🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a50581cd1845d7072037b1f42e30139b6a48cdb0b28edd3368d3bb31a31007bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 9


Intelligence 9 IOCs YARA 9 File information Comments

SHA256 hash: a50581cd1845d7072037b1f42e30139b6a48cdb0b28edd3368d3bb31a31007bc
SHA3-384 hash: d6d0cb50c024919e81a613d0d261dd93da199ae92e57df27fc87c8402d817d2e71537f23028141fe56c9c66373f31116
SHA1 hash: fd81a802a1d0c9405e4d3baf149aba9174e09ff0
MD5 hash: 8ab30d737717734f09bbddd8ad8067c1
humanhash: idaho-shade-mississippi-echo
File name:UKVMer.zip
Download: download sample
Signature LummaStealer
File size:10'335'543 bytes
First seen:2025-09-26 04:47:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:n8VJvPpgAnO6Tlx8PQGlmfXrD2SeuY8JfUnLe+zR7nOhXLdC4WpXZ:nkJJlz3GUfrqLu9JfULJR7nOh7bWpJ
TLSH T15AA63391A701CB74C84772C9FD279BF2814BF29821380EBE1CCF5B58BE4AE57E466419
Magika zip
Reporter GDHJDSYDH1
Tags:CoinMiner LummaStealer Uacbypass UPX VMProtect zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
224
Origin country :
US US
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:UKVMer.exe
File size:149'320 bytes
SHA256 hash: 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8
MD5 hash: 5251b98614acffe5c856f4039ca03da3
MIME type:application/x-dosexec
Signature LummaStealer
File name:Ars8oOPq.exe
File size:670'720 bytes
SHA256 hash: d983967db817b40b1303f88abde969ebd3d3914c34607c7715992b7aae86d74d
MD5 hash: fc7198604edbcd1e85037e2fc580ad73
MIME type:application/x-dosexec
Signature LummaStealer
File name:image.png
File size:4'883'781 bytes
SHA256 hash: 1ae60e9704a06ac42097fd6a0bca6aa08797181409d8a27ab4f917256cae7e69
MD5 hash: a780e0f0124284b41703383c4aa1f6a5
MIME type:image/png
Signature LummaStealer
File name:XPSPLOG.dll
File size:4'816'928 bytes
SHA256 hash: 8d357b4a4070537b79c8a7c67313b4bc5b4fd8709db6c89a89d7a10d78f8738e
MD5 hash: 809a3665d1d1b88f42c2f7d14e874a6d
MIME type:application/x-dosexec
Signature LummaStealer
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lumma overlay packed redcap unsafe zusy
Verdict:
Adware
File Type:
zip
Detections:
not-a-virus:HEUR:RiskTool.Win32.BitMiner.gen
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-26 04:38:08 UTC
File Type:
Binary (Archive)
Extracted files:
42
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution exploit persistence privilege_escalation trojan upx
Behaviour
UPX packed file
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:weird_png_data_after_end
Author:Maxime THIEBAUT (@0xThiebaut)
Description:Detects data suspiciously located after a PNG's end header
Reference:https://www.bleepingcomputer.com/news/microsoft/windows-11-snipping-tool-privacy-bug-exposes-cropped-image-content/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LummaStealer

zip a50581cd1845d7072037b1f42e30139b6a48cdb0b28edd3368d3bb31a31007bc

(this sample)

  
Delivery method
Distributed via web download

Comments