d3ccf2aa0fcf82f571cd756c48c89869a55d952936bf6
MD5 hash: b0739745e782946a0dae3c0026e24d32
MIME type:text/plain
Signature LummaStealer
File name:icudtl.dat
File size:10'505'952 bytes
SHA256 hash: 594637e10b8f5c97157413528f0cbf5bc65b4ab9e79f5fa34fe268092655ec57
MD5 hash: 3f019441588332ac8b79a3a3901a5449
MIME type:application/octet-stream
Signature LummaStealer
File name:qicns.dll
File size:46'080 bytes
SHA256 hash: c020ceee7c397b59ecd9419e46f2144c1243387ce097fa89b4d0ed67c9cc818b
MD5 hash: d05a6ab50a7d4471fcce902dcd32ce6a
MIME type:application/x-dosexec
Signature LummaStealer
File name:ro.pak
File size:304'171 bytes
SHA256 hash: ac3134a201073f6482a4cceb29a745104325ac76b7ad0d262ac7567584f450a1
MD5 hash: 14ee5c1a362e753a5c44b11343430fdb
MIME type:application/octet-stream
Signature LummaStealer
File name:qsqlodbc.dll
File size:100'864 bytes
SHA256 hash: 1a180319f7719dea47b033fdde38f642041a0e84280595a7e53ce87a2653bc48
MD5 hash: b0b9263aada0e1d13d019c2c77238034
MIME type:application/x-dosexec
Signature LummaStealer
File name:qjpeg.dll
File size:330'752 bytes
SHA256 hash: dede0ec14d4fd310f9aed0a81ff36063099915a093e6729d878da3cbbbc7a54b
MD5 hash: ea85b6bfc6f6bf1c9ae2f14a03cb7503
MIME type:application/x-dosexec
Signature LummaStealer
File name:qsqlite.dll
File size:1'027'072 bytes
SHA256 hash: 61f2d69173b63b1341c91b709d48ad4ae0b21f38fdce93e11dd670ba5c257a97
MD5 hash: e98ba766bb736a59f9e59faa8c5dc542
MIME type:application/x-dosexec
Signature LummaStealer
File name:Setup.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:225'012'224 bytes
SHA256 hash: fe512723bbd382d1711876be791a868e7c4a914da997a612770203d0954a91b6
MD5 hash: 0a46bfc4d2b57e06de479d7296cc70a6
De-pumped file size:1'665'536 bytes (Vs. original size of 225'012'224 bytes)
De-pumped SHA256 hash: b2a18311c4d0ff420978ce61a0e098013b9dd614c5c528c284c8cfb760774ac7
De-pumped MD5 hash: 13467e34adb31d60165864883a887034
MIME type:application/x-dosexec
Signature LummaStealer
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HUNTING_SUSP_TLS_SECTION
Author:chaosphere
Description:Detect PE files with .tls section that can be used for anti-debugging
Reference:Practical Malware Analysis - Chapter 16
Rule name:pe_detect_tls_callbacks
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LummaStealer

rar 0a255b352a2c5b483f7afc34c1000616c250e213a7e16585f491187358352231

(this sample)

Comments