Malicious
Malicious

b6291601663c7a8d748b1119985dd3aa

PE Executable
MD5: b6291601663c7a8d748b1119985dd3aa
Size: 12.57 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b6291601663c7a8d748b1119985dd3aa
Sha1 4856b8991ee233bbbb68b87d664f9d89a2a3727f
Sha256 2070e2483590dd3b6ccbe4339d29c095edbbc4cadd6b57dac3ec006ff76c7bbc
Sha384 295f91ed5fbaca63f0379dad6a6311a4e5656cd65a5631f57b520fb9980d6eb5d78d60009cef7458205c67b666beaa24
Sha512 b77836cd9588bd45343d9b99a6e75a2bd247519620aff8d0f2c89205d5b4724e41c7117c47dae9833b76f7b19ced1cc36339f4c73e9c0f78e1359899420c3ff3
SSDeep 98304:sGsqTIVri2C3jGdD4/Lobr4i3HVd7EqO/:hTx3jUDsirTeqO/
TLSH B5C65C11FACB54F6F9036831416BB27F23315D048B28DB9BEB583B6BF877691186A305
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPeStubOEP v1.xPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙