Malicious
Malicious

8ba88cb3e6a21e5b3f9e6047b266aa4f

PE Executable
MD5: 8ba88cb3e6a21e5b3f9e6047b266aa4f
Size: 7.95 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8ba88cb3e6a21e5b3f9e6047b266aa4f
Sha1 d0662aa95fc1d76581356a0c6b1884bc43271da9
Sha256 f7e58d2955db86e33b95939f645abc6f362cf86f396c548bdf22dbf707e5914a
Sha384 40658dcef152ed1215de1b9942673b07ab5f688e451f72e10b8974b9c40ca9a58de2d5bb39b205bc3ea2edd4c748606e
Sha512 cf18dac94b5660616dc4d117b3c61e143d8c2cc86a094b4df5a0f4973891bb9f79028cb85ec44f619e4d9b07a263a167f4fd3beeccd62d7d72a44e0e01c35701
SSDeep 24576:ewjSLlwdhIx+iyJNKLE4NF1erBl8Ss3p1hDfym+wLYhZsSmW2K:eRLlwPIx+VcEmIwLxc
TLSH 8386E95971C410EDCA8E837648F45DBE33B22DBB1613A68A0755FBA12F13BE65F20D48
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_f82f7cdf.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x793800 size 8112 bytes
[Authenticode]_f82f7cdf.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙