Malicious
Malicious

cbef72ebf8da4b28d5a4f46ba116cbc3

PE Executable
MD5: cbef72ebf8da4b28d5a4f46ba116cbc3
Size: 5.97 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cbef72ebf8da4b28d5a4f46ba116cbc3
Sha1 dc1c8f3bde521ab48f75032938a30807553e7992
Sha256 9a3cdbde39449e66ea28e1913d5434f196813b11e63736d73591ff0b3727fc39
Sha384 7fd54adfa85e0ed891d708e35a8c60fcec9c19debb19bc08018972c655064da447e6ede58d08b177a2d6ca5fd2f9824c
Sha512 a8527d113aeb409ffdc72bf9732f6fd8449c78b19188a9c8f9800b404c09f041719e11a32a672945df4ff5cc147af68e303696cc45837cc68b023b00b3323e3e
SSDeep 49152:Mt2hatauNlixHz3cgqsu+geO/4CrZZCrqQY0Fq14NsZpYhWLwJpEqah+fKiK9KYo:MAJU+SZi57FOL5WCZsUcgF7pE
TLSH 9E565B47ECA555E9C1AAE23186629112BF717C881B3123D33B90F7382F76BD06EB9354
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamUPolyX 0.3 -> delikontElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙