852f4955e3d61518e3653abba37ef23ae2d86a9ea94198856955a99d656fbc20
Classification: Malicious
852f4955e3d61518e3653abba37ef23ae2d86a9ea94198856955a99d656fbc20 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 46 antivirus detections
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 9 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-08-01 17:00:03 |
2026-09-02 22:45:05 |
malicious-activity
|
|
| Luca Stealer |
ThreatFox Abuse.ch |
2024-08-02 21:00:21 |
2024-08-04 20:18:48 |
|
|
Tags
win.luca_stealer
trojan
bot
Sample information
- Filenames
- 852f4955e3d61518e3653abba37ef23ae2d86a9ea94198856955a99d656fbc20, 2.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 275968 bytes
- MD5
8987604aedffcf3b2ed8033f4b41ce84
- SHA-1
fb8c15a8716be523b364aa647ced8e546cab025a
- SHA-256
852f4955e3d61518e3653abba37ef23ae2d86a9ea94198856955a99d656fbc20
- First indexed
- 2024-08-01 16:52:23
- Last updated
- 2026-09-02 22:45:05
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.Zusy.534615 |
| APEX | Malicious |
| AhnLab-V3 | Trojan/Win.Generic.C5566047 |
| Alibaba | Trojan:Win32/Tasker.68835697 |
| Arcabit | Trojan.Zusy.D82857 |
| Avira | HEUR/AGEN.1319014 |
| BitDefender | Gen:Variant.Zusy.534615 |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.generic |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.MulDrop28.1326 |
| ESET-NOD32 | Win32/Agent.AGPC trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Zusy.534615 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1319014 |
| Fortinet | PossibleThreat.ARN.M |
| GData | Win32.Trojan.ZharkBot.A |
| Google | Detected |
| Ikarus | Trojan.Win32.Amadey |
| K7AntiVirus | Trojan ( 005e85171 ) |
| K7GW | Trojan ( 005e85171 ) |
| Kingsoft | Win32.HeurC.KVMH017.a |
| Lionic | Trojan.Win32.Amadey.4!c |
| Malwarebytes | Generic.Malware/Suspicious |
| McAfeeD | Real Protect-LS!8987604AEDFF |
| MicroWorld-eScan | Gen:Variant.Zusy.534615 |
| Microsoft | Trojan:Win32/Amadey.KAA!MTB |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Symantec | Trojan.Whispergate |
| Tencent | Malware.Win32.Gencirc.1414c375 |
| Trapmine | suspicious.low.ml.score |
| TrellixENS | Artemis!8987604AEDFF |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9t |
| VBA32 | Trojan.Tasker |
| VIPRE | Gen:Variant.Zusy.534615 |
| Varist | W32/ABTrojan.HZRV-4814 |
| VirIT | Trojan.Win32.Genus.WFA |
| Webroot | W32.Trojan.Amadey |
| Xcitium | Malware@#tpl7m49f6ilk |
| Zillya | Trojan.Agent.Win32.3990544 |
| alibabacloud | Trojan:Win/Acll.Gen |
| huorong | Trojan/Agent.buw |
Process list
| Name | Command line |
| 2.exe | |
| schtasks.exe | %WINDIR%\System32\schtasks.exe /Create /SC MINUTE /MO 1 /TN Aptitude.exe /TR "%TEMP%\43895672139432\Aptitude.exe" /F |
| Aptitude.exe | |
| Aptitude.exe | |
| Aptitude.exe | |