87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f00d02d197078cf8e9c3

Classification: Malicious

87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f00d02d197078cf8e9c3 is a malicious file sample. Linked to Lumma Stealer malware.

Detection summary

  • 41 antivirus detections (56% detection ratio)
  • 1 IDS alerts
  • 27 processes observed
  • 17 contacted hosts
  • 18 DNS requests

MITRE ATT&CK associations

Malware families: LUMMA STEALER (S1213)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-11-29 06:15:03 2026-09-03 01:45:07 malicious-activity
Downloader VM-Ray 2023-11-29 07:22:15 2023-11-29 09:23:38
Injector VM-Ray 2023-11-29 07:22:15 2023-11-29 09:23:38
LummaStealer MalwareBazaar Abuse.ch 2023-11-29 05:45:36 2023-11-29 05:45:36 malicious-activity S1213 Lumma Stealer

Tags

windows-server-utility

Sample information

Filenames
87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f00d02d197078cf8e9c3, 87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
2023424 bytes
MD5
49f4b13f62f843ae67ac8c26ecab79c9
SHA-1
c35e2035f7597302adf895775a6a1fc29ad4426f
SHA-256
87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f00d02d197078cf8e9c3
First indexed
2023-11-29 05:45:53
Last updated
2026-09-03 01:45:07

Antivirus detections

EngineDetection
BkavW32.AIDetectMalware
ClamAVWin.Malware.Zard-10015589-0
SkyhighBehavesLike.Win32.Generic.tc
McAfeeArtemis!49F4B13F62F8
MalwarebytesDisabler.Trojan.MSIL.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005aad751 )
K7GWTrojan ( 005aad751 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 99)
KasperskyUDS:Trojan-PSW.Win32.RisePro.gen
NANO-AntivirusTrojan.Win32.Mint.kegarr
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf62cd
SophosMal/Behav-204
F-SecureTrojan.TR/Agent.azfwy
DrWebTrojan.MulDrop24.22194
VIPREGeneric.Dacic.7CB2327F.A.28870786
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI - Malicious SFX
JiangminTrojan.Script.awbz
GoogleDetected
AviraTR/Agent.azfwy
Antiy-AVLTrojan/Win32.Agent
KingsoftWin32.Trojan-PSW.RisePro.gen
GridinsoftSpy.Win32.Redline.lu!heur
MicrosoftTrojan:Win32/RiseProStealer.PA!MTB
ZoneAlarmHEUR:Trojan-PSW.Win32.RisePro.gen
GDataWin32.Trojan.PSE.1RTMWHR
VaristW32/Kryptik.JKR.gen!Eldorado
ALYacGen:Trojan.Heur.ceX@JG9mxh
RisingBackdoor.Agent!8.C5D (TFE:1:QCrKrn9GWAD)
YandexTrojan.Agent!E34nJNo+lBI
IkarusTrojan.Win32.SmokeLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ADVG!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

Network contacts

194.49.94.152 31.13.70.36 142.250.189.205 142.250.72.238 23.59.200.146 142.250.191.67 96.16.55.45 142.250.191.74 184.26.129.66 142.250.191.35 142.251.46.195 96.16.55.7 104.244.42.193 172.217.12.100 142.250.191.46 152.199.24.185 142.250.189.206

DNS requests

** abs.twimg.com accounts.google.com accounts.youtube.com community.akamai.steamstatic.com fonts.googleapis.com fonts.gstatic.com ocsp.digicert.com ocsp.pki.goog play.google.com steamcommunity.com store.akamai.steamstatic.com store.steampowered.com twitter.com www.facebook.com www.google.com www.gstatic.com www.youtube.com

Process list

NameCommand line
87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f.exe
Cz3Js38.exe
we4pZ94.exe
vz2Kg11.exe
1sL92vc6.exe
schtasks.exeschtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 HR" /sc HOURLY /rl HIGHEST
schtasks.exeschtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 LG" /sc ONLOGON /rl HIGHEST
2cG0873.exe
AppLaunch.exe
3ct40Lc.exe
4Ai174ie.exe
iexplore.exehttps://accounts.google.com/
iexplore.exeSCODEF:1880 CREDAT:275457 /prefetch:2
iexplore.exehttps://www.facebook.com/login
iexplore.exeSCODEF:2464 CREDAT:406529 /prefetch:2
iexplore.exehttps://accounts.google.com/
iexplore.exeSCODEF:1548 CREDAT:275457 /prefetch:2
iexplore.exehttps://store.steampowered.com/login
iexplore.exeSCODEF:3308 CREDAT:275457 /prefetch:2
iexplore.exehttps://twitter.com/i/flow/login
iexplore.exeSCODEF:3784 CREDAT:275457 /prefetch:2
iexplore.exehttps://accounts.google.com/
iexplore.exeSCODEF:3560 CREDAT:275457 /prefetch:2
5dD8fu8.exe
AppLaunch.exe
WerFault.exe-u -p 1172 -s 1360
WerFault.exe-u -p 2992 -s 212