Malicious
Malicious

156b6e957d1c8cfca30351e0b1bccd3a

Share on LinkedIn
Print
PE Executable
MD5: 156b6e957d1c8cfca30351e0b1bccd3a
Size: 11.76 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 156b6e957d1c8cfca30351e0b1bccd3a
Sha1 13308ac704a70154856b5f75ec3d33bd628be888
Sha256 a1e52621549b26c9ea46fdb4da21e159d2332fb0887c56ee317648597e99df63
Sha384 ee3d1f07e09b1400a2c95f906faeda27eafe3aa184380e76fefa2b18622c28183e8add734a68ac7eced077387923e5a8
Sha512 0921581b85a4b77d8fb02c7b95edaf92a32358b201927c7cfacbcca5c618e3f6db8401d8d79109b257080716322d168ad763e0057edaa3e327b63c1c7b188bb0
SSDeep 24576:yOp7Eo6xJSG5o3+z2lTvjBDykeDfym+wp8SGXkumBA6tWt0v:yg7Eo6JnYD1jwpQzmTJ
TLSH 8EC6876871C410EDDA8E837608F45DBE23B30EBB1513968907A9BBE56F13BA65F14C4C
[Authenticode]_6dc9d8f5.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xB34800 size 8080 bytes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙