Malicious
Malicious

30877dd0a5d0ade6f40906c1d4809566

PE Executable
MD5: 30877dd0a5d0ade6f40906c1d4809566
Size: 12.54 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 30877dd0a5d0ade6f40906c1d4809566
Sha1 3109c0c1406c66c383b0553c11493db617387b75
Sha256 bb232b41ed862f03708c61ce55ab28da86ba548447ec9c1514f514707bf02ddc
Sha384 b44925407d9677589644fd3b3c33439d4c2e6fb7ac8137c696b1a256e86c4656b99c0efe965c0c9a5022fba0510fb9ba
Sha512 acae7ab3998822b78b638271df3f873835fb90a4bfda0485ea319eac14428adf344c76808dab97c0d07419234454f1ef9b4481986dd9c46c282da0fd1319d825
SSDeep 98304:8ZzLWEMAoBxW/ol8EXYWTxSS4479JEuO/:wWEMAGlXXRTMSLo7
TLSH 2EC65B01FA8B65F6E9035831416BB27F23315D048B28DBDBEB583F2AFC776A11836645
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPeStubOEP v1.xPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙