Malicious
Malicious

4f088f1bc965ff0e11a9c75e4ee3f97a

PE Executable
MD5: 4f088f1bc965ff0e11a9c75e4ee3f97a
Size: 8.02 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4f088f1bc965ff0e11a9c75e4ee3f97a
Sha1 064abc2a0f9d251a90506416aadbae536bd7f348
Sha256 e2b3d893f7fe9400b37f390e6c87e979bd5201cdd149816cd70e942fa0ebac74
Sha384 4a0282f1344c79e308741d68707a7e373720faa0c79a28cfd8fe433831ab39513e1fcd0ee56c6accf4c7265d4f9a5361
Sha512 01065709c5d5a6907b80dfe01231584103239d0f9605e707794869057d30ca0984ad2b32d71f681478f49a1756f70bc9630239960556947e44ec7be3f555b4c4
SSDeep 24576:TdMTOKs4u/HjJPkb7ly5sJCVt6lhnakdtS09h7jCAoQ8LOcAFtS/1PjvAJTAnZLx:TAOKxyRkbC6DbutC9W08SxM
TLSH 2986D759758410EDCA8E837608F45DBA23B21DBB172393CB0759BBA52F13BE65F20D48
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_649eae17.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x7A3600 size 8064 bytes
[Authenticode]_649eae17.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙