863c177542f93d6e42ba2dc7633cec75da9515c39ed13915f63e9361f5cf7a6b
Classification: Malicious
863c177542f93d6e42ba2dc7633cec75da9515c39ed13915f63e9361f5cf7a6b is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-03.
Detection summary
- 62 antivirus detections
- 5 IDS alerts
- 0 processes observed
- 4 contacted hosts
- 8 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-09-03 00:45:09 | 2026-09-03 00:45:09 | malicious-activity | |
| Luca Stealer | ThreatFox Abuse.ch | 2024-09-24 06:55:49 | 2024-09-26 06:20:19 | ||
| LummaStealer | MalwareBazaar Abuse.ch | 2024-09-24 05:29:26 | 2024-09-24 05:29:26 | malicious-activity |
Tags
win.luca_stealer maliciousSample information
- Filenames
- 863c177542f93d6e42ba2dc7633cec75da9515c39ed13915f63e9361f5cf7a6b, 94c5abd0eccd77846b4e0f641906bb19.exe
- File type
- application/x-dosexec
- MD5
94c5abd0eccd77846b4e0f641906bb19- SHA-1
3fb0119c89952f61aee14abbe693a293ee916439- SHA-256
863c177542f93d6e42ba2dc7633cec75da9515c39ed13915f63e9361f5cf7a6b- First indexed
- 2024-09-24 07:17:19
- Last updated
- 2026-09-03 00:45:09
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.GenericKD.74098991 |
| APEX | Malicious |
| AVG | Win32:PWSX-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.C5669147 |
| Alibaba | TrojanPSW:MSIL/Lumma.fea26fcb |
| Arcabit | Trojan.Generic.D46AA92F |
| Avast | Win32:PWSX-gen [Trj] |
| Avira | TR/AD.Nekark.oizny |
| BitDefender | Trojan.GenericKD.74098991 |
| Bkav | W32.AIDetectMalware.CS |
| CTX | exe.trojan.msil |
| ClamAV | Win.Packed.Pwsx-10035189-0 |
| CrowdStrike | win/malicious_confidence_70% (D) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.PWS.Lumma.424 |
| ESET-NOD32 | a variant of MSIL/GenKryptik.HBHS |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.GenericKD.74098991 (B) |
| F-Secure | Trojan.TR/AD.Nekark.oizny |
| FireEye | Generic.mg.94c5abd0eccd7784 |
| Fortinet | MSIL/GenKryptik.HBNC!tr |
| GData | Trojan.GenericKD.74098991 |
| Detected | |
| Gridinsoft | Spy.Win32.Gen.tr |
| Ikarus | Trojan.MSIL.Krypt |
| Jiangmin | Trojan.PSW.MSIL.eydv |
| K7AntiVirus | Trojan ( 005ba0eb1 ) |
| K7GW | Trojan ( 005ba0eb1 ) |
| Kaspersky | HEUR:Trojan-PSW.MSIL.Stealerc.gen |
| Kingsoft | MSIL.Trojan-PSW.Stealerc.gen |
| Lionic | Trojan.Win32.Lumma.1u!c |
| Malwarebytes | Trojan.Crypt |
| MaxSecure | Trojan.Malware.204074003.susgen |
| McAfee | Trojan-FWBQ!94C5ABD0ECCD |
| McAfeeD | ti!863C177542F9 |
| MicroWorld-eScan | Trojan.GenericKD.74098991 |
| Microsoft | Trojan:MSIL/Lumma.MBXT!MTB |
| NANO-Antivirus | Trojan.Win32.Nekark.krpmgo |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:9pOrkwsxDYvGBWBQ9qifiA) |
| Sangfor | Infostealer.Msil.Kryptik.Vorm |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | Trojan-FWBQ!94C5ABD0ECCD |
| Sophos | Mal/MSIL-WA |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Trojan.Msil.Kryptik.16001398 |
| Trapmine | suspicious.low.ml.score |
| TrendMicro | TrojanSpy.Win32.LUMMASTEALER.YXEIKZ |
| TrendMicro-HouseCall | TrojanSpy.Win32.LUMMASTEALER.YXEIKZ |
| VBA32 | TScope.Trojan.MSIL |
| VIPRE | Trojan.GenericKD.74098991 |
| Varist | W32/MSIL_Agent.ILW.gen!Eldorado |
| ViRobot | Trojan.Win.Z.Genkryptik.328744 |
| VirIT | Trojan.Win32.GenusT.DZFZ |
| Webroot | W32.Trojan.Gen |
| Xcitium | Malware@#3fwfi24l48yv7 |
| Zillya | Trojan.GenKryptik.Win32.953813 |
| ZoneAlarm | HEUR:Trojan-PSW.MSIL.Stealerc.gen |
| alibabacloud | Trojan[stealer]:MSIL/Lumma.MKFK3DGW |
| huorong | Trojan/MSIL.Agent.li |
Network contacts
DNS requests
basedsymsotp.shop charistmatwio.shop commisionipwn.shop complainnykso.shop grassemenwji.shop ignoracndwko.shop preachstrwnwjw.shop stitchmiscpaew.shop