MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1733c1d12e4b799ac0165a933b3bbf246ad078883be359749510b44d2eb775cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 10


Intelligence 10 IOCs YARA 1 File information Comments

SHA256 hash: 1733c1d12e4b799ac0165a933b3bbf246ad078883be359749510b44d2eb775cb
SHA3-384 hash: 8fd9958bf31f3932878ff4f9cbd07bd7756e7528b5ee2f581968f0c2176b563900157b95d5c1e6f57ebe3541e92e6761
SHA1 hash: f40cc66dc9271564311e8d904d713999f6a05956
MD5 hash: f897788e12be9d7c9d7477c946d1bdaf
humanhash: potato-mars-salami-hawaii
File name:SETUP.zip
Download: download sample
Signature LummaStealer
File size:2'247'024 bytes
First seen:2026-03-16 23:08:25 UTC
Last seen:2026-03-16 23:08:54 UTC
File type: zip
MIME type:application/zip
ssdeep 49152:PctTRa/mq3l3MOeAuv0EdVA499GAfZcQN:PYwmOl3sAfK9xf
TLSH T137A5239DB63615F5EBDD84F42B9A2B0763E39324CE0A43664A3C285F7E3235A4449C1F
Magika zip
Reporter user35335
Tags:file-pumped zip


Avatar
user35335
https://dwnlods.onl -> https://disk.yandex.com/d/Uf4CRvgkZF44DQ

Intelligence


File Origin
# of uploads :
2
# of downloads :
221
Origin country :
CA CA
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Setup_Installer.exe
File size:104'857'600 bytes
SHA256 hash: e6247dc164c4b5b4c02df95e455e21182bfba6c9a1d981b4ad1c980a7115bdd0
MD5 hash: 7811ceda896ddff1a622972e9a1ea73f
MIME type:application/x-dosexec
Signature LummaStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
autoit emotet
Result
Verdict:
Malicious
File Type:
ZIP File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context autoit CAB installer installer installer-heuristic lolbin microsoft_visual_cc rundll32 runonce sfx
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Zip Archive
Threat name:
Win64.Trojan.HulkAggressive
Status:
Malicious
First seen:
2026-03-16 23:09:17 UTC
File Type:
Binary (Archive)
Extracted files:
25
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_Redline_Stealer
Author:Varp0s

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LummaStealer

zip 1733c1d12e4b799ac0165a933b3bbf246ad078883be359749510b44d2eb775cb

(this sample)

  
Delivery method
Distributed via web download

Comments