Malicious
Malicious

42d83ae444f44406c4fb9c604cbe6b58

PE Executable
MD5: 42d83ae444f44406c4fb9c604cbe6b58
Size: 4.45 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 42d83ae444f44406c4fb9c604cbe6b58
Sha1 61fc74c936fb4ca434f2c146f72a2a89f319f37a
Sha256 e19bc63e2a6521f74b322dae41fd0d8d9125b968eb3f073c1368b0e82d45dabc
Sha384 6810fb0c323251dbdcc88a0b2d27c88d960fd3bd1eb2bf8dbc14e296750cc780cddbb784aa080e0cea3bc6eff01524dd
Sha512 2c0d91a166ee1beb85eff649db20f00f1eb56749acbe65716f87431902dd20337030a9ba19baf80f6de5ea086a30942e41d597fe60c6ea0d42d33d9d64da3793
SSDeep 24576:lmm7gNiI6co98elSjDkv7Z+Tlym/XJMo0tDfyJYqD7Mt5YHTi2a8KW/aH5H:lmqgNiI6P983DC4lym/m7qD6R2uj1
TLSH 20262816B5C000EDC58ED33649E4696A37B63CAA4733A7C71B54BB742F22BD55B38B08
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_17160442.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x43BE00 size 8096 bytes
[Authenticode]_17160442.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙