Malicious
Malicious

dfea342c0c087d3ea0d0f6e59a618714

PE Executable
MD5: dfea342c0c087d3ea0d0f6e59a618714
Size: 12.51 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dfea342c0c087d3ea0d0f6e59a618714
Sha1 67466cd004abf3c6d65c158f7fcbac83f6c83b69
Sha256 7201e2ca1792e127587564991099a805ff6554bfa17f8b6ff8eed8a4cabf4b96
Sha384 198416fff321e799a933d05fcc283acdfdad66dfacefd7305d73b7619f811c2ba67a6c0eb3df55ad8a5c50c1f5e648c9
Sha512 4a97b77a506a81046727ce3409712bb32ee40bfbbb7020e60587a2e17936673c5f18c1fef8f5e41449d6437fd055916c26c25bdbfe0585cc6506eaab07e2ea74
SSDeep 98304:Lg03Qop48mDuIC0JuXxudkV62oQP1B//6t:Lg1owD9QhuWX//4
TLSH 76C64B03B95804F4C955AA34C0BF5263EA64FC8DCB3977A71E50B9702F6ABD136B6384
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_27d70b23.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xBEB600 size 8136 bytes
[Authenticode]_27d70b23.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙