CLEAN — 066c4ab954fc1270ee62c0d7c582c4c691e58e0ffef0c654bc204a46e440d16d.bin
CLEAN — 066c4ab954fc1270ee62c0d7c582c4c691e58e0ffef0c654bc204a46e440d16d.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (32/100). 3 of 55 detection engines flagged it.
Identification
- SHA-256:
066c4ab954fc1270ee62c0d7c582c4c691e58e0ffef0c654bc204a46e440d16d - SHA-1:
d1d019a9316c04eb89ac26d2f3ceae9ac3987c8f - MD5:
810a6ff1fa3ec467ad9e9bd565a2d533 - imphash:
c6f3cd14e6e9208703f2d401d79fb9c9 - ssdeep:
6144:i2/lLQy+IMnmIh8ly48KUjOt3WAfBaST0NpGPA1:fJtyHhS85St3WApaST0OPA1 - TLSH:
T1E346085A6681B7A2FBF2EAA5C1FD8B1E402F618151F34FCC6D4AE5140298C834C357B6 - Submitted as: 066c4ab954fc1270ee62c0d7c582c4c691e58e0ffef0c654bc204a46e440d16d.bin
- File type: pe · Size: 312832 bytes
- Verdict: clean (32/100)
Source: MalShare · first seen 2026-08-19T22:04:47.732Z · SHA-256 verified
Detections (3 of 55 engines)
- Microsoft Defender: Trojan:Win32/LummaStealer.GPT!MTB
- Trellix Stinger (McAfee): PWS-FDXP!810A6FF1FA3E
- Kaspersky (KVRT): UDS:Trojan-PSW.Win32.Lumma.abcg
Why this verdict
The clean score of 32/100 is the fusion of 1 weighted signal:
- Contacted 19 external host(s) at runtime (16 HTTP) - network signal, weight 0.40, confidence 0.80
Dynamic analysis (windows)
15 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- msedge.api.cdp.microsoft.com
- www.msn.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787782036&P2=404&P3=2&P4=boXRiG49SjCgwoNJGop1e9xpn0ByqEd%2f7EDDCARpvqs8U8WWnrXT%2bAGjoqh8la9g%2fiW628NeMcWq0linqR%2bohw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.184.175.14
- 52.110.12.49
- 52.110.12.31
- 4.247.188.233
- 4.230.171.124
- 20.247.184.142
- 135.233.95.144
- 20.165.94.54
- 52.168.117.170
- 20.231.239.246
- 52.123.129.14
- 40.99.133.226
- 52.123.128.14
- 203.26.79.13
- 135.234.160.244
- 52.148.114.188
- 72.145.35.104
- 52.110.12.55
- 74.178.76.44
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report