Dropped Files | ZeroBOX
Name 696df4047d493365_goopdateres_ro.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ro.dll
Size 52.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 1fa704e367a641656e04c2be4784978f
SHA1 3d3b2cfdb60530b04a5d6022009f0ec1ea61cb72
SHA256 696df4047d493365a2d9939e3d1d9fdb565a8881be2492acec2e58ae36b9765f
CRC32 0E35B839
ssdeep 768:M3CRNNDM7qm0GdVqT541naEpoLvPxWEA9LRKPxWEP8:MldVqlcafPxOKPxO
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name ebbfe3456d8034e8_goopdateres_fi.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_fi.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 04bd5ba759f82c8427bb431c86cc9083
SHA1 c267855e91408309a566677fcfc7b50f0a9ece61
SHA256 ebbfe3456d8034e81ab099053e9505c64a9c3ec9e1850b588364fd55e9074cc2
CRC32 D0F2C294
ssdeep 384:ubgXtfEzPhXY7RzYd99hKh1GAVLOZsHLoGVuPxh8E9VF0NywCWbLOZsHLo3UPxhA:tXtfEVmKghLL8PxWEevfLJPxWENBA
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name e44154e058b00e0d_goopdateres_uk.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_uk.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c9732d030a45d8e4931a152f72315fbc
SHA1 ea50ab22762d340d9875946b9ab154f480e3a0d2
SHA256 e44154e058b00e0d0e0fc76dbfbb484c1036c1ce801910894b3ad3a3687a4ae4
CRC32 DAF38D17
ssdeep 384:utGmWKgHWyC2EeovVHE/Gfu7LOZsHL42yu6Pxh8E9VF0Ny4boLOZsHLwyMPxh8EE:NmW2u/LePxWESELAPxWEcp5J
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 6e1bc1b363d90bf0_goopdateres_fr.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_fr.dll
Size 53.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 bb9c0590a950d61a376f2f1fdeb799a3
SHA1 f1c3646f75c8743095a3bccc6aceeeb2d81aeb29
SHA256 6e1bc1b363d90bf040d945b46a6a1353be86d5e0f131c49a93a7431af84f4272
CRC32 52F43117
ssdeep 384:uUc/98EoycpW4xkLOZsHLMEgPxh8E9VF0NyzrTiPCLOZsHLwPPxh8E9VF0NyUHI0:k/aycN0LRgPxWEVpLQPxWE2wnu
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 1348910f8716135b_goopdateres_vi.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_vi.dll
Size 51.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c2bdedd6bfad9b7119813fe36e34f91c
SHA1 4cf7c1cd145e5ac7c05e98654f20b620ea32bdcf
SHA256 1348910f8716135bc28ce247d50880263f9c97b115f27a01181ceed87f3996d8
CRC32 4426C946
ssdeep 384:uIUBMKFjncDLOZsHLo0MPxh8E9VF0NyluySOYnLOZsHLojbYPxh8E9VF0Ny3VLz:MBMKVcnLCPxWE//6LkYPxWEtF
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name ac39536c7e1e4309_goopdateres_sl.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sl.dll
Size 52.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 a90732b2ee0641960117fa56d0742170
SHA1 13f37d290afcfa287fb45e4d1f15f39cac27cc6e
SHA256 ac39536c7e1e43096342f26c91dbd9831ca83a1caa839483fef4918e7e0579c8
CRC32 1B4E03CD
ssdeep 384:urHnTsshVyigOHHTpWBdH1i2IXouswLOZsHL4UZZPxh8E9VF0NygZlVLOZsHLwBI:GuhOHHy1YZsALxPxWE6fhLOPxWEAR
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 9f31017dc56bffe3_goopdateres_pt-pt.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_pt-PT.dll
Size 52.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 bff8ad68557b2c980942e4aa2b67e997
SHA1 68679101e2b53c4cb0738a4c9399b0d9f1c04169
SHA256 9f31017dc56bffe3fe6b3258353b4bd20d878e08238ff5e0a62c51955e9185ac
CRC32 B6C4A561
ssdeep 384:uU4MestnEx6ewBsLOZsHL4cCPxh8E9VF0NyShJDCLOZsHLoAjhZPxh8E9VF0NyS8:bvEx/U8L4PxWEor+L/hZPxWEyA
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 96bcec06264976f3_2d85f72862b55c4eadd9e66e06947f3d
Submit file
Filepath C:\Users\test22\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Size 1.4KB
Processes 3056 (LumuUpdate.exe)
Type data
MD5 0cd2f9e0da1773e9ed864da5e370e74e
SHA1 cabd2a79a1076a31f21d253635cb039d4329a5e8
SHA256 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
CRC32 65E5A5B2
ssdeep 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1
Yara None matched
VirusTotal Search for analysis
Name 7d7a37615bbf20af_goopdateres_ca.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ca.dll
Size 53.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 4557561cbec7963f895afa98da1d5a1b
SHA1 a0050143d5f175f30dff846cda5ca8838c64d871
SHA256 7d7a37615bbf20af1e71f717ed7c491b6a614f3a01f95b7a6d4452b3f219b8d0
CRC32 2F999C01
ssdeep 384:uRzf2ArzVuRm4bPmLOZsHLM0LPxh8E9VF0NymViYLOZsHLwqYPxh8E9VF0NyPBOS:4f2ArBup2LTLPxWEYgoLkPxWEVTH/
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name c51f644954057ded_goopdateres_is.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_is.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 757d4fa4492897956c4fb14f55208d3d
SHA1 81656bfa178c996fe3450ad1a4b4affea501069f
SHA256 c51f644954057ded7cb30fbb6447b374a9d24b3c70d4af11e38833416990404b
CRC32 D478F65C
ssdeep 768:CH6ibAIErkUVQF5UefV3eLJPxWEYQVlLOPxWEeD/:CH6ibAIErkUVurfVAPxJVwPxu
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name c3a122bb09b93e79_goopdateres_ur.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ur.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 8f295d24f7be8b310961b1bf4de5b20a
SHA1 810dacdb9ba82a49df51dc11b9ce32fd411137e9
SHA256 c3a122bb09b93e7952cf6158d72d9a4c7fd10552ba07e4360ac1a519ae459549
CRC32 286139C6
ssdeep 768:M5Q4+OmAcoWACeesY6LIYPxWEwMLFPxWEWa:MBPxfPxj
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 3ef3490526a1ec52_goopdateres_ar.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ar.dll
Size 50.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 3fd0013c775d4dabfe00c2b5f8015911
SHA1 3648e162032abc6a2d9484202a4183bc5250010b
SHA256 3ef3490526a1ec52cd782f8c3b878f0af771717e957609bdfdd1f90664145168
CRC32 D9F17A52
ssdeep 384:uaMfdkCLu+JG9LOZsHLMc4Pxh8E9VF0NyDW3i60LOZsHLwNPxh8E9VF0Ny7IZ/I:yfdkCLd4LT4PxWEJJLiPxWEVgI
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 3ca294e903f4b170_goopdateres_pt-br.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_pt-BR.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 23a9d4aebea01e05dd7dc47983396984
SHA1 60e3048ad5c9f9f4e4bba906d73be282838b8531
SHA256 3ca294e903f4b1707463f5f5442587d0e2932797522c7a983bf6b03b3cfbd118
CRC32 41B918D3
ssdeep 384:ujX8lZcOZX8bLOZsHLoHqr0WPxh8E9VF0Nyjl7PLOZsHLo2Pxh8E9VF0NyhIY:AMbgfL5JPxWElRLHPxWE3L
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 4bfe3385d92e83bc_goopdateres_lv.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_lv.dll
Size 52.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 8e30985704359cc2d1fb0405d611c7ae
SHA1 c9ec64c06da4e037f5c0e84cfd6ece8d70df54ae
SHA256 4bfe3385d92e83bcc788cb7af178044109e490b6b5a34581de5b3807eb68d9a1
CRC32 8930ECFC
ssdeep 384:uF5H5yAxOeK6eBLOZsHLMMcPxh8E9VF0NymT61LOZsHLwUfuPxh8E9VF0NyE/UQ:uXutLcPxWE8eBL3fuPxWEuF
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name e6b0cee5118fad29_goopdateres_mr.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_mr.dll
Size 53.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 5183cd6a0d31baf1359770912acb2457
SHA1 cd3406520df7f6e21fe6a855efb6b86f8bbf43ff
SHA256 e6b0cee5118fad29f2766c444e88127896a203f2dc7deeaec46f029eb9e2363a
CRC32 851626FD
ssdeep 384:ujqid4/7JK7bABk5LOZsHL49PPxh8E9VF0Ny/ZvSvLOZsHLwbuLPxh8E9VF0Ny5M:344/7JK7b5lLgPxWENZCLJPxWEbC+W
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 154f2a264282a5c5_lumuupdatecomregistershell64.exe
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuUpdateComRegisterShell64.exe
Size 183.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 f7e30234a03bba86c0460055a7199d0c
SHA1 630a3c4bbbf3affc9ea3357be7500ef7c9b2a84e
SHA256 154f2a264282a5c5fc045c3e82f65255200efcf293a7681ae5b74bf991692625
CRC32 45B7AEB2
ssdeep 3072:zXU6EZe7CmXRU269IQNHtpEb6JaZokcHC0ZpMJ8xoY46tBmPEn+9o/JxMx8:zXU6E8Omhr69IGHtaTNkohlBI
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name a911cb0603b54f57_goopdateres_de.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_de.dll
Size 54.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 9058651a07f241dc8d3df2c1f46354a9
SHA1 bb874dc8021639dc7e1c8fd466619ae875d8785c
SHA256 a911cb0603b54f57850f66b84732d08d13d99dc69f5a7d580cd0e5d6515f72d8
CRC32 19094310
ssdeep 384:u7mBUM8QtPM0Me6INK/AELOZsHLokblWjPxh8E9VF0NysjS+LOZsHLoHqPxh8E9p:bnjMePsAULZMjPxWEujLLrPxWE8Y
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name a601890580ba6542_lumucrashhandler.exe
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuCrashHandler.exe
Size 302.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ac6ca129d6654a39eda04f14f0e3bf6d
SHA1 7c62f411015420093f5d7daf61395c796366307c
SHA256 a601890580ba6542ae8c2adac95536d80a4c00a46e6313eaafa4c86f7464b804
CRC32 D6F5314F
ssdeep 6144:8E32p2bSW67XMp0OQKqFb+ajYcN6ORyJF7qAsAOmA0yYQu40h+lVpE9:8E3vbp67s0bKqFb+ajYcN6ORMqlgA0y2
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 50a5d9278b2a3eea_goopdateres_ta.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ta.dll
Size 54.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 042f63de8b6655bc80564ea93e0a0c9f
SHA1 a640bb6e7e5b4843f6cfa2bd393b25762f1465a7
SHA256 50a5d9278b2a3eea23e02f68e169609fa558834f1c5e065f9e286082da2406b0
CRC32 30113F65
ssdeep 384:umQiwsY51ZLm+4Hw/LOZsHL4ItPxh8E9VF0NyyOZl7LOZsHLw+iPxh8E9VF0Ny81:uiXY51ZLm+4HwDLzPxWEYIl/LoPxWEe1
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 1294ba913a902d01_goopdateres_bn.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_bn.dll
Size 53.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 f9f4e76c8a78df027d6f7e03d54a0959
SHA1 e42dca2a320be8ece1bba294345f8e15ae6ca4dd
SHA256 1294ba913a902d01aaa7a14cbc9d6a6d797c846a9205f477718fff83305ede6e
CRC32 29DEFDF5
ssdeep 384:u05i5vUx7tYF7qKF0FrHF6zjbmBw2LOZsHLoXRtTPxh8E9VF0Nyq42owLOZsHLoG:A5rlF0FrF3BwGLEzPxWEYjBLsPxWEeJ
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name de9311b5dfb1d2b9_goopdateres_hi.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_hi.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 f6c78f1c334949cea31eb6ed91edead4
SHA1 55d04b9cd8384c6c90786dbbdb7f4025bd61450a
SHA256 de9311b5dfb1d2b96e86684079f103e6af053b875a53e9fe22893207ce934c99
CRC32 AA1B2054
ssdeep 768:aSh6AN6AQqjexbyqKXhHqCPLAPxWEoUCLOIPxWEusH:aSBXePxHtIPxr
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name aaa538665663ffb2_goopdateres_zh-cn.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_zh-CN.dll
Size 46.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 873ec5d3f914603ac858ddc671b36982
SHA1 3edfda7a49fa58279635b1a29e0947ce8d7aabfb
SHA256 aaa538665663ffb2534074d5e10a928459b8fc4b0422e029fd19e04db82b3ea2
CRC32 D2F971A5
ssdeep 384:uEjr5shAWBmLOZsHL4AfLPxh8E9VF0NylzYCLOZsHLws6Pxh8E9VF0Ny3Ar8KN:3YAWB2LnDPxWErUSLn6PxWEpAAKN
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name c5e67915d47f7b09_goopdateres_en-gb.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_en-GB.dll
Size 51.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 cc4ac8050e7da4462bf44ad8276fbc2f
SHA1 545a36c5281963405f5c8002a62954799f60b4d8
SHA256 c5e67915d47f7b0961bc77024aa9365a2ff64528cdc7c7d04a160b69cce9b88f
CRC32 F77C4170
ssdeep 384:uPplagyh6QuVLOZsHLogIYPxh8E9VF0NyeeQjLOZsHLoj8Pxh8E9VF0NyVi9:glagyhihLnPxWE4HHLBPxWEHg
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name b08956de3d47c542_goopdateres_gu.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_gu.dll
Size 53.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 d767406637ca48c1baae24f826f36aff
SHA1 9720029e9f3e7554e13de321768d0e558b401e43
SHA256 b08956de3d47c5421c6b9aacc53761049f97cccfb3ab382d3c4dfce8163f015c
CRC32 43DCCF77
ssdeep 384:uafi3UreAV4DnYCRfwmkIzLOZsHLobnJZfPxh8E9VF0NydlcSSLOZsHLo5Pxh8E6:RAUre7hbXLm1PxWE32RLMPxWEaxp
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name a25c60fc2b71ccaf_goopdateres_zh-tw.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_zh-TW.dll
Size 46.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 3760533805b558056e8ca8a88738426e
SHA1 495a3ba90505923c9145309ce914f3034f857094
SHA256 a25c60fc2b71ccafeb79763e8098c2a351746c314bb9395e9612e5bf21efcd72
CRC32 27AD1F34
ssdeep 384:uMTvb9GBnLOZsHLMw/Pxh8E9VF0Nyu6IkvrLOZsHLwtPxh8E9VF0Nyox5Z:Xv+LLvPxWEkYvL+PxWEaF
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name fc037085c501fddb_goopdateres_ru.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ru.dll
Size 51.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 499ac2fe7e722aa2b0d20836bc8a7c3d
SHA1 f45989d39294ca7d45fe5b0348aeefa3d89dc2d0
SHA256 fc037085c501fddb3e082ddae64e8b3c4a5bfa342bf9a0f3a245f6a673af8747
CRC32 FA2A04CB
ssdeep 384:u0paFA47AvHlho4d2HLOZsHLo0sGPxh8E9VF0NyfDcPLOZsHLonPxh8E9VF0NyyV:13vHUrLqGPxWE9QTLuPxWELU
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 4881ffa616930737_goopdateres_sw.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sw.dll
Size 53.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 701aa669cd63d4d4d57a365773abf314
SHA1 938a3919deecef7a4cdffdabf14526f0a7b12f66
SHA256 4881ffa61693073745a7954a2999971566c1933f3c636423c873f9f8ed1fabbe
CRC32 9C8C30D0
ssdeep 384:uLQlgicgiY7upr4M5tLOZsHL4J3MPxh8E9VF0NyBh3D9CrLOZsHLoyPxh8E9VF0q:1lQ07Gr4M5ZLWMPxWEndcvLbPxWEVOOj
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name f421936406fa085e_goopdateres_id.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_id.dll
Size 51.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 888a6103b0201fbb3aad322fbe1ca272
SHA1 fb72572f2f30f4f86dbcdf5d25a4ba613e36e89b
SHA256 f421936406fa085e9450ca4c23c4201af371a0805d7ab639eab6d1b63ddb4af9
CRC32 4E5F8A2C
ssdeep 384:uYQBL3THRNkAHqQ3lFRf2I9ByrULLOZsHLoI/WPxh8E9VF0NyYWJSLOZsHLoeQ/n:Y3hR5PLSPxWEyhLCPxWEK6
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 159f8ffb7e0b52f2_psuser.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\psuser.dll
Size 275.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 dc9a0b59d7d0171c131290cbfeed9960
SHA1 9bd93e3f4829c2524ce61d75a01ca3dc4eddf1df
SHA256 159f8ffb7e0b52f239b536ad20960227f6f0e4ba23c045c4cb61f50be32b2e15
CRC32 36DE2D15
ssdeep 6144:Q+BXgGk0dl+kdR4vOYTPFhIzBiA9oD5qAO+hBzpKyiS+YsWh08R:QqQGk0dl+qmvOYTPFhIzBix5qYHNKA0c
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 3203e18fa0528245_goopdateres_bg.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_bg.dll
Size 53.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 275ef31d96299f14795c04c8a26cfa22
SHA1 6428822f1d85d29ccb22d1b41fb321003f062f82
SHA256 3203e18fa052824598822b4ded8233e6bcb4cbd1014ef0682fd0edebaa7db41c
CRC32 860DB4BE
ssdeep 384:uPTEdckbeGZBOcALOZsHLMqPxh8E9VF0Ny5q1SLOZsHLwtUMPxh8E9VF0Ny0Yoc:+EV7DQL9PxWEnciLZMPxWEes
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name be6af7027ecacb76_lumuupdatecore.exe
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuUpdateCore.exe
Size 221.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 dca16e5baf4bb818c200cd224b3d9966
SHA1 c08b57a48e5b51630e5dcb7cda62091e115978c7
SHA256 be6af7027ecacb7662d206df305e97da4edf4d2311125917ddf4100c97bf9173
CRC32 7BB4C4FF
ssdeep 6144:xMfa64F5code2LIGeW7U4M3I9K0AAObjI3ECYMPh+cPVb:Wfa64F5code2LIGeW7UhIc0AxjIZYehL
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name d3806a24302213b5_lumuupdate.exe
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuUpdate.exe
Size 167.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 5898750d5773d2fe862a005794b8587d
SHA1 5eceaf65a358e2b6fe71d0db40863798926f9d17
SHA256 d3806a24302213b5bb7b12f6e46ec45d4107fdb38872f0f2020278e931849e8b
CRC32 9E8A3320
ssdeep 3072:DUl1WFu5iPZaXrUoErcud21F8wWLqioVLiqW2B+suLRAhpaVTCIvuYHV7D07hPpR:3u0PZaXrUoStwdzpB+E
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name ae981d48233dcebe_gutf00e.tmp
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUTF00E.tmp
Size 6.5MB
Processes 2580 (lum_agent_online.exe)
Type POSIX tar archive (GNU)
MD5 9ab5daafb76def62284d803dbaa71e83
SHA1 eefd6289b1d332498435d8a21bdaeebbc5cba4c2
SHA256 ae981d48233dcebef03b6f9c2b6ccd4ea65db3b088150cbfa2898b0fc3884a1e
CRC32 D7F79512
ssdeep 98304:kazxnV0fZsOROzQ9LZGJl0A5zucq9usdIy9q5reGYTB6JDaqJDmWYT5OJDGWNxVH:lxngqozAoPIYnSrrXDLcW3VH
Yara
  • Malicious_Library_Zero - Malicious_Library
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 84e450b5831e515b_goopdateres_nl.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_nl.dll
Size 53.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 9de8e84013dc22acad0b9e2024975883
SHA1 5f0edac10d01391e8de0b2bbd2e1699d6d2ee4d6
SHA256 84e450b5831e515bdaaf0fed9ade50f0d83e167318121ae0d94b8c58eca22b1f
CRC32 60316249
ssdeep 384:uSjh7Xd/T3kPLOZsHLMXPxh8E9VF0NynUbLOZsHLwLPxh8E9VF0NyxHH:/7tgTLoPxWExELYPxWEnn
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 5a81a41b654d50f6_goopdateres_et.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_et.dll
Size 51.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 fa14d6d49f9c5b86f058997d7b90e8b0
SHA1 4902d92e033ca11db1d40fb812be743b8cf0e0da
SHA256 5a81a41b654d50f6eee734d3c3794c9cedb2ee0acd5eb0e39abe94c3c0c99ad7
CRC32 7E4820B8
ssdeep 384:uXYqQrbDFbDZETJ9TSQLLOZsHL4Ek0Pxh8E9VF0Ny8Q5jLOZsHLwoPxh8E9VF0Nv:us96nHPL1PxWEOyHLzPxWEcp
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name d51f6779aea6f986_goopdateres_hr.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_hr.dll
Size 52.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 19b559bcad8742a7f2e70a0983c0e10c
SHA1 2fddcad60d35362e61e5ee54c577578189c96a31
SHA256 d51f6779aea6f986dad6353035b65205f78010270c138ef7305848a774f5e252
CRC32 B77E82DE
ssdeep 384:uD+ERNOXz19szMH5KBL/KLOZsHLoSkPlPxh8E9VF0NyzXXALOZsHLoPPxh8E9VFs:TEi5oL/aLLyPxWElQLWPxWE3u
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 8f1f739ed816996c_lumucrashhandler64.exe
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuCrashHandler64.exe
Size 378.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 f621292474cb54533db8f9da7994216e
SHA1 aeb81724f6aac0492e2137ba94948a3cce114ed3
SHA256 8f1f739ed816996c244993b52f62302d7a64775f30b04a21533be1670d343f62
CRC32 9867269E
ssdeep 6144:3rkWkQzGM2c6KcSfhAKCnYBIlpdzV78MAohiPQqXYQDFAh+g:Np12T/SuKMp38loUPQMYzh+g
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 6285a0b5413957d6_psmachine_64.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\psmachine_64.dll
Size 336.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 9d7f96d3e4c15f54f7b9161b3876ad9c
SHA1 337df4b5e9f78261f1787d47fdf0913e85244623
SHA256 6285a0b5413957d652cda549b09080e2c04ad8768cec898b9b29033e3f640082
CRC32 D2D214D6
ssdeep 6144:O5wQ7asjHVqP7bVHTSfy1D9KHKohYbI5OSOKyZAZc+Ya:OD+EVsVzJD9nodM7Kx
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name a6a6e6376c6e17f5_goopdateres_te.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_te.dll
Size 53.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 33a59db4d0785141d315abc8acf9a70a
SHA1 6a970848eece24bb907336961eeaf497bf2dc401
SHA256 a6a6e6376c6e17f564182eb72d3b3867462cc5f870d757d0ed9b0100727151c2
CRC32 DA2DDA80
ssdeep 384:uHvrXw45Z4aJ8LDaLOZsHLobI6aPxh8E9VF0NyQ+DaLOZsHLo8UPxh8E9VF0Ny2v:yrXd5ya+LDqLDPxWEOTLPUPxWEIv
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 03458d213d6084aa_goopdateres_lt.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_lt.dll
Size 51.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c693c83b456e7b7b4d64c8325a3cb5b1
SHA1 c99da9c478bb8cd92856bd7f89809d458302a4c0
SHA256 03458d213d6084aa9c1e11efe0e121d6d33c2713f97f620736eef5760e07f4d5
CRC32 B35786E7
ssdeep 768:ciTckHz05TmDq09xLEdyPxWED6fLTPxWEdT:ciTckHz05+KdyPxEHPxD
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name ce7476a8b859e8e9_goopdateres_iw.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_iw.dll
Size 49.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 cb3a7d4e73b5ec5afbb36f11978b1e19
SHA1 9d6474297fd23ffd97ee844ae8a574342429e3dc
SHA256 ce7476a8b859e8e93a80fe711f041421fc0e7cee33e6870c95c5a05fd477bd27
CRC32 FD259441
ssdeep 384:uPDyIv7hdVexaDywGfJss4LOZsHLMRPxh8E9VF0NyM4WBLOZsHLwlPxh8E9VF0Nd:vgNM1ILCPxWEOnLePxWEF6
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 5eba339e7877ef4a_goopdateres_ko.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ko.dll
Size 48.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 ef2ac4db5ee64c3a71cc018d7c87850b
SHA1 82f3066bec43c8dfb55850774ff2b3675a539546
SHA256 5eba339e7877ef4a0bf735b4688af6b6b321a58f6b2511a39618a1ae43b1ef8a
CRC32 50496C56
ssdeep 384:uvprqzd4IY+N1vZsYoRHgA12plxB4xRkkTY1M5tkOgLOZsHLoDEPxh8E9VF0Nyk/:orq2mAf/jvwLhPxWEqtALHbPxWEBe5
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name addeb994adc891c6_goopdateres_fil.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_fil.dll
Size 53.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 503ea489b6e98f5ab35a5686dc7f1ba7
SHA1 9e5ab038dd76f5b4b8a520520016b45faa60baf8
SHA256 addeb994adc891c6742197c5da63b3ec5d553fd1f173345452267360082a46f1
CRC32 D6F2CB65
ssdeep 768:fLU9w+B3RVawWFLcPxWEe8WLJPxWEbFyP:fqw+B3RVawTPxH2PxS
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name d474d1ba14a6b018_goopdateres_am.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_am.dll
Size 51.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 f7e6e5c8377ca12d148cfa464f76ffee
SHA1 48706085986ae4140f3098ae31306a987a6bc50e
SHA256 d474d1ba14a6b0188455c259f87270046e923738b334248e9a1b482ebdd0eb50
CRC32 21F0B13D
ssdeep 384:uRNOCR4k4+J2ULOZsHL4C8QmEjPxh8E9VF0Ny6Y8mZLOZsHLwnPxh8E9VF0NyBbL:O/RZJDL/XPxWEF8sLcPxWELn
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 14e9a226130a0228_goopdateres_da.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_da.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 65b32996c72bed443c7737aee0402f4d
SHA1 e387aaa44ea608d95902ee982968e8ebcd035c62
SHA256 14e9a226130a022803bb4f21c9a607ff62c2c786924b09de33d1d8f3aa19568e
CRC32 9F2D4436
ssdeep 384:ukR0fNnwtpTqPTLOZsHL4grPxh8E9VF0NyzqHwcLOZsHLwVMr4Pxh8E9VF0NyiGd:Bcnw/+3LZPxWElmLzr4PxWEoiR
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name ef811beecc3e8e73_goopdateres_it.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_it.dll
Size 53.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 7978e588f14a1846b3f508d0d96fc7d3
SHA1 7e88e3b1e14ba1b1f94cb9a379b6755328aca189
SHA256 ef811beecc3e8e7390a4bca23e99b240e3dff3479d410f40057da326a4c4af46
CRC32 DBCB94D1
ssdeep 384:uCgDpIN+shh3MLOZsHL4xNPxh8E9VF0NyCG8mcLOZsHLoKQkPxh8E9VF0NyCPvq3:+FIN+q3cLwNPxWEs7LDbPxWEIQ
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 1d2698a394fd4253_goopdateres_ja.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ja.dll
Size 48.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 4d3c4be737a584873470d63ea8863c05
SHA1 e5fc383cb02de3e682719eea715155c18078743b
SHA256 1d2698a394fd42535962febdd987f83c9f3672ed98ee0e8307527feef5d661cf
CRC32 31C90BD9
ssdeep 384:u5vGEHj0FgWILOZsHL4nJPxh8E9VF0Ny1R61LOZsHLwx4U5Pxh8E9VF0Ny8jhr:0GED0FgWYLMPxWEjABLw5PxWECtr
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 36b12a8bca76934f_goopdateres_kn.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_kn.dll
Size 53.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 9df4c787aab648880cdb7459b2699eae
SHA1 e13674bd527baeb0f0a98352323172853fb35680
SHA256 36b12a8bca76934fa1fb2c41300abf9a60877f2f7b6f4ab1bab8e36f0308a6c8
CRC32 DC890968
ssdeep 384:u4hREIRBSlLOZsHL4OoPxh8E9VF0NydGrLOZsHLwVPxh8E9VF0NyD7TcTm:xRE8kxL8PxWE/6LyPxWER7Um
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name d20b70aeb49b4be5_goopdateres_sk.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sk.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 6625cafbe3e047fd51353a0e51fae0e0
SHA1 f5c6a04efc0eb4c53e8c844329ad7e66fa857391
SHA256 d20b70aeb49b4be5b7bab26977cb1cbb7e94557a0d2990d592a29ae7c1f07f49
CRC32 9F95F8C3
ssdeep 384:uhlP8uhJPiR6gLTzLOZsHL4anyPxh8E9VF0Nyd1JLOZsHLwWPxh8E9VF0NyvgsU:uF8RjXLuPxWELvLlPxWEJvU
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 18a5ec099e77cf8a_goopdateres_el.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_el.dll
Size 53.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 46399c39117c5645fe38ead7a84e25cd
SHA1 76573174757cd745945ddc5282f331392eb46e06
SHA256 18a5ec099e77cf8af8a8136f05a44fb93d5e6495ab1b40db308dce9285e10692
CRC32 FCD9E8F9
ssdeep 384:udZOEDleILkSIrGCSqlIxRFiAhAc8zBtfsBsTbqqLOZsHLMDdxPxh8E9VF0NyLqC:CTZlLO+R52/S6LmxPxWEdmkLyPxWEGUO
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 256f38f632ec9e03_goopdateres_hu.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_hu.dll
Size 52.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 a77dbc85e8dd00bccc3663f86ae75f19
SHA1 ab61dbb12c60dc2f100fcb2a5ce135c8720f888a
SHA256 256f38f632ec9e03fd473d9ca24dba06d93f52a3f1e781d2bdb2627ca41a5900
CRC32 FC69F95F
ssdeep 1536:FH7U791C2TzpwGFTbZY6d1lBVZ5qAy3FGLgPxSmPxk:FH7U791C2TzpwGFTbZpd1lBVZMAy3FG5
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name e5f30cecb093d8d7_lumuupdateondemand.exe
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuUpdateOnDemand.exe
Size 105.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e2f37cbf0a02350d5862816f15291a89
SHA1 a0057961c14555c154dfdc5a7f648448db8d5e33
SHA256 e5f30cecb093d8d7f431537a89375bcb9a803c74057e3bb207b3204060f050f1
CRC32 09FDDEF4
ssdeep 3072:f4WJjITG0/ksooGvnW2EK4C5irB+9gJjxJxH:f4WJkGOGSrB+It
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name adca169d08321d6d_psmachine.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\psmachine.dll
Size 275.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 d43f64a952833b03798eeedaf9bb20d4
SHA1 3e57b20473fce2b05960becf569be19ff862ca0e
SHA256 adca169d08321d6df3a8d65f8dcd85453132746390e37e435deae0988c4eae5b
CRC32 56142329
ssdeep 6144:3+BXgGMctl+kF5Yv+YTPFxAjBiY9405qAOuhBtpKCiS+YsWh0ES:3qQGMctl+Sev+YTPFxAjBiO5q4HzKQ0j
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 160d2979315b9d28_goopdateres_cs.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_cs.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 be7642a472c24ec47ef54f62359e3b36
SHA1 638a5bacc9849a70d8cd586e4fb99b72bed61d91
SHA256 160d2979315b9d280d5c8b0056bffeec1c6fd5a14fa8ba4017f353070afc5a32
CRC32 18E8EC74
ssdeep 384:uCq1BWpaJkhYwA+fjLOZsHL4RPxh8E9VF0Ny9J4mLOZsHLohPPxh8E9VF0Nyxkd:Q8HLCPxWEnm2LMPxWE3c
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name ba03274418e34042_goopdateres_ml.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ml.dll
Size 55.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 ed6547db17d0ae139e095490ff586594
SHA1 ab740cb0ff06ca30f10fb75bf2b7f7935ccce945
SHA256 ba03274418e340425cffbbd71f67a394b7bb2cba9f480c1c65ad0287e29e82d9
CRC32 0616EE20
ssdeep 384:uULjBLFZygp8/JLsLOZsHL4gx/Pxh8E9VF0Nywm/LOZsHLwICPxh8E9VF0NyCB7X:b1WJL8L1PxWE2aLQPxWEs2K
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 1ffc40ea07fdd6d8_goopdateres_es.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_es.dll
Size 54.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 5605277ea3265093c8e284e8cf3c2bc2
SHA1 4ea48f37ced074662665997a0f1fa9768ea1d2ff
SHA256 1ffc40ea07fdd6d84983deb17647cc9164fb247cbfb6b6eb5c43a39dc661c589
CRC32 D0FC241A
ssdeep 384:uuD1K0Nzf1MLOZsHL4Oh1cPxh8E9VF0NynnFLOZsHLwqPxh8E9VF0Ny210QR:vK0Nj1cL9h2PxWE1RLpPxWEw1/
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 6a49efb5a427180d_goopdateres_sr.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sr.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 561eaf3c8f086ddba7b176e2358330fb
SHA1 7af7ac6607a7cd1f5889a09bb7aff3c9d01fef24
SHA256 6a49efb5a427180d7a18b01069dd7dea17efb3624c443f8203d61c726961d931
CRC32 2A6AC823
ssdeep 384:u22guxCx7UjYN3tGVLOZsHLMDPxh8E9VF0Ny47yZYLOZsHLwNvPxh8E9VF0Ny+sR:ogVUj+dGhLYPxWEeeZoLovPxWEY2
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 7ac94fa159b27588_goopdateres_pl.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_pl.dll
Size 52.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 fa160cdc3e3112771633ac1db57ee793
SHA1 e8b5294361370a58ad5c81a1e52be4b5356cc09f
SHA256 7ac94fa159b27588b5138b45fdbb9aee4e2fd151ae8a378c2a5a3dca28d956d0
CRC32 B9B5DD17
ssdeep 384:uTOvGWn7KZHCCA7U8Gp6oLOZsHLMmgPxh8E9VF0NyusbNLOZsHLwbPxh8E9VF0Nz:Deky3AIy4LEPxWEguL4PxWEaFJ
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name c797959c43fd0a06_goopdateres_th.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_th.dll
Size 51.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 2e806b2be517ff671cbc824040c04912
SHA1 412c2a0d60ac42d1e051d55c9515d7a5553dad42
SHA256 c797959c43fd0a06902c16f7bc126615c878cb3dec41301b98d1fb5733e01cb2
CRC32 52C2AF7B
ssdeep 384:uDFPlrGsMKNMfetN8LOZsHLo4gPxh8E9VF0NyfMCRLOZsHLoQPxh8E9VF0NyNObr:wPlrGszNMfetNML+PxWEF7LtPxWEXy
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 4cd5230099402d62_goopdateres_fa.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_fa.dll
Size 51.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 73fef05435bfe17c22f1652d8db52d6b
SHA1 7c73d0945cfae34525c7c671cdf8e5f687c6db1a
SHA256 4cd5230099402d627c15cbd319e9fcfe355ed6f95cf60ef7f6d2d69eae99e14d
CRC32 8ADFC57A
ssdeep 384:u0VyZMK9Y5YLOZsHL4ksrxPxh8E9VF0NyMrInpHLOZsHLwvPxh8E9VF0NyCpiWe:BxBoLS1PxWEKSpLgPxWEUE
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 3e12f1091f2a7286_lumuupdatebroker.exe
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\LumuUpdateBroker.exe
Size 105.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 f11978f7baaf2a0ec7f8962d1a41af62
SHA1 e7cd07e3720b5f2f0c025fc71d3f9bd940a69472
SHA256 3e12f1091f2a7286205cddc3baf65d445cd1278d4c292e5a9e96e42a419e5727
CRC32 7F31CCC4
ssdeep 3072:fSAWpjITGk/ssooGvnm2Puw0ifi6B+9QZ7x9c8xhT:fSAWpEGmGq6B+gXD
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 9c1a64775791ac37_goopdate.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdate.dll
Size 1.1MB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0f36e0177d10cf57958258c129c4f198
SHA1 bb97ee4ecbd8fcbed7f34dc2358267c591edd858
SHA256 9c1a64775791ac3752b1a9823fa8efb46c94bd810b8859ac594162f867aee798
CRC32 7919B207
ssdeep 24576:pI5dYYvzN3ss51tx02pEoVYcBAajh5PtGJlSFGf+TP2zfZ9WA5HDqe:pI0Q9tq2pTGJloM+TOzfZ9WA5HDqe
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name bd3e47a06c17b440_goopdateres_tr.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_tr.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 aedb32c658b13dde02efad879b4c1aca
SHA1 6413e7a6cbbbebc4ae05cfcfbad89f317c88ddc1
SHA256 bd3e47a06c17b440ef5325494a751d6ab7c5db459e6481eb397449f691fa6856
CRC32 83B30DFC
ssdeep 768:Wap9ABk6qXQEdmvgh3FGk+G9Ahrx++BzQSXmL9PxWEh1SwL4PxWEjP:WaZhdmvMFGkSxLQKmPxNiPxx
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 8f386f175af1fa01_goopdateres_en.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_en.dll
Size 51.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 85b3ac9b022fdae4f1d5fb6136a88d59
SHA1 7b4e2c81314de96780fb966d9b7a9301ed68ef4f
SHA256 8f386f175af1fa01b59d1b73cc80a1ab1f568438ce282e478cbf201080b41238
CRC32 FF7B68BA
ssdeep 384:uF4kagyMk9R1RLOZsHL40KDEPxh8E9VF0Ny6SrLOZsHLoLbPxh8E9VF0Nyjwty:bkagyM4fLjKAPxWEgiLSbPxWElt
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 7ec80a48980110f6_goopdateres_no.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_no.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 9c95be6102b5c684d1cae1c3a507274d
SHA1 dfd1d21ced3514969040164ad9e24002544630ca
SHA256 7ec80a48980110f65dcde26edc2a5786dcdfd46c2242e6525f33c3fd5dae04ad
CRC32 EAC3D1DC
ssdeep 384:uFi5JZSiyCSiyZsVvAYiTvaK3QILOZsHLo2JPxh8E9VF0Nylf8qxLOZsHLoRPxht:0sVoYGiK3QYLpPxWEvEqdL4PxWEBf
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 44a7334f717d3a7e_goopdateres_ms.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_ms.dll
Size 51.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 d2c1c03991a4d4e2b5042fac4727103a
SHA1 b30fd2bdbadeed78752e78979ed29ecfd7555f35
SHA256 44a7334f717d3a7eaa906d1508a17988126aa4f8b1cff3cd340aca4af51c6419
CRC32 0A9D2F98
ssdeep 384:umqU1CrQLtUv6oNpaMkYjZZ/fbMgTRlREwLOZsHL4Y4b+Pxh8E9VF0NyYfQRLOZl:YzZf3TFfLOSPxWEio9LgPxWEQ0
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 4e4b3d42c3914e24_psuser_64.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\psuser_64.dll
Size 336.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 f2c8b664746bfa9e8350b86fd1eac9fe
SHA1 7a207a642302a658bd8182cfb0e514b20b1b4b21
SHA256 4e4b3d42c3914e244fc0e38adeb2ca3181665c8be89231b798ff28449703f7d3
CRC32 2D7319F2
ssdeep 6144:OdwQ7asjnVqP7bVHTSfy1D9dHKohnbO5OxOKSZAZc+Y+:O/+EVsVzJD9QokMQKp
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name e3b0c44298fc1c14_GUMF00D.tmp
Empty file or file not found
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 8407c8cd847f885a_goopdateres_sv.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_sv.dll
Size 52.2KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c4a2115662e1025b1b0aa147f64fb2be
SHA1 ad1920f5f33af22e7e3f3a6cc9ecfeebf95f573c
SHA256 8407c8cd847f885acc9bdd968badd0feed7002946db39a30ad6fdcb2d0226ff0
CRC32 8DE15441
ssdeep 384:uG+7xC7Ec3EVLOZsHL4DPxh8E9VF0Ny064KuLOZsHLo25Pxh8E9VF0NyTsav:U7xCYc3EhLMPxWEKKeLt5PxWExF
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 385b7a9c6a34f8d0_goopdateres_es-419.dll
Submit file
Filepath C:\Program Files (x86)\Lumu\Temp\GUMF00D.tmp\goopdateres_es-419.dll
Size 52.7KB
Processes 2580 (lum_agent_online.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 f79a321e40b80f3960815282b20ae983
SHA1 f5e8d5060e9723ef2771f4f3c6d436d203afaeb8
SHA256 385b7a9c6a34f8d0318235522c9fecff7c49185e79e8a68d207621705b768d7d
CRC32 1FD56109
ssdeep 384:uIVmWfs4eLOZsHLMqjPxh8E9VF0NyBe90LOZsHLwaPxh8E9VF0NyyRN:hmWfs4OLLPxWEXMEL9PxWEI7
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 7711c78bd7d33001_2d85f72862b55c4eadd9e66e06947f3d
Submit file
Filepath C:\Users\test22\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Size 192.0B
Processes 3056 (LumuUpdate.exe)
Type data
MD5 e3c3ba2669f51477eb7a6c82523dec16
SHA1 72d7b6b9fc2221d862945734ec805cf35b9cfe47
SHA256 7711c78bd7d33001a8eda10453d7063aced633119be34b85bd692210bc3171a1
CRC32 F958D120
ssdeep 3:kkFkll+zGpMlXfllXlE/HT8kIzlXNNX8RolJuRdxLlGB9lQRYwpDdt:kKvzGpM2T8N7NMa8RdWBwRd
Yara None matched
VirusTotal Search for analysis