Malicious
Malicious

2986bdb8dd1f62b11c1c57e58f00ae50

PE Executable
MD5: 2986bdb8dd1f62b11c1c57e58f00ae50
Size: 6.94 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2986bdb8dd1f62b11c1c57e58f00ae50
Sha1 24f8618ede8ebf037ca603114b5d917bd5c9966b
Sha256 4dbc2a3dcbd0a5a711f45789a4367cd959fc0dcc37ddc1d6e335cb98925aa688
Sha384 601eb2952462e0c9b2556276767b29df893c9ac26c3d4eba603d1d4bba719ebe6714a9b26615b43b7467adc5c97dd4ab
Sha512 435400f71fcc6ea361967e09073fb5d43c8f8b3a6a89d7e15dd861b3058b699bd827d40f17b07ae1235e90cf447e75225e2c884269125131a287293513835df4
SSDeep 24576:jNeqwjuAnWdLOiLDY9yeKCa1gSl1UegyH+wlEDsuottW27:jNr4uAWxDLkPaCwlttD
TLSH 1566DA5871C414EDCA8E837608F45DBE23B21DBB1613A68A0759BBA53F13BE65F20D4C
[Authenticode]_6c43ece8.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x69CC00 size 8064 bytes
[Authenticode]_6c43ece8.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙