lu4-win64-shipping.exe

Classification: Malicious

lu4-win64-shipping.exe is a malicious file sample. Reported by 1 threat source, last seen 2025-06-22. Detected by 18 antivirus engines.

Detection summary

  • 18 antivirus detections
  • 1 IDS alerts
  • 1 processes observed
  • 4 contacted hosts
  • 4 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-06-22 10:15:02 2025-06-22 12:15:10

Tags

suspicious

Sample information

Filenames
lu4-win64-shipping.exe
File type
PE32+ executable (GUI) x86-64, for MS Windows, 9 s ...
Size
49528944 bytes
MD5
35cdbfb928b07be2a81272cfb5a7863c
SHA-1
3f09ca4d34d6e6ba7311eb761e46bae4255b4c7a
SHA-256
4ee4b3ea06b8f20c0ab48e95e3e6c9071a6029d54a8730b9e080cf1e6e3f8c3f
First indexed
2025-06-22 10:06:56
Last updated
2025-06-22 12:15:11

Antivirus detections

EngineDetection
ALYacGen:Variant.Barys.494608
AhnLab-V3Trojan/Win.Generic.C5772960
ArcabitTrojan.Barys.D78C10
BitDefenderGen:Variant.Barys.494608
CTXexe.trojan.barys
CylanceUnsafe
DeepInstinctMALICIOUS
EmsisoftGen:Variant.Barys.494608 (B)
FortinetW32/PossibleThreat
GDataGen:Variant.Barys.494608
GoogleDetected
IkarusTrojan.Win32.Yomal
MaxSecureTrojan.Malware.219104223.susgen
MicroWorld-eScanGen:Variant.Barys.494608
MicrosoftTrojan:Win32/Yomal!rfn
SkyhighArtemis
VIPREGen:Variant.Barys.494608
VaristW64/ABTrojan.ZBYN-3624

Network contacts

95.164.94.71 34.224.149.186 104.21.96.1 199.59.243.228

DNS requests

lu4.mw2.global test.com test2.com www.squadhelp.com

Process list

NameCommand line
lu4-win64-shipping.exe