Suspicious
Suspect

207d4828fdaf1908615e4637216efc0a

PE Executable
MD5: 207d4828fdaf1908615e4637216efc0a
Size: 15.24 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 207d4828fdaf1908615e4637216efc0a
Sha1 94761b6d8e39539c3bdc325ff37750f57d7cd17a
Sha256 2fb29d2e5dfcf750a9af59f19ca38c3ce19710130644841f940ae7b48a413fda
Sha384 548e043e88d084250774e2e4019a718ec34d7bc9e1c8abe994a3ba727a614c8b72019129f46942be6acae43ad0f3d3e5
Sha512 4fd99fdade2965107968e761efa97286837721cf06637644e057a913e050ac589bf60f01361636fc292c9e2cb5d950316ddf196dbc00aa3a20737dca154a0841
SSDeep 196608:9rf2BveqfBpcQV8LK9F0dIHOIYN0U8p31n:9aB/pcroFmIG0FxZ
TLSH A8E69D47E8B106A5C0EA92B6C6768663BA347C884F3163D36B50F7392F77BD06A75700
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
4
19
32
46
65
78
90
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
4
19
32
46
65
78
90
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙