Malicious
Malicious

b474726d5d410a8edf0e4b9374ac609d

PE Executable
MD5: b474726d5d410a8edf0e4b9374ac609d
Size: 6.59 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b474726d5d410a8edf0e4b9374ac609d
Sha1 edeeae623480d4be1c15b8ddeedcf15bf25a8b71
Sha256 d86cb6fcca1b22095d00707c35c22ca7bb721063d8a38e820b7393f3998062c9
Sha384 c6004203d099398fa5a43eb7e65b86b6a86592e4af4bbff57aae1ae24c909daa3823d918d762f288919b5e8018d4c8d5
Sha512 e2d0d0216e982ef19368a4dc7dbdace74c21838e6a93de2980f748184399221ec6304da6a693cf51aebf0a182689a836b3004cda8206aad765d59098e4de46d2
SSDeep 49152:EHqCx6tkXlWfS9QVCYD7JX3f3Nfz4O3Hq5o8uWCQttttattta87FtK3YYA3AHxXN:EHxWL99b4jFUtKIYlXEIo5TPYvw1+
TLSH FF666B4BADE54864C4A2DA3981769290B434B988CF3037F73F65B9B43F213D067B6B64
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_5837a701.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x648000 size 8056 bytes
[Authenticode]_5837a701.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙