7da733f143c45f0b42d304e48be8fa55d34fdd279b5efd02ed1d34a5553c50ed

Classification: Malicious

7da733f143c45f0b42d304e48be8fa55d34fdd279b5efd02ed1d34a5553c50ed is a malicious file sample. Linked to Lumma Stealer malware.

Detection summary

  • 42 antivirus detections (58% detection ratio)
  • 22 IDS alerts
  • 23 processes observed
  • 40 contacted hosts
  • 37 DNS requests

MITRE ATT&CK associations

Malware families: LUMMA STEALER (S1213)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-11-11 02:45:04 2026-09-02 11:45:05 malicious-activity
LummaStealer MalwareBazaar Abuse.ch 2023-11-11 02:15:22 2023-11-11 02:15:22 malicious-activity S1213 Lumma Stealer

Tags

evasive suspicious

Sample information

Filenames
7da733f143c45f0b42d304e48be8fa55d34fdd279b5efd02ed1d34a5553c50ed, 7da733f143c45f0b42d304e48be8fa55d34fdd279b5efd02ed1d34a5553c50ed.exe, e589ae5fd4bbfdde8a7868a1f1811bfc.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
1391104 bytes
MD5
e589ae5fd4bbfdde8a7868a1f1811bfc
SHA-1
272c86c0917fdd8c97312b26a678cb1399cd960d
SHA-256
7da733f143c45f0b42d304e48be8fa55d34fdd279b5efd02ed1d34a5553c50ed
First indexed
2023-11-11 02:16:12
Last updated
2026-09-02 11:45:05

Antivirus detections

EngineDetection
BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealerc.i!c
SkyhighBehavesLike.Win32.Downloader.tc
ALYacGen:Variant.Lazy.285513
MalwarebytesMalware.AI.344822107
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005aad751 )
K7GWTrojan ( 005aad751 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GPYJ
APEXMalicious
ClamAVWin.Downloader.Crifi-10009289-0
KasperskyUDS:Trojan-PSW.Win32.Stealerc.gen
Rising[email protected] (RDML:XzKwVgpHPZHl6iyuS4nc/g)
DrWebTrojan.Inject4.63898
VIPREGen:Variant.Lazy.285513
TrendMicroTrojanSpy.Win32.TRICKBOT.SMC
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Spy.Stealer
JiangminTrojan.Script.awbz
GoogleDetected
VaristW32/Kryptik.JKR.gen!Eldorado
KingsoftWin32.PSWTroj.Undef.a
MicrosoftTrojan:Win32/Stealerc.NS!MTB
GridinsoftMalware.Win32.Gen.bot
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmUDS:Trojan-PSW.Win32.Stealerc
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!E589AE5FD4BB
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMC
SentinelOneStatic AI - Suspicious SFX
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HUTD!tr
AVGFileRepMalware [Trj]
Cybereasonmalicious.0917fd
AvastFileRepMalware [Trj]

Network contacts

142.251.163.84 142.251.219.3 142.251.219.131 157.240.22.35 142.251.219.46 8.45.176.205 142.251.157.119 157.240.254.7 23.54.42.115 162.159.140.229 23.54.40.202 104.18.20.94 104.19.230.21 104.18.20.177 3.232.130.55 18.238.80.36 151.101.129.21 99.84.160.83 18.164.123.208 13.226.94.103 18.238.45.26 52.84.24.24 142.251.153.4 142.251.218.202 142.251.218.131 150.171.109.115 5.42.92.51 157.240.11.35 142.250.189.205 5.42.92.43 23.59.200.146 104.244.42.129 142.250.189.195 142.250.176.14 142.251.32.35 152.199.24.185 142.251.46.164 142.250.72.142 104.21.53.57 142.250.189.206

DNS requests

accounts.google.com accounts.youtube.com c.pki.goog crl.r2m04.amazontrust.com crl.rootca1.amazontrust.com crl.rootg2.amazontrust.com crt.rootg2.amazontrust.com fonts.googleapis.com fonts.gstatic.com js.hcaptcha.com moskhoods.pw numpersb.fun o.ss2.us ocsp.digicert.cn ocsp.pki.goog ocsp.r2m04.amazontrust.com ocsp.rootca1.amazontrust.com ocsp.rootg2.amazontrust.com s.ss2.us ssl.gstatic.com static-assets-prod.unrealengine.com static.xx.fbcdn.net steamcommunity.com store.steampowered.com tracking.epicgames.com twitter.com www.epicgames.com www.facebook.com www.google.com www.noticeofpleadings.net www.paypal.com www.youtube.com abs.twimg.com killredls.pw ocsp.digicert.com play.google.com www.gstatic.com

Process list

NameCommand line
e589ae5fd4bbfdde8a7868a1f1811bfc.exe
ss5Xc68.exe
Sj0Yr81.exe
3Vk348xA.exe
iexplore.exehttps://accounts.google.com/
iexplore.exeSCODEF:176 CREDAT:275457 /prefetch:2
iexplore.exehttps://www.facebook.com/login
iexplore.exeSCODEF:484 CREDAT:275457 /prefetch:2
iexplore.exeSCODEF:484 CREDAT:5321730 /prefetch:2
iexplore.exehttps://accounts.google.com/
iexplore.exeSCODEF:1060 CREDAT:340993 /prefetch:2
iexplore.exehttps://store.steampowered.com/login/
iexplore.exeSCODEF:3108 CREDAT:275457 /prefetch:2
iexplore.exehttps://twitter.com/i/flow/login
iexplore.exeSCODEF:3300 CREDAT:275457 /prefetch:2
iexplore.exehttps://steamcommunity.com/openid/loginform/
iexplore.exeSCODEF:3916 CREDAT:275457 /prefetch:2
4MN1XS8.exe
AppLaunch.exe
5ye52kR.exe
AppLaunch.exe
6YR939.exe
AppLaunch.exe