The name "LUMINOSITY" comes from its own builder named Luminosity Link. This builder allows actors to host a Luminosity Link server as well as generate customized binaries, which are compiled with .NET code. With this compiler, it is difficult to perform reverse engineering for the said customized binaries.
Costing roughly about US$40, this builder is very affordable to the actor, thus making it a dangerous threat both to organizations and individuals alike.
Click image to enlarge.
VSAPI Pattern (Malicious File Detection)
Layer | Detection | Pattern Branch | Release Date |
---|---|---|---|
INFECTION | BKDR_LUMINOSITY.X | OPR 12.929 | 9/8/2016 |
WRS Pattern (Malicious URL and Classification)
Layer | URL | Rating | Release Date |
---|---|---|---|
EXPOSURE | {blocked}45.35.190.47/invoice/proforma_invoice_pdf.exe | Malware Accomplice | 11/14/2016 |
EXPOSURE | gibsan.5gbfree{blocked}.com/horas/word.exe | Malware Accomplice | 10/16/2016 |
AEGIS Pattern (Behavior Monitoring Pattern)
Layer | Detection | Pattern Branch | Release Date |
---|---|---|---|
DYNAMIC | 2730T | OPR 1625 | 1/17/2017 |
DCT Pattern (System Clean Pattern)
Layer | Detection | Pattern Branch | Release Date |
---|---|---|---|
CLEAN-UP | TSC_GENCLEAN | latest DCT OPR | (Built-in) |
Solution Map
Major Products | Versions | Virus Pattern | Behavior Monitoring | Web Reputation | DCT Pattern | Antispam Pattern | Network Pattern |
---|---|---|---|---|---|---|---|
OfficeScan | 10.6 and above | Update pattern via web console. | Update pattern via web console. | Enable Web Reputation Service*. | Update pattern via web console. | (not applicable) | Update pattern via web console. |
Worry Free Business Suite | Standard | (not applicable) | |||||
Advanced/MSA | Update pattern via web console. | ||||||
Hosted | |||||||
Deep Security | 8.0 and above | (not applicable) | (not applicable) | Update pattern via web console. | |||
ScanMail | SMEX 10 and later | (not applicable) | Update pattern via web console. | (not applicable) | |||
SMD 5 and later | |||||||
InterScan Messaging | IMSVA 8.0 and above | ||||||
InterScan Web | IWSVA 6.0 and later | ||||||
Deep Discovery | DDI 3.0 and later | (not applicable) | Update pattern via web console. | ||||
DDAN | |||||||
DDEI |
For further information, refer to the KB article on Recommendations on how to best protect your network using Trend Micro products.
Also visit Trend Micro's Threat Encyclopedia for further details on BKDR_LUMINOSITY.X.
Use this KB article to guide you in submitting suspicious or undetected virus for file analysis to Technical Support.