81d6f774c002106258af4350818c9c3687185584c59e1a797b4019bd462a086c
Classification: Malicious
81d6f774c002106258af4350818c9c3687185584c59e1a797b4019bd462a086c is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.
Detection summary
- 34 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 8 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-09-02 17:45:04 | 2026-09-02 17:45:04 | malicious-activity | |
| Lumma Stealer | ThreatFox Abuse.ch | 2025-04-02 16:34:18 | 2025-04-04 17:30:35 | ||
| Generic.Malware | MalwareBazaar Abuse.ch | 2024-10-19 14:29:02 | 2024-10-19 14:29:02 | malicious-activity |
Tags
win.lumma lummac2 stealer evasiveSample information
- Filenames
- 81d6f774c002106258af4350818c9c3687185584c59e1a797b4019bd462a086c, 60ba9344dd5355681145a108e27ea4ee
- File type
- application/x-dosexec
- MD5
60ba9344dd5355681145a108e27ea4ee- SHA-1
5c4a627e15e1aeac3a58ac416ed45685576fe0f5- SHA-256
81d6f774c002106258af4350818c9c3687185584c59e1a797b4019bd462a086c- First indexed
- 2024-10-19 15:26:12
- Last updated
- 2026-09-02 17:45:04
Antivirus detections
| Engine | Detection |
|---|---|
| Alibaba | TrojanDropper:Application/Runner.0b0c63cb |
| Arcabit | Trojan.Generic.D232C108 |
| Avira | TR/Redcap.ncywg |
| BitDefender | Trojan.Generic.36880648 |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.runner |
| CrowdStrike | win/grayware_confidence_60% (D) |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | NSIS/Runner.CM |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Generic.36880648 (B) |
| F-Secure | Trojan.TR/Redcap.ncywg |
| FireEye | Generic.mg.60ba9344dd535568 |
| GData | Win32.Trojan.Agent.T2QW4V |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| Lionic | Trojan.Win32.Runner.4!c |
| McAfee | Artemis!60BA9344DD53 |
| McAfeeD | ti!81D6F774C002 |
| MicroWorld-eScan | Trojan.Generic.36880648 |
| Microsoft | Trojan:Win32/Sonbokli.A!cl |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Trojan.Runner/NSIS!1.10448 (CLASSIC) |
| Sangfor | Trojan.Win32.Runner.V7lw |
| Skyhigh | Artemis!Trojan |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Win32.Trojan.FalseSign.Fajl |
| VIPRE | Trojan.Generic.36880648 |
| ZoneAlarm | UDS:DangerousObject.Multi.Generic |
| alibabacloud | Trojan[dropper]:Win/Runner.CZ |
| huorong | Trojan/Runner.bm |
| tehtris | Generic.Malware |
DNS requests
condifendteu.sbs drawwyobstacw.sbs ehticsprocw.sbs enlargkiw.sbs mathcucom.sbs rOKrnmMdUDNYhr.rOKrnmMdUDNYhr resinedyw.sbs vennurviot.sbs