Suspicious
Suspect

7bcf228c5f9acc5fce436dd87d6cfff7

HTML
MD5: 7bcf228c5f9acc5fce436dd87d6cfff7
Size: 13.77 MB
text/html

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7bcf228c5f9acc5fce436dd87d6cfff7
Sha1 5771cc7002fdc049085fd20c63c7b81831682069
Sha256 603264cbf503d230902ee89324431bf3b81aebbdb31ca3cafe2deef0652405fc
Sha384 16a954bd74c531b84537a76911cf143ddb330a882164bc5e8efe2270f7bca4498f63ea932a60ab913bad58b377d3575c
Sha512 15f73ee2fbf9677f07eebb110082907d756a996c6d093ddb9867fa52fa4b2559f0e5655dc438ccaad2e050ca1a95d3a63469c47342c14bf69af5591d431756e3
SSDeep 98304:Gwm5+mpCxSK2lzEHFs4iiTKwbO9b66GDqfqWpnjXV1T4EW:PVamSbj41TKwbO9W61B1tW
TLSH 8CD64917E96540E8C0EEC17489B79622BB70BC490B3123E71B64F6292F77BE06DB9354
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
7bcf228c5f9acc5fce436dd87d6cfff7
[Base64-Block@0x001CB36D]
[Base64-Block-Decoded]
[Base64-Block@0x001E2884]
[Base64-Block-Decoded]
0x0066BE38.svg
[Authenticode]_1125b4a9.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0003
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
[Base64-Block@0x00BAEB26]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.jpg
[Base64-Block@0x00BE7D34]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 2secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>html>enc:b64
Shape pe:exe>html>enc:b64
3 nodes
Path pe:exe>enc:b64
Shape pe:exe>enc:b64
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xD1F600 size 10776 bytes
7bcf228c5f9acc5fce436dd87d6cfff7
[Base64-Block@0x001CB36D]
[Base64-Block-Decoded]
[Base64-Block@0x001E2884]
[Base64-Block-Decoded]
0x0066BE38.svg
[Authenticode]_1125b4a9.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0003
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1033
[Base64-Block@0x00BAEB26]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.jpg
[Base64-Block@0x00BE7D34]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙