Malicious
Malicious

e04ec82a3f36d57e0c4e6c8d522c08b7

Share on LinkedIn
Print
PE Executable
MD5: e04ec82a3f36d57e0c4e6c8d522c08b7
Size: 3.81 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e04ec82a3f36d57e0c4e6c8d522c08b7
Sha1 fd672c337acab290a1710544aeea7b638af678bb
Sha256 49412b0064a7bb0a5ce6678e63f6fe2d1dc95d6e07e580aa78ef0d93dd060154
Sha384 54b64d7965f3720666d92505b63136632f24a0119ffb7170b5589d5be1fb69d9488725cd7875b0a58dd4c616d859af06
Sha512 b0730066e3ac0f1955045405eca55169f36153a464a9a1dd9fa69d904ea90af5d345463ca457a60d746f57b7ab4319a4db0ffc2795cdf7664b0c72b02ff1fc50
SSDeep 49152:RjXv5L5a1F7e6qeMgmt5dzI9RKWwqxhSFzhsqyxw:RjxPeFmt5dc9RKWwwEthoxw
TLSH 2906AD07AC918D6CC0D9737145B39281B72EBC04573967E32EA1B9B92F362D1ADB7B40
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft Team
[Authenticode]_9bbc6fbe.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.CRT
.tls
.reloc
4
19
31
45
57
70
81
92
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll~T1027~T1055>bin
Shape pe:dll>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x3A2690 size 2424 bytes
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙