Created 2024.07.03 18:38 Machine s1_win7_x6403
Filename lumma0207.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
Behavior Score
ZERO API file : clean
VT API (file) 26 detected (AIDetectMalware, Lazy, Jaik, Unsafe, malicious, Attribute, HighConfidence, high confidence, score, Generic@AI, RDMK, cmRtazrvgeobD4fMKaqUBoKDLz2p, high, LummaStealer, ai score=84, Injuke, Detected, Locky, BScope, TrojanPSW, Convagent, Static AI, Malicious PE, confidence, 100%)
md5 168c5908924803d268d26965c32a5620
sha256 2fd72d0d0fbc053a53adee5d9ec6cffde3fb5a3c6ba0c0490e24552b264d5449
ssdeep 24576:YlrD4dQCg30l8cwMKAWgXkALsi3XoiHbL1/2E47kRh2gPilPfy:6RE6cwMKAHO6XoGR/Slhi
imphash a2b3c9bb8bf21aa189ddce7cb05111e0
impfuzzy 48:E4y5K9hIcpVlzWs9xLzXtXqroGtoGzPpm63euFZGM7:lzIcpVlzW2x/XtXQoGtoGTpm8h
  Network IP location

Signature (6cnts)

Level Description
warning File has been identified by 26 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info This executable has a PDB path

Rules (6cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids


EAT(Export Address Table) Library

0x487d60 AwakeSound

