Malicious
Malicious

fd7df4328041ac35221ae50322f29799

PE Executable
MD5: fd7df4328041ac35221ae50322f29799
Size: 6.59 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fd7df4328041ac35221ae50322f29799
Sha1 928abe52b847583b1d35b8f735b0f8291ca1a6b3
Sha256 6b0afb349635fb95996f7cc4e5ee22feb695df41ab2a86024f9603013e94a8e5
Sha384 ef29186c6293f52e81e38a3b8250acbc0e6372e938eeaa67f0e55882f35f27eac35561cdb4586a3c208bae10f2f25927
Sha512 11f0b0acc6f2ff3c416b8d2e2ebcff06bbdb407d966ad121a836f0b933a86d7c0ce6d855d2c0602ea42ce29dc416bae2fe9500c627da9e59b8a9b86a3d679c2b
SSDeep 49152:jj7taF2WPokP5APbxB6pTy+VHAN8K9RUpYKRN3pLj2O1/hEs+htzL03CHk2Mk2fO:jPaoUPLE8GKrpLd15NytCFbG8EX3
TLSH B0664A03EDA515E5C0ADD230896B9252BB727C885B3123D72FA0F7286F72BD06E75790
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft TeamUPolyX 0.3 -> delikontElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Attribution
Loader Go Factory-v3 : le stealer livré (Vidar, Lumma ou RemusStealer selon le build) est mappé en mémoire et n'est pas attribuable statiquement.
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙