81a3a8a0412d519ebc63f7020adff204ea2ea0c117fd0ad8d7828615895ea648
Classification: Malicious
81a3a8a0412d519ebc63f7020adff204ea2ea0c117fd0ad8d7828615895ea648 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 61 antivirus detections
- 16 IDS alerts
- 0 processes observed
- 6 contacted hosts
- 9 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-09-02 17:45:06 | 2026-09-02 17:45:06 | malicious-activity | |
| Lumma Stealer | ThreatFox Abuse.ch | 2025-04-02 16:34:17 | 2025-04-04 17:30:43 |
Tags
win.lumma lummac2 stealer evasive maliciousSample information
- Filenames
- 81a3a8a0412d519ebc63f7020adff204ea2ea0c117fd0ad8d7828615895ea648
- File type
- PE32 executable for MS Windows 6.00 (GUI), Intel i ...
- MD5
a996397cd4d1502f1eed95cd693d5752- SHA-1
e66aed1fe77966fe2d9eebc5ba8e44f873485589- SHA-256
81a3a8a0412d519ebc63f7020adff204ea2ea0c117fd0ad8d7828615895ea648- First indexed
- 2025-04-02 19:28:29
- Last updated
- 2026-09-02 17:45:06
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Gen:Variant.Symmi.93663 |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.R683293 |
| Alibaba | TrojanPSW:Win32/CryptBot.fadacc68 |
| Antiy-AVL | Trojan[PSW]/Win32.StealerC |
| Arcabit | Trojan.Symmi.D16DDF |
| Avast | Win32:Evo-gen [Trj] |
| Avira | TR/Crypt.XPACK.Gen |
| BitDefender | Gen:Variant.Symmi.93663 |
| Bkav | W32.Common.78BB3651 |
| CAT-QuickHeal | Trojan.Ghanarava.17354920623d5752 |
| CTX | exe.trojan.themida |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.PWS.Lumma.1113 |
| ESET-NOD32 | a variant of Win32/Packed.Themida.HZB |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Symmi.93663 (B) |
| F-Secure | Trojan.TR/Crypt.XPACK.Gen |
| FireEye | Generic.mg.a996397cd4d1502f |
| Fortinet | W32/PossibleThreat |
| GData | Gen:Variant.Symmi.93663 |
| Detected | |
| Gridinsoft | Trojan.Heur!.038120A1 |
| Ikarus | Trojan.Win32.CryptBot |
| K7AntiVirus | Trojan ( 00587f0f1 ) |
| K7GW | Trojan ( 00587f0f1 ) |
| Kaspersky | HEUR:Trojan-PSW.Win32.Stealerc.pef |
| Kingsoft | Win32.HeurC.KVMH008.a |
| Lionic | Trojan.Win32.Themida.i!c |
| MAX | malware (ai score=80) |
| Malwarebytes | Trojan.MalPack.Themida.Generic |
| MaxSecure | Trojan.Malware.215961091.susgen |
| McAfee | Artemis!A996397CD4D1 |
| McAfeeD | Real Protect-LS!A996397CD4D1 |
| MicroWorld-eScan | Gen:Variant.Symmi.93663 |
| Microsoft | Trojan:Win32/CryptBot!rfn |
| NANO-Antivirus | Trojan.Win32.Stealerc.ktvqzk |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Trojan.Agent!1.106C0 (CLASSIC) |
| Sangfor | Infostealer.Win32.Cryptbot.Val5 |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.tc |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Win32.Trojan-QQPass.QQRob.Fajl |
| Trapmine | malicious.high.ml.score |
| VBA32 | TScope.Malware-Cryptor.SB |
| VIPRE | Gen:Variant.Symmi.93663 |
| Varist | W32/Themida.DA.gen!Eldorado |
| VirIT | Trojan.Win32.GenusT.EDWA |
| Yandex | Trojan.Themida!QwreFE73WC0 |
| Zillya | Trojan.Themida.Win32.124465 |
| ZoneAlarm | UDS:DangerousObject.Multi.Generic |
| Zoner | Probably Heur.ExeHeaderL |
| huorong | HEUR:TrojanSpy/Stealer.ay |
| tehtris | Generic.Malware |
Network contacts
52.16.171.153 52.27.79.221 34.229.166.50 44.244.22.128 3.238.30.69 50.16.27.236
DNS requests
atten-supporse.biz covery-mover.biz dare-curbys.biz dwell-exclaim.biz formy-spill.biz impend-differ.biz print-vexer.biz se-blurry.biz zinc-sneark.biz