Malicious
Malicious

1894469a7bc31fd828f45e5c0331e86c

PE Executable
MD5: 1894469a7bc31fd828f45e5c0331e86c
Size: 5.18 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1894469a7bc31fd828f45e5c0331e86c
Sha1 53ab276f200ab2b75bc5e884b9d399428de5f9cc
Sha256 b57ad2c4ff3696ad974acce3c3ba3e2727759a84a79f08ba459904420fc40e41
Sha384 b7e07f0b35c6b00da8178c1ea66678f2405bf8a128bca2a8ff14bbbf09728cdad3050e99f66dd29c4f6a2cd21dbaaeaa
Sha512 9bfcb5d989e5ac00d9135a23b70c27ee5b7e638650aa4e065e926d4660b9718396c8ac481314359695ac5fd92b347eac607e146e28e0dac8f252e62d8ae364f6
SSDeep 49152:ELwBrgP32Ej8Hmo56jhmTx0iGbu5LMKuHduADO:EkYY/TYKuHgF
TLSH 64367B17AD9168A6C0A9E371C9BB4215FAB0BC0D4B3133D72E51BE782F327D12AB5744
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_5be28002.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x4A2600 size 2400 bytes
[Authenticode]_5be28002.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙