Malicious
Malicious

ef77cbff6f7e2157c38d27fea5b927ac

PE Executable
MD5: ef77cbff6f7e2157c38d27fea5b927ac
Size: 12.09 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ef77cbff6f7e2157c38d27fea5b927ac
Sha1 5b84234672c3f2219f8c6c1124cc9e7240eb3b55
Sha256 3d10f5aa66dbf90ab7b1f3736bd9b3f3bf52b4b241a3eb67ba8a0c35d53f2fac
Sha384 1dce1f3f80458950198242843bee5400d3337f3b961ea12bfe208279594478d7a8a726d4b8c6131fa4b13e017dd90fc3
Sha512 cf2ae8bddc75b42ac4940524a4e36074015925223ad1ec6781cb0f77b47c8987186d1e2eabbb893a0fb1b1c289ce9ed9266c0ba2cd17fa588e4aab6ea5f5412e
SSDeep 49152:wJW7mTvJ+qY1qPQQEXG58VyysDQz9IP+FD2hg5RhFCaoHOkUhFe07IHbNMURptXk:wjgqod4cyy33+1HarU7WwVaHN0jfBA
TLSH 91C66B03A96502E5C9AAD778C5F74242777878488B3233E36E10BAB42F757D0BEB6714
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_4a82aa37.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xB86C00 size 8064 bytes
[Authenticode]_4a82aa37.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙