Malicious
Malicious

0131ba44d5cd6d5616a4ee5a80817a74

PE Executable
MD5: 0131ba44d5cd6d5616a4ee5a80817a74
Size: 7.91 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0131ba44d5cd6d5616a4ee5a80817a74
Sha1 5a11e72f06a1bf052d1f59db75bd2e955c0971d4
Sha256 59754b318d60186718cb0cbc187f6c334c54b3b0ef6bd64f312ec8379904a182
Sha384 f64ff3f195d9c939043d917967dde6331133be821bf9e083af3dc3a5ff9d18e0d422502265d3c350d70576020d5abbdb
Sha512 69d2c63c3983200a48aee64327ec2c156a6d3490ac9d7bf43ff31c42507ed58be644fc766ee2d430e8df3ca97c637fd513fd7383c5b082d515d7ca2906f55090
SSDeep 49152:cu5XhilZQZ9sxTZt3ijLwPqsakg9qT+9+aBFFSL4NoaLaSN3T5wPlo5:coqzL5ndK
TLSH 5786C3033B5811ECC4A7EBB0C4B5666622B03C8D4A39757B5DA46E252F24788AFFDF05
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_e6b95813.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x789C00 size 8120 bytes
[Authenticode]_e6b95813.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙