Malicious
Malicious

7fe5ef54494754cb29581d25611ed527

PE Executable
MD5: 7fe5ef54494754cb29581d25611ed527
Size: 5.97 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7fe5ef54494754cb29581d25611ed527
Sha1 19fc578c28dc08f97b0b12dc2ffa1cd83eeea6d8
Sha256 cc20751d5a5d88fbb2f03e3d3afdc9fb4859176229c42a48bdf5097b7baa797b
Sha384 04032b80752d1da29bf96c4e20d7243932aa32503d56b185a724bace928493800e383923bed7815ee945e7a23b1d8cfc
Sha512 166184a4215a5c1f141f9a686fc27329c00ebff79ccd8ef64000c0b5c1337b110254025dcb17530ab9bfe868b5d6bd8d6b6176291b1ec41ac23e971361bad3c6
SSDeep 49152:2t2hatauNlixHz3cgqsu+geO/4CrZZCrqQY0Fq14NsZpYhWLwbpEqah+fKiK9KYo:2AJU+SZi57FOL5cCZsUcgF7pE
TLSH 4D565B47ECA555E9C1AAE23186629112BF717C881B3123D33B90F7382F76BD06EB9354
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamUPolyX 0.3 -> delikontElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙