Malicious
Malicious

2bbe2a6af1ed4e1538b2a5420614606d

PE Executable
MD5: 2bbe2a6af1ed4e1538b2a5420614606d
Size: 5.79 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2bbe2a6af1ed4e1538b2a5420614606d
Sha1 bff36409b6b65d7358cc3aa5da99cfa03e66b109
Sha256 7fdd4c3e1a3f88b723d381468107540349533d0665fbc569c6daa739a37c8efc
Sha384 88f213589348413e03b80c9bac43dee6247ee6ddffc6423d203aa839c69c8c3f477fe72ec3e70731151458474130b973
Sha512 3e9c6d88f7c99c2549eb9e42802208e40569b02da99ded6aaf5af57fa5aec2d8492bb813e1a3244f37fe6161fea83a108ec1b79b53056fa5e8cb93b056bbed8e
SSDeep 49152:L++VY7QzJNBQ2kzfxy0Nmydb0HLg6KfYhWYUMYubyEBfebYNmtbKbokyedXAPm7w:LbN45HVQs6pWYUAGpEldhYjT73jr
TLSH E6467C476D912569D86AD738E47B4361BAB4BC8CC73673A32D50B6302F207C0AEF6B15
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_bbcf5c29.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x583200 size 8104 bytes
[Authenticode]_bbcf5c29.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙