Malicious
Malicious

dab36a1cc0fb50b4de38af12fa182824

PE Executable
MD5: dab36a1cc0fb50b4de38af12fa182824
Size: 11.32 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dab36a1cc0fb50b4de38af12fa182824
Sha1 d1622797f6e738e16edcfdece128a74df0268e34
Sha256 3e9037ffef55f057d814f66f700e550df13371dd109bfcbd729b7d3c76c22405
Sha384 c7d412e6d5f40bb8d81cb454303b76c62e7f5396f0064c422adeddc37afe0947cf1825696fc34e19016b6b07afe93a7d
Sha512 8e25e7039827b116fbe78c9b77bc35c61a3e77474bbfe18dc4cf48b8c8365386249918a09946587c69442efafa239bec4278349b64605e5920d1834ed9409f70
SSDeep 49152:cXj4CPUlt79Tj2AUZdYhnK6VowZyrsKMDKiA356r3fQx+Nc7:cOjaZqnKyEPMm73cr3fjNc7
TLSH 6CB64A03B9A845F0C995AA34C1BF5223EA64FC8CC73977971E40A9702F6ABD177B6344
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_53e1237a.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xAC9400 size 8136 bytes
[Authenticode]_53e1237a.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙