Suspicious
Suspect

cffac6c24519fd656a99ddfe63611a27

PE Executable
MD5: cffac6c24519fd656a99ddfe63611a27
Size: 11.81 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cffac6c24519fd656a99ddfe63611a27
Sha1 21a14766846449b8f7b65b2b680b936e87320385
Sha256 ab4394c429efc69b6927a5eb6ecfe7e2cc3df99dd2d279f96729d72a8283e85f
Sha384 53eef5d27453d12afdf73b0e4eb10148dae5247c1055e7955ebe2461d2f7fea5fe5f282e0025f38238d5ad5fbef715f2
Sha512 0c971bf7beee62ca4282e447614818bbed91b9832e816073e4fde929649b8a300fcb662734d900af98561f69f50dba1311a606f5c43a0c9d65c8da4fff4e0750
SSDeep 196608:LJby2bfcDO0vqQjOCeQ/K6l6vaSCE5/i7/s:LlhfmO0ChY/FFzE5/i7/s
TLSH F5C6BE03EC6515E9C1ADD63189639262BB717C885B3123D72B90F2252F77BD0BEBA344
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙