s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-e08c0890b11d91b7ee58de25cc190e1fdf760d76b6d0821aa2d1f442b43e719a high

📛 Threat Title

LummaStealer: setup.exe

Category: LummaStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 4717920 bytes. Tags: exe, LummaStealer, signed. Reporter: iamaachum. First seen: 2026-08-04 19:38:41.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 1aae8bf580c846f39c71c05898e57e88

IOC database

Type
hash_imphash
Value
1aae8bf580c846f39c71c05898e57e88
First seen
Last seen
Attached to this threat
Appears in
59 threats
Description
imphash of URLhaus payload d06c8ee46e760f39…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 e08c0890b11d91b7ee58de25cc190e1fdf760d76b6d0821aa2d1f442b43e719a

IOC database

Type
hash_sha256
Value
e08c0890b11d91b7ee58de25cc190e1fdf760d76b6d0821aa2d1f442b43e719a
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
LummaStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 b0fda8fa73f02276d2b5fff52e1a256043ad69e1

IOC database

Type
hash_sha1
Value
b0fda8fa73f02276d2b5fff52e1a256043ad69e1
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 6f62e6118343703a0ce6311074f236be

IOC database

Type
hash_md5
Value
6f62e6118343703a0ce6311074f236be
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 4717920 bytes. Tags: exe, LummaStealer, signed. Reporter: iamaachum. First seen: 2026-08-04 19:38:41.

Remediations (10)

  • web:cybernews.com

    The Lumma Stealer is a nasty piece of malware that can steal your data and money. In this article, I'll give you a quick guide on how to remove and avoid this virus.

  • web:forums.malwarebytes.com

    Hi all. Bit Of a PC noob here. I recently got infected with a LummaStealer according to Windows Defender. At this point neither Windows Defender or Malwarebytes can locate any viruses. I am planning to Reset my PC via Windows, is there any possible thing I have to do after doing so to ensure I am...

  • web:forums.malwarebytes.com

    Go to topic listing by CleanTalk Home Malware Removal Help Windows Malware Removal Help & Support Resolved Malware Removal Logs Infected with LummaStealer

  • web:learn.microsoft.com

    Hello! Stupidly I ran a fake captcha resulting in LummaStealer being installed. Microsoft Defender however says it has blocked the threat. Saying it is now quarantined and will be deleted automatically. Does this mean I just got really lucky? Or do I need to take additional steps to make sure everything is safe? As of writing this, I am running a full scan by Microsoft Defender. Thank you!

  • web:learn.microsoft.com

    Sometimes, remnants can be left behind and keep getting flagged after removal. If you haven't noticed any suspicious account activity, odd processes in task manager, and you never actually visited any unsafe sites/downloaded cracked software, you are likely in the clear.

  • web:malwaretips.com

    Bitdefender researchers have discovered a surge in LummaStealer activity, showing how one of the world's most prolific information-stealing malware operations managed to survive despite being almost brought down by law enforcement less than a year ago. LummaStealer is a highly scalable information-stealing threat with a long history, having operated under a malware-as-a-service model since it ...

  • web:socprime.com

    Summary LummaStealer is an infostealer that has re-emerged following a major 2025 law-enforcement disruption. Recent activity pivots to CastleLoader, a script-based loader that delivers LummaStealer through social-engineering lures like fake "cracked" software and counterfeit CAPTCHA pages. The chain emphasizes in-memory execution, aggressive obfuscation, and shared infrastructure across ...

  • web:windowsloop.com

    Learn how to scan your computer for Lumma malware and the steps to clean and disinfect your Windows system.

  • web:www.microsoft.com

    Enable investigation and remediation in full automated mode to allow Microsoft Defender for Endpoint to take immediate action on alerts to resolve breaches, significantly reducing alert volume. Use Microsoft Defender for Office 365 for enhanced phishing protection and coverage against new threats and polymorphic variants.

  • web:www.pcrisk.com

    What kind of malware is Lumma? Lumma is a piece of malicious software categorized as a stealer. Malware within this category is designed to steal sensitive data. These programs are capable of exfiltrating data from infected systems and the applications installed onto them. The threats posed by stealers can be extensive and depend on the program's capabilities, the information available on ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.