Malicious
Malicious

b044f6e32bda15e0a61a40afd0ff0c53

PE Executable
MD5: b044f6e32bda15e0a61a40afd0ff0c53
Size: 5.29 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b044f6e32bda15e0a61a40afd0ff0c53
Sha1 a8716f7f0948f4305f18271bede2123c1abd03ac
Sha256 4b9dbcbddde9eed3f77df929449c3b499356c91f0a94ea1ef0b8bd79411dab6b
Sha384 fbd7c207ed6f27398cd22cc77992951a7f86e42865eed586b4058f6c4b158b7d5caf9274ead30de9910fa2433d9c56ae
Sha512 79bff7b0e6bf42cd0e44a5e1b74eaf53ab553d20f8e72b70d2cd80fb74d2d360693e3e30dff1135e1269554c7f62deef88bf760d9843552310871304a52d0cc2
SSDeep 98304:/g8TjEd9nfTh7Dkk8syJh9F34Vmn7xjh1lJKR2/nNhezLiLtncaPF8eglSIHvm0K:/nEUQtyG0yU
TLSH 43366B47AB623874C094E27494B75751B678BC8C873873F72DA0A9756F223D4AA3DB03
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft Team
[Authenticode]_ce8f3b40.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.CRT
.tls
.reloc
4
19
31
45
57
70
81
92
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll~T1027~T1055>bin
Shape pe:dll>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x50AF20 size 2416 bytes
[Authenticode]_ce8f3b40.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.CRT
.tls
.reloc
4
19
31
45
57
70
81
92
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙