๐Ÿคฒ๐Ÿผ NEW | abuse.ch Community Hub! Earn recognition ๐Ÿ… for the malware intelligence you share, climb the leaderboards ๐Ÿ“ˆ, and connect with like-minded contributors who share your hunting focus ๐Ÿค. Ready to unlock your profile? Go to the Community Hub โ†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 be0ddf92f163c6b8eb15ce3514040bbbb9d8a7702bd1d261672eaaee3391990f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 5


Intelligence 5 IOCs YARA 16 File information Comments

SHA256 hash: be0ddf92f163c6b8eb15ce3514040bbbb9d8a7702bd1d261672eaaee3391990f
SHA3-384 hash: 9e67f99aba3928c6c9cf72b36d9a75a5da7f161e2cfa096101fe16b43c65e72f661c2218c40e8fb8d7fc83402454d9c2
SHA1 hash: 444cab5890a86a1671d36d7f7dc6dd4510ba2ae6
MD5 hash: fcec553f3fc95d6a5f075c0f2ac118e5
humanhash: batman-orange-zulu-echo
File name:๐——0๐—ช๐—ก๐—Ÿ๐—ข@๐—”๐——_๐—–๐—ข๐— ๐—ฃ๐—Ÿ๐—˜๐—ง๐—˜โโค–๐—ฆ๐—˜๐—ง3๐—จ๐—ฃโœท๐—–๐—ข2๐——๐—˜_6833.zip
Download: download sample
Signature LummaStealer
File size:10'893'957 bytes
First seen:2025-03-30 20:05:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:Fk2KDOAVfDXU5EijKTy38XxJj+xdWoREGmsYOLBGbnXpD3Jk1:Fk2cOAdEE5JydW1lstLBoX13G1
TLSH T127B6341A25528EC02118C783D2A69CBF4EC26CB262F958E656424FD46487FCD5B373EF
TrID 60.0% (.WMZ) Windows Media Player skin (6000/1/1)
40.0% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter GDHJDSYDH1
Tags:file-pumped lumma LummaStealer stealer trojan zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
US US
File Archive Information

This file archive contains 22 file(s), sorted by their relevance:

File name:Setup.exe
File size:27'696 bytes
SHA256 hash: ab5b956eca5ce83bf763d5f952316f17ba771adfd5cafd8ca9e262de61de4b4e
MD5 hash: 5b8fb06983be9063ef128fa5aee80b3a
MIME type:application/x-dosexec
Signature LummaStealer
File name:internal.log
File size:56'189 bytes
SHA256 hash: 2c7f37e9fd4addd503087a322ec54adc280ea8da367753f344d3f5295b99ccbf
MD5 hash: 2c2c7a322b17304abb8c7df824d8b5a1
MIME type:application/octet-stream
Signature LummaStealer
File name:msvcp80.dll
File size:548'864 bytes
SHA256 hash: 35b15b78c31111db4fa11d9c9cad3a6f22c92daa5e6f069dc455e72073266cc4
MD5 hash: 272a9e637adcaf30b34ea184f4852836
MIME type:application/x-dosexec
Signature LummaStealer
File name:libcrypto-1_1.dll
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:850'820'206 bytes
SHA256 hash: a978f7c0adb29d3eda11b34afb91c6bcb7c791a34aed89e6970d2eed415db361
MD5 hash: bd22d7b158ba9e74372549ce3a63fdb8
De-pumped file size:2'681'091 bytes (Vs. original size of 850'820'206 bytes)
De-pumped SHA256 hash: 6eac8cfba64352b012271cf75d174c1551bff678c0ea31efd6f722cca8a0cdcd
De-pumped MD5 hash: 187d26153cbdee3d6a8065be3f321a6c
MIME type:application/x-dosexec
Signature LummaStealer
File name:Microsoft.TeamFoundation.WorkItemTracking.WebApi.dll
File size:239'024 bytes
SHA256 hash: 59118f9da8bc436a21aa654e68087ff9f1330fc3497dcadd140caaec0d236a03
MD5 hash: 0291be401303be1996471c1c398b62f9
MIME type:application/x-dosexec
Signature LummaStealer
File name:msvcr80.dll
File size:626'688 bytes
SHA256 hash: cb8928ff2faf2921b1eddc267dce1bb64e6fee4d15b68cd32588e0f3be116b03
MD5 hash: 43143abb001d4211fab627c136124a44
MIME type:application/x-dosexec
Signature LummaStealer
File name:System.Formats.Tar.dll
File size:272'560 bytes
SHA256 hash: 11ee3dfa2c651b72794ed016c17b9c7754087e576e00f99f5bc921688db438b8
MD5 hash: 2cecb333830b0a119f048f01044f134e
MIME type:application/x-dosexec
Signature LummaStealer
File name:antiparticle.json
File size:3'841'738 bytes
SHA256 hash: 92e5ece45f6aad38e6717fc7f92621b0d7d306ae5ad0bfd35821db963cc79e36
MD5 hash: 4d27b358416d60e1b419992de29b8ed9
MIME type:application/octet-stream
Signature LummaStealer
File name:ContactPicker.dll
File size:222'592 bytes
SHA256 hash: ea3f179042fd9a989d534de224cbcb702661511205d89b97fac740752391ca7d
MD5 hash: 6ec535cdded7fce5feba28669b6b2923
MIME type:application/x-dosexec
Signature LummaStealer
File name:webview2_integration.dll
File size:32'840 bytes
SHA256 hash: 84379ff59a4a9c16ba253e8c8d6dce96d92493ebad0a3d9c52e1abfe29a58ee3
MD5 hash: 2cc080a0a56fd3be5967879c75d433a3
MIME type:application/x-dosexec
Signature LummaStealer
File name:Microsoft.ServiceHub.HostLib.dll
File size:256'032 bytes
SHA256 hash: b147759b4e67f6086337fa7ef96b2f5dc971b5d96fc8f8cf438b6e7e72282dac
MD5 hash: fd8286c40dff72e4d07e60953deabc35
MIME type:application/x-dosexec
Signature LummaStealer
File name:ACETXT.DLL
File size:297'360 bytes
SHA256 hash: ded28bef03257244fff18e03462733c1285ae2fd3e78bc9bb39cc06018c4f016
MD5 hash: 77b7d9b2b8530d927c453f1200bf9f35
MIME type:application/x-dosexec
Signature LummaStealer
File name:zlib1.dll
File size:209'408 bytes
SHA256 hash: 485521ec00c1903c52f3d75aa570a061939c473ef727ad459afb34cdb6b9930b
MD5 hash: 332d59acac8ffdeea505d506d356f9b5
MIME type:application/x-dosexec
Signature LummaStealer
File name:MOG_Framework_2.2.14_vc10.dll
File size:308'936 bytes
SHA256 hash: 6686a74882961a361d49ee8da80b18939fad230fd5aa8a10dad16253b31aed68
MD5 hash: dba793bc86370520da5028125ffbcf81
MIME type:application/x-dosexec
Signature LummaStealer
File name:Microsoft.VisualStudio.LiveShare.DebuggerService.VSCore.dll
File size:337'336 bytes
SHA256 hash: b753677837d61886850da971d9f9bcea51ab8ea6cfe15f48f5f55748996723bb
MD5 hash: 9388cbf31946cd6a6a66e0d7c0ef4989
MIME type:application/x-dosexec
Signature LummaStealer
File name:WzAddropocts64.dll
File size:284'312 bytes
SHA256 hash: df8ea8c658e4fefa220c3588d035a9d7fa484f9aeaf59f4d43a35fefd7197516
MD5 hash: 9c3ff8823e9e55069374568c36b60f3a
MIME type:application/x-dosexec
Signature LummaStealer
File name:libssl-1_1.dll
File size:656'552 bytes
SHA256 hash: 0813c77df688b39f26bad0be2b3e4afde13e97d9a1ebcbdb3b1f4184218d1a57
MD5 hash: cdbf8cd36924ffb81b19487746f7f18e
MIME type:application/x-dosexec
Signature LummaStealer
File name:EntityPicker.dll
File size:268'672 bytes
SHA256 hash: 2d3378162fd8ada1b102643c7e3f140a22bb1f519619045b1d4486e89b6fddcd
MD5 hash: bd367d1144b99ed63128437166b12e11
MIME type:application/x-dosexec
Signature LummaStealer
File name:VsGraphicsNativeUtils.dll
File size:223'624 bytes
SHA256 hash: b885c134dc3af6a806899b3ce63a4616859c2ed39c385023fbb3068b3404228a
MD5 hash: 01c9d3f698e9f6893c31fcd0b56c5fcd
MIME type:application/x-dosexec
Signature LummaStealer
File name:Comn.dll
File size:357'824 bytes
SHA256 hash: 0576fc3b0c9381c47a8a9443abdd195eebb34ece0adc5c6d17624ca0e914e8e3
MD5 hash: f76f5a566cbb5f561d26e7aca841c723
MIME type:application/x-dosexec
Signature LummaStealer
File name:NAudio.Wasapi.dll
File size:185'704 bytes
SHA256 hash: 4f2ed63257bdc650b2c276058e4d3b97cd3ed8b84abef5db8b18cb5ef28f8e15
MD5 hash: f423a27d54849dd4be4689d2320d71d3
MIME type:application/x-dosexec
Signature LummaStealer
File name:Microsoft.WebTools.Languages.Rest.VS.dll
File size:219'072 bytes
SHA256 hash: 94d44198cfea0af1beb23c9873c43e6d9cfba4da37fa3ec622fd91498c56af35
MD5 hash: 856b0fcf4d66e2ff610f4d61d45590a4
MIME type:application/x-dosexec
Signature LummaStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
malware
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2025-03-30 20:06:18 UTC
File Type:
Binary (Archive)
Extracted files:
70
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:extracted_at_0x44b
Author:cb
Description:sample - file extracted_at_0x44b.exe
Reference:Internal Research
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:with_urls
Author:Antonio Sanchez <asanchez@hispasec.com>
Description:Rule to detect the presence of an or several urls
Reference:http://laboratorio.blogs.hispasec.com/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

LummaStealer

zip be0ddf92f163c6b8eb15ce3514040bbbb9d8a7702bd1d261672eaaee3391990f

(this sample)

Comments