🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8e8a98af2e41ea76445bf055b124553bddd2311d7765cfddaa0b8137ef2b48f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 8


Intelligence 8 IOCs YARA 45 File information Comments 1

SHA256 hash: b8e8a98af2e41ea76445bf055b124553bddd2311d7765cfddaa0b8137ef2b48f
SHA3-384 hash: 97e59e264f17684164f9eca9501f54866bdb9292e2c4abb6e5f9df99f1664eb347cd8be378dd5e0061743d7d1d6b6da8
SHA1 hash: 93f6f41098dec28971277ad7046aa0bf9a140523
MD5 hash: b5bd7e9f8bc407ffee120057489f7f52
humanhash: tennis-shade-gee-iowa
File name:b5bd7e9f8bc407ffee120057489f7f52
Download: download sample
Signature LummaStealer
File size:25'416'976 bytes
First seen:2024-10-11 01:50:11 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:N1nSX39Cn4HTESwiEzhnQOZj5twAqwIrFg31qwp10HRrdElvoclFYTQSXyrFg31W:N1K1A1imhQO1vwAi6x1mwocl2G6x1I
TLSH T1014733DEA45B6A15DF2CA1E984F5FAA12F5493378FB9A8FD9977001C2B07BFD1010902
Magika zip
Reporter zbetcheckin
Tags:LummaStealer zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
223
Origin country :
FR FR
File Archive Information

This file archive contains 74 file(s), sorted by their relevance:

File name:CP1253.TXT
File size:9'207 bytes
SHA256 hash: 2d36bec3e1ecbf2b6de8a37c98717ae21ca8c5bc0b487556996b3fff2b6f6fd9
MD5 hash: 6b77baac03038b028948d2a667efdaa1
MIME type:text/plain
Signature LummaStealer
File name:he.pak
File size:127'834 bytes
SHA256 hash: ca440d0128b62e35333730c5925992ae5b4b05a37c10105a9145eb5cf7a77071
MD5 hash: 209974550cc2a835f1879995851b424a
MIME type:application/octet-stream
Signature LummaStealer
File name:CENTEURO.TXT
File size:12'919 bytes
SHA256 hash: ae8fdf0311fe249ee1a3e08fe36c394ca2da791c622b665ddebcb623ac248903
MD5 hash: 3ea4a9a2765040c721374ccbb8e7bd59
MIME type:text/plain
Signature LummaStealer
File name:fr.pak
File size:112'576 bytes
SHA256 hash: 0ddb18e05d4a58c010a42207af0ffdfaf12f9bee29f6971459bd69fdf26b0e79
MD5 hash: b5bce917fb4d322dad4b26febaaef09f
MIME type:application/octet-stream
Signature LummaStealer
File name:fi.pak
File size:95'737 bytes
SHA256 hash: 528e453ee8fd16b6e2066b5417b115504cd31afc4ffbd79206369c747caad1fe
MD5 hash: c865b2cab8dd25682b40006832a4b604
MIME type:application/octet-stream
Signature LummaStealer
File name:zdingbat.txt
File size:12'296 bytes
SHA256 hash: e7651bcf12532af30c79c499e7a280ccbcd7f208436999a21b1500b07149bc95
MD5 hash: 691886379048a5f9065ee903757af29b
MIME type:text/plain
Signature LummaStealer
File name:CourierStd-Bold.otf
File size:30'488 bytes
SHA256 hash: a3c25f2ec60f8d44f150cd4e478067b06cc7267fbaaf844da600ce1c31c6e5c1
MD5 hash: 404952ec4d0ae00dd2f58fb980a99326
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:zx______.pfm
File size:683 bytes
SHA256 hash: b3e66a48a576f1d90277aefb89af9cfd370e7c216978234bfe66b6ab6fa2c0fd
MD5 hash: 705cd85804c3dc1eef81b624ea813bfb
MIME type:application/x-font-pfm
Signature LummaStealer
File name:CourierStd.otf
File size:30'824 bytes
SHA256 hash: 54cb5c8e9775cb432afe32b0af688536354ad04ef9c9f1450ee7c88a73bc884d
MD5 hash: f4c2d3851e2781b2b3ff60a2e34e81ac
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:zy______.pfm
File size:684 bytes
SHA256 hash: 1a5660f3f8bb9d18fd6a710d70af26cf1e167fe040d7daf3ce41e527236e1fec
MD5 hash: 7d3be2ec810fa01a9ea7d2a26551cff7
MIME type:application/x-font-pfm
Signature LummaStealer
File name:Set-up.exe
File size:3'666'320 bytes
SHA256 hash: 3dbdf3bca365811e23299b43d5578088dc545d6ac2692552c1483244f97392d4
MD5 hash: fa2a8da7a01b532d22621256a8768d34
MIME type:application/x-dosexec
Signature LummaStealer
File name:CP1251.TXT
File size:9'474 bytes
SHA256 hash: f87ed4480cfddb8f5f6226292338ca407ccc7b1a543f3832f1d20aff6cb72a58
MD5 hash: 2926366654dbc6711ee71ba2589161c3
MIME type:text/plain
Signature LummaStealer
File name:AdonisUI.xml
File size:78'454 bytes
SHA256 hash: 3dbc7b701f01ca178359a1de543792c919ed49c16dfa06d766c545c8ffa51c50
MD5 hash: a310f32ce7eb9a28e9b0fa5e87ac71de
MIME type:text/xml
Signature LummaStealer
File name:ar.pak
File size:151'672 bytes
SHA256 hash: 776db47dd91bce8bc813a54a815be3e73b6e58e9fe5f24db7bf0d8c06a240f6a
MD5 hash: 70bb1c831327b26e4dd74097f59a55b0
MIME type:application/octet-stream
Signature LummaStealer
File name:UKRAINE.TXT
File size:4'605 bytes
SHA256 hash: 98dd24a56e7d0e2bd2fc6a8bf429aa7bd3820b0d2d90456b972914639d2278ed
MD5 hash: 96431211151b2e58c23262cce683e033
MIME type:text/plain
Signature LummaStealer
File name:fil.pak
File size:106'027 bytes
SHA256 hash: 500906ac9cab570726fe2c3c819eec3f88cb69f326857920d8423883c222c773
MD5 hash: 60d50ee0763200548c9df4b4bc712cd1
MIME type:application/octet-stream
Signature LummaStealer
File name:UniKS-UTF16-V
File size:3'198 bytes
SHA256 hash: 7e403dae40df21fe3f9b221f7ce750f7f5bff9cc73d82d011c4bcc48a0db60ed
MD5 hash: aba47550affb435a1dcc6b70efab5b52
MIME type:application/postscript
Signature LummaStealer
File name:SaslPrepProfile_norm_bidi.spp
File size:13'724 bytes
SHA256 hash: f2501579fc7ab062324b4e1a45428f69f9a37e0363a4fc1d3734157b587b92e1
MD5 hash: 787dcae108ef9d5fcd9f60ce6387e7b1
MIME type:application/octet-stream
Signature LummaStealer
File name:am.pak
File size:148'881 bytes
SHA256 hash: 4c0b4273dc4103c666ff01ed8b9db995f68c5c178973465bb25cd5cdf99ef01a
MD5 hash: 4e7db89a9f5c07a295de43b745e5658b
MIME type:application/octet-stream
Signature LummaStealer
File name:CP1254.TXT
File size:9'615 bytes
SHA256 hash: 32fa83c6f8ad346e66e544640942906e0a91cc0d2075324b7f244695de5740a5
MD5 hash: 65d7c9205e1a1393b8530670add4e596
MIME type:text/plain
Signature LummaStealer
File name:AdonisUI.ClassicTheme.xml
File size:146 bytes
SHA256 hash: e97828272a7a30780a4b92c791ae94b3adc4268463c53f81df0a27a372c77348
MD5 hash: 68a996036a022036a7260c21aca60d8d
MIME type:text/xml
Signature LummaStealer
File name:hi.pak
File size:211'379 bytes
SHA256 hash: 1ca6a0546f9627fa9ba3d377d79a21ff26ec9b349d47247c9b241a70728d0699
MD5 hash: fa034eb13d21ce4e9fc2d3eafdf40cd2
MIME type:application/octet-stream
Signature LummaStealer
File name:CP1252.TXT
File size:9'624 bytes
SHA256 hash: fca3ab5882f0a562794f05d7f15a39157c59d7c07fcbac79ab7cf3d12c979541
MD5 hash: 93fb108016f8a1e87e4129b21fe9984b
MIME type:text/plain
Signature LummaStealer
File name:symbol.txt
File size:10'745 bytes
SHA256 hash: 52dbabcdebe38f3e19e9071d6796fe49f1463f03d2d82064aab4a10bfbd4dddf
MD5 hash: 31d752fa13b4d1fc7b7b4747a3f6d3f9
MIME type:text/plain
Signature LummaStealer
File name:hr.pak
File size:101'535 bytes
SHA256 hash: 64e531e46cf5b644d1b7f1df885efcf51a65db50fab65ab250f5e4e1adfa9d29
MD5 hash: 624bce9b02382312f4588d3147b738a3
MIME type:application/octet-stream
Signature LummaStealer
File name:SQLite.Interop.dll
File size:1'374'512 bytes
SHA256 hash: 83f332ea9535814f18be4ee768682ecc7720794aedc30659eb165e46257a7cae
MD5 hash: 8be215abf1f36aa3d23555a671e7e3be
MIME type:application/x-dosexec
Signature LummaStealer
File name:MinionPro-Bold.otf
File size:210'284 bytes
SHA256 hash: 6af523a01b268ddaab5177e6c0df5024f7192d72b0b1ca9523721fbaa2aa9257
MD5 hash: b3870be83f40b14cb382bd498920a137
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:opengl64.dll
File size:152'875'008 bytes
SHA256 hash: e7d625cf255360b0ea96a52ca990be6f1cef522ff7440393e45b12793ac88031
MD5 hash: 71466589eb444bbf272c0f5c920c57f0
MIME type:text/plain
Signature LummaStealer
File name:MyriadPro-Regular.otf
File size:90'404 bytes
SHA256 hash: c812279db1ed52876e3b59791645424cb4714cb710f60da45f1b40757c3263e3
MD5 hash: 1aed3bcf1b764f4ac6d9b988b0e724c0
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:GREEK.TXT
File size:13'326 bytes
SHA256 hash: 1ce082e86367551b2a21465d1b1c2edc103242f7d565411dcea0762e3dd63aa1
MD5 hash: 962d73ae58ea74dfa492bda68064f130
MIME type:text/plain
Signature LummaStealer
File name:UniKS-UTF16-H
File size:131'902 bytes
SHA256 hash: ab87d320c81e4c761b7a4cbd342e212db4ebe169b5d10848f2f57d828874e342
MD5 hash: f65c06189a55139e13885d9716bfe35c
MIME type:application/postscript
Signature LummaStealer
File name:CP1257.TXT
File size:9'487 bytes
SHA256 hash: 7cb16a0b949f8573b06f22f091c44a1ea251cc9904591fceb2743475302c4640
MD5 hash: 002134c7ea7f619246bbf445caad9f08
MIME type:text/plain
Signature LummaStealer
File name:ICELAND.TXT
File size:14'175 bytes
SHA256 hash: e04b3c96f65a27030b5e4b071d8e61b8ede1d94cf7bf7845262b29be2b7656ac
MD5 hash: 48f0f1332aca28076f1d479d8a1c0447
MIME type:text/plain
Signature LummaStealer
File name:SY______.PFM
File size:672 bytes
SHA256 hash: 035af7591938139c78f8ad715047c16cd439c6a7791035deec013439921e6925
MD5 hash: 692b5b1be7394e93fd6e0750cae81474
MIME type:application/x-font-pfm
Signature LummaStealer
File name:glioma.asp
File size:1'511'802 bytes
SHA256 hash: 7cddf32de8b02b3ecf42c50ded8593770c5ab96d76247155f28d1d3cc87a541f
MD5 hash: 99083617f7139ee9ad5d6b719286ac3a
MIME type:application/octet-stream
Signature LummaStealer
File name:ZY______.PFB
File size:96'418 bytes
SHA256 hash: 1182fcc2fb887713fb954a804f83fae3417c27b6929ecb07c5034dac24586e8b
MD5 hash: 72abd7f6b6b7e6f2ccb06626aa8b46f1
MIME type:application/octet-stream
Signature LummaStealer
File name:carferry.flv
File size:12'108 bytes
SHA256 hash: dc260b93c358e10fc6f74c0b9f487dd0c2fd58e791ec5b0925b0546258923b36
MD5 hash: 16a30926e4ebc495d3659854c3731f63
MIME type:application/octet-stream
Signature LummaStealer
File name:CourierStd-Oblique.otf
File size:32'296 bytes
SHA256 hash: c54815a2729d633e400a6835679613090c20b91da6cb40fa761aaa475efb77f5
MD5 hash: 71ec484296a30c9379607e36158ca809
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:Identity-V
File size:2'761 bytes
SHA256 hash: 7483db44e4449a7ae232b30d6cba0d8746592757d0e91be82ec45b646c608807
MD5 hash: b5084cbf0ab0c3deac97e06cd3cb2ecc
MIME type:application/postscript
Signature LummaStealer
File name:id.pak
File size:93'327 bytes
SHA256 hash: 03e35e4c8d682d80ebde0492ba01d5a922766daf70df6cb2a22a5a5365adff1e
MD5 hash: c26b55aa25d424653e75ac278b0bca42
MIME type:application/octet-stream
Signature LummaStealer
File name:hu.pak
File size:108'879 bytes
SHA256 hash: fdd99d667419612bf98200783e0ccf0f7c11913ca03ca162d72d43f6861e5478
MD5 hash: ca8a821ff5a6b848c5a170ff9a97bb39
MIME type:application/octet-stream
Signature LummaStealer
File name:Register.dll
File size:1'081'320 bytes
SHA256 hash: 372b14fce2eb35b264f6d4aeef7987da56d951d3a09ef866cf55ed72763caa12
MD5 hash: 40b9628354ef4e6ef3c87934575545f4
MIME type:application/x-dosexec
Signature LummaStealer
File name:Identity-H
File size:8'228 bytes
SHA256 hash: aae946bc17203b5df12838d07ae5cafc9e85a1d42d1b94d8475ab2d42b77a5cb
MD5 hash: 40f5dc1383e3e8f870ed8f763ed51878
MIME type:application/postscript
Signature LummaStealer
File name:BouncyCastle.Crypto.dll
File size:3'316'968 bytes
SHA256 hash: e51721dc0647f4838b1abc592bd95fd8cb924716e8a64f83d4b947821fa1fa42
MD5 hash: 0cf454b6ed4d9e46bc40306421e4b800
MIME type:application/x-dosexec
Signature LummaStealer
File name:CP1250.TXT
File size:9'799 bytes
SHA256 hash: cf79ba755416ae5628a9dd1f870306b5a45fd6b256efed0c2ac1cc2ccb3307f0
MD5 hash: 3c9476725fbfeeffb9f549d995ee2815
MIME type:text/plain
Signature LummaStealer
File name:AdonisUI.ClassicTheme.dll
File size:293'888 bytes
SHA256 hash: 8103f2cce6a864ceefe6c5b0c05087ac85ab04a2abf150e93bc9db90c54d9d20
MD5 hash: 8a1b183bca062f48402c74f2daba7b92
MIME type:application/x-dosexec
Signature LummaStealer
File name:MinionPro-Regular.otf
File size:210'808 bytes
SHA256 hash: 327cb2238a82a89176ff6601139cbd0a5cdd8f8e1e057343eae13fa9b1e10ab8
MD5 hash: a4ea2690cfd854b24c968ac6cdce9c33
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:resources.pak
File size:5'113'668 bytes
SHA256 hash: 11d0f55c105883d203137a87a610ba793299dc4774fd6d8b3a86666a2c337041
MD5 hash: df15387bf046715cc592a690da33e4b1
MIME type:application/octet-stream
Signature LummaStealer
File name:SYMBOL.TXT
File size:15'702 bytes
SHA256 hash: c57c451d4a524159bf143573cd0568869c8eed814a999bff7f3e560dabd39f1d
MD5 hash: 46485e1a024abc31e8b9d2b4ca9a3b39
MIME type:text/plain
Signature LummaStealer
File name:gu.pak
File size:203'977 bytes
SHA256 hash: 5a23541ce618f91b78a809fe91a0c68681e20018c4411e00d8c205ab1d850dbf
MD5 hash: b0b1b848ceafcaf9e0dcde8bcf7492d8
MIME type:application/octet-stream
Signature LummaStealer
File name:AdobePIStd.otf
File size:85'552 bytes
SHA256 hash: 5dbc496c0b5a12d9f9ffdb83a46b9fcda8d1fc1fcd50832c783be5e9277a698e
MD5 hash: 8653bfe4c32a8528e981748e28c59570
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:BouncyCastle.Crypto.xml
File size:1'804'624 bytes
SHA256 hash: de94c224474fad71cd45a2fcd802976f16b8edf7dc290f1e353752d495703e10
MD5 hash: 253aec9d04057e346233763b2ae93a11
MIME type:text/xml
Signature LummaStealer
File name:ROMANIAN.TXT
File size:14'763 bytes
SHA256 hash: ff13110e8b448b033f464184a1a07b4cd32f0f0fea203a4401c284073fffad66
MD5 hash: d39f6c0a8cfe6f118ffd105cf44dea90
MIME type:text/plain
Signature LummaStealer
File name:rtl120.bpl
File size:1'112'040 bytes
SHA256 hash: d6dd7a4f46f2cfde9c4eb9463b79d5ff90fc690da14672ba1da39708ee1b9b50
MD5 hash: adf82ed333fb5567f8097c7235b0e17f
MIME type:application/x-dosexec
Signature LummaStealer
File name:CP1258.TXT
File size:9'477 bytes
SHA256 hash: f53d0ffb7f3c8182794331cfdd2fbcf77ff6dbdb05b415c98cc8d6fc49dce2fb
MD5 hash: 88e9b5216b90d0332bd2cd4fcee88a22
MIME type:text/plain
Signature LummaStealer
File name:CourierStd-BoldOblique.otf
File size:31'948 bytes
SHA256 hash: 698fd9169ad62bd6faedd1c8e8637abc9cc65b3b1a5ba8698242b1447303fbee
MD5 hash: 6804e7413898972e05823add91b1dfc5
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:ROMAN.TXT
File size:14'394 bytes
SHA256 hash: a58f56f7cf7767658cff9fdfd1ba182cc74a513b3a2b6f34e44625ff811f53dd
MD5 hash: 94a43862cb0159469484841d8370e552
MIME type:text/plain
Signature LummaStealer
File name:CORPCHAR.TXT
File size:18'923 bytes
SHA256 hash: 83246b8c942cbacf1031445a99e62acbb4733ef4167bebfba2bd852869824eab
MD5 hash: 0fbad8e1c335ac42617936aa6f89ec89
MIME type:text/plain
Signature LummaStealer
File name:MyriadPro-Bold.otf
File size:90'456 bytes
SHA256 hash: 2d09971801f2c18fc5a825379404113db237866073ab463a9bf0f3da8c62459a
MD5 hash: e6d1585e6c81e3206948d8548d914fec
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:libvlccore.dll
File size:2'673'912 bytes
SHA256 hash: 9126d9abf91585456000fffd9336478e91b9ea07ed2a25806a4e2e0437f96d29
MD5 hash: e25413bb41c2f239ffdd3569f76e74b0
MIME type:application/x-dosexec
Signature LummaStealer
File name:CYRILLIC.TXT
File size:13'403 bytes
SHA256 hash: 10738cd5bba3b23c02d3655bf2afdf72daeaaef778cda562c6d10ae8d25ca591
MD5 hash: db4ed5c205fddd693dc9ce69cccad036
MIME type:text/plain
Signature LummaStealer
File name:MinionPro-It.otf
File size:252'108 bytes
SHA256 hash: 90def22f2b7b3e4aa78a160084a7a2c8f28883b700abaedc004dc74cbc2d9b4c
MD5 hash: 45e2315e99f24ab596f9d3aed29a0fc3
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:icudt26l.dat
File size:214'512 bytes
SHA256 hash: b388595d6e96e51430bec6022b1a5635ca541e60936abd73342ae8319dfe6802
MD5 hash: 525de57b8d1167a4efb7eb00c013354f
MIME type:application/octet-stream
Signature LummaStealer
File name:UCS2-GBK-EUC
File size:243'835 bytes
SHA256 hash: 66cdcaed3aa94525c59a82a39a93b96885883bffadea1e572464d559d21443a6
MD5 hash: fb9d6cd4449ec7478ee8ad1bd7465bf5
MIME type:application/postscript
Signature LummaStealer
File name:CROATIAN.TXT
File size:13'523 bytes
SHA256 hash: f353d83def5c9632ffd1925a0f1480e3dc0e00c096aff5680e448cbfd97fad05
MD5 hash: 5c36e2cba7fdd612c575d50974ef708a
MIME type:text/plain
Signature LummaStealer
File name:TURKISH.TXT
File size:12'796 bytes
SHA256 hash: 9ecde6f591caed9c2ce4438884da5f22e35fbdbb97e8d80b43129b23a6791891
MD5 hash: 6bfac3d4ab3ac941a0b2a29a56de6f64
MIME type:text/plain
Signature LummaStealer
File name:SY______.PFB
File size:34'705 bytes
SHA256 hash: b0480c6f9cee6bb87c1ae159a89a8a9d1ffa46e0ab70461fdf2fc291e2c94b4a
MD5 hash: 6fd0724d1fee177adad6a13c65af5268
MIME type:application/octet-stream
Signature LummaStealer
File name:lv.pak
File size:109'598 bytes
SHA256 hash: 605d916a697824c4ad6c418d6e7cc157b85825da5dc08a0716d89c56bef0a6fc
MD5 hash: 2ac1161c66a47bb69378559c2c6fb44d
MIME type:application/octet-stream
Signature LummaStealer
File name:AdonisUI.dll
File size:167'936 bytes
SHA256 hash: db46b6106dc1b30041ce3f287ded91166895ff3f1928250fc79dd46c444b1e45
MD5 hash: 3d4c8b6aad28ec574e56ccda22b34ef3
MIME type:application/x-dosexec
Signature LummaStealer
File name:lt.pak
File size:110'440 bytes
SHA256 hash: 70996649507cc815f0c4886f8c4822d45c5e201e8e41dc464ab4973ea19d8a23
MD5 hash: 6b4c975b9a0b31fa4c0f8818ec53942c
MIME type:application/octet-stream
Signature LummaStealer
File name:ZX______.PFB
File size:75'573 bytes
SHA256 hash: ba8f3996fad32c042bf1f474a08b7452f252060882dc4de5a97ec389209e2301
MD5 hash: 5eb6497ffaa36909f6b2a824054bd4d9
MIME type:application/octet-stream
Signature LummaStealer
File name:MyriadPro-BoldIt.otf
File size:92'636 bytes
SHA256 hash: 7bcfa54cb8fb5b64dfe36f411d5265f7f71dc6f3b685c7ed0eb3753ee194bb45
MD5 hash: 01e3d8472c3cbc43799fed290b0dc219
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:MinionPro-BoldIt.otf
File size:251'140 bytes
SHA256 hash: beb1ca56f9b4f89fb1549fe63a4bc578d2bd8747f967c1df26dacd3ded3f0223
MD5 hash: a7487befbf3c7ba8c957d269d9ba24e1
MIME type:application/vnd.ms-opentype
Signature LummaStealer
File name:MyriadPro-It.otf
File size:91'132 bytes
SHA256 hash: f234adafb66ad5e47a024ff4881c2edc347d0453c15e811288ef10eb573cc33e
MD5 hash: 4413059068c27d82ad49621ae4aaeb5b
MIME type:application/vnd.ms-opentype
Signature LummaStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
Powershell Autorun Gumen
Result
Verdict:
Malicious
File Type:
ZIP File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Gathering data
Gathering data
Threat name:
Win32.Spyware.Lummastealer
Status:
Malicious
First seen:
2024-10-07 19:21:50 UTC
File Type:
Binary (Archive)
Extracted files:
1022
AV detection:
15 of 24 (62.50%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:lumma discovery stealer
Behaviour
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Malware Config
C2 Extraction:
https://wickedneatr.sbs
https://invinjurhey.sbs
https://laddyirekyi.sbs
https://exilepolsiy.sbs
https://bemuzzeki.sbs
https://exemplarou.sbs
https://isoplethui.sbs
https://frizzettei.sbs
https://basizuw.buzz
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Borland
Author:malware-lu
Rule name:Check_OutputDebugStringA_iat
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_Malicious_VBScript_Base64
Author:daniyyell
Description:Detects malicious VBScript patterns, including Base64 decoding, file operations, and PowerShell.
Rule name:extracted_at_0x44b
Author:cb
Description:sample - file extracted_at_0x44b.exe
Reference:Internal Research
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:PickleOrNot
Author:Eoin Wickens - Eoin@HiddenLayer.com
Description:Detects Pickle files with dangerous c_builtins or non standard module imports. These are indicators of possible malicious intent
Rule name:PK_PUMP_AND_DUMP
Author:Will Metcalf @node5
Description:Walks Zip Central Directory filename entries looking for abused extension then checks for a file that's at least 25M and then check to see how much uncompressed size is vs compressed size
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RC6_Constants
Author:chort (@chort0)
Description:Look for RC6 magic constants in binary
Reference:https://twitter.com/mikko/status/417620511397400576
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:Sectigo_Code_Signed
Description:Detects code signed by the Sectigo RSA Code Signing CA
Reference:https://bazaar.abuse.ch/export/csv/cscb/
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LummaStealer

zip b8e8a98af2e41ea76445bf055b124553bddd2311d7765cfddaa0b8137ef2b48f

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2024-10-11 01:50:13 UTC

url : hxxps://apocalypsedoer.com/requested/kbsn1.zip