Malicious
Malicious

bceb030e4b414b89e196a0f5b83a3e82

PE Executable
MD5: bceb030e4b414b89e196a0f5b83a3e82
Size: 4.33 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bceb030e4b414b89e196a0f5b83a3e82
Sha1 69a0504783512b90fb209f8b32ea87a7f9989de0
Sha256 6b9b2d689ad1a93566f6972e4d29dd9dc46dfdb33e304eae7327aca23a8ce3f2
Sha384 b4b3bd93c515e594119e57895820d6d6972cd9a3885a6f08486f1b585cb2626a080b016b1e39f4e0f5434374c8ab5862
Sha512 2e89d72a1598a124710a430216f0f526d4d8fced46190830966f0db74b3b41a50b7d5d837ebfc7b239e6dad9f0bafcfd2a1b6f23d539148e56889a70a8fc437c
SSDeep 49152:NV4E4mZIWNk8SDpBHNhdiWtcSAWglXS5krmmF7vEvpBkr+lO+2rPXt:Ny0etLiWRAW+yx0rE8Xt
TLSH 14169D07BDE194A4C0999732587B42267B28FC9E873573E72F91AA313F663C09D76B40
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLL
[Authenticode]_df8fa5e3.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.CRT
.tls
.reloc
4
19
31
45
57
70
81
92
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll~T1027~T1055>bin
Shape pe:dll>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x421628 size 2408 bytes
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
[Authenticode]_df8fa5e3.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.CRT
.tls
.reloc
4
19
31
45
57
70
81
92
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙