MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9bde0fbcc81974a22c1c9c7d6fc7e73860a8f5cbf07ddd4a675fa2d0e25dca3d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 9bde0fbcc81974a22c1c9c7d6fc7e73860a8f5cbf07ddd4a675fa2d0e25dca3d
SHA3-384 hash: 7432e1d5326aae341d76686886ac4150b4f7759d61a6d0ba76223f641f77bf7d27d105a1dac7fa64eb923fcbcef89f2f
SHA1 hash: 726162a8be28a2335b23a1fadd22db44b7b44bff
MD5 hash: 05e8443a4ea2679f8b95c0aa438efa91
humanhash: washington-oranges-vermont-alanine
File name:700815a50547b01b29cf3a1ca55d7a7e3058e7d911072018.html.ps1
Download: download sample
Signature LummaStealer
File size:11'296'570 bytes
First seen:2025-03-31 11:37:32 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 24576:vhodhoRhoJhoWho9hoRhorhoShophoEhoIhoVhoRhochoghochovho/ho3ho0hoG:T
TLSH T123B6FFDB639C87FDA6988DDE820A354F61F2C1B73C6F128CA9E14507B42FE117625A70
Magika powershell
Reporter aachum
Tags:ClickFix FakeCaptcha LummaStealer ps1


Avatar
iamaachum
https://a.uueui.shop/700815a50547b01b29cf3a1ca55d7a7e3058e7d911072018.html

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
virus crypt spawn
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
crypt masquerade
Result
Threat name:
LummaC Stealer
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Antivirus detection for URL or domain
Attempt to bypass Chrome Application-Bound Encryption
C2 URLs / IPs found in malware configuration
Found malware configuration
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Uses an obfuscated file name to hide its real file extension (double extension)
Yara detected LummaC Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1652754 Sample: 700815a50547b01b29cf3a1ca55... Startdate: 31/03/2025 Architecture: WINDOWS Score: 100 27 oreironx.live 2->27 29 cvrsystem.fr 2->29 31 bargainsphere.shop 2->31 49 Found malware configuration 2->49 51 Antivirus detection for URL or domain 2->51 53 Multi AV Scanner detection for submitted file 2->53 55 6 other signatures 2->55 9 powershell.exe 15 19 2->9         started        signatures3 process4 dnsIp5 41 bargainsphere.shop 104.21.80.1, 443, 49729, 49730 CLOUDFLARENETUS United States 9->41 57 Attempt to bypass Chrome Application-Bound Encryption 9->57 59 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 9->59 61 Injects a PE file into a foreign processes 9->61 13 powershell.exe 9->13         started        17 conhost.exe 9->17         started        signatures6 process7 dnsIp8 43 oreironx.live 172.67.141.196, 443, 49731, 49758 CLOUDFLARENETUS United States 13->43 45 cvrsystem.fr 91.216.107.206, 443, 49767 RMI-FITECHFR France 13->45 47 127.0.0.1 unknown unknown 13->47 63 Query firmware table information (likely to detect VMs) 13->63 65 Tries to harvest and steal ftp login credentials 13->65 67 Tries to harvest and steal browser information (history, passwords, etc) 13->67 69 Tries to steal Crypto Currency Wallets 13->69 19 chrome.exe 13->19         started        signatures9 process10 dnsIp11 33 192.168.2.5, 138, 443, 49684 unknown unknown 19->33 22 chrome.exe 19->22         started        25 chrome.exe 19->25         started        process12 dnsIp13 35 www.google.com 142.251.32.100, 443, 49735, 49736 GOOGLEUS United States 22->35 37 plus.l.google.com 142.251.40.174, 443, 49754 GOOGLEUS United States 22->37 39 2 other IPs or domains 22->39
Threat name:
Script-PowerShell.Spyware.Lummastealer
Status:
Malicious
First seen:
2025-03-31 11:38:13 UTC
File Type:
Text
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Blocklisted process makes network request
Downloads MZ/PE file
Suspicious use of NtCreateUserProcessOtherParentProcess
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LummaStealer

PowerShell (PS) ps1 9bde0fbcc81974a22c1c9c7d6fc7e73860a8f5cbf07ddd4a675fa2d0e25dca3d

(this sample)

Comments