Suspicious
Suspect

0b130d9fec6bb8f9b80b13e110d4e0b0

PE Executable
MD5: 0b130d9fec6bb8f9b80b13e110d4e0b0
Size: 4.85 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0b130d9fec6bb8f9b80b13e110d4e0b0
Sha1 94c1d86395777db22933c0d97cac2b535d543c87
Sha256 0f1af10b96c08c9aeecf28c2fa238542e667d218df65ce51701aaaeb7dcc75b1
Sha384 a01af1d7c9aafdd3de491d22b56f7d240c54139b5d28a2b54f924df0667bd9e643b882bd168e6c2f33bd025ff318775f
Sha512 e751dc248dd5c072e5c0f5eb2fceadf51c89a42a36307eec68f55053ba2e4f0793e23082f94991c7fcead648737f80d2794a5d0f5025b8d07a5cd3ca7330e480
SSDeep 49152:b5C9BM3XsbcNhz4rwcFYIytSRjQGyiLgGeHLVkF5AgPgFnr/hD1:eosg014wRjl4yTAgq
TLSH 4B266B073B4080E5D94AEA38823E82B1A6317CCDD73577D72E4578B96BB67E43A74B10
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙