Suspicious
Suspect

a6a805492262d48a585c61bf3949ec62

PE Executable
MD5: a6a805492262d48a585c61bf3949ec62
Size: 5 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a6a805492262d48a585c61bf3949ec62
Sha1 a0fade7e52ce271bcba5041c76ca48055bffc441
Sha256 236af436fd7fff6ed0f093b1cee2aa98951dba51b0211539edc68e42cfb6ce0f
Sha384 ab92fe64c45289a76b633ac3b39079768dec8f0d6ac04d8f5b02a49d58e5f2a326804d18fd5d7c20c5f02e421199bca8
Sha512 657060342dc1863b253518cbfa6c45698e37578f579b07fa6474a5a52071307bf22d3b1d15a4d8791ff7ab4fb165350c4199c360cab960ddff4e31c047d7a987
SSDeep 49152:uFKpz7i7FAlc03DCBGcm+a1h6TczyJPj4RRHrYvAaa6:uc3XND1aJrCOk6
TLSH F4366B03EEA548F9D296D73588774242B764BC499B3533D32E60BA742F363D0AE79B40
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙