Malicious
Malicious

e117651af56afef33dd689a397c2465c

Share on LinkedIn
Print
PE Executable
MD5: e117651af56afef33dd689a397c2465c
Size: 5.49 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e117651af56afef33dd689a397c2465c
Sha1 5842fbe47647a293b30ab36c4ee9d4937ff11975
Sha256 b6db5193051ca68bcb4c0c301c1f476f75e5e86b8d0ec4b493b994a0ff533ff8
Sha384 5510d49ae6c06ef027de0b0e5bd30df530f299cd4b5c7992a2018c73dbe56bb26d97cda53befc37d332bd14f41fefdd6
Sha512 8241eb969337be9ae42e56f4918d4c0d8799deb2a4e255f4d199cf9057a6186f7a9e7fc93abac3d41907c66944ddca6d0b1353b6143d602b145b16768031a2be
SSDeep 49152:OwaT8uHJtm1vVUfE8SBV+zUSeKNgJ5EFVUPVnafw5yWt5:A21dKzUSgEuafqL
TLSH 5A464B47EC9545E8D0AED2358666A253BA71BC494B3527D73F60F7382F72BD0AA78300
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙