Threat name:
LummaC, Python Stealer, Amadey, LummaC S
Alert
Classification:
phis.troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains very large array initializations
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Creates multiple autostart registry keys
Detected unpacking (changes PE section rights)
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found stalling execution ending in API Sleep call
Gathers network related connection and port information
Hides threads from debuggers
Injects a PE file into a foreign processes
LummaC encrypted strings found
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Modifies the windows firewall
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Potentially malicious time measurement code found
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Sigma detected: Capture Wi-Fi password
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Suspicious Script Execution From Temp Folder
System process connects to network (likely due to code injection or exploit)
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal WLAN passwords
Tries to steal Crypto Currency Wallets
Tries to steal Instant Messenger accounts or passwords
Uses netsh to modify the Windows network and firewall settings
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected Amadeys Clipper DLL
Yara detected Amadeys stealer DLL
Yara detected Generic Downloader
Yara detected Generic Python Stealer
Yara detected LummaC Stealer
Yara detected Monster Stealer
Yara detected PureLog Stealer
Yara detected RedLine Stealer
Yara detected RisePro Stealer
behaviorgraph
top1
signatures2
2
Behavior Graph
ID:
1412444
Sample:
file.exe
Startdate:
20/03/2024
Architecture:
WINDOWS
Score:
100
171
Multi AV Scanner detection
for domain / URL
2->171
173
Found malware configuration
2->173
175
Malicious sample detected
(through community Yara
rule)
2->175
177
27 other signatures
2->177
10
explorgu.exe
2
62
2->10
started
15
file.exe
5
2->15
started
17
MPGPH131.exe
2->17
started
19
2 other processes
2->19
process3
dnsIp4
127
185.215.113.32
WHOLESALECONNECTIONSNL
Portugal
10->127
129
91.215.85.131
PINDC-ASRU
Russian Federation
10->129
135
3 other IPs or domains
10->135
111
C:\Users\user\AppData\Roaming\...\cred64.dll, PE32+
10->111
dropped
113
C:\Users\user\AppData\Roaming\...\clip64.dll, PE32
10->113
dropped
115
C:\Users\user\AppData\Local\...\green.exe, PE32
10->115
dropped
123
30 other malicious files
10->123
dropped
211
Antivirus detection
for dropped file
10->211
213
Multi AV Scanner detection
for dropped file
10->213
215
Detected unpacking (changes
PE section rights)
10->215
229
5 other signatures
10->229
21
judith1234.exe
10->21
started
25
osminog.exe
2
10->25
started
27
random.exe
10->27
started
29
3 other processes
10->29
117
C:\Users\user\AppData\Local\...\explorgu.exe, PE32
15->117
dropped
217
Found evasive API chain
(may stop execution
after reading information
in the PEB, e.g. number
of processors)
15->217
219
Tries to evade debugger
and weak emulator (self
modifying code)
15->219
221
Tries to detect virtualization
through RDTSC time measurements
15->221
223
Machine Learning detection
for dropped file
17->223
225
Tries to detect sandboxes
/ dynamic malware analysis
system (registry check)
17->225
131
23.51.58.94
TMNET-AS-APTMNetInternetServiceProviderMY
United States
19->131
133
185.93.1.246
CDN77GB
Czech Republic
19->133
119
SystemMechanic_548...38868BD1.exe (copy), PE32
19->119
dropped
121
C:\Users\user\AppData\Local\...\BITA5C3.tmp, PE32
19->121
dropped
227
Benign windows process
drops PE files
19->227
file5
signatures6
process7
file8
99
C:\Users\user\AppData\...\_quoting_c.pyd, PE32+
21->99
dropped
101
C:\Users\user\AppData\...\vcruntime140.dll, PE32+
21->101
dropped
103
C:\Users\user\AppData\...\unicodedata.pyd, PE32+
21->103
dropped
109
32 other files (31 malicious)
21->109
dropped
179
Multi AV Scanner detection
for dropped file
21->179
181
Machine Learning detection
for dropped file
21->181
183
Tries to detect sandboxes
and other dynamic analysis
tools (process name
or module or function)
21->183
31
stub.exe
21->31
started
185
Found many strings related
to Crypto-Wallets (likely
being stolen)
25->185
187
Contains functionality
to inject code into
remote processes
25->187
189
Writes to foreign memory
regions
25->189
191
LummaC encrypted strings
found
25->191
36
RegAsm.exe
25->36
started
38
RegAsm.exe
25->38
started
50
2 other processes
25->50
105
C:\Users\user\AppData\Local\...\RageMP131.exe, PE32
27->105
dropped
107
C:\ProgramData\MPGPH131\MPGPH131.exe, PE32
27->107
dropped
193
Detected unpacking (changes
PE section rights)
27->193
195
Found stalling execution
ending in API Sleep
call
27->195
197
Creates multiple autostart
registry keys
27->197
201
3 other signatures
27->201
40
schtasks.exe
27->40
started
42
schtasks.exe
27->42
started
199
System process connects
to network (likely due
to code injection or
exploit)
29->199
203
2 other signatures
29->203
44
rundll32.exe
25
29->44
started
46
RegAsm.exe
29->46
started
48
conhost.exe
29->48
started
signatures9
process10
dnsIp11
137
208.95.112.1
TUT-ASUS
United States
31->137
139
185.199.108.133
FASTLYUS
Netherlands
31->139
145
2 other IPs or domains
31->145
97
C:\Users\user\AppData\Local\...\Monster.exe, PE32+
31->97
dropped
147
Tries to detect sandboxes
and other dynamic analysis
tools (process name
or module or function)
31->147
149
Tries to harvest and
steal browser information
(history, passwords,
etc)
31->149
151
Modifies the windows
firewall
31->151
169
2 other signatures
31->169
52
cmd.exe
31->52
started
54
cmd.exe
31->54
started
56
cmd.exe
31->56
started
68
14 other processes
31->68
141
172.67.217.100
CLOUDFLARENETUS
United States
36->141
153
Query firmware table
information (likely
to detect VMs)
36->153
155
Found many strings related
to Crypto-Wallets (likely
being stolen)
36->155
157
Tries to steal Crypto
Currency Wallets
36->157
159
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
38->159
161
Queries sensitive disk
information (via WMI,
Win32_DiskDrive, often
done to detect virtual
machines)
38->161
59
conhost.exe
40->59
started
61
conhost.exe
42->61
started
163
Tries to steal Instant
Messenger accounts or
passwords
44->163
165
Uses netsh to modify
the Windows network
and firewall settings
44->165
167
Tries to harvest and
steal ftp login credentials
44->167
63
powershell.exe
44->63
started
66
netsh.exe
2
44->66
started
143
4.185.137.132
LEVEL3US
United States
46->143
file12
signatures13
process14
file15
70
systeminfo.exe
52->70
started
83
5 other processes
52->83
73
WMIC.exe
54->73
started
75
conhost.exe
54->75
started
209
Tries to harvest and
steal WLAN passwords
56->209
85
2 other processes
56->85
125
C:\Users\user\...\246122658369_Desktop.zip, Zip
63->125
dropped
77
conhost.exe
63->77
started
79
conhost.exe
66->79
started
81
tasklist.exe
68->81
started
87
25 other processes
68->87
signatures16
process17
signatures18
205
Queries sensitive network
adapter information
(via WMI, Win32_NetworkAdapter,
often done to detect
virtual machines)
70->205
89
WmiPrvSE.exe
70->89
started
207
Queries sensitive service
information (via WMI,
Win32_LogicalDisk, often
done to detect sandboxes)
73->207
91
Conhost.exe
81->91
started
93
net1.exe
83->93
started
95
quser.exe
83->95
started
process19
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.