Advertisement
VRad

#lumma_120224

Feb 12th, 2024 (edited)
437
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.19 KB | None | 0 0
  1. #IOC #OptiData #VR #Lumma #Stealer #AutoIt #7z #RAR #PWD #EXE
  2.  
  3. https://pastebin.com/uRwsPe70
  4.  
  5. previous_contact:
  6. 31/01/24 https://pastebin.com/0sqGs6aV
  7. 30/01/24 https://pastebin.com/pgjwR07Z
  8. 27/01/24 https://pastebin.com/4B3hwvpx
  9. 25/01/24 https://pastebin.com/pwL5HdeX
  10.  
  11. FAQ:
  12. https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma
  13.  
  14. attack_vector
  15. --------------
  16. email attach .7z > .rar (PWD) > .exe > .pif (AutoIt) > Z (Java Script) > C2
  17.  
  18. # # # # # # # #
  19. email_headers
  20. # # # # # # # #
  21. Date: Mon, 12 Feb 2024 12:13:15 +0300
  22. Subject: вихідний № 350985 - 12.02.2024
  23. From: Андрусів Влада Мстиславівна <info@ athenssquare_gr>
  24. Reply-To: Чекалюк Доморад Жданович <dsp@ dp_dsp_gov_ua>
  25. Received: from smtp02_prd_hc_generation - y_net ([95_216_185_242])
  26. Received: from kappa_generation - y_net (kappa_generation - y_net [88_99_102_100])
  27. Received: from [5_42_92_31] (port=50066 helo=DESKTOP - TCRDU4C)
  28.  
  29. Date: Mon, 12 Feb 2024 13:04:06 +0300
  30. Subject: вихідний № 24062 - 12.02.2024
  31. From: Шульга Надіслава Никодимівна <natsu@ mosimon_com>
  32. Reply-To: Іщенко Єпистима Вікторівна <dsp@ dp_dsp_gov_ua>
  33. Received: from mosimon_com (mosimon_com [124_146_222_175])
  34. Received: from unknown (HELO DESKTOP - TCRDU4C) (natsu@ mosimon_com @ 5_42_92_31) by dc11_etius_jp (124_146_222_175) with ESMTPA
  35.  
  36. # # # # # # # #
  37. files
  38. # # # # # # # #
  39. SHA-256 91d1973486af73f2c30d0cf608005a75b53abd017f4fbf19a9c53a5b23a9429b
  40. File name Запит інформації щодо платежів..7z
  41. File size
  42.  
  43. SHA-256 3743dec7693f67e4b87f6b926a8196ae04973ce18e052e6a0eb1aaaf30d776f3
  44. File name Додатки 1. Запит інформації щодо платежів..rar !PWD
  45. File size
  46.  
  47. SHA-256 b756f04d1cd713bb11d5ae1032f8e8580d7cb11ad9e58f0219c9a9fb02c20d42
  48. File name Додатки 1. Запит інформації щодо платежів.pdf.exe
  49. File size
  50.  
  51. SHA-256 f58d3a4b2f3f7f10815c24586fae91964eeed830369e7e0701b43895b0cefbd3
  52. File name Immigrants.pif !AutoIt
  53. File size
  54.  
  55. SHA-256 a388bbf5baf8b3fb09340031dac1c88edc8929a630586af3dcbb37cfe580e26a
  56. File name Z !Lumma
  57. File size
  58.  
  59. # # # # # # # #
  60. activity
  61. # # # # # # # #
  62.  
  63. PL_SCR email_attach
  64.  
  65. C2
  66. bleednumberrottern _home,
  67. brakesummitfiightre _pics,
  68. legislationdictater _mom,
  69. developmentalveiop _home,
  70. baketransparentadw _pics,
  71. lawwormroleveinn _momu,
  72. hunterstrawmersp _home,
  73. mercyaloofprincipleo _pics,
  74. ironshottallinko _funu,
  75. bleednumberrottern _home,
  76. brakesummitfiightre _pics,
  77. legislationdictater _mom,
  78. developmentalveiop _home,
  79. baketransparentadw _pics,
  80. lawwormroleveinn _momu,
  81. hunterstrawmersp _home,
  82. mercyaloofprincipleo _pics,
  83. ironshottallinko _funu,
  84. bleednumberrottern _home,
  85. brakesummitfiightre _pics,
  86. legislationdictater _mom,
  87. developmentalveiop _home,
  88. baketransparentadw _pics,
  89. lawwormroleveinn _momu,
  90. hunterstrawmersp _home,
  91. mercyaloofprincipleo _pics,
  92. ironshottallinko _funu
  93.  
  94. netwrk
  95. --------------
  96.  
  97. comp
  98. --------------
  99.  
  100. proc
  101. --------------
  102. Earn + Program + Asset + Reserve + Slowly 15968\Immigrants.pif
  103. Viking + Chaos + Participated 15968\Z
  104.  
  105. persist
  106. --------------
  107. n/a
  108.  
  109.  
  110. drop
  111. --------------
  112. Immigrants.pif
  113. Z
  114.  
  115. # # # # # # # #
  116. additional info
  117. # # # # # # # #
  118. n/a
  119.  
  120. # # # # # # # #
  121. VT & Intezer
  122. # # # # # # # #
  123. https://www.virustotal.com/gui/file/91d1973486af73f2c30d0cf608005a75b53abd017f4fbf19a9c53a5b23a9429b/details
  124. https://www.virustotal.com/gui/file/3743dec7693f67e4b87f6b926a8196ae04973ce18e052e6a0eb1aaaf30d776f3/details
  125. https://www.virustotal.com/gui/file/b756f04d1cd713bb11d5ae1032f8e8580d7cb11ad9e58f0219c9a9fb02c20d42/details
  126. https://www.virustotal.com/gui/file/f58d3a4b2f3f7f10815c24586fae91964eeed830369e7e0701b43895b0cefbd3/details
  127. https://www.virustotal.com/gui/file/a388bbf5baf8b3fb09340031dac1c88edc8929a630586af3dcbb37cfe580e26a/details
  128.  
  129. VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement