Malicious
Malicious

c8d00fa8c120721945a74cb657ac633d

PE Executable
MD5: c8d00fa8c120721945a74cb657ac633d
Size: 3.36 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c8d00fa8c120721945a74cb657ac633d
Sha1 b297d73c38eb0dfa01f1a7bbd8a43cb24ed17b92
Sha256 77b3ca522f338bd41a022b34dc12e79b1ff6f650ae1d2801d2aaee99d965ab92
Sha384 6123bb5710d9f1165575cdff0c946901dec347adcde75551f082021335c0e77db6ce14327904e68e2ba3f2585c3fa88d
Sha512 09492e59bd6084ed523f3d03234110e64fd2dbdcfe27ed33d6e59f82c35e8edde9359704ef0e59ba5a860ccc6678eaa42abca8d53a1c23c8e725ae3efd7906ca
SSDeep 24576:YnN8zPcn4oZ8VfyRgFMor9DdkeDfym+wp8SGak2GYI4W3lK:YN8zPO4oMyWmwpPxGm3
TLSH 15F5291679C404E9C58E933248F5596A77B27CAA1B3363C70B94BBB42F23BD55E34B08
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_c3dd4e58.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x331800 size 8080 bytes
[Authenticode]_c3dd4e58.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙