87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f00d02d197078cf8e9c3
Classification: Malicious
87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f00d02d197078cf8e9c3 is a malicious file sample. Linked to Lumma Stealer malware.
Detection summary
- 41 antivirus detections (56% detection ratio)
- 1 IDS alerts
- 27 processes observed
- 17 contacted hosts
- 18 DNS requests
MITRE ATT&CK associations
Malware families: LUMMA STEALER (S1213)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2023-11-29 06:15:03 | 2026-09-03 01:45:07 | malicious-activity | |
| Downloader | VM-Ray | 2023-11-29 07:22:15 | 2023-11-29 09:23:38 | ||
| Injector | VM-Ray | 2023-11-29 07:22:15 | 2023-11-29 09:23:38 | ||
| LummaStealer | MalwareBazaar Abuse.ch | 2023-11-29 05:45:36 | 2023-11-29 05:45:36 | malicious-activity | S1213 Lumma Stealer |
Tags
windows-server-utilitySample information
- Filenames
- 87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f00d02d197078cf8e9c3, 87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 2023424 bytes
- MD5
49f4b13f62f843ae67ac8c26ecab79c9- SHA-1
c35e2035f7597302adf895775a6a1fc29ad4426f- SHA-256
87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f00d02d197078cf8e9c3- First indexed
- 2023-11-29 05:45:53
- Last updated
- 2026-09-03 01:45:07
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.AIDetectMalware |
| ClamAV | Win.Malware.Zard-10015589-0 |
| Skyhigh | BehavesLike.Win32.Generic.tc |
| McAfee | Artemis!49F4B13F62F8 |
| Malwarebytes | Disabler.Trojan.MSIL.DDS |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Trojan ( 005aad751 ) |
| K7GW | Trojan ( 005aad751 ) |
| Symantec | ML.Attribute.HighConfidence |
| Elastic | malicious (high confidence) |
| ESET-NOD32 | multiple detections |
| APEX | Malicious |
| Cynet | Malicious (score: 99) |
| Kaspersky | UDS:Trojan-PSW.Win32.RisePro.gen |
| NANO-Antivirus | Trojan.Win32.Mint.kegarr |
| Avast | Win32:TrojanX-gen [Trj] |
| Tencent | Malware.Win32.Gencirc.10bf62cd |
| Sophos | Mal/Behav-204 |
| F-Secure | Trojan.TR/Agent.azfwy |
| DrWeb | Trojan.MulDrop24.22194 |
| VIPRE | Generic.Dacic.7CB2327F.A.28870786 |
| Trapmine | malicious.moderate.ml.score |
| SentinelOne | Static AI - Malicious SFX |
| Jiangmin | Trojan.Script.awbz |
| Detected | |
| Avira | TR/Agent.azfwy |
| Antiy-AVL | Trojan/Win32.Agent |
| Kingsoft | Win32.Trojan-PSW.RisePro.gen |
| Gridinsoft | Spy.Win32.Redline.lu!heur |
| Microsoft | Trojan:Win32/RiseProStealer.PA!MTB |
| ZoneAlarm | HEUR:Trojan-PSW.Win32.RisePro.gen |
| GData | Win32.Trojan.PSE.1RTMWHR |
| Varist | W32/Kryptik.JKR.gen!Eldorado |
| ALYac | Gen:Trojan.Heur.ceX@JG9mxh |
| Rising | Backdoor.Agent!8.C5D (TFE:1:QCrKrn9GWAD) |
| Yandex | Trojan.Agent!E34nJNo+lBI |
| Ikarus | Trojan.Win32.SmokeLoader |
| MaxSecure | Trojan.Malware.300983.susgen |
| Fortinet | W32/Agent.ADVG!tr |
| AVG | Win32:TrojanX-gen [Trj] |
| DeepInstinct | MALICIOUS |
Network contacts
194.49.94.152 31.13.70.36 142.250.189.205 142.250.72.238 23.59.200.146 142.250.191.67 96.16.55.45 142.250.191.74 184.26.129.66 142.250.191.35 142.251.46.195 96.16.55.7 104.244.42.193 172.217.12.100 142.250.191.46 152.199.24.185 142.250.189.206
DNS requests
** abs.twimg.com accounts.google.com accounts.youtube.com community.akamai.steamstatic.com fonts.googleapis.com fonts.gstatic.com ocsp.digicert.com ocsp.pki.goog play.google.com steamcommunity.com store.akamai.steamstatic.com store.steampowered.com twitter.com www.facebook.com www.google.com www.gstatic.com www.youtube.com
Process list
| Name | Command line |
|---|---|
| 87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f.exe | |
| Cz3Js38.exe | |
| we4pZ94.exe | |
| vz2Kg11.exe | |
| 1sL92vc6.exe | |
| schtasks.exe | schtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 HR" /sc HOURLY /rl HIGHEST |
| schtasks.exe | schtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 LG" /sc ONLOGON /rl HIGHEST |
| 2cG0873.exe | |
| AppLaunch.exe | |
| 3ct40Lc.exe | |
| 4Ai174ie.exe | |
| iexplore.exe | https://accounts.google.com/ |
| iexplore.exe | SCODEF:1880 CREDAT:275457 /prefetch:2 |
| iexplore.exe | https://www.facebook.com/login |
| iexplore.exe | SCODEF:2464 CREDAT:406529 /prefetch:2 |
| iexplore.exe | https://accounts.google.com/ |
| iexplore.exe | SCODEF:1548 CREDAT:275457 /prefetch:2 |
| iexplore.exe | https://store.steampowered.com/login |
| iexplore.exe | SCODEF:3308 CREDAT:275457 /prefetch:2 |
| iexplore.exe | https://twitter.com/i/flow/login |
| iexplore.exe | SCODEF:3784 CREDAT:275457 /prefetch:2 |
| iexplore.exe | https://accounts.google.com/ |
| iexplore.exe | SCODEF:3560 CREDAT:275457 /prefetch:2 |
| 5dD8fu8.exe | |
| AppLaunch.exe | |
| WerFault.exe | -u -p 1172 -s 1360 |
| WerFault.exe | -u -p 2992 -s 212 |