LummaStealer Malware Analizi
Dosya Ozellikleri
SHA256: 4a58cddf58435367ded0958fe806f3ad68efee97a2a4c152e3b9c081f5993ce5
MD5: 9d11eb411ea2dd7243ef302214db8d67
Dosya Tipi: exe
Boyut: 1,319,936 byte
Ilk Gorulme: 2026-01-25
AV Imzasi: LummaStealer
Imphash: 4cea7ae85c87ddc7295d39ff9cda31d1
Raporlayan: iamaachum
Etiketler: AsgardProtector, dropped-by-OffLoader, exe, LummaStealer, SunWukong
Statik analiz: metadata tabanli (ornek indirilmedi)
LummaStealer — Perfil do malware
LummaStealer (LummaC2) is a C-based infostealer sold as MaaS. Steals credentials, crypto wallets, browser data. Highly active 2023-2025. Uses dead drop resolvers.
Detalhes técnicos
LummaStealer (LummaC2) is a C-based information stealer sold as Malware-as-a-Service since 2022. Targets 40+ browser extensions, crypto wallets (MetaMask, Exodus, Electrum, Binance, Coinbase, Atomic), browser credentials/cookies, 2FA authenticator databases, FTP clients, and custom file patterns. Uses dead drop resolvers: Steam profiles, Telegram channels, GitLab repositories to retrieve current C2 address. Anti-sandbox: CSPRNG-based timing checks, VM artifact detection, sleep timers. Delivered via fake software cracks, YouTube video descriptions, SEO-poisoned download pages. C2 communication: HTTPS POST to /c2sock or /api endpoint. Highly active 2023-2025, frequent updates to bypass AV detection.
Atribuição / Ator da ameaça
Unknown (Eastern European actor suspected)
Capacidades e comportamento
Lista IOC (1 indicadores)
# FILEPATH
4a58cddf58435367ded0958fe806f3ad68efee97a2a4c152e3b9c081f5993ce5
| Tipo | Valor | Nota |
|---|---|---|
| filepath | 4a58cddf58435367ded0958fe806f3ad68efee97a2a4c152e3b9c081f5993ce5 | PDB |
Servidores C2 (4 servidores registrados para esta família)
| Endereço | Tipo | Porta | Protocolo | Status | País |
|---|---|---|---|---|---|
| 45.133.174.124 | ip | 443 | HTTPS | inactive | US |
| 194.165.16.77 | ip | 443 | HTTPS | inactive | RU |
| 94.156.66.79 | ip | 443 | HTTPS | inactive | RU |
| 185.196.8.210 | ip | 443 | HTTPS | inactive | RU |
Os endereços C2 são fornecidos apenas a partir de amostras de malware verificadas manualmente pela equipe KEYDAL. O uso comercial é proibido.