Suspicious
Suspect

cbf4167c8684449858268bf36d2049a3

PE Executable
MD5: cbf4167c8684449858268bf36d2049a3
Size: 4.61 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cbf4167c8684449858268bf36d2049a3
Sha1 fd044a41ba47c934bcfba111b61f1a18ca1b4d78
Sha256 9cc1484aaeefb46feb49edf79bd0c0f2a82eadbe630a7c1937bf7c4b0bd87e35
Sha384 b8e6e62fd95bc53f44957e13eb79b0eddf057dcae81123ab59a4964cc740daa07e06ec9b30b54403acc817bebabb13a0
Sha512 c0d0cf73dc884238f9172cc2a74e7f476c7cb22c3bbd03b0cbb674258fe41c7c321a54e827a4113e2a15a3784ad3fa9a1998c8dd0c1b1885ff9a3cb24edddae7
SSDeep 49152:yoHVmHat/2n9oeLgDkF+9tRoH0NM18wlX2NhAbcsqZTUaP6jc:yGf489+18wlX2/ocsqZP
TLSH D9267B07BEA108F9C1AAE33589AB4212BB74BC4D4B3233D32E50AA782F727D15D75754
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙