Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #Lumma #Stealer #LNK #SMB #RAR #PWD
- https://pastebin.com/pgjwR07Z
- previous_contact:
- 27/01/24 https://pastebin.com/4B3hwvpx
- 25/01/24 https://pastebin.com/pwL5HdeX
- FAQ:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma
- attack_vector
- --------------
- email attach .7z > .rar (PWD) > .url > \\ 89_23_98_22 \ UR \ lmncr2rs.exe > crisisestimatehealtwh_site / api (C2)
- # # # # # # # #
- email_headers
- # # # # # # # #
- Date: Tue, 30 Jan 2024 08:52:51 +0300
- Subject: Запит ДПСУ (Вимога)
- From: Рак Ясногор Тимурович <facebook @ spacollection_hk>
- Reply-To: Державна податкова служба України <post @ tax_gov_ua>
- Received: from mail_spacollection_hk ([103_226_95_162])
- Received: from WIN - LCETV91VPS6 (plum - development2_aeza_one [79_137_205_213])
- Message-ID: <C35FA500- D8C7- 477E- A139- BA159B9F55CD @ mail_spacollection_hk>
- # # # # # # # #
- files
- # # # # # # # #
- SHA-256 34b826565968ff34edc9617c3f6d997ce9721baf514de310d2761bc203b81f81
- File name Запит.7z [7-zip archive data, version 0.4]
- File size 855 B (855 bytes)
- SHA-256 57aaab5b85b3e0d4b6b3033d15bfbf170ab93da94188df339ef4401f76fe6762
- File name doc.rar [RAR archive data, v5] !PWD
- File size 446 B (446 bytes)
- SHA-256 c73de9036435ed3a51b4864af55b159901914ddc0e90b0ca7d954a6e500cf26f
- File name Офіційний запит.pdf.url [URL, Internet shortcut]
- File size 170 B (170 bytes)
- SHA-256 cc47d0324b09a84924c41bf62b955e73688483645489ae8638164feac38192d3
- File name lmncr2rs.exe [.NET executable , Smart Assembly ] !LUMMA
- File size 10.85 MB (11374080 bytes)
- SHA-256 d484cb34534d598e0597aa44ae065b7ff666922e481fcf4e83cb7d1011972266
- File name unpacked.exe [PE32 executable] !LUMMA
- File size 536.00 KB (548864 bytes)
- # # # # # # # #
- activity
- # # # # # # # #
- PL_SCR \\ 89_23_98_22 \ UR \ lmncr2rs.exe
- C2 crisisestimatehealtwh_site / api
- netwrk
- --------------
- 89_23_98_22 445 SMB Negotiate Protocol Request
- 89_23_98_22 445 TCP 49348 → 445 [SYN]
- comp
- --------------
- System 4 TCP 89_23_98_22 445 ESTABLISHED
- System 4 TCP 89_23_98_22 445 ESTABLISHED
- proc
- --------------
- Explorer.EXE \\ 89_23_98_22 \ UR \ lmncr2rs.exe
- lmncr2rs.exe
- lmncr2rs.exe
- persist
- --------------
- n/a
- drop
- --------------
- n/a
- # # # # # # # #
- additional info
- # # # # # # # #
- n/a
- # # # # # # # #
- VT & Intezer
- # # # # # # # #
- https://www.virustotal.com/gui/file/34b826565968ff34edc9617c3f6d997ce9721baf514de310d2761bc203b81f81/details
- https://www.virustotal.com/gui/file/57aaab5b85b3e0d4b6b3033d15bfbf170ab93da94188df339ef4401f76fe6762/details
- https://www.virustotal.com/gui/file/c73de9036435ed3a51b4864af55b159901914ddc0e90b0ca7d954a6e500cf26f/details
- https://www.virustotal.com/gui/file/cc47d0324b09a84924c41bf62b955e73688483645489ae8638164feac38192d3/details
- https://www.virustotal.com/gui/file/d484cb34534d598e0597aa44ae065b7ff666922e481fcf4e83cb7d1011972266/details
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement