LummaStealer Malware Analizi

Dosya Ozellikleri

SHA256: 66055f98d8b1e513d5312cc62b1644aa478f0611feb9353539e805c4daa7e0b0

MD5: bc52f954e5a25b408559dea257f49653

Dosya Tipi: exe

Boyut: 1,194,965 byte

Ilk Gorulme: 2025-09-12

AV Imzasi: LummaStealer

Imphash: 32f3282581436269b3a75b6675fe3e08

Raporlayan: iamaachum

Etiketler: AutoIT, CypherIT, exe, LummaStealer

Statik analiz: metadata tabanli (ornek indirilmedi)

LummaStealer — Malware-Profil

LummaStealer (LummaC2) is a C-based infostealer sold as MaaS. Steals credentials, crypto wallets, browser data. Highly active 2023-2025. Uses dead drop resolvers.

Malware-Typ
Infostealer
Programmiersprache
C
C2-Protokoll
HTTPS
Zielsysteme
Windows
Auch bekannt als (AKA)
LummaC2, Lumma C2, lummac

Technische Details

LummaStealer (LummaC2) is a C-based information stealer sold as Malware-as-a-Service since 2022. Targets 40+ browser extensions, crypto wallets (MetaMask, Exodus, Electrum, Binance, Coinbase, Atomic), browser credentials/cookies, 2FA authenticator databases, FTP clients, and custom file patterns. Uses dead drop resolvers: Steam profiles, Telegram channels, GitLab repositories to retrieve current C2 address. Anti-sandbox: CSPRNG-based timing checks, VM artifact detection, sleep timers. Delivered via fake software cracks, YouTube video descriptions, SEO-poisoned download pages. C2 communication: HTTPS POST to /c2sock or /api endpoint. Highly active 2023-2025, frequent updates to bypass AV detection.

Attribution / Bedrohungsakteur

Unknown (Eastern European actor suspected)

Fähigkeiten & Verhalten

Tarayıcı Kimlik Bilgileri
Çerez Hırsızlığı
Kripto Cüzdan Çalma
Sistem Bilgisi
Ekran Görüntüsü
FTP/SSH İstemci Şifreleri
E-posta İstemcisi Çalma
Veri Sızıntısı

IOC-Liste (1 Indikatoren)

IOC — LummaStealer
# FILEPATH 66055f98d8b1e513d5312cc62b1644aa478f0611feb9353539e805c4daa7e0b0
TypWertBemerkung
filepath 66055f98d8b1e513d5312cc62b1644aa478f0611feb9353539e805c4daa7e0b0 PDB

C2-Server (4 erfasste Server für diese Familie)

Adresse Typ Port Protokoll Status Land
45.133.174.124 ip 443 HTTPS inactive US
194.165.16.77 ip 443 HTTPS inactive RU
94.156.66.79 ip 443 HTTPS inactive RU
185.196.8.210 ip 443 HTTPS inactive RU

C2-Adressen stammen ausschließlich aus vom KEYDAL-Team manuell verifizierten Malware-Samples. Kommerzielle Nutzung ist untersagt.

Tags
AutoITCypherITexeLummaStealer