MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e4d9fb58159ee1189b286fc3cabde1bf180ebc46c01e78c6e41656b7a0d00cb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
LummaStealer
Vendor detections: 6
| SHA256 hash: | e4d9fb58159ee1189b286fc3cabde1bf180ebc46c01e78c6e41656b7a0d00cb2 |
|---|---|
| SHA3-384 hash: | 95daa231554b9097feb3db607b5119270dd2f38f3677bf43d4b618c26a7421154edcbb917befb85c9706431102341f25 |
| SHA1 hash: | b793a963dc4063b2481b79974906c3e9f9533b3c |
| MD5 hash: | 35dd2ebdaca625f397e0be0705acec0a |
| humanhash: | vermont-early-mirror-texas |
| File name: | The Wolf Among Us 2 instruction for YouTube partners.pdf |
| Download: | download sample |
| Signature | LummaStealer |
| File size: | 10'862'611 bytes |
| First seen: | 2024-09-06 09:33:30 UTC |
| Last seen: | 2024-12-19 00:20:06 UTC |
| File type: | |
| MIME type: | application/pdf |
| ssdeep | 196608:10KoRubVve95wzqzVQbES238lDwvQlT4sk5ydVO0MoTqAxNfnYCPmBj/1zV:1NFv8ebE9MlvHkb0MbAfYCPmBRV |
| TLSH | T1CFB633D4C6F59D5DE8C5D77BDB0A1A8C533C81C7607B0E888A9ABB020C5A5BE43B12D7 |
| Magika | |
| Reporter | |
| Tags: | dropper lumma LummaStealer pdf phishing |
devmihaylov
.PDF file used in a phishing e-mail with an embedded downloadable link leading to Dropbox URL with a .RAR file containing 6 files, 2 of which are executables and are both LummaInfostealer malware, hijacking on BitLockerToGo.EXE in order to establish connection to multiple C2 servers (14 hops in total)Intelligence
File Origin
# of uploads :
2
# of downloads :
746
Origin country :
BGVendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
Execution Infostealer Network Ransomware Stealth
Result
Verdict:
Clean
File Type:
PDF File
Verdict:
Unknown
Threat level:
2.5/10
Confidence:
89%
Tags:
action
Label:
Benign
Suspicious Score:
4/10
Score Malicious:
4%
Score Benign:
96%
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
3 / 100
Behaviour
Behavior Graph:
n/a
Score:
14%
Verdict:
Benign
File Type:
PDF
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-09-05 11:58:20 UTC
File Type:
Document
Extracted files:
12
AV detection:
8 of 23 (34.78%)
Threat level:
2/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Lumma
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Dropping
LummaStealer
Delivery method
Distributed via e-mail link
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.