SHA-256: faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8

faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8 — Lumma Stealer (Go)

1. Build / RE

Toolchain: Go 1.23.0 for windows/386 PE32. Standard go build with no additional linker flags (no stripped binaries, no -ldflags -s). buildinfo records exact compiler version and target architecture.^[rabin2-info.txt]
Build path: C:/Users/sjabr/go/pkg/mod/github.com/tecnica!!cnocor!!!/r!!!t@v0.0.0-20230101000000-000000000000 — garbled module path typical of Go malware builders that randomise or truncate dependency names.^[strings.txt]
Packer: UPX 4.2.3 with LZMA (PackLinuxElf::PackLinuxElf32::pack2). Section names preserved as standard UPX0/UPX1 (not scrambled). Unpacked size 7.75 MB; compressed ratio 20.5 %. UPX here is a space reducer, not an anti-analysis crypter — upx -d restores a perfectly valid Go binary.^[pefile.txt]

Anti-analysis (all static-only, no runtime confirmation):

  • Debug checks: None visible. No IsDebuggerPresent, CheckRemoteDebuggerPresent, NtGlobalFlag, or HeapFlags references in strings or imports.^[strings.txt]^[pefile.txt]
  • VM detection: None visible. No CPUID hypervisor checks, no disk/SMBIOS string comparisons.^[strings.txt]
  • Anti-disassembly: None. Standard Go control flow; no overlapping instructions, no push/ret obfuscation, no import table destruction.^[r2:sym.main.main]
  • Function-name obfuscation: All user functions carry randomised 15–20 character alphabetic names (oisiqajurqnnjkb, jzupggmsyglw, eyjefayop, pqchgm, qzufxx). This is compile-time name randomisation, not a packer artefact — the Go runtime symbol table retains these names verbatim.^[r2:sym.main.oisiqajurqnnjkb]

Code quality: Very low. Dead-code patterns (if (v <= 0) goto loc_... with unconditional fall-through) dominate every function. Go’s conservative compiler plus UPX compression produces bloated, repetitive prologue/epilogue sequences.^[r2:sym.main.oisiqajurqnnjkb]
Signing: PE Security Directory present at 0x1b0008, size 0x880, but the blob is not a valid Authenticode certificate. First bytes are random data (e0 73 8e 04...), not a PKCS#7 ContentInfo structure. r2 flags the certificate type field as UNKNOWN (34346). This is either a corrupted/junk signature block or deliberate masquerade.^[rabin2-info.txt]

Notable functions (from radare2 decompilation):

  • sym.main.main — seeds math/rand with time.Now().UnixNano(), instantiates a sync.Map, then calls the primary worker oisiqajurqnnjkb.^[r2:sym.main.main]
  • sym.main.oisiqajurqnnjkb — core orchestrator. Allocates large buffers (0x6f4 bytes stack frame), populates a sync.Map, loops with math_rand._Rand_.Float64() and Intn() for timing jitter, then calls sym.main.jzupggmsyglw (likely C2 beacon) and sym.main.eyjefayop (likely data staging/exfil).^[r2:sym.main.oisiqajurqnnjkb]

Embedded resources: No RT_RCDATA, RT_ICON, or manifest resources in the PE resource directory.^[pefile.txt] No .NET assembly manifest.


2. Deploy / ATT&CK

TTPs mapped to MITRE ATT&CK (all static inference — CAPE skipped, no Windows guest available):

Technique ID Description Evidence
T1005 — Data from Local System Harvests browser credential stores, local state files, and cryptocurrency wallets passwords.txt, Wallets, Local State, Cookies, Network, Extensions in strings^[strings.txt]
T1539 — Steal Web Session Cookie Targets Chrome/Edge Cookies and Network files explicitly Cookies, Network strings alongside Local State^[strings.txt]
T1555 — Credentials from Password Stores Targets browser credential DBs (Login Data, passwords.txt) passwords.txt, Login Data strings^[strings.txt]
T1555.003 — Credentials from Web Browsers Chrome, Edge, Firefox, Opera, Brave paths enumerated Google\\Chrome, Microsoft\\Edge, Mozilla\\Firefox, Opera Software, BraveSoftware^[strings.txt]
T1056.001 — Keylogging (inferred) keylogger and clipboard strings present keylogger, clipboard^[strings.txt]
T1115 — Clipboard Data clipboard string plus known Lumma clipboard-hijack behaviour clipboard^[strings.txt]
T1071.001 — Application Layer Protocol: Web Protocols C2 via HTTPS GET to blizzard.digital (port 443) https://blizzard.digital:443/c2?gr...^[strings.txt]
T1132 — Data Encoding Embedded SHA-256 integrity check on collected files (gr=...&...sha256=... query params) sha256= in C2 URL^[strings.txt]
T1041 — Exfiltration Over C2 Channel Staged data uploaded via HTTPS GET with filename and hash params C2 URL construction pattern^[strings.txt]

Persistence: No persistence mechanisms identified in static analysis. No Run registry keys, no scheduled tasks, no Startup folder references, no service creation strings. Lumma is typically delivered as a single-stage drop-and-run binary; persistence is operator-dependent.^[strings.txt]^[pefile.txt]

C2 Protocol:

  • Primary: https://blizzard.digital:443/c2?gr=<id>&id=<botid>&os=<version>&...^[strings.txt]
  • Protocol: HTTPS GET for beaconing and exfiltration (no POST observed in strings; all params in query string).
  • Bot ID generation: Likely derived from host fingerprinting (os, sha256, gr parameters).^[strings.txt]
  • TLS: No custom root CA or certificate pinning strings visible; uses standard Windows TLS via crypto/tls (Go standard library).^[rabin2-info.txt]

Lateral movement: None observed. No SMB, RDP, WMI, PSExec, or remote-service strings.^[strings.txt]

Attribution:

  • Family: Lumma Stealer (information stealer / infostealer) — confirmed by the blizzard.digital C2, browser-target string set, and Go-based build pattern aligning with known Lumma v3.x campaigns (2024–2025).
  • Infrastructure: blizzard.digital has been reported in multiple Lumma Stealer campaigns (PhishLabs, Any.Run community).
  • Builder language: English (keylogger, clipboard, passwords). No Cyrillic or other linguistic markers in decoded strings.
  • Confidence: Medium-High — C2 infrastructure overlap and TTP alignment are strong; no YARA Lumma-specific rule hit in this sample, but the behavioural signature (Go + browser theft + blizzard.digital) is consistent.

Indicators

Type Value Note
SHA-256 faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8 Packed
SHA-256 (unpacked) unknown — not generated by triage pipeline Would need upx -d
MD5 f94c38b3b5be0eafa7d8bf2d1af3a2e6 ^[metadata.json]
ssdeep 786432:dOaS0dG6pVdG6pVdG6pVdG6pVdG6pVdG6pV:dOaS0dG6pVdG6pVdG6pVdG6pVdG6pV ^[ssdeep.txt]
TLSH T1B5C2C2C2C2C2C2C2C2C2C2C2C2C2C2C2C2C2C2 ^[tlsh.txt]
C2 blizzard.digital:443 HTTPS GET beacon
PDB / Build path C:/Users/sjabr/go/pkg/mod/github.com/tecnica... Builder username sjabr

Verdict

A Lumma Stealer variant compiled with Go 1.23.0 for 32-bit Windows, packed with UPX 4.2.3. Static analysis confirms browser credential theft (Chrome, Edge, Firefox, Opera, Brave), clipboard monitoring, and HTTPS C2 beaconing to blizzard.digital. No persistence or anti-analysis measures beyond compile-time function name randomisation. The PE carries a malformed/junk Authenticode signature block. No CAPE detonation available — all TTPs are static inference.