Threat Database Trojans Trojan.Lumma.AP

Trojan.Lumma.AP

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Lumma.AP
Signature status: Hash Mismatch

Known Samples

MD5: 69f03c7487ee5feadf16fc75dd4c52ad
SHA1: a126801cf4955911bf69416c5a170fae8dd44392
File Size: 1.38 MB, 1380392 bytes
MD5: 9c15be32b362a305a016d0ca04846e1e
SHA1: 51816e197883fe0a409ad7960f43cfa897acb93f
SHA256: 940B084C27FA17A44F3DB52D47B22174F291310B4795C116ADAFFF435749FF18
File Size: 1.28 MB, 1276416 bytes
MD5: 7249d7f74abc73e68e29eae933bc0921
SHA1: 7834d6265e71519e821cac5cc01c6efaae7ad124
SHA256: CC8A223B9967A9FFADA7BFBFEE927C0089F7C07D5829029CDC36D61478E53F07
File Size: 997.89 KB, 997888 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Microsoft Windows Media Player Setup Utility
File Version 12.0.19041.1 (WinBuild.160101.0800)
Internal Name unregmp2.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename unregmp2.exe
Product Name Microsoft® Windows® Operating System
Product Version 12.0.19041.1

Digital Signatures

Signer Root Status
NVIDIA Corporation DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Version
  • No Version Info
  • x64

Block Information

Total Blocks: 2,153
Potentially Malicious Blocks: 273
Whitelisted Blocks: 1,323
Unknown Blocks: 557

Visual Map

? x 0 0 ? x x ? ? ? ? 0 x ? x ? x ? ? 0 ? ? x 0 x x ? 0 0 0 0 ? 0 x x ? ? ? x ? 0 0 0 ? 0 ? x ? x ? ? ? x 0 ? ? ? ? 0 x ? 0 ? ? 0 0 ? x 0 0 ? ? ? 0 0 ? ? x x 0 ? 0 ? ? 0 ? ? 0 0 ? ? ? 0 x 0 ? x x 0 x 0 x ? 0 ? ? ? ? x ? 0 ? 0 ? x ? 0 ? x ? 0 0 ? 0 ? 0 ? ? ? 0 0 ? ? 0 x x 0 ? 0 ? ? 0 ? 0 ? ? 0 ? x ? ? x ? 0 x 0 x ? ? 0 0 0 0 0 ? 0 x ? 0 0 ? 0 ? 0 0 x 0 0 0 x ? ? ? 0 0 ? x 0 0 x 0 ? 0 0 x ? ? ? 0 ? ? 0 0 0 x ? 0 ? 0 ? ? x x 0 x 0 0 ? x ? 0 ? ? 0 ? ? x 0 ? x 0 x ? 0 ? x x x 0 x x ? 0 x x 0 x 0 ? 0 0 0 ? 0 ? 0 x ? ? ? 0 x ? ? 0 x ? 0 0 ? ? ? 0 0 ? ? x 0 0 x 0 x x 0 0 0 0 0 ? ? ? ? ? ? ? ? ? x 0 x ? 0 x ? ? x 0 ? 0 0 x 0 ? x ? ? 0 ? ? 0 x x ? ? ? ? ? 0 x 0 x ? 0 x 0 0 0 ? ? 0 0 x 0 ? ? 0 ? ? 0 x x ? ? ? ? ? 0 x 0 x ? 0 ? 0 0 0 ? ? 0 0 ? 0 ? ? 0 0 x 0 ? ? 0 0 x 0 ? ? 0 0 x 0 x ? ? 0 ? 0 0 x 0 0 0 ? ? 0 0 x 0 0 ? x 0 0 0 ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 x ? ? ? 0 x ? ? 0 0 0 ? 0 x ? ? ? x 0 x 0 0 ? ? 0 0 ? ? 0 ? ? ? x x ? 0 0 ? 0 ? 0 ? ? ? x ? 0 ? ? 0 ? ? 0 ? ? ? 0 0 ? ? ? ? 0 0 x ? 0 0 0 ? 0 x ? ? 0 x x 0 0 ? 0 x 0 ? x ? 0 ? ? ? x ? 0 0 x ? ? 0 0 x x x ? ? ? 0 ? ? x 0 x 0 0 ? 0 ? ? ? ? ? 0 0 0 0 ? ? ? x ? x 0 0 ? ? ? ? x 0 x 0 x 0 x 0 0 ? 0 ? ? 0 ? x ? 0 ? ? ? ? ? ? ? x ? ? x 0 ? ? ? 0 ? x x ? 0 0 ? ? ? x ? 0 ? 0 ? ? ? 0 x x 0 ? 0 ? ? ? x x 0 0 ? ? ? x 0 ? ? 0 0 0 x 0 0 ? 0 0 ? 0 ? ? ? 0 ? ? 0 ? 0 ? ? 0 ? 0 ? x x 0 ? ? 0 x x ? 0 ? ? ? x ? 0 0 ? x x ? ? x x x ? x 0 ? ? x 0 x x x 0 ? x 0 0 ? 0 x x x 0 0 x ? ? x 0 ? ? x 0 ? x ? x x ? ? 0 ? x x ? ? ? 0 ? ? ? ? ? ? ? ? ? x ? x ? x 0 x 0 0 ? ? ? 0 ? ? 0 0 ? ? x ? 0 x ? 0 ? 0 0 ? x ? x x x 0 x x 0 0 0 0 0 0 x 0 0 0 ? x ? x ? ? ? 0 0 x ? ? 0 x ? 0 ? x x ? 0 x ? x 0 ? x 0 0 0 0 x x x x ? x x x ? 0 ? x 0 x ? ? ? 0 ? 0 ? 0 x x ? x ? x 0 ? 0 0 ? 0 ? ? ? 0 ? 0 x x ? 0 ? x ? ? 0 0 ? 0 0 x x ? ? ? x x x x 0 ? ? ? 0 ? 0 0 ? 0 x ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 x x ? ? ? ? ? ? ? 0 x ? 0 ? ? ? 0 ? 0 ? ? ? 0 x x ? ? ? ? ? 0 ? 0 0 ? ? 0 ? x x 0 ? ? 0 ? ? ? 0 x x ? 0 ? ? ? 0 ? 0 0 ? ? 0 ? 0 ? ? 0 0 x 0 ? ? 0 x ? 0 ? ? x ? ? ? ? ? ? ? x ? x 0 ? 0 x 0 x ? ? x 0 x ? x x 0 x 0 ? ? 0 x x 0 ? x ? ? 0 ? ? ? ? x x 0 x 0 0 x ? ? x 0 0 x ? x x 0 0 x x ? ? 0 ? 0 x 0 x 0 x ? 0 ? 0 0 x ? x 0 ? 0 x ? ? ? 0 0 ? 0 0 0 0 ? x 0 ? ? 0 0 0 0 x x ? 0 0 0 0 x x ? 0 0 0 0 x ? ? 0 ? 0 x ? 0 x x ? 0 x 0 0 0 x x ? 0 x 0 ? 0 ? ? 0 ? 0 ? 0 0 ? ? 0 0 ? x 0 ? 0 0 0 ? ? x ? ? ? 0 ? 0 0 ? 0 0 x ? 0 0 ? ? 0 ? 0 x ? ? ? x x ? 0 x x 0 ? ? 0 ? 0 x 0 ? ? ? ? 0 x 0 x ? x 0 ? x ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 x ? 0 ? 0 ? ? 0 x ? 0 0 x x 0 ? ? x ? 0 0 0 ? 0 ? 0 0 0 x ? ? ? 0 0 0 ? 0 0 ? x ? x ? ? x ? 0 x 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Lumma.AP

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtTestAlert
Show More
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...