🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e4d9fb58159ee1189b286fc3cabde1bf180ebc46c01e78c6e41656b7a0d00cb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LummaStealer


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e4d9fb58159ee1189b286fc3cabde1bf180ebc46c01e78c6e41656b7a0d00cb2
SHA3-384 hash: 95daa231554b9097feb3db607b5119270dd2f38f3677bf43d4b618c26a7421154edcbb917befb85c9706431102341f25
SHA1 hash: b793a963dc4063b2481b79974906c3e9f9533b3c
MD5 hash: 35dd2ebdaca625f397e0be0705acec0a
humanhash: vermont-early-mirror-texas
File name:The Wolf Among Us 2 instruction for YouTube partners.pdf
Download: download sample
Signature LummaStealer
File size:10'862'611 bytes
First seen:2024-09-06 09:33:30 UTC
Last seen:2024-12-19 00:20:06 UTC
File type: pdf
MIME type:application/pdf
ssdeep 196608:10KoRubVve95wzqzVQbES238lDwvQlT4sk5ydVO0MoTqAxNfnYCPmBj/1zV:1NFv8ebE9MlvHkb0MbAfYCPmBRV
TLSH T1CFB633D4C6F59D5DE8C5D77BDB0A1A8C533C81C7607B0E888A9ABB020C5A5BE43B12D7
Magika pdf
Reporter devmihaylov
Tags:dropper lumma LummaStealer pdf phishing


Avatar
devmihaylov
.PDF file used in a phishing e-mail with an embedded downloadable link leading to Dropbox URL with a .RAR file containing 6 files, 2 of which are executables and are both LummaInfostealer malware, hijacking on BitLockerToGo.EXE in order to establish connection to multiple C2 servers (14 hops in total)

Intelligence


File Origin
# of uploads :
2
# of downloads :
746
Origin country :
BG BG
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
Execution Infostealer Network Ransomware Stealth
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
89%
Tags:
action
Label:
Benign
Suspicious Score:
4/10
Score Malicious:
4%
Score Benign:
96%
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
3 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-09-05 11:58:20 UTC
File Type:
Document
Extracted files:
12
AV detection:
8 of 23 (34.78%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

LummaStealer

pdf e4d9fb58159ee1189b286fc3cabde1bf180ebc46c01e78c6e41656b7a0d00cb2

(this sample)

  
Dropping
LummaStealer
  
Delivery method
Distributed via e-mail link

Comments