Malicious
Malicious

bb0438616439b60170233a6c41e036fe

PE Executable
MD5: bb0438616439b60170233a6c41e036fe
Size: 6.69 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bb0438616439b60170233a6c41e036fe
Sha1 5adbc92ae75fa92b8e6fa13656a47214927f4477
Sha256 44d642befc8738199f8ce2a97940cbf5fdbfdf3fefd004266b526197d3c4b317
Sha384 38fc8b6d3a78c8c0c9e224210189e7d5c4ed12f4c5710a886666b42e220fff99e79254e3d6d7cf166372ebe4921fe2d0
Sha512 3a28e2cd440e0158277dcbf8baef6591a2fade4f3467227b2689df8f434cdce2eec0fa35b2d085ef9a16729c6539b88a25d79f99ce0b2b072a1278ac2f2bcdab
SSDeep 98304:gtJndFRPOCbDjyoG0qzKaW2wsTRukz3x0:gtlYCPjyoG6aXTEk
TLSH 04665B07AE5441A5C96BA73CC6BB0225A6B8BC4CEF753ADB1E8174307FB67D06976300
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙