Malicious
Malicious

feb50ef8bd0eaaa534ad0492f2f76c2a

PE Executable
MD5: feb50ef8bd0eaaa534ad0492f2f76c2a
Size: 3.27 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 feb50ef8bd0eaaa534ad0492f2f76c2a
Sha1 274d0d5c321a304b527a4f031a91687ea575b208
Sha256 adface52a197a6390571da0f0b4b9ca53393aa02d1ac4d3fc5f9dcfa419c7329
Sha384 2132e98494ae29b334094d26fdcab4f5e731288bd71dceb10b7bffd6cf7baa18967cf5dcad1c9d2ea50f64c00e0b631e
Sha512 00aaf5eaa5f6904180ff7d69d28b23ff5f401073810111e02de3d60b5b27046e245aebd33a4929bc8883b6579dfcbc799811ef01311dc4dfb1d1b8354d72c9ab
SSDeep 49152:ReapMK0f0mf2TSQ/pxWb5fviN9t9SNbF5yS7XXLng9p8eb1:R8K3UwUryS7X7nepR
TLSH 11E59D477CE145EAC0AA933189BA4291BB35BC194B3263D72E90B7383F767D08D72B54
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_cc7f5faa.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x31D600 size 2408 bytes
[Authenticode]_cc7f5faa.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙