Malicious
Malicious

a3343cd92b0c761c8cabcd6222c0e006

PE Executable
MD5: a3343cd92b0c761c8cabcd6222c0e006
Size: 4.35 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a3343cd92b0c761c8cabcd6222c0e006
Sha1 1f06877b559cdfa55ac111e5d4e2acf7d0c0693a
Sha256 aa3e272241995ceb22e7b70239b1d010482af721ce7c6ac6bde70c5cfb3e156a
Sha384 27fe7629623ed3a69830e45ba15ad0024b2d8a1a10e6b360c76545fdaf9d0f28b821005c9f3c54ede9b4dd5d58bd1dd5
Sha512 d40b630ba95cdb77912660212d81a3209978dab5cfd3594180fd732c2509eceb402636b58f45552745f7e2277269b7e26f8f07982d3bd8f998ef25d7e3d7aedf
SSDeep 49152:P4v/38WuOQzqTN6ePntwajwt4VjtD0SgVW/TJEICWPE:G/38WuzFeDTJEICCE
TLSH 64161B54F6C900F9DA4B427504F56A7F23760E6E1A23DB8ACB547B95BF237A61F2080C
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPeStubOEP v1.xPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_982b907e.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x424400 size 8128 bytes
[Authenticode]_982b907e.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙