Malicious
Malicious

53648dee77c997e3665a8c3add00eeaa

PE Executable
MD5: 53648dee77c997e3665a8c3add00eeaa
Size: 8.35 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 53648dee77c997e3665a8c3add00eeaa
Sha1 dfeedc4eae6c517ef1286bd041cc36de8a608f46
Sha256 6c2446f06869a50df82165dbbc78527186cc70e8ebb50c48634de0ab9057c00a
Sha384 90b44d5d5e251b97072540aca0c3dfb834e35de82557309074b983d3d2c07749481e349946ff37c636665e1670471896
Sha512 598afff16262ee75f9866a62a124407c6ef5dff8c577371ea79ea8817805be998ba6d0553497400312c1cf5c0106772696727f312bd55ac99a8c23dd6e138f65
SSDeep 98304:V3T2h9PPeJzgg3ty1qrMGUjEBoSMeduU8gsHZVY/YK2:VjigJMg3E1qwQFM/U8gsHCYX
TLSH FC867C43EC9159E9C1A9A33089A79253BB71BC481B3223D72B90F7392F76BD06E75350
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
4
19
32
46
65
78
95
112
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
4
19
32
46
65
78
95
112
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙