Malicious
Malicious

06f5ec9866854e9a8641973d0727e376

PE Executable
MD5: 06f5ec9866854e9a8641973d0727e376
Size: 8.7 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 06f5ec9866854e9a8641973d0727e376
Sha1 00f9028502d47ffa8b1bf2997f139c3b1fdf7ed6
Sha256 0af69f4befc8e461da46f5ea8352e84ff797b27a38154b436d7ad4e9fb3e90d0
Sha384 962392eae6af30bc38784b065a43f1fa3d3b6c844534b4bd7631248986f397be491aead3672d716bd660babbe93523b7
Sha512 9d1b502dac5af9adb3044a2c081df67723d7b3d5bff8fd6573f7c6c97422ee820a96ac28d3555c5833c4469a1fe65205895b73a056c4b363b018d79eb6a0ae00
SSDeep 98304:JxJBHSwqt2hAdEuNI4NgJ9LIEGpenYqrMgoXHnGvAdZixk:JI26dEW7adGpYYqrM9XH9Qxk
TLSH 1A967C03ECA155E9C1A9A230C9A79253BB71BC491B3223D32B90F7392F767D46E79350
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
4
19
32
46
65
78
95
112
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
4
19
32
46
65
78
95
112
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙