MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 88a0d9c95e04567d60692e60ad1a7384fb2eaf1890bb2e69ac9d3baa21025e60. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
LummaStealer
Vendor detections: 17
| SHA256 hash: | 88a0d9c95e04567d60692e60ad1a7384fb2eaf1890bb2e69ac9d3baa21025e60 |
|---|---|
| SHA3-384 hash: | 34afd2a2658aacdcbce70c167359b5d2e5803de396b25ece84bb729003f8a1bbc23acb4f07a38e34b986225399209c97 |
| SHA1 hash: | 0d76f561c812387d9f39483ed62b1a3114080efa |
| MD5 hash: | 3bd80b1ee216619e14f529d4fd7483e0 |
| humanhash: | floor-april-autumn-rugby |
| File name: | file |
| Download: | download sample |
| Signature | LummaStealer |
| File size: | 887'296 bytes |
| First seen: | 2023-10-19 13:53:17 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 646167cce332c1c252cdcb1839e0cf48 (8'473 x RedLineStealer, 4'851 x Amadey, 290 x Smoke Loader) |
| ssdeep | 12288:jMrFy90gBtPubpUqhiYFBrTph63uxe+Xb34wBupOFOegDqfqGm3GT76opub0qADk:yyxBtPuF3P/rT7xe+LIIVYDlmT76bI6 |
| TLSH | T14C152242BBDD4422DAF127F04CF6029307367CE78EA853672B548DAA1CF2595B876372 |
| TrID | 70.4% (.CPL) Windows Control Panel Item (generic) (197083/11/60) 11.1% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 5.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 3.7% (.EXE) Win64 Executable (generic) (10523/12/4) 2.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) |
| File icon (PE): | |
| dhash icon | f8f0f4c8c8c8d8f0 (8'803 x RedLineStealer, 5'078 x Amadey, 288 x Smoke Loader) |
| Reporter | |
| Tags: | exe LummaStealer |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
77.91.124.55:19071
http://77.91.124.1/theme/index.php
85.209.176.128:80
https://pastebin.com/raw/8baCJyMF
http://host-file-host6.com/
http://host-host-file8.com/
Unpacked files
88b6c85fa9f0c81ea2d29b2b07401e4be1935f35f02dde3eeea2cb423c8d942d
23036cfd0482390c6d77d9c56611037bd5270c4847137722b7755489939ecf15
fb7e5ff47a1c2ad42e8473ff2a9422c9921a83f68958df02953d877a89bf87aa
ee950c53a47f11f7d59440c37b03bf5dbc51f8950844e5768e6972fd7cbca733
727d2598abc67340296c370af4cf1b498135721c5ce5c915bf411eedce6d9857
0f440b132f6faf655b012cac333d83638643551669bb45227f474e19296cbd8a
ead75b2eb8431569d268d1215229137c019fc6c527bdfd9d13f9b0ebc3d9f850
a204cce7e40f377c1697747536f60384aecf00c5f66c1957edc2b281eecea989
3e14b3981918f6e22ba3bb6836cdc49552e0ed6325bb3c76cffdf33ea61efcf5
7b5301f71b7191a63d8fdc84018c3a9e9ae11a1dfda4f1a74b8eca762edf27c7
10c9b045aaa79765ae2b785ee2463439753b360e9e1712b839849af736ef9539
e2f3379b09a3ac4a2a986c775e7f0bf7c4c4360157e0731f465d17d99dfd45d9
0f35d8c854713e65056bf6913bf2ba5e5b7eee819d92d71f5480783fc925f9b1
db2d5629df8d990ffb67b0573563b53fcaa3676c21cc164053f4abce40cfa8ae
f71d57cde789cc5d42cf24a71c5648f43ad3fd51586b34a6ce7c930d526b2403
15e4313dddb45875ed67d1ab25f1f5b76f0b3a23e4fa9308c521e3fb30068028
66d830fe6769c073d8d8e9e83d8d32178d513c024dc613bcaf2781d86180d3d6
7a0a8007ee1b3f56c17a89b5f9872bcbbb9bd52545daa6ac62484b3312bb8a7c
7932899544025eb132921b174af481caf38caca73a162306f7dadc250c403c16
d14f3781a88172e83ee0797e6388a05c9a1cf8026ccaa0331c86ad8a72ec5775
88a0d9c95e04567d60692e60ad1a7384fb2eaf1890bb2e69ac9d3baa21025e60
072028180a894acc9ea5946a82afbfbfbb6b20df80bb68a66c6df6791b456f26
fe801414a07a9d15e329e477f5e0a2e688e3e6399b3a70891d54f1cebd3798c8
f177559b9554c377c6ba9748ba79e1215db35a279c9cb6bdc4d612facf66b7ee
db10bd703b6cbc584fd7e9d6b62c86cdb35b871d81544059a618fb31ce1f9976
1be4fb960acf57b1ad1bb57613f3d4d8d84e5b7b59096ea5364318becda76d73
1ffa4da1c354188eb0e3f406db9f93ecdcdfa152e50f0bd6ca2c78a9991977c5
05e1e433970cd6b3e85edbb6aa9bb2a85a7505e6eeb2cdb0f243ecc71afdf431
235f6ded171cdfe2a74b3feda159ef5e746ad7955d8a1a5112d4e8e38eb4e8cd
72c0366fa6c8d1623a89b4d7a3f8be72ed8442a86d680f0eaa3a8246c513be51
eabd0bd2d942ed6013525df7ffc82dac2e1c7289308952de7dbabe6a03d71e00
1a2c2245d13efea03727190dc9de4fa34d4a0e46c734b2ba6e384a28f21850ee
dacfe896395865b6fed377a805eee8e4ec5f1a6ef762aae6ce10c4d12b363bf3
bae695d097b890cff199e0aeaeea8cedf4d1b520a0d77a0789fc4f9e5c0bbcd8
cbf2171616a11736845095e1a1e40b71c7a6b51e3c4453da03db769132820714
84565296d0d5de7fb6cfda5def970e597b09d90038003113a9d72b0307033c96
801da7d6cedd0ba03ad2ded6f85e726451ffad38d05a02b5aba0d26659641448
96e9f0ef9354933006a9ddde91c5a0bad64f94eecc040655d47f6e5b0033c375
13ce85057303db2f0e27cbf81a12e7a1381ccc5367facb68d329e4c88e811569
99c860e50ce141cd665e7c0f852147aa62d50d755567fc59b23b20976caf5f0b
6eadbfe729ca755e16c196fb1b602e9809793a9718af47e9a75df3d0c983453e
c233f31adfdf240f44d5d0be0b1204cca870e8c4a52db2c933a2e2184a3463d0
5e662905b9ab01aa9ca7a0c34b98a6de1cf2e1bf821030b7a61ba7e639615e25
78f0f3f1b525fb795edb0574f5ae2b760767d8c836bb783ec2c6f628cb0bacfd
23036cfd0482390c6d77d9c56611037bd5270c4847137722b7755489939ecf15
fb7e5ff47a1c2ad42e8473ff2a9422c9921a83f68958df02953d877a89bf87aa
ee950c53a47f11f7d59440c37b03bf5dbc51f8950844e5768e6972fd7cbca733
727d2598abc67340296c370af4cf1b498135721c5ce5c915bf411eedce6d9857
0f440b132f6faf655b012cac333d83638643551669bb45227f474e19296cbd8a
ead75b2eb8431569d268d1215229137c019fc6c527bdfd9d13f9b0ebc3d9f850
a204cce7e40f377c1697747536f60384aecf00c5f66c1957edc2b281eecea989
3e14b3981918f6e22ba3bb6836cdc49552e0ed6325bb3c76cffdf33ea61efcf5
7b5301f71b7191a63d8fdc84018c3a9e9ae11a1dfda4f1a74b8eca762edf27c7
10c9b045aaa79765ae2b785ee2463439753b360e9e1712b839849af736ef9539
e2f3379b09a3ac4a2a986c775e7f0bf7c4c4360157e0731f465d17d99dfd45d9
db2d5629df8d990ffb67b0573563b53fcaa3676c21cc164053f4abce40cfa8ae
f71d57cde789cc5d42cf24a71c5648f43ad3fd51586b34a6ce7c930d526b2403
15e4313dddb45875ed67d1ab25f1f5b76f0b3a23e4fa9308c521e3fb30068028
66d830fe6769c073d8d8e9e83d8d32178d513c024dc613bcaf2781d86180d3d6
7a0a8007ee1b3f56c17a89b5f9872bcbbb9bd52545daa6ac62484b3312bb8a7c
7932899544025eb132921b174af481caf38caca73a162306f7dadc250c403c16
d14f3781a88172e83ee0797e6388a05c9a1cf8026ccaa0331c86ad8a72ec5775
88a0d9c95e04567d60692e60ad1a7384fb2eaf1890bb2e69ac9d3baa21025e60
072028180a894acc9ea5946a82afbfbfbb6b20df80bb68a66c6df6791b456f26
fe801414a07a9d15e329e477f5e0a2e688e3e6399b3a70891d54f1cebd3798c8
f177559b9554c377c6ba9748ba79e1215db35a279c9cb6bdc4d612facf66b7ee
db10bd703b6cbc584fd7e9d6b62c86cdb35b871d81544059a618fb31ce1f9976
1be4fb960acf57b1ad1bb57613f3d4d8d84e5b7b59096ea5364318becda76d73
05e1e433970cd6b3e85edbb6aa9bb2a85a7505e6eeb2cdb0f243ecc71afdf431
235f6ded171cdfe2a74b3feda159ef5e746ad7955d8a1a5112d4e8e38eb4e8cd
72c0366fa6c8d1623a89b4d7a3f8be72ed8442a86d680f0eaa3a8246c513be51
eabd0bd2d942ed6013525df7ffc82dac2e1c7289308952de7dbabe6a03d71e00
dacfe896395865b6fed377a805eee8e4ec5f1a6ef762aae6ce10c4d12b363bf3
bae695d097b890cff199e0aeaeea8cedf4d1b520a0d77a0789fc4f9e5c0bbcd8
cbf2171616a11736845095e1a1e40b71c7a6b51e3c4453da03db769132820714
84565296d0d5de7fb6cfda5def970e597b09d90038003113a9d72b0307033c96
96e9f0ef9354933006a9ddde91c5a0bad64f94eecc040655d47f6e5b0033c375
13ce85057303db2f0e27cbf81a12e7a1381ccc5367facb68d329e4c88e811569
99c860e50ce141cd665e7c0f852147aa62d50d755567fc59b23b20976caf5f0b
6eadbfe729ca755e16c196fb1b602e9809793a9718af47e9a75df3d0c983453e
5e662905b9ab01aa9ca7a0c34b98a6de1cf2e1bf821030b7a61ba7e639615e25
78f0f3f1b525fb795edb0574f5ae2b760767d8c836bb783ec2c6f628cb0bacfd
23036cfd0482390c6d77d9c56611037bd5270c4847137722b7755489939ecf15
fb7e5ff47a1c2ad42e8473ff2a9422c9921a83f68958df02953d877a89bf87aa
ee950c53a47f11f7d59440c37b03bf5dbc51f8950844e5768e6972fd7cbca733
727d2598abc67340296c370af4cf1b498135721c5ce5c915bf411eedce6d9857
3e14b3981918f6e22ba3bb6836cdc49552e0ed6325bb3c76cffdf33ea61efcf5
7b5301f71b7191a63d8fdc84018c3a9e9ae11a1dfda4f1a74b8eca762edf27c7
10c9b045aaa79765ae2b785ee2463439753b360e9e1712b839849af736ef9539
e2f3379b09a3ac4a2a986c775e7f0bf7c4c4360157e0731f465d17d99dfd45d9
db2d5629df8d990ffb67b0573563b53fcaa3676c21cc164053f4abce40cfa8ae
15e4313dddb45875ed67d1ab25f1f5b76f0b3a23e4fa9308c521e3fb30068028
66d830fe6769c073d8d8e9e83d8d32178d513c024dc613bcaf2781d86180d3d6
7a0a8007ee1b3f56c17a89b5f9872bcbbb9bd52545daa6ac62484b3312bb8a7c
d14f3781a88172e83ee0797e6388a05c9a1cf8026ccaa0331c86ad8a72ec5775
88a0d9c95e04567d60692e60ad1a7384fb2eaf1890bb2e69ac9d3baa21025e60
072028180a894acc9ea5946a82afbfbfbb6b20df80bb68a66c6df6791b456f26
f177559b9554c377c6ba9748ba79e1215db35a279c9cb6bdc4d612facf66b7ee
db10bd703b6cbc584fd7e9d6b62c86cdb35b871d81544059a618fb31ce1f9976
1be4fb960acf57b1ad1bb57613f3d4d8d84e5b7b59096ea5364318becda76d73
05e1e433970cd6b3e85edbb6aa9bb2a85a7505e6eeb2cdb0f243ecc71afdf431
72c0366fa6c8d1623a89b4d7a3f8be72ed8442a86d680f0eaa3a8246c513be51
bae695d097b890cff199e0aeaeea8cedf4d1b520a0d77a0789fc4f9e5c0bbcd8
96e9f0ef9354933006a9ddde91c5a0bad64f94eecc040655d47f6e5b0033c375
99c860e50ce141cd665e7c0f852147aa62d50d755567fc59b23b20976caf5f0b
6eadbfe729ca755e16c196fb1b602e9809793a9718af47e9a75df3d0c983453e
78f0f3f1b525fb795edb0574f5ae2b760767d8c836bb783ec2c6f628cb0bacfd
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | detect_Redline_Stealer |
|---|---|
| Author: | Varp0s |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.