General

  • Target

    Fatal.exe

  • Size

    959KB

  • Sample

    250508-ltjtlsslz7

  • MD5

    c36fdea105ecf7b4bac67dc824cb198b

  • SHA1

    6d25a994b3140ca69fd59980f7bf88236e3588f7

  • SHA256

    5253dfef2c47e3b319bf7384362fad0582582084f280e9af3e825f982d1c7b83

  • SHA512

    080154e919d9b693ece3c9d942c7a6e64ee5134ca1475eae5357ca026cbecd9dffdeb5faa0d7f992bb1a5a74e0cd2bd248a711be5e7cf7f0ba72c1e71645739d

  • SSDEEP

    24576:nYuste6M3bVFs2fu6fS+3ZLRO6LE3ZLRO6L:nU+dIyEdIy

Score
10/10

Malware Config

Extracted

Family

lumma

C2

https://fdvecturar.top/zsia

https://brandihx.run/lowp

https://viriatoe.live/laopx

https://exitiumt.digital/xane

https://opusculy.top/keaj

https://civitasu.run/werrp

https://scriptao.digital/vpep

https://praetori.live/vepr

https://disciplipna.top/eqwu

Targets

    • Target

      Fatal.exe

    • Size

      959KB

    • MD5

      c36fdea105ecf7b4bac67dc824cb198b

    • SHA1

      6d25a994b3140ca69fd59980f7bf88236e3588f7

    • SHA256

      5253dfef2c47e3b319bf7384362fad0582582084f280e9af3e825f982d1c7b83

    • SHA512

      080154e919d9b693ece3c9d942c7a6e64ee5134ca1475eae5357ca026cbecd9dffdeb5faa0d7f992bb1a5a74e0cd2bd248a711be5e7cf7f0ba72c1e71645739d

    • SSDEEP

      24576:nYuste6M3bVFs2fu6fS+3ZLRO6LE3ZLRO6L:nU+dIyEdIy

    Score
    10/10
    • Lumma Stealer, LummaC

      Lumma or LummaC is an infostealer written in C++ first seen in August 2022.

    • Lumma family

    • Suspicious use of SetThreadContext

MITRE ATT&CK Enterprise v16

Tasks

OSZAR »