Edit tour
Windows
Analysis Report
file.exe
Overview
General Information
Detection
LummaC
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Yara detected LummaC Stealer
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Creates autostart registry keys with suspicious names
Found Tor onion address
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
LummaC encrypted strings found
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Sigma detected: Execution from Suspicious Folder
Sigma detected: New RUN Key Pointing to Suspicious Folder
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses known network protocols on non-standard ports
Writes to foreign memory regions
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Searches for user specific document files
Sigma detected: CurrentVersion Autorun Keys Modification
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match
Classification
- System is w10x64
- file.exe (PID: 6388 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 817C11005CA185252E666C25769A2591) - BitLockerToGo.exe (PID: 2992 cmdline:
C:\Windows \BitLocker DiscoveryV olumeConte nts\BitLoc kerToGo.ex e MD5: A64BEAB5D4516BECA4C40B25DC0C1CD8) - Z914UZ05TWILZJPY6FFQ8Q.exe (PID: 3004 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\Z914UZ 05TWILZJPY 6FFQ8Q.exe " MD5: 29E57E917FDBA537D4D31A6F12A1A9BC) - BitLockerToGo.exe (PID: 5752 cmdline:
C:\Windows \BitLocker DiscoveryV olumeConte nts\BitLoc kerToGo.ex e MD5: A64BEAB5D4516BECA4C40B25DC0C1CD8)
- (29e57e917fdba537d4d31a6f12a1a9bc)Z914UZ05TWILZJPY6FFQ8Q.exe (PID: 6992 cmdline:
"C:\Users\ Public\Acc ountPictur es\(29e57e 917fdba537 d4d31a6f12 a1a9bc)Z91 4UZ05TWILZ JPY6FFQ8Q. exe" MD5: 29E57E917FDBA537D4D31A6F12A1A9BC) - BitLockerToGo.exe (PID: 2656 cmdline:
C:\Windows \BitLocker DiscoveryV olumeConte nts\BitLoc kerToGo.ex e MD5: A64BEAB5D4516BECA4C40B25DC0C1CD8) - WerFault.exe (PID: 1276 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 2 656 -s 412 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- (29e57e917fdba537d4d31a6f12a1a9bc)Z914UZ05TWILZJPY6FFQ8Q.exe (PID: 1196 cmdline:
"C:\Users\ Public\Acc ountPictur es\(29e57e 917fdba537 d4d31a6f12 a1a9bc)Z91 4UZ05TWILZ JPY6FFQ8Q. exe" MD5: 29E57E917FDBA537D4D31A6F12A1A9BC) - BitLockerToGo.exe (PID: 2356 cmdline:
C:\Windows \BitLocker DiscoveryV olumeConte nts\BitLoc kerToGo.ex e MD5: A64BEAB5D4516BECA4C40B25DC0C1CD8) - WerFault.exe (PID: 3672 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 2 356 -s 412 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Lumma Stealer, LummaC2 Stealer | Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell. | No Attribution |
{"C2 url": ["wifeplasterbakewis.shop", "mealplayerpreceodsju.shop", "bordersoarmanusjuw.shop", "suitcaseacanehalk.shop", "absentconvicsjawun.shop", "pushjellysingeywus.shop", "economicscreateojsu.shop", "entitlementappwo.shop", "stripmarrystresew.shop"], "Build id": "DIJQ6z--"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_LummaCStealer_3 | Yara detected LummaC Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Msfpayloads_msf_9 | Metasploit Payloads - file msf.war - contents | Florian Roth |
| |
Msfpayloads_msf_9 | Metasploit Payloads - file msf.war - contents | Florian Roth |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Msfpayloads_msf_9 | Metasploit Payloads - file msf.war - contents | Florian Roth |
| |
Click to see the 3 entries |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems), Tim Shelton: |
Source: | Author: Florian Roth (Nextron Systems), Markus Neis, Sander Wiebing: |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp: | 04/21/24-04:17:19.927912 |
SID: | 2855478 |
Source Port: | 49746 |
Destination Port: | 30001 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 04/21/24-04:17:20.718735 |
SID: | 2855539 |
Source Port: | 21195 |
Destination Port: | 49747 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 04/21/24-04:17:50.707667 |
SID: | 2855538 |
Source Port: | 21195 |
Destination Port: | 49747 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 04/21/24-04:17:42.144684 |
SID: | 2855478 |
Source Port: | 49749 |
Destination Port: | 30001 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 04/21/24-04:17:20.718951 |
SID: | 2855536 |
Source Port: | 49747 |
Destination Port: | 21195 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 04/21/24-04:17:32.110131 |
SID: | 2855478 |
Source Port: | 49748 |
Destination Port: | 30001 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 04/21/24-04:17:50.473675 |
SID: | 2855537 |
Source Port: | 49747 |
Destination Port: | 21195 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Code function: | 2_2_02F35B57 |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 2_2_02F37239 | |
Source: | Code function: | 2_2_02F2F7CD | |
Source: | Code function: | 2_2_02F35390 | |
Source: | Code function: | 2_2_02F3347E | |
Source: | Code function: | 2_2_02F3403B | |
Source: | Code function: | 2_2_02F29D20 | |
Source: | Code function: | 2_2_02F376E1 | |
Source: | Code function: | 2_2_02F2FED9 | |
Source: | Code function: | 2_2_02F2D2C0 | |
Source: | Code function: | 2_2_02F3B2A0 | |
Source: | Code function: | 2_2_02F36E69 | |
Source: | Code function: | 2_2_02F37A78 | |
Source: | Code function: | 2_2_02F36A62 | |
Source: | Code function: | 2_2_02F35216 | |
Source: | Code function: | 2_2_02F37BF5 | |
Source: | Code function: | 2_2_02F30F4D | |
Source: | Code function: | 2_2_02F31739 | |
Source: | Code function: | 2_2_02F33722 | |
Source: | Code function: | 2_2_02F34F10 | |
Source: | Code function: | 2_2_02F30C5B | |
Source: | Code function: | 2_2_02F225E0 | |
Source: | Code function: | 2_2_02F36582 | |
Source: | Code function: | 2_2_02F3B930 |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | String found in binary or memory: |