MB-e08c0890b11d91b7ee58de25cc190e1fdf760d76b6d0821aa2d1f442b43e719a
high
📛 Threat Title
LummaStealer: setup.exe
Description
File type: exe. Size: 4717920 bytes. Tags: exe, LummaStealer, signed. Reporter: iamaachum. First seen: 2026-08-04 19:38:41.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
1aae8bf580c846f39c71c05898e57e88
IOC database
- Type
- hash_imphash
- Value
1aae8bf580c846f39c71c05898e57e88- First seen
- Last seen
- Attached to this threat
- Appears in
- 59 threats
- Description
- imphash of URLhaus payload d06c8ee46e760f39…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
e08c0890b11d91b7ee58de25cc190e1fdf760d76b6d0821aa2d1f442b43e719a
IOC database
- Type
- hash_sha256
- Value
e08c0890b11d91b7ee58de25cc190e1fdf760d76b6d0821aa2d1f442b43e719a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- LummaStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
b0fda8fa73f02276d2b5fff52e1a256043ad69e1
IOC database
- Type
- hash_sha1
- Value
b0fda8fa73f02276d2b5fff52e1a256043ad69e1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
6f62e6118343703a0ce6311074f236be
IOC database
- Type
- hash_md5
- Value
6f62e6118343703a0ce6311074f236be- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 4717920 bytes. Tags: exe, LummaStealer, signed. Reporter: iamaachum. First seen: 2026-08-04 19:38:41.
Remediations (10)
-
web:cybernews.com
The Lumma Stealer is a nasty piece of malware that can steal your data and money. In this article, I'll give you a quick guide on how to remove and avoid this virus.
-
web:forums.malwarebytes.com
Hi all. Bit Of a PC noob here. I recently got infected with a LummaStealer according to Windows Defender. At this point neither Windows Defender or Malwarebytes can locate any viruses. I am planning to Reset my PC via Windows, is there any possible thing I have to do after doing so to ensure I am...
-
web:forums.malwarebytes.com
Go to topic listing by CleanTalk Home Malware Removal Help Windows Malware Removal Help & Support Resolved Malware Removal Logs Infected with LummaStealer
-
web:learn.microsoft.com
Hello! Stupidly I ran a fake captcha resulting in LummaStealer being installed. Microsoft Defender however says it has blocked the threat. Saying it is now quarantined and will be deleted automatically. Does this mean I just got really lucky? Or do I need to take additional steps to make sure everything is safe? As of writing this, I am running a full scan by Microsoft Defender. Thank you!
-
web:learn.microsoft.com
Sometimes, remnants can be left behind and keep getting flagged after removal. If you haven't noticed any suspicious account activity, odd processes in task manager, and you never actually visited any unsafe sites/downloaded cracked software, you are likely in the clear.
-
web:malwaretips.com
Bitdefender researchers have discovered a surge in LummaStealer activity, showing how one of the world's most prolific information-stealing malware operations managed to survive despite being almost brought down by law enforcement less than a year ago. LummaStealer is a highly scalable information-stealing threat with a long history, having operated under a malware-as-a-service model since it ...
-
web:socprime.com
Summary LummaStealer is an infostealer that has re-emerged following a major 2025 law-enforcement disruption. Recent activity pivots to CastleLoader, a script-based loader that delivers LummaStealer through social-engineering lures like fake "cracked" software and counterfeit CAPTCHA pages. The chain emphasizes in-memory execution, aggressive obfuscation, and shared infrastructure across ...
-
web:windowsloop.com
Learn how to scan your computer for Lumma malware and the steps to clean and disinfect your Windows system.
-
web:www.microsoft.com
Enable investigation and remediation in full automated mode to allow Microsoft Defender for Endpoint to take immediate action on alerts to resolve breaches, significantly reducing alert volume. Use Microsoft Defender for Office 365 for enhanced phishing protection and coverage against new threats and polymorphic variants.
-
web:www.pcrisk.com
What kind of malware is Lumma? Lumma is a piece of malicious software categorized as a stealer. Malware within this category is designed to steal sensitive data. These programs are capable of exfiltrating data from infected systems and the applications installed onto them. The threats posed by stealers can be extensive and depend on the program's capabilities, the information available on ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.