819c6b1f9706d8644dfd1d081ac34a501c7af55ada4f43815af40cdcccc577e8

Classification: Malicious

819c6b1f9706d8644dfd1d081ac34a501c7af55ada4f43815af40cdcccc577e8 is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.

Detection summary

  • 44 antivirus detections
  • 2 IDS alerts
  • 4 processes observed
  • 1 contacted hosts
  • 8 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-10-16 01:15:09 2026-09-02 17:45:06 malicious-activity
Lumma Stealer ThreatFox Abuse.ch 2025-04-02 16:34:17 2025-04-04 17:30:42
Generic.Malware MalwareBazaar Abuse.ch 2024-10-13 01:32:40 2024-10-13 01:32:40 malicious-activity

Tags

evasive win.lumma lummac2 stealer malicious

Sample information

Filenames
819c6b1f9706d8644dfd1d081ac34a501c7af55ada4f43815af40cdcccc577e8, 819c6. Trojan.exe, file
File type
application/x-dosexec
Size
1910272 bytes
MD5
3d0bd95b0f36182c6a2087f96369bedf
SHA-1
0ba2f80e6cf9895f13bcd473deb7bf785aba2c9e
SHA-256
819c6b1f9706d8644dfd1d081ac34a501c7af55ada4f43815af40cdcccc577e8
First indexed
2024-10-13 03:18:53
Last updated
2026-09-02 17:45:07

Antivirus detections

EngineDetection
ALYacTrojan.GenericKDZ.108241
APEXMalicious
AVGWin32:Evo-gen [Trj]
AhnLab-V3Trojan/Win.Generic.C5678949
ArcabitTrojan.Generic.D1A6D1
AvastWin32:Evo-gen [Trj]
AviraTR/Crypt.ZPACK.Gen
BitDefenderTrojan.GenericKDZ.108241
BkavW32.AIDetectMalware
CTXexe.trojan.generickdz
CrowdStrikewin/malicious_confidence_100% (D)
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
ESET-NOD32a variant of Win32/Packed.Themida.HZB
Elasticmalicious (high confidence)
EmsisoftTrojan.GenericKDZ.108241 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
FireEyeGeneric.mg.3d0bd95b0f36182c
FortinetW32/Themida.HZB!tr
GDataTrojan.GenericKDZ.108241
GoogleDetected
GridinsoftTrojan.Heur!.03A120A1
KasperskyHEUR:Trojan.Win32.Generic
LionicTrojan.Win32.Themida.4!c
MalwarebytesTrojan.Amadey
McAfeeArtemis!3D0BD95B0F36
McAfeeDReal Protect-LS!3D0BD95B0F36
MicroWorld-eScanTrojan.GenericKDZ.108241
MicrosoftTrojan:Win32/Wacatac.B!ml
RisingTrojan.Generic!8.C3 (LESS:bWQ1Oj0L2VsPNhgsaiCH+WNpvt8)
SangforTrojan.Win32.Themida.V79f
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.tc
SophosML/PE-A
SymantecML.Attribute.HighConfidence
TencentTrojan-DL.Win32.Deyma.kh
Trapminemalicious.high.ml.score
VBA32TScope.Malware-Cryptor.SB
VIPRETrojan.GenericKDZ.108241
VaristW32/Themida.CQ.gen!Eldorado
ZoneAlarmHEUR:Trojan.Win32.Generic
ZonerProbably Heur.ExeHeaderL
alibabacloudTrojan:Win/Sabsik.FE

Network contacts

3.250.92.156

DNS requests

bathdoomgaz.store clearancek.site dissapoiznw.store eaglepawnoy.store licendfilteo.site mobbipenju.store spirittunek.store studennotediw.store

Process list

NameCommand line
819c6.Trojan.exe
WerFault.exe-u -p 7660 -s 756
WerFault.exe-u -p 7660 -s 756
WerFault.exe-pss -s 440 -p 7660 -ip 7660