85249f0315e249612b070d49b61f6550e5088a7f27ebbb4704f0ff0215138ab5
Classification: Malicious
85249f0315e249612b070d49b61f6550e5088a7f27ebbb4704f0ff0215138ab5 is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.
Detection summary
- 23 antivirus detections
- 0 IDS alerts
- 6 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-08-25 15:00:03 |
2026-09-02 22:45:06 |
malicious-activity
|
|
| Lumma Stealer |
ThreatFox Abuse.ch |
2025-04-02 16:34:35 |
2025-04-04 17:28:54 |
|
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2024-08-25 14:23:02 |
2024-08-25 14:23:02 |
malicious-activity
|
|
Tags
win.lumma
lummac2 stealer
Sample information
- Filenames
- 85249f0315e249612b070d49b61f6550e5088a7f27ebbb4704f0ff0215138ab5, 2024-08-25_8794f2bc2fde02646ff6c0d6a7022949_poet-rat_snatch.exe, 85249f0315e249612b070d49b61f6550e5088a7f27ebbb4704f0ff0215138ab5.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 18320896 bytes
- MD5
8794f2bc2fde02646ff6c0d6a7022949
- SHA-1
9fe279752e02f69e01c058f5beb51f41f1b6c945
- SHA-256
85249f0315e249612b070d49b61f6550e5088a7f27ebbb4704f0ff0215138ab5
- First indexed
- 2024-08-25 14:42:44
- Last updated
- 2026-09-02 22:45:06
Antivirus detections
| Engine | Detection |
| AVG | FileRepMalware [Misc] |
| AhnLab-V3 | Infostealer/Win.LummaC2.R662335 |
| Avast | FileRepMalware [Misc] |
| Avira | TR/AVI.Agent.xzcwc |
| Bkav | W32.AIDetectMalware |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of WinGo/Injector.EM |
| F-Secure | Trojan.TR/AVI.Agent.xzcwc |
| Fortinet | W32/PossibleThreat |
| GData | Win32.Trojan.Agent.L9J3CW |
| Google | Detected |
| Ikarus | Trojan-Spy.WinGo.Agent |
| Jiangmin | Server-Proxy.Agent.a |
| Kaspersky | Trojan-PSW.MSIL.Stealerc.sh |
| Kingsoft | malware.kb.a.793 |
| McAfeeD | ti!85249F0315E2 |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Sangfor | Trojan.Win32.Agent.Vy5z |
| Sophos | Mal/Generic-S |
| Tencent | Msil.Trojan-QQPass.QQRob.Jajl |
| Trapmine | malicious.moderate.ml.score |
| ZoneAlarm | Trojan-PSW.MSIL.Stealerc.sh |
| alibabacloud | Trojan[stealer]:Multi/Stealerc.sq |
Process list
| Name | Command line |
| 85249f0315e249612b070d49b61f6550e5088a7f27ebbb4704f0ff0215138ab5.exe | |
| BitLockerToGo.exe | |
| memtest.exe | |
| Microsoft.Msn.Money.exe | |
| Microsoft.Msn.News.exe | |
| Microsoft.Msn.Sports.exe | |