Malicious
Malicious

441c019714d0fa3d09d26f7d134f5658

Share on LinkedIn
Print
PE Executable
MD5: 441c019714d0fa3d09d26f7d134f5658
Size: 5.49 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 441c019714d0fa3d09d26f7d134f5658
Sha1 89d4eba1dcc89aedece745ca7235bc3aa5b61418
Sha256 7e6a43db7d19645225f0d9d1e3573ae4aefbe67bde41e1cf78aa504504e4b4fe
Sha384 1b8db38ab54279c0b0b147a2067df64db131c0169e8cfc3c4d1df73725431e916df2f9856f396457eb465afd854cdddf
Sha512 656d5936811fd19a377fbc2e5702719cdc3ce4edde8ec0c10c54459408edcd3a9561149c9405bc07b99d8862872bc1d2b2d9aafef00fe9b7e2ac1930a7ecfd2f
SSDeep 49152:AXqU9iSEAfXYFLQuvttzEw/IpbWNiP5Ea72/Vnafw5yWui:cAFLZzEwsEHafqf
TLSH 8A464A07EC9545E8D0AED2358A66A253BB717C484B3527D72F90F7382F76BD0AA79300
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙