Suspicious
Suspect

397428bfc9374c1cc2e5949292de2790

PE Executable
MD5: 397428bfc9374c1cc2e5949292de2790
Size: 8.03 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 397428bfc9374c1cc2e5949292de2790
Sha1 e4e27e7433d751664c1110450bcd0af3e9433367
Sha256 37df7136ea350adee09219edab16c2e2ee2bfa4d5145295a32294c4e2b3e67b2
Sha384 062a4ea6a0eea2dc404129da356c3cb7d8a50bdb9e0a2a4c0be637898eed624e3b1d0d627e3a525fc0c0cf46ddfb129b
Sha512 cd64871a63e2789d4dbb7c38b7f99e1f08e7aea5f76199e47b25d5d95eca67917feca457e03fbe52da834e14d7ed59aa2b684ea7652b38d889786b4a543e1509
SSDeep 49152:wh517DFYLfhiSJJv2L5A2sJ5ccW9Jn46WuA35ELX6a7W69MddiUD2pCxV6+gamRg:DHO
TLSH 6D865E037B4800D8C867EEB080B54A7951B03DDD9631BA5B8DE97EA41F1A3996FEDF01
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙