Malicious
Malicious

b291da47a833133d9e13f6a205105e61

Share on LinkedIn
Print
PE Executable
MD5: b291da47a833133d9e13f6a205105e61
Size: 2.29 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b291da47a833133d9e13f6a205105e61
Sha1 f5f549ebc8c9fcdee31867dccc076a1d7d95ba12
Sha256 29a056bb652664dde097e9259b0769a2d51d0d01302d0ad19710b34bb64ee52f
Sha384 7001134cccc9866d822f5e0959d148837026c462c21923e53a4db07d78dda698f02b6e1627caccbbc3b99d7aff393dbf
Sha512 80e9a7f5f1406f68c97701d1ece2908549e13495ca519341c220c9b7d534c895b99546bd21a3c68a123c8b80253a02f961b283b421a4158afa09906da12a2d8a
SSDeep 24576:oLRnNgTez6oqD7M9j0C3CGfKeQ3d/c2fbXIEGckV5D9HaMsNA8jW:oLETeSY9j0ICGfKeUZc2z4Rd8j
TLSH 15B53A57FC9218A6C0AAA231896295527A71BC483F3223D37F90F77C2FB2BD45979710
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙