Malicious
Malicious

d2b6020fff86044a4c3b229a3af9807c

PE Executable
MD5: d2b6020fff86044a4c3b229a3af9807c
Size: 7.03 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d2b6020fff86044a4c3b229a3af9807c
Sha1 0f358366052b1bb3b02a741ceff93d3d85166e54
Sha256 c3b75a86f2ba1e087a983534bc576392ff43d3b1eb309ae2b7f50c7a01a8114d
Sha384 cee14d50f2de9fc609778905676f5ab4a1267781c88ad0895466d737836e099466a56294023e25c63d870ef27b32fc1b
Sha512 8a8015efe40cb78f49eba5e54a1b05931fef1dfcbd333bf5f69665a57713bbeabcd03589e80e01cae0eeceee7cd2468794705fb05c7d521fca2882f0fd17eba2
SSDeep 98304:mq/hpfWK5rYyOeGnNvOlw373E6h9TTSiz:mqJp1BYyOeGQ491z
TLSH EF667B0B3E9081A5E05E963585BB5252AB34BC4C9F7673D32E80B2341F763D47BBAB44
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_57d43382.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x6B3600 size 8112 bytes
[Authenticode]_57d43382.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙