🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e4a158d2103e24a8d05070425c062dda66fac4ef982117009865af6c18b0c71f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 16


Intelligence 16 IOCs YARA 1 File information Comments 1

SHA256 hash: e4a158d2103e24a8d05070425c062dda66fac4ef982117009865af6c18b0c71f
SHA3-384 hash: ca991e4d7965a432f6608c98f6d27c41a170f93374bc9eb520f990b57140bce0d910e076ad287b296075d0a60766006c
SHA1 hash: 70e4a9834a0968fdb4df5b4f96c723e21f8bcc17
MD5 hash: c48a26db30cbcdea8a59f5f85abc606d
humanhash: july-carbon-bluebird-foxtrot
File name:random.exe
Download: download sample
Signature LummaStealer
File size:1'891'840 bytes
First seen:2025-02-07 15:39:07 UTC
Last seen:2025-02-07 16:29:37 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 2eabe9054cad5152567f0699947a2c5b (2'861 x LummaStealer, 1'312 x Stealc, 1'026 x Healer)
ssdeep 24576:MtajJyTCp8nrVwiiHIgydiLhcJQUJH5GCiSUsuDBm+ZLJbTl07ijhG90eXlXIjTN:YaVyFOHIgygtTIAPFJb+7ijDeVQFtp
TLSH T1239533A4A81B26C1CE280C785A620056A4517A714DDF8DC77A4DF2362F6FFDA83F0D78
TrID 42.7% (.EXE) Win32 Executable (generic) (4504/4/1)
19.2% (.EXE) OS/2 Executable (generic) (2029/13)
19.0% (.EXE) Generic Win/DOS Executable (2002/3)
18.9% (.EXE) DOS Executable Generic (2000/1)
Magika pebin
Reporter aachum
Tags:9c9aa5 Amadey exe LummaStealer


Avatar
iamaachum
http://185.215.113.16/luma/random.exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
473
Origin country :
ES ES
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
random.exe
Verdict:
Malicious activity
Analysis date:
2025-02-07 15:53:12 UTC
Tags:
amadey botnet stealer loader themida lumma telegram exfiltration autoit remote xworm crypto-regex ims-api generic redline lefthook stealc credentialflusher gcleaner vidar auto

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
autorun lien spam
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
Searching for analyzing tools
Connection attempt to an infection source
Using the Windows Management Instrumentation requests
Query of malicious DNS domain
Sending a TCP request to an infection source
Malware family:
LummaC2 Stealer
Verdict:
Malicious
Result
Threat name:
Amadey, Cryptbot, LummaC Stealer, PureLo
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Creates HTML files with .exe extension (expired dropper behavior)
Creates multiple autostart registry keys
Detected unpacking (changes PE section rights)
Drops PE files with a suspicious file extension
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Potentially malicious time measurement code found
Protects its processes via BreakOnTermination flag
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Sigma detected: New RUN Key Pointing to Suspicious Folder
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Writes to foreign memory regions
Yara detected Amadey
Yara detected Amadeys stealer DLL
Yara detected Cryptbot
Yara detected LummaC Stealer
Yara detected PureLog Stealer
Yara detected Telegram RAT
Yara detected UAC Bypass using CMSTP
Yara detected Vidar stealer
Yara detected XWorm
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1609504 Sample: random.exe Startdate: 07/02/2025 Architecture: WINDOWS Score: 100 119 Found malware configuration 2->119 121 Malicious sample detected (through community Yara rule) 2->121 123 Antivirus detection for URL or domain 2->123 125 22 other signatures 2->125 8 skotes.exe 4 105 2->8         started        13 random.exe 1 2->13         started        process3 dnsIp4 61 185.215.113.43 WHOLESALECONNECTIONSNL Portugal 8->61 63 185.215.113.97 WHOLESALECONNECTIONSNL Portugal 8->63 49 C:\Users\user\AppData\...\b6eea6c95f.exe, PE32 8->49 dropped 51 C:\Users\user\AppData\...\63b072183d.exe, PE32 8->51 dropped 53 C:\Users\user\AppData\...\ec26d009e3.exe, PE32 8->53 dropped 57 47 other malicious files 8->57 dropped 127 Creates multiple autostart registry keys 8->127 129 Hides threads from debuggers 8->129 131 Tries to detect sandboxes / dynamic malware analysis system (registry check) 8->131 133 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 8->133 15 7fOMOTQ.exe 8->15         started        19 938497fc21.exe 8->19         started        21 b9504b08e4.exe 8->21         started        26 11 other processes 8->26 65 185.215.113.16 WHOLESALECONNECTIONSNL Portugal 13->65 67 188.114.97.3 CLOUDFLARENETUS European Union 13->67 55 C:\Users\user\...\H270CKK518PTA77A3KEU.exe, PE32 13->55 dropped 135 Detected unpacking (changes PE section rights) 13->135 137 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 13->137 139 Query firmware table information (likely to detect VMs) 13->139 141 4 other signatures 13->141 23 H270CKK518PTA77A3KEU.exe 4 13->23         started        file5 signatures6 process7 dnsIp8 83 104.21.0.135 CLOUDFLARENETUS United States 15->83 93 Multi AV Scanner detection for dropped file 15->93 95 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 15->95 97 Query firmware table information (likely to detect VMs) 15->97 99 Tries to detect sandboxes and other dynamic analysis tools (window names) 15->99 85 172.67.139.144 CLOUDFLARENETUS United States 19->85 115 3 other signatures 19->115 101 Injects a PE file into a foreign processes 21->101 28 b9504b08e4.exe 21->28         started        32 WerFault.exe 21->32         started        47 C:\Users\user\AppData\Local\...\skotes.exe, PE32 23->47 dropped 103 Detected unpacking (changes PE section rights) 23->103 105 Tries to evade debugger and weak emulator (self modifying code) 23->105 117 2 other signatures 23->117 34 skotes.exe 23->34         started        87 37.27.182.109 UNINETAZ Iran (ISLAMIC Republic Of) 26->87 89 149.154.167.99 TELEGRAMRU United Kingdom 26->89 91 7 other IPs or domains 26->91 107 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 26->107 109 Writes to foreign memory regions 26->109 111 Allocates memory in foreign processes 26->111 113 Potentially malicious time measurement code found 26->113 36 RegAsm.exe 26->36         started        38 uniq.exe 26->38         started        40 L65uNi1.exe 26->40         started        42 8 other processes 26->42 file9 signatures10 process11 dnsIp12 69 104.21.38.167 CLOUDFLARENETUS United States 28->69 143 Query firmware table information (likely to detect VMs) 28->143 145 Tries to harvest and steal ftp login credentials 28->145 147 Tries to harvest and steal browser information (history, passwords, etc) 28->147 71 20.42.65.92 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 32->71 149 Detected unpacking (changes PE section rights) 34->149 151 Creates HTML files with .exe extension (expired dropper behavior) 34->151 153 Tries to evade debugger and weak emulator (self modifying code) 34->153 163 3 other signatures 34->163 73 95.216.115.242 HETZNER-ASDE Germany 36->73 79 2 other IPs or domains 36->79 155 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 36->155 157 Protects its processes via BreakOnTermination flag 36->157 75 104.21.48.1 CLOUDFLARENETUS United States 38->75 159 Tries to steal Crypto Currency Wallets 38->159 77 104.21.94.205 CLOUDFLARENETUS United States 40->77 81 3 other IPs or domains 42->81 59 C:\Users\user\AppData\...\Macromedia.com, PE32 42->59 dropped 161 Drops PE files with a suspicious file extension 42->161 45 conhost.exe 42->45         started        file13 signatures14 process15
Threat name:
Win32.Trojan.LummaC
Status:
Malicious
First seen:
2025-02-07 15:40:18 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
lummastealer
Similar samples:
Result
Malware family:
Score:
  10/10
Tags:
family:amadey family:asyncrat family:healer family:lumma family:redline family:sectoprat family:stealc family:stormkitty family:vidar family:xworm botnet:9c9aa5 botnet:cheat botnet:default botnet:reno bootkit credential_access defense_evasion discovery dropper evasion execution infostealer persistence pyinstaller rat spyware stealer trojan
Behaviour
Suspicious use of WriteProcessMemory
Suspicious use of SendNotifyMessage
Suspicious use of FindShellTrayWindow
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious behavior: EnumeratesProcesses
Scheduled Task/Job: Scheduled Task
Modifies system certificate store
Modifies data under HKEY_USERS
Modifies Internet Explorer settings
Kills process with taskkill
Enumerates system info in registry
Delays execution with timeout.exe
Checks processor information in registry
System Location Discovery: System Language Discovery
Program crash
Enumerates physical storage devices
Detects Pyinstaller
Browser Information Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Suspicious use of NtSetInformationThreadHideFromDebugger
Enumerates processes with tasklist
AutoIT Executable
Writes to the Master Boot Record (MBR)
Checks installed software on the system
Adds Run key to start application
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks computer location settings
.NET Reactor proctector
Checks BIOS information in registry
Windows security modification
Executes dropped EXE
Identifies Wine through registry keys
Loads dropped DLL
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Blocklisted process makes network request
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Uses browser remote debugging
Identifies VirtualBox via ACPI registry values (likely anti-VM)
Xworm family
Xworm
Vidar family
Vidar
Stormkitty family
StormKitty payload
StormKitty
Stealc family
Stealc
Sectoprat family
SectopRAT payload
SectopRAT
Redline family
RedLine
Modifies Windows Defender notification settings
Modifies Windows Defender TamperProtection settings
Modifies Windows Defender Real-time Protection settings
Modifies Windows Defender DisableAntiSpyware settings
Lumma family
Lumma Stealer, LummaC
Healer family
Healer
Detects Healer an antivirus disabler dropper
Detect Xworm Payload
Detect Vidar Stealer
Asyncrat family
AsyncRat
Amadey family
Amadey
Malware Config
C2 Extraction:
http://185.215.113.115
http://185.215.113.43
https://paleboreei.biz/api
https://cozyhomevpibes.cyou/api
https://rampnatleadk.click/api
103.84.89.222:33791
159.100.19.137:7707
https://t.me/sok33tn
https://steamcommunity.com/profiles/76561199824159981
127.0.0.1:33333
95.216.115.242:33333
Dropper Extraction:
http://185.215.113.16/defend/random.exe
http://185.215.113.16/mine/random.exe
Verdict:
Malicious
Tags:
lumma_stealer lumma c2 stealer
YARA:
n/a
Unpacked files
SH256 hash:
e4a158d2103e24a8d05070425c062dda66fac4ef982117009865af6c18b0c71f
MD5 hash:
c48a26db30cbcdea8a59f5f85abc606d
SHA1 hash:
70e4a9834a0968fdb4df5b4f96c723e21f8bcc17
SH256 hash:
802e496ab24bfeb7a16f526f7eb9091e5fe14db046e71d6fcdc58a7083aa4ec5
MD5 hash:
bf2fab1a7b19ee515c6fe238c40c5c17
SHA1 hash:
b079a9c9af1ff20982a164e987e6f065c92f1bd4
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LummaStealer

Executable exe e4a158d2103e24a8d05070425c062dda66fac4ef982117009865af6c18b0c71f

(this sample)

  
Dropped by
Amadey
  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical

Comments



Avatar
commented on 2025-02-07 15:40:45 UTC

Amadey C2: http://185.215.113.43/Zu7JuNko/index.php
Amadey Botnet: 9c9aa5