Suspicious
Suspect

cbaa7af0343ed2c7dde10ff62ebefc99

PE Executable
MD5: cbaa7af0343ed2c7dde10ff62ebefc99
Size: 13.99 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cbaa7af0343ed2c7dde10ff62ebefc99
Sha1 b63783d23951aef068d44f61051c7adb57b1cf71
Sha256 efe029e85f522a8de77ddecee6d3241c6f3abf90be43bae8a2adee91d1b3cb73
Sha384 17b4dea1649bb0153109248d88a3206495e576047c94c9141982d83ab36a9e558e2848010df999372da2849ce6e16385
Sha512 cffbdc1425c35c413878271c12a1f55e23fbeaa04b3708456d54d4320e195e78735e5c8b74d4d8855c79ceba41d44ae2092cb491545bf1095d80b546433115eb
SSDeep 98304:+tMF5gQKh8Ebcew6Pn8VXCK6CSrNWPgbo5J6DxesEkXnfYLzQe6gr+kTW7r4I9w:GMoT8E4tcvMgZskXnfYLzQe6gr+Xf+
TLSH 68E65B47E9A501E4C0AED535C6669663BA707C884B3463D77F50F7382F36BD0AAB9B00
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙