Malicious
Malicious

39dc9c06c0d6c39d673916dc39f70cdb

PE Executable
MD5: 39dc9c06c0d6c39d673916dc39f70cdb
Size: 9.05 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 39dc9c06c0d6c39d673916dc39f70cdb
Sha1 fba51f3792e5ae02d81033efd2603b738a90d4ac
Sha256 685cc1323f45a0c0153013c5bbfe774b869a6cb9cc9ea9388cb73e8bcdfbe811
Sha384 1ad445ee6a0b6e5efc2bc2fbfe7271c01b7d5f8806140a4a4f215237fcc9cffe8d147875b234cdcaf79a31cc3ac87c23
Sha512 8caa731b77e4001561255c71ffd24042a8b072213293f3d5c11c591f2be62adf02a37e4bdafe7cb85cb6598a192300fce2026283bad9f861f9d4248048f13301
SSDeep 49152:6Bo2qtTjhkRtUc6rnK5AOofQfqDStgsqqiuxmLpzy5I+fWPY0iV0EtlVozXO/+yW:vhMBmOqnciu0LpzX5NhEJJqMw/Zok
TLSH 69963A07ECA148E4C0ADC5748A769253BB717C498B3127D72B90F7782F76BD06ABA350
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙