Suspicious
Suspect

f5ba3b8c0b27e16c55dd6bce4c56bb88

PE Executable
MD5: f5ba3b8c0b27e16c55dd6bce4c56bb88
Size: 5 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f5ba3b8c0b27e16c55dd6bce4c56bb88
Sha1 ab86bc9e956654536c6584f4c1298f981c17bf18
Sha256 df69782430b28eb41a95e95bf739f86297019bd806507324064ce4deea6fcaa1
Sha384 489d11301b32e908a99038075649be044a0c324ceea0270a2fa795d83a1734b8df3546ee391ba5f2f25637bc48237c3a
Sha512 894f656449f38b44ce991589dda3253c1de8a187e4c5a7ebda18fd5152fb8eee58388ca3adbeb8f547ecc5ec37b0b4359ee633d20cfd7710e73c1fddffc3a97b
SSDeep 49152:uFKpz7i7FAlc03DCBGcm+a1h6TczyJPj4RRHrYvAaac:uc3XND1aJrCOkc
TLSH B0366A03EEA548F9D296D73588774242B764BC499B3533D32E60BA742F363D0AE79B40
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙