Malicious
Malicious

b48ab50ceaedaba80efd3cc165426b4b

PE Executable
MD5: b48ab50ceaedaba80efd3cc165426b4b
Size: 5 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b48ab50ceaedaba80efd3cc165426b4b
Sha1 d17c4120291588085a2bca4a203f4dce3f95de62
Sha256 54620981fdf60ef62541fc467aacf3acdcfbdc9df8de23e2dd0fbe33e3489c96
Sha384 c2bc958f2ebfa686938e91f674cb23a4b2a3391cc0363c0ea544c2b4f90b297ba80848ef0ca879113cde23629f984f2d
Sha512 1fb42294e16627a943766407942121bc1667d51090a26ad4d0a1d272834456d00e2d3cc2b3a2a024351731b0721153b7f0134b5b9c27978e8e3d3a06c8db8ca4
SSDeep 49152:uFKpz7i7FAlc03DCBGcm+a1h6TczyJPj4RRHrYvAaaW:uc3XND1aJrCOkW
TLSH 01366A03EEA548F9D296D73588774242B764BC499B3533D32E60BA742F363D0AE79B40
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙