Malicious
Malicious

da6049ec17fd01ff99433bdd7753889b

VBScript
MD5: da6049ec17fd01ff99433bdd7753889b
Size: 10.98 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 da6049ec17fd01ff99433bdd7753889b
Sha1 ef24074cd2d8a8643c32c200045f67c5d1de2931
Sha256 323a0ad213a0154b60ad7e7300b40f389ef7ff2dc922e1235a418a46addda464
Sha384 6ed0ad2bf66784662a03dc3eedb2360db8d0b57c7ad0137523157413d5911eb248323ae33c89c9243300c1d7e0f88adc
Sha512 9a89f6be10a0f9f7389afeef3f9766e7bf12aecfee88a71a9fdd5e9b88acbc9f47b75bc048edfeb214436eb4bf776ff9ba28d334ca425af0dbe1ee92a717bd2a
SSDeep 98304:W1JSi4VlXnGXx2MoP2e8pSWGzhdhup8Jg6EEv:WvuGXx2hOe4SWGFr9G69v
TLSH C5B66B43ED9145E4C8AD91308A6792A3BF717C495B3123C72B60F7686FBABE05E79340
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0003
ID:1033
ID:1033.exif
ID:1033-preview.png
RT_GROUP_CURSOR4
ID:0002
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>pe:rsrc>img>img
Shape pe:exe>pe:rsrc>img>img
malicious 4 nodes
Path pe:exe~T1027~T1055>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0003
ID:1033
ID:1033.exif
ID:1033-preview.png
RT_GROUP_CURSOR4
ID:0002
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙