Report - CW.exe

Lumma Stealer UPX PE File PE32
ScreenShot
Created 2024.08.10 12:34 Machine s1_win7_x6401
Filename CW.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
11
Behavior Score
1.2
ZERO API file : malware
VT API (file) 59 detected (AIDetectMalware, LummaStealer, Windows, Lumma, Malicious, score, Artemis, Unsafe, Mint, Zard, V41j, Attribute, HighConfidence, Lazy, LummaC, ccmw, YglkxfxvbwO, XPACK, YXEHHZ, Real Protect, high, Detected, ai score=83, CCJF, Eldorado, R657991, BScope, TrojanPSW, Genetic, Gencirc, SDa623Xcz+M, susgen, confidence)
md5 d3a4c97bab4c5dc62e4144f68f11b6ef
sha256 3419c7e1d200f175d80bef7a993a39da7f654994eb48f86ff4780cfea54577d4
ssdeep 6144:fyZUtiVOFLjVFCc6qbxoNnR606FniBv7n+4zU:fe3ULj/owotR606IF+
imphash 93d38faa538d34592b2dd571bcadf806
impfuzzy 12:rwxrPTkJZG5TZtJjqTleRzdwdV3EQg3EiA/tHqH3Q4oA7QNt25hDLO1UkH:rwxzTiY173qvEQ4EPlZ4Fk/wh3MUkH
  Network IP location

Signature (1cnts)

Level Description
danger File has been identified by 59 AntiVirus engines on VirusTotal as malicious

Rules (4cnts)

Level Name Description Collection
danger lumma_Stealer Lumma Stealer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

ole32.dll
 0x441808 CoCreateInstance
 0x44180c CoInitializeEx
 0x441810 CoInitializeSecurity
 0x441814 CoSetProxyBlanket
 0x441818 CoUninitialize
KERNEL32.dll
 0x441820 ExitProcess
 0x441824 GetCurrentProcessId
 0x441828 GetCurrentThreadId
 0x44182c GetLogicalDrives
 0x441830 GetProcessVersion
 0x441834 GetSystemDirectoryW
 0x441838 GlobalLock
 0x44183c GlobalUnlock
OLEAUT32.dll
 0x441844 SysAllocString
 0x441848 SysFreeString
 0x44184c SysStringLen
 0x441850 VariantClear
 0x441854 VariantInit
USER32.dll
 0x44185c CloseClipboard
 0x441860 GetClipboardData
 0x441864 GetDC
 0x441868 GetSystemMetrics
 0x44186c GetWindowLongW
 0x441870 OpenClipboard
 0x441874 ReleaseDC
GDI32.dll
 0x44187c BitBlt
 0x441880 CreateCompatibleBitmap
 0x441884 CreateCompatibleDC
 0x441888 DeleteDC
 0x44188c DeleteObject
 0x441890 GetCurrentObject
 0x441894 GetDIBits
 0x441898 GetObjectW
 0x44189c SelectObject

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure