Threat Database Trojans Trojan.MSIL.Lumma.J

Trojan.MSIL.Lumma.J

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Lumma.J
Signature status: No Signature

Known Samples

MD5: 99138122c12efbb499e6b76bd91e107f
SHA1: 286786b0708bf08e0d192374276f6b791170b5e8
SHA256: A61525F9B5B24572111616AC596CCDE037EC91FB8225C21ACDFD8B96C3892554
File Size: 637.44 KB, 637440 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 4.0.0.0
Comments MSBuild.exe
Company Name Microsoft Corporation
File Description MSBuild.exe
File Version 4.8.9037.0
Internal Name QuinnLiamChloe.exeOjX
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename QuinnLiamChloe.exeOjX
Product Name Microsoft® .NET Framework
Product Version 4.8.9037.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 29
Potentially Malicious Blocks: 15
Whitelisted Blocks: 14
Unknown Blocks: 0

Visual Map

0 x x 0 0 x 0 x 0 0 x x x x x 0 0 x x 0 0 0 0 0 x x x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Lumma.J

Files Modified

File Attributes
c:\users\user\appdata\roaming\gdi32.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\gdi32.dll Synchronize,Write Attributes

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation

Trending

Most Viewed

Loading...