Threat Database Trojans Trojan.Lumma.AP

Trojan.Lumma.AP

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 49
First Seen: April 8, 2025
Last Seen: September 7, 2025
OS(es) Affected: Windows

The detection of Trojan.Lumma.AP on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, guidance on how to remove it from your system. It's crucial to approach this situation with a clear understanding of the risks and the steps necessary to mitigate them.

What Is Trojan.Lumma.AP?

Trojan.Lumma.AP is identified as a Trojan-type threat, which is a broad category of malware designed to deceive users into installing it on their systems. Unlike viruses, Trojans do not replicate themselves but can cause significant harm by allowing unauthorized access to the victim's system. This can lead to data theft, installation of additional malware, and exploitation of system vulnerabilities. The name "Trojan.Lumma.AP" itself does not specify a known malware family but indicates it's a type of Trojan horse malware.

How Trojan.Lumma.AP Operates

Trojan.Lumma.AP, like other Trojans, operates by disguising itself as legitimate software. Once installed, it can open a backdoor on the infected system, allowing attackers to access it remotely. This access can be used for a variety of malicious activities, including stealing sensitive information, installing additional malware, or using the system as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming. The operational specifics of Trojan.Lumma.AP, such as its propagation methods and the exact nature of its payload, can vary and are typically designed to evade detection by traditional security measures.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common indicators include unusual system behavior, such as unexpected pop-ups, slow system performance, and unfamiliar programs or icons. Additionally, if your system is being used for malicious activities, you might notice increased network activity even when you're not using the internet. It's also possible for a system infected with a Trojan to not display any noticeable symptoms at all, making regular system scans crucial for detection.

  • Unexplained changes to system settings or files
  • Appearance of unfamiliar or suspicious programs
  • Increased network activity without apparent cause
  • System crashes or instability

How to Remove Trojan.Lumma.AP

  1. Boot into Safe Mode with Networking: This will limit the malware's ability to interfere with the removal process. To do this, restart your computer and press the key to access your boot menu (this key varies by manufacturer but is often F8, F12, or Del).
  2. Perform a Full Scan with a Reputable Tool: Use an anti-malware tool such as SpyHunter to scan your system for malware. Ensure the tool is updated to the latest version to improve detection capabilities.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall any that you don't recognize or that were installed around the time your system became infected.
  4. Reset Your Browsers: Malware often affects web browsers, so resetting them can help remove malicious extensions or settings. This can usually be done through the browser's settings menu for Chrome, Firefox, and Edge.
  5. Reboot and Re-scan: After completing the above steps, restart your system and perform another full scan to ensure no remnants of the malware remain.

Conclusion

Removing Trojan.Lumma.AP from your system requires careful and methodical steps to ensure all components of the malware are eliminated. It's essential to stay vigilant and regularly scan your system for malware to prevent future infections. Maintaining up-to-date antivirus software, being cautious with email attachments and downloads, and avoiding suspicious links can significantly reduce the risk of infection. By following the removal steps outlined and adopting safe computing practices, you can protect your system and data from threats like Trojan.Lumma.AP.

Analysis Report

General information

Family Name: Trojan.Lumma.AP
Signature status: Hash Mismatch

Known Samples

MD5: 69f03c7487ee5feadf16fc75dd4c52ad
SHA1: a126801cf4955911bf69416c5a170fae8dd44392
File Size: 1.38 MB, 1380392 bytes
MD5: 9c15be32b362a305a016d0ca04846e1e
SHA1: 51816e197883fe0a409ad7960f43cfa897acb93f
SHA256: 940B084C27FA17A44F3DB52D47B22174F291310B4795C116ADAFFF435749FF18
File Size: 1.28 MB, 1276416 bytes
MD5: 7249d7f74abc73e68e29eae933bc0921
SHA1: 7834d6265e71519e821cac5cc01c6efaae7ad124
SHA256: CC8A223B9967A9FFADA7BFBFEE927C0089F7C07D5829029CDC36D61478E53F07
File Size: 997.89 KB, 997888 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Microsoft Windows Media Player Setup Utility
File Version 12.0.19041.1 (WinBuild.160101.0800)
Internal Name unregmp2.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename unregmp2.exe
Product Name Microsoft® Windows® Operating System
Product Version 12.0.19041.1

Digital Signatures

Signer Root Status
NVIDIA Corporation DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Version
  • No Version Info
  • x64

Block Information

Total Blocks: 2,153
Potentially Malicious Blocks: 273
Whitelisted Blocks: 1,323
Unknown Blocks: 557

Visual Map

? x 0 0 ? x x ? ? ? ? 0 x ? x ? x ? ? 0 ? ? x 0 x x ? 0 0 0 0 ? 0 x x ? ? ? x ? 0 0 0 ? 0 ? x ? x ? ? ? x 0 ? ? ? ? 0 x ? 0 ? ? 0 0 ? x 0 0 ? ? ? 0 0 ? ? x x 0 ? 0 ? ? 0 ? ? 0 0 ? ? ? 0 x 0 ? x x 0 x 0 x ? 0 ? ? ? ? x ? 0 ? 0 ? x ? 0 ? x ? 0 0 ? 0 ? 0 ? ? ? 0 0 ? ? 0 x x 0 ? 0 ? ? 0 ? 0 ? ? 0 ? x ? ? x ? 0 x 0 x ? ? 0 0 0 0 0 ? 0 x ? 0 0 ? 0 ? 0 0 x 0 0 0 x ? ? ? 0 0 ? x 0 0 x 0 ? 0 0 x ? ? ? 0 ? ? 0 0 0 x ? 0 ? 0 ? ? x x 0 x 0 0 ? x ? 0 ? ? 0 ? ? x 0 ? x 0 x ? 0 ? x x x 0 x x ? 0 x x 0 x 0 ? 0 0 0 ? 0 ? 0 x ? ? ? 0 x ? ? 0 x ? 0 0 ? ? ? 0 0 ? ? x 0 0 x 0 x x 0 0 0 0 0 ? ? ? ? ? ? ? ? ? x 0 x ? 0 x ? ? x 0 ? 0 0 x 0 ? x ? ? 0 ? ? 0 x x ? ? ? ? ? 0 x 0 x ? 0 x 0 0 0 ? ? 0 0 x 0 ? ? 0 ? ? 0 x x ? ? ? ? ? 0 x 0 x ? 0 ? 0 0 0 ? ? 0 0 ? 0 ? ? 0 0 x 0 ? ? 0 0 x 0 ? ? 0 0 x 0 x ? ? 0 ? 0 0 x 0 0 0 ? ? 0 0 x 0 0 ? x 0 0 0 ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 x ? ? ? 0 x ? ? 0 0 0 ? 0 x ? ? ? x 0 x 0 0 ? ? 0 0 ? ? 0 ? ? ? x x ? 0 0 ? 0 ? 0 ? ? ? x ? 0 ? ? 0 ? ? 0 ? ? ? 0 0 ? ? ? ? 0 0 x ? 0 0 0 ? 0 x ? ? 0 x x 0 0 ? 0 x 0 ? x ? 0 ? ? ? x ? 0 0 x ? ? 0 0 x x x ? ? ? 0 ? ? x 0 x 0 0 ? 0 ? ? ? ? ? 0 0 0 0 ? ? ? x ? x 0 0 ? ? ? ? x 0 x 0 x 0 x 0 0 ? 0 ? ? 0 ? x ? 0 ? ? ? ? ? ? ? x ? ? x 0 ? ? ? 0 ? x x ? 0 0 ? ? ? x ? 0 ? 0 ? ? ? 0 x x 0 ? 0 ? ? ? x x 0 0 ? ? ? x 0 ? ? 0 0 0 x 0 0 ? 0 0 ? 0 ? ? ? 0 ? ? 0 ? 0 ? ? 0 ? 0 ? x x 0 ? ? 0 x x ? 0 ? ? ? x ? 0 0 ? x x ? ? x x x ? x 0 ? ? x 0 x x x 0 ? x 0 0 ? 0 x x x 0 0 x ? ? x 0 ? ? x 0 ? x ? x x ? ? 0 ? x x ? ? ? 0 ? ? ? ? ? ? ? ? ? x ? x ? x 0 x 0 0 ? ? ? 0 ? ? 0 0 ? ? x ? 0 x ? 0 ? 0 0 ? x ? x x x 0 x x 0 0 0 0 0 0 x 0 0 0 ? x ? x ? ? ? 0 0 x ? ? 0 x ? 0 ? x x ? 0 x ? x 0 ? x 0 0 0 0 x x x x ? x x x ? 0 ? x 0 x ? ? ? 0 ? 0 ? 0 x x ? x ? x 0 ? 0 0 ? 0 ? ? ? 0 ? 0 x x ? 0 ? x ? ? 0 0 ? 0 0 x x ? ? ? x x x x 0 ? ? ? 0 ? 0 0 ? 0 x ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 x x ? ? ? ? ? ? ? 0 x ? 0 ? ? ? 0 ? 0 ? ? ? 0 x x ? ? ? ? ? 0 ? 0 0 ? ? 0 ? x x 0 ? ? 0 ? ? ? 0 x x ? 0 ? ? ? 0 ? 0 0 ? ? 0 ? 0 ? ? 0 0 x 0 ? ? 0 x ? 0 ? ? x ? ? ? ? ? ? ? x ? x 0 ? 0 x 0 x ? ? x 0 x ? x x 0 x 0 ? ? 0 x x 0 ? x ? ? 0 ? ? ? ? x x 0 x 0 0 x ? ? x 0 0 x ? x x 0 0 x x ? ? 0 ? 0 x 0 x 0 x ? 0 ? 0 0 x ? x 0 ? 0 x ? ? ? 0 0 ? 0 0 0 0 ? x 0 ? ? 0 0 0 0 x x ? 0 0 0 0 x x ? 0 0 0 0 x ? ? 0 ? 0 x ? 0 x x ? 0 x 0 0 0 x x ? 0 x 0 ? 0 ? ? 0 ? 0 ? 0 0 ? ? 0 0 ? x 0 ? 0 0 0 ? ? x ? ? ? 0 ? 0 0 ? 0 0 x ? 0 0 ? ? 0 ? 0 x ? ? ? x x ? 0 x x 0 ? ? 0 ? 0 x 0 ? ? ? ? 0 x 0 x ? x 0 ? x ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 x ? 0 ? 0 ? ? 0 x ? 0 0 x x 0 ? ? x ? 0 0 0 ? 0 ? 0 0 0 x ? ? ? 0 0 0 ? 0 0 ? x ? x ? ? x ? 0 x 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Lumma.AP

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtTestAlert
Show More
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...