Malicious
Malicious

56dc8b4906ff5d5995e35fd3316ff46a

PE Executable
MD5: 56dc8b4906ff5d5995e35fd3316ff46a
Size: 6.34 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 56dc8b4906ff5d5995e35fd3316ff46a
Sha1 786f528d1f90d462ea5680825846940324d0f06e
Sha256 08d463f435f20fd7f4f42ec3c9a5ca6f9e47059d7c93a3f002513d06a5f60b03
Sha384 c44b178b2115cf536c220add69ad0afd94e108823fd5c64ab4417b06c3c79dd92dd9884a51f14209fd1fe4687b5fe7fe
Sha512 f39df39d2c592580fee623ae7dcbd7aec9934de9a143a6d69eb190d14bc7e877df36036cf6c28f24aeab098670f6054d9280987ddb8089a3d166b539dac8eed1
SSDeep 49152:97nth69UVogsHnt7H1OjkxlNYQyRHV1cUr3vwaPMasNc4iUT038SOHf7PwnQ:9yhg0b/sH7wSkSUx3ToQ
TLSH 9D567C037B81C1B0D495EA7AC4B6515077B87C4D833433AB6EA5AA302F263D1B67AF64
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_4533f5d4.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x5BD800 size 8080 bytes
[Authenticode]_4533f5d4.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙