Malicious
Malicious

6e4188eab774c2d0641bfcb032f19799

PE Executable
MD5: 6e4188eab774c2d0641bfcb032f19799
Size: 10.62 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6e4188eab774c2d0641bfcb032f19799
Sha1 d26d8c35d534f72ea44f1e7a71db4cdcf3ec4f34
Sha256 950eb350edf0887058c64221846564f054d8ace58b504abd6b97ba3ce45c66e2
Sha384 93af2b1e7e203c2b8da01bf255bb433cb8b2eaa8ef916458a6eab59f2bf086f67f65d56ba886c870b8a506247c6dbdbc
Sha512 73a9ee920d000107fe7c43dcd792e2f4d2b84f2cf9e454a1fee4078d1f5dfd1ba92395458cf95e51873831166dbe2613b1954f66488e4e50561a403ca20bdd15
SSDeep 98304:0KwrI7+B+GODxbgHqmuFp+iuZVjFm5IzJKIkddNZHRohAE6:0C+oGOZgKnbuZC5IzJKhve6
TLSH DCB68C47ECA555E8C0ADE53186629213BB71BC885B2123D72F50F7282F77BD0AEB9314
[Authenticode]_a09df291.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xA1F200 size 10512 bytes
[Authenticode]_a09df291.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙