Malicious
Malicious

b08c40a5d165172f3d7311f184f21d4d

PE Executable
MD5: b08c40a5d165172f3d7311f184f21d4d
Size: 6.75 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b08c40a5d165172f3d7311f184f21d4d
Sha1 c8fd1d5792363439b3e0bb88191345219dbf74d7
Sha256 ac2e0a1276d3dd563ce5148844cb76d3ceac86ba30b5188964f1a780f1e3f646
Sha384 44b5e578493066f4b2384e8ca67bbfb63b385020dea3e2b82d3a01a22ade3d7aca0807029f59b90d134f7c4e9cce92b6
Sha512 836841b7bfd0dbd064c27839b9320e0766f73cc3efb27b634e61fa8196fbdb96267c1b338fc56220fb9068968fadc33b09f2ba9b6182c05bf07803824c20ea39
SSDeep 24576:p6djyRiV8HkRyvH5P9yaIjVSJ0NDfymYq1Y267f8l9VwNoWprNbx:p6YiV8CyR1ylSq1PHHVwNogr7
TLSH 9066B85971C410EDCA4F837609F45DBE23B21DBB1613A68A0799BBE42F13BE65F20D48
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_71d09592.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x66D000 size 8136 bytes
[Authenticode]_71d09592.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙