Malicious
Malicious

f88819dc3e07a82e29a076572e67c887

PE Executable
MD5: f88819dc3e07a82e29a076572e67c887
Size: 4.41 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f88819dc3e07a82e29a076572e67c887
Sha1 9ad4f150a71c454381682ceadeea7881a5797386
Sha256 e55a67c005c7c70758cf680e8fbdabebeb0c9c0bc060d31082a57eafe05281ba
Sha384 a324a73b8939b342a60821bb9446dbce9c5b13da86684b903709c3807759598ad689a7fc75c119298bd86f41b3d803eb
Sha512 f41620eedec073d4cc3dee02306820768fd3146320324195e20a4c7eb8bd5c47b5454b3124ed8aa65f1abdd3e808368bbcb60f9ba6f19d310bf0c7e5c0d61412
SSDeep 24576:2q+henJwO+alH6XDUNjrtfJEW+eYQPY6kEfO+86f6rQzimLQUgt0/1PjvAJTAcZu:2qIenJvxHgujrMzeYlc/QUDW0oiNv
TLSH C516380BB99404E9C88A933188E6466637727C9A4B33A3DB1B54B7782F37BD05E74F44
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_55575f55.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x432800 size 8064 bytes
[Authenticode]_55575f55.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙