Suspicious
Suspect

01b52c3f023147284c8efe0c7b708b03

PE Executable
MD5: 01b52c3f023147284c8efe0c7b708b03
Size: 10.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 01b52c3f023147284c8efe0c7b708b03
Sha1 6b1616f98baaa7528fa399674ac780498b8bd84e
Sha256 3b1d59c71cf19f0be3f66f4ad7d89e3593bbcd1c461b835f663bce969d07dc53
Sha384 b69dc2402ce2bacdfa0992e656ee78ebb4bee22169f85eedfbf02f0d7ee69aedc90c743e7c3672a936cb75d414d90025
Sha512 bf8687770824074b8b98e1159f1e64fd3c5ebe43770e3cc7579c2ef35939873f06e5e4fe31c37802657b88f15d5c42bc1e63a0c1047cb07220ac9eb77d427f3d
SSDeep 196608:M3AuLfhprcQ1M6yRc/lhiR73n7TH/wjnOAPJ2k:Mwchf1hF+PH/wjnOM2
TLSH 51A69D03EC9555EAC1A9A231C9B29253BB717C495B3263D76B50F3382F77BC06AB8710
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
4
19
32
46
65
78
90
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
4
19
32
46
65
78
90
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙