General

  • Target

    2025-05-08_77ff57ebcd764ae8566f9516b8fe30cb_black-basta_cobalt-strike_ryuk_satacom

  • Size

    1.1MB

  • Sample

    250508-ns2zxadr2x

  • MD5

    77ff57ebcd764ae8566f9516b8fe30cb

  • SHA1

    4a81ee36104f6bf7e5a454fc281fda6890c19417

  • SHA256

    12b31cbce20704ce3e92338e66906c2ba2fc515cd68f19a009f08f7430a10bba

  • SHA512

    4f3c20bacb09c71a44ae147a281dd24837c1c7c1d6950e0619171feb71ac4ff5deadfd0ca828aa58e3f1dfaa770d7530aac4a09607e4a7db362b52a046fab9bf

  • SSDEEP

    24576:VzpkcOCV5wLtcM1rVzmN9szwLtcM1rVzmN9s:VzpGCUcM1rVzAcM1rVz

Score
10/10

Malware Config

Extracted

Family

lumma

C2

https://tremelzxiy.live/atok

https://stuffgull.top/qwio

https://insidegrah.run/ieop

https://homewappzb.top/tqba

https://tortoisgfe.top/paxk

https://descenrugb.bet/woap

https://grizzlqzuk.live/qhbu

https://-octalfbsh.bet/mben

https://snakejh.top/adsk

Targets

    • Target

      2025-05-08_77ff57ebcd764ae8566f9516b8fe30cb_black-basta_cobalt-strike_ryuk_satacom

    • Size

      1.1MB

    • MD5

      77ff57ebcd764ae8566f9516b8fe30cb

    • SHA1

      4a81ee36104f6bf7e5a454fc281fda6890c19417

    • SHA256

      12b31cbce20704ce3e92338e66906c2ba2fc515cd68f19a009f08f7430a10bba

    • SHA512

      4f3c20bacb09c71a44ae147a281dd24837c1c7c1d6950e0619171feb71ac4ff5deadfd0ca828aa58e3f1dfaa770d7530aac4a09607e4a7db362b52a046fab9bf

    • SSDEEP

      24576:VzpkcOCV5wLtcM1rVzmN9szwLtcM1rVzmN9s:VzpGCUcM1rVzAcM1rVz

    Score
    10/10
    • Lumma Stealer, LummaC

      Lumma or LummaC is an infostealer written in C++ first seen in August 2022.

    • Lumma family

    • Suspicious use of SetThreadContext

MITRE ATT&CK Enterprise v16

Tasks

OSZAR »