Malicious
Malicious

6eb58bba50732638a3a17e5a23f55678

PE Executable
MD5: 6eb58bba50732638a3a17e5a23f55678
Size: 8.23 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6eb58bba50732638a3a17e5a23f55678
Sha1 a4af68cb38e8f99ce1df74e2950f7d1c1949e0b3
Sha256 170d46202f09e9b3a5cbb5e2056123838e7370e5f4e5edf7f4c4497d47842d01
Sha384 50f641d163ec273369b1260c56064e73bf97bbf30404d54c52963256bdb5579f8c6840d81a06368710ea09b9f536c410
Sha512 8f65d54ec08e1d6ac031537fc1c4edd927885dbccc377cf7e4b21e02205b36a792fc0d0a9123bea5b99e4344a272a1ebca0240f4bbe783757725fed8066245cd
SSDeep 49152:VrC6fB2e3pPfTtkBIL4EuQ9lpfPtSDTdJ7aVgkVBVY0kgnsTxvfBT+neBsC7qcAH:Vrpj9qFQf16J7a8hTBXz7UM+yWl8yd
TLSH FA864A077A9151B4D099AE30C07E9213BB65BCCCC73533A31E606A741F797E0BAB6B19
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_cc9a5a66.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x7D8400 size 8136 bytes
[Authenticode]_cc9a5a66.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙