Suspicious
Suspect

cb3856e810c990828d31ee1a32d285b4

PE Executable
MD5: cb3856e810c990828d31ee1a32d285b4
Size: 12.57 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cb3856e810c990828d31ee1a32d285b4
Sha1 b87d0c7358e671867ca3e715f1b80001aece23d3
Sha256 60d74ab66cb37bdaa5877d21d17fdcfdbf741796fcf38425fb2681250c9cf9f9
Sha384 a98c94a21a2e28011249c7e5813e8af927f7f69f3596edae545d7f2ab03df1dbdb8ccd307c8248dd40ca51b1b6f98826
Sha512 4ad6fb29cffd305c4c168f0c72c8a4abd51bbaa91f9d538e3b3ed20f97b73158468755a8c199503c036cd7cebc3f9336bbca2c4bcb6f382207a05aa092842870
SSDeep 98304:szxwfsG35rWoi7GrtP9LVVPMgoLsE6I4BG20CGE7:SGIJG5P9LQgohRfm7
TLSH 8BC66B11FACB58F1E903583140ABB27F63315D048B38DB9BEB143B6AF87B6A11976705
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPeStubOEP v1.xPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙