🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 849288791072a40d933ebc102f60d79145e7c2d5abfb0171f02d2ce9fbe7ea17. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 6


Intelligence 6 IOCs YARA 16 File information Comments

SHA256 hash: 849288791072a40d933ebc102f60d79145e7c2d5abfb0171f02d2ce9fbe7ea17
SHA3-384 hash: 845980d0463eba457be17a2501c7bdfd0a9154ed0b0688d0b0fb22029130defee2837fb3a624a283b150a110b57be29a
SHA1 hash: a7959586d62e3f21dcb6df7f8e2bf9b28ccf8e56
MD5 hash: 432a6e0f35f812d5c808192fea466b4e
humanhash: connecticut-arizona-muppet-wolfram
File name:mal1.zip
Download: download sample
Signature LummaStealer
File size:1'438'698 bytes
First seen:2025-06-01 08:03:58 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:li8/u7dQRwBLPGVyzs1U2LgOnzss3sDXSw4PfFTnFdmCrdvO0qIRm93twZ5uU:08/uZRGkiHLlos2SjPdaCrVO3XmZf
TLSH T11E65333C29A9774A24E61D0AD0998CC4B13F4549F23BC6E3DDA10C6BBB85686C6673C7
Magika zip
Reporter GDHJDSYDH1
Tags:dllHijack injector lumma LummaStealer spyware stealer zip


Avatar
GDHJDSYDH1
More Reference: https://www.hybrid-analysis.com/sample/849288791072a40d933ebc102f60d79145e7c2d5abfb0171f02d2ce9fbe7ea17

Intelligence


File Origin
# of uploads :
1
# of downloads :
608
Origin country :
US US
File Archive Information

This file archive contains 5 file(s), sorted by their relevance:

File name:Setup.exe
File size:67'920 bytes
SHA256 hash: 4f8aaadbf10d38b5a6edee498a5061f8028b14548261f36f44ed56998f5a86c4
MD5 hash: 3f8f49d756681fba89f727737ff17c46
MIME type:application/x-dosexec
Signature LummaStealer
File name:Grerboundtib.jv
File size:45'271 bytes
SHA256 hash: 8706b7ec1e49b73b08c6d979c94bf3d412a7937cd580300ecc2604333c0cc115
MD5 hash: 3279a2d02417f54715f414bf77a0b742
MIME type:application/octet-stream
Signature LummaStealer
File name:Theek.jxk
File size:1'155'862 bytes
SHA256 hash: aa1b7a00f66f3c305c9c5607b76516f658ef2b94667179bb8d7687e88abc81d1
MD5 hash: aed5a47b0031fc03b0d4e5f3cc0dde46
MIME type:application/octet-stream
Signature LummaStealer
File name:AliyunConfig.ini
File size:2 bytes
SHA256 hash: b3d510ef04275ca8e698e5b3cbb0ece3949ef9252f0cdc839e9ee347409a2209
MD5 hash: f3b25701fe362ec84616a93a45ce9998
MIME type:text/plain
Signature LummaStealer
File name:AliyunWrap.DLL
File size:508'752 bytes
SHA256 hash: c7753cee74cbcb08ada1e61e9ef708cffc11d4c8f70493e439187b97acf0b238
MD5 hash: a7dc5c08e8b9c058c90a2c0c4ab2d998
MIME type:application/x-dosexec
Signature LummaStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
injection obfusc smtp
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
fingerprint microsoft_visual_cc signed
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2025-06-01 07:55:16 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LummaStealer

zip 849288791072a40d933ebc102f60d79145e7c2d5abfb0171f02d2ce9fbe7ea17

(this sample)

  
Delivery method
Distributed via web download

Comments