Malicious
Malicious

6a0c941dae3bb120394e6633a11dde28

PE Executable
MD5: 6a0c941dae3bb120394e6633a11dde28
Size: 8.31 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6a0c941dae3bb120394e6633a11dde28
Sha1 dda196c26ad8e8903a7ea480081be8ca8708160d
Sha256 dcf932ee3436bd34d8408a04ea0578eae7254fc23ce8f7e78dcd0256292f5fae
Sha384 b1e6a481c3eeaa64ee0b8a6094d6888c6ecfd1bffaf3f30608f9eaa92d7b6e4fd63284a2de87f9c2b770b0940a18a0d7
Sha512 9a6d9066070047a5fd7752650324ddf24f00d811d0e3fe88a07981f8a11dc7e95aeaeb322c74f0635d8e8d77c90abc281341380f5d3fe5924ba15293c0862127
SSDeep 98304:HLmdAtbOjBQ3YlxIDEd5uRzPE8eKeGmeuB803jO:HvONQ3YvIDE6w8pm8
TLSH 4F867B13ECA149E9C0A9E2308A6A9252BB717C495F3123D72B50F3283F77BD46E79750
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamUPolyX 0.3 -> delikontElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
install-meta.ini
[Authenticode]_aa21a4a1.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
.rsrc
.reloc
Resources
AFX_DIALOG_LAYOUT
ID:0067
ID:1033
RT_BITMAP
ID:006C
ID:0
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_DIALOG
ID:0067
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0071
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Install.html
icons
chrome.png
chrome.png-preview.png
edge.png.exif
edge.png-preview.png
notepad.png
notepad.png-preview.png
paint.png
paint.png-preview.png
windows_media_player.png
windows_media_player.png-preview.png
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
6 / 6
Path pe:exe~T1027~T1055>arc:zip>pe:exe>pe:rsrc>bin
Shape pe:exe>arc:zip>pe:exe>pe:rsrc>bin
malicious 5 nodes
Path pe:exe~T1027~T1055>arc:zip>img>img
Shape pe:exe>arc:zip>img>img
malicious 4 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_56b64477.bin (1948446 bytes)
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
install-meta.ini
[Authenticode]_aa21a4a1.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
.rsrc
.reloc
Resources
AFX_DIALOG_LAYOUT
ID:0067
ID:1033
RT_BITMAP
ID:006C
ID:0
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_DIALOG
ID:0067
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0071
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Install.html
icons
chrome.png
chrome.png-preview.png
edge.png.exif
edge.png-preview.png
notepad.png
notepad.png-preview.png
paint.png
paint.png-preview.png
windows_media_player.png
windows_media_player.png-preview.png
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙