Malicious
Malicious

b589474826533bfd5c5f2ec87e8bc480

PE Executable
MD5: b589474826533bfd5c5f2ec87e8bc480
Size: 7.99 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b589474826533bfd5c5f2ec87e8bc480
Sha1 1485fae94b74763afb18ad2e2265e02ec9aa1992
Sha256 6e0be4286b64a2550897b08ea8ba6a219391e02d1d70c199eaf1f5d08dfc3823
Sha384 d58ad3b550c37d9ae954032a6bcb6752ca1eaff1e5e1da6181b26e7f7ce229d326ea286c2a7d1a117f2aa04033ef88dc
Sha512 55a78f80a3fb66fe2a54c2dc063d694f126d8362051af65d2a21c6e6eb22efa1120f0184e1445c19c7de2e3a52467a484c49511ca64a5071c9145aaa6f6194c0
SSDeep 98304:+yhg0v/sH7wSkSUx3TSQxx4qUYIHHW0YVCQRalESti/g8fz:+yhrXq7kbTxx4hY2jACYal2r
TLSH BB86AE037F8181B0D496EA7AC8B2515177B47C4D833433AB6EA5A9303F263D1B67AF64
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_0d06c188.p7b
Overlay_e5893d6b.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x5BD800 size 8080 bytes
Info
Overlay extracted: Overlay_e5893d6b.bin (1966080 bytes)
[Authenticode]_0d06c188.p7b
Overlay_e5893d6b.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙