Threat Database Trojans Trojan.Lumma.F

Trojan.Lumma.F

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 9
First Seen: August 23, 2024
Last Seen: January 23, 2026
OS(es) Affected: Windows

Your system has been detected to be infected with Trojan.Lumma.F, a type of malicious software that can cause significant harm to your computer and compromise your personal data. It is essential to take immediate action to remove this threat and prevent further damage.

What Is Trojan.Lumma.F?

Trojan.Lumma.F is a Trojan-type threat, which means it is a type of malware that disguises itself as a legitimate program or file to gain unauthorized access to a computer system. Trojans can be used to steal sensitive information, install additional malware, or provide a backdoor for remote access to the infected system. The name Trojan.Lumma.F suggests that it is a specific variant of malware, but its exact nature and behavior may vary.

How Trojan.Lumma.F Operates

Trojan.Lumma.F, like other Trojans, operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can communicate with its command and control servers to receive instructions and transmit stolen data. The malware may also attempt to download and install additional malware or create backdoors to allow remote access to the infected system. The exact mechanisms used by Trojan.Lumma.F are not known, but it is likely to use common Trojan tactics to evade detection and achieve its goals.

Symptoms of Infection

Systems infected with Trojan.Lumma.F may exhibit a range of symptoms, including slow performance, frequent crashes, and unusual network activity. Users may also notice unfamiliar programs or files on their system, or receive unexpected pop-ups and alerts. In some cases, the malware may attempt to steal sensitive information, such as login credentials or financial data, which can lead to identity theft and financial loss. If you suspect that your system is infected with Trojan.Lumma.F, it is crucial to take immediate action to remove the threat.

How to Remove Trojan.Lumma.F

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove all instances of Trojan.Lumma.F.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Lumma.F from your system requires careful attention and a thorough approach. By following the steps outlined above, you can help ensure that your system is clean and free from this malicious software. It is also essential to take preventive measures to avoid reinfection, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious when opening email attachments or downloading files from the internet. Remember, prompt action is key to minimizing the damage caused by Trojan.Lumma.F and protecting your personal data and system security.

Analysis Report

General information

Family Name: Trojan.Lumma.F
Signature status: No Signature

Known Samples

MD5: d41b4cfadd6d5b8bbd65a650581dbc42
SHA1: a1efe06fdc672c2d7c959c86ed592e55c20b1778
SHA256: 9C576765B3C0B3D237E6589FE76116583F50FBF558DDB984B16D972FC28C4983
File Size: 10.24 KB, 10240 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • x86

Block Information

Total Blocks: 20
Potentially Malicious Blocks: 1
Whitelisted Blocks: 19
Unknown Blocks: 0

Visual Map

x 0 0 0 0 2 0 0 0 0 0 2 2 0 0 2 1 0 0 2
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\mediaplayer\preferences::launchindex  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::sqmlaunchindex  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::appcolorlimited RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::firstrun RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::nextlaunchindex  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::xv11 192 RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::yv11 120 RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::widthv11 6 RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::heightv11 960 RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::maximized 0 RegNtPreCreateKey
Show More
HKCU\software\microsoft\mediaplayer\preferences::currenteffecttype Bars RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::currenteffectpreset  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::videozoom d RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::shrinktofit RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::stretchtofit  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::showeffects  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::showfullscreenplaylist RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\player\tasks\nowplaying::showhorizontalseparator  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\player\tasks\nowplaying::showverticalseparator  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\player\tasks\nowplaying::playlistwidth º RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\player\tasks\nowplaying::playlistheight d RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\player\tasks\nowplaying::settingswidth d RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\player\tasks\nowplaying::settingsheight ‡ RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\player\tasks\nowplaying::metadatawidth º RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\player\tasks\nowplaying::metadataheight   RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\player\tasks\nowplaying::captionsheight d RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::nowplayingquickhide RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::showtitles  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::showcaptions RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::nowplayingplaylist  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::nowplayingmetadata  RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::nowplayingsettings RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::currentdisplayview VizView RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::currentsettingsview EQView RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::currentmetadataview MediaInfoView RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::currentdisplaypreset RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::currentsettingspreset RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::currentmetadatapreset RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userdisplayview VizView RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userwmpdisplayview VizView RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userwmpsettingsview EQView RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userwmpmetadataview MediaInfoView RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userdisplaypreset RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userwmpdisplaypreset RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userwmpsettingspreset RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userwmpmetadatapreset RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userwmpshowsettings RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::userwmpshowmetadata RegNtPreCreateKey
HKCU\software\microsoft\mediaplayer\preferences::showalbumart RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSAStartup

Shell Command Execution

C:\Program Files (x86)\Windows Media Player\wmplayer.exe /device:dvd

Trending

Most Viewed

Loading...